Auvik Warns AI Can Erase Cyberattack Evidence
Techstrong TV Interviews
•
16m
AI Is Changing the Cyber Forensics Challenge
Mike Vizard speaks with Steve Petryschuk, vice president of product and market strategy at Auvik, during Techstrong TV’s Black Hat 2026 coverage. The conversation looks at AI-powered cyberattacks and a troubling new concern for defenders. Attackers may use AI not only to launch attacks, but also to erase or obscure the forensic evidence that proves they were there.
Petryschuk explains that this is a natural extension of the same AI arms race shaping cybersecurity. Defenders are using AI to improve productivity, security operations and response. Attackers are also finding ways to use AI for speed, scale and stealth. That means security teams need to rethink what evidence they collect and how they confirm what changed.
Erased Evidence Still Leaves Signals Behind
The discussion explores what happens when logs and telemetry no longer provide a clean smoking gun. Petryschuk says teams may still be able to find surrounding evidence. Even if an attacker covers tracks, the environment may still show that something changed. The challenge is knowing what normal looked like before the incident.
That makes visibility more important. Security and IT teams need accurate inventories of assets, services, configurations and exposed systems. They also need enough context to compare the current state against a trusted baseline. Without that foundation, AI-powered cyberattacks can become harder to investigate and harder to contain.
The Network Perimeter Remains a Target
Petryschuk also points to threat activity around the network perimeter. Attackers continue to target edge devices and exposed services as a way into organizations. This is not a new tactic, but AI can increase the speed and scale of the activity. It can also make cleanup and evidence review more difficult.
Auvik’s perspective centers on improving visibility across the environment. Petryschuk says teams should understand what is exposed, what services are running and which assets need attention. That includes traditional infrastructure and the growing SaaS landscape. Better documentation gives defenders a clearer view of risk.
Defenders Need to Know What Good Looks Like
Mike and Petryschuk also discuss the speed of modern attacks. As activity moves closer to machine speed, human teams cannot rely only on manual review. They need systems that help them understand previous state, current state and the differences between the two. That comparison is central to detection, investigation and recovery.
For IT and security leaders, the takeaway is clear. AI-powered cyberattacks raise the value of network visibility, asset inventory and reliable telemetry. If attackers try to erase evidence, defenders need other ways to prove what happened. Auvik’s message is that knowing what good looks like may become one of the most important defenses of all.
Up Next in Techstrong TV Interviews
-
Glow Rethinks Endpoint Security for t...
Endpoint Security Faces a New AI Reality
Mike Vizard speaks with Omer Singer, co-founder and CTO of Glow, during Techstrong TV’s Black Hat 2026 coverage. The conversation focuses on endpoint security for AI agents and why traditional endpoint detection and response may not be enough for the next ... -
Mitiga Sees J-Space as New AI Agent T...
AI Models May Need a New Telemetry Layer
Mike Vizard speaks with Ariel Parnes, co-founder and COO of Mitiga, during Techstrong TV’s Black Hat 2026 coverage. The conversation focuses on AI agent telemetry and a research concept from Anthropic known as J-space. Parnes explains that J-space appears ... -
Sauce Labs Warns AI Coding Is Outpaci...
AI Coding Creates a Verification Gap
Mike Vizard speaks with Prince Kohli, CEO of Sauce Labs, about AI software verification and the growing gap between faster code generation and slower testing processes. Kohli says AI coding tools can help teams write code much faster, but verification has not ...