.webp)
Meet Prophet Security at Booth #33
See what happens when agentic AI investigates every alert. Visit us at Booth 33, September 15-16 .

Join Prophet Security during CYBER.SEC.CON at George R. Brown Convention Center, Houston, TX.
Stop by to see how Prophet AI is redefining security operations.

Closed as Developer Activity: Anatomy of a Supply Chain Attack
A single medium-severity EDR alert on a developer laptop. Trusted parent process, nothing matching a known indicator. In most SOCs, it closes as developer activity. The reality was different: It was the Axios npm compromise, a poisoned transitive dependency whose post-install hook deployed self-deleting remote access tooling across Windows, macOS, and Linux.This session follows what happened when an agentic AI analyst picked it up instead: lineage reconstructed to the exact package and version, pivots across endpoint, DNS, cloud, and build telemetry that no playbook anticipated, six hypotheses tested in the time one usually takes, and the hardest call in the incident, the one where SOCs have the most trouble: which cloud credentials were actually reachable, and whether anything used them.
.jpg)
How to detect a web shell, confirm one without guessing, and hunt for the ones that never fired an alert: telemetry, provenance, and the investigation methodology.