Four Critical Threat Profiles MSPs Need to Know!
In this video, Wes and Andrew Morgan delve into the critical topic of threat modeling and discuss the importance of understanding threat profiles, particularly focusing on APT 29 and LockBit. The conversation highlights the significance of third-party risk management, the use of deception in cybersecurity, and the increasing relevance of cloud security. With insights from experts like Dan Garcia, Brian Milbier, and Javier Salinas, the video provides practical advice for MSPs on implementing effective security measures and leveraging threat intelligence.<ul><li>The webinar focused on threat modeling and the creation of threat profiles specifically targeting MSPs.</li><li>The speakers emphasized the importance of understanding threat actors' tactics to better defend against cyber threats.</li><li>There was a discussion on the use of deception and attack emulation as strategies to improve cybersecurity defenses.</li></ul>
Guests
Video Transcript
Welcome everybody to week 70. Wes, Wes week. Crazy. You hear That? That's crazy. Yeah. You know, when you told me you were gonna start this thing weekly, I'm like, man, that's ambitious. I don't know anybody that can do a weekly cadence for something like this and you do it. So hat's off to Andrew Morgan. Well Done, my friend. We're coming up on four 4,000, which, uh, in that have, uh, kind of participated at various shapes and times here. Yeah. You know, we haven't done this in a while.
I'm gonna pop the, the URL, it's just the same one you're on. If you guys will do us a favor, just jump on Twitter or LinkedIn or whatever and be like, Hey, we're live with Cyber Call Pace. That, that guy out there, let's hit 4,000. Nice. So, um, Wes and I decided to fire Gary and Ryan this past weekend, and we hired, uh, Dan Garcia, his deputy, uh, uh, ciso, and Brian Milby, the head of threat operations at Datto.
And then, um, we got rid of Gary and got, uh, Xavier VP of Threat ops at Black Black Point Cyber. So this is a completely, uh, redo now. So what's going on is we obviously have Kase Connect where Gary is, and Ryan, I think has to decompress. Is that a fair statement, Dan? After DattoCon? Yeah. Yeah. Much earned rest in, uh, relaxation at this point. Fair enough. Okay. So, um, and Keith, thanks as always for your kind words. Um, just real quick, I want to put something in chat.
Um, this, um, just came out from the Datto, um, security team. Really, really awesome article. Um, on, uh, adversary on relation. Obviously we've done threat modeling. We started talking about that here on the cyber call, which is kind of the theme for today around threat profiles. One other quick announcement, and this is something that is really cool, you'll notice in the call to action I have hack it, uh, highlighted. That is Huntress upcoming, um, education event.
Um, and few important things about this. Number one I get to give away today, one of their bootcamps, uh, which is sold out, but Andrew Kaiser said, um, he, uh, will let me give one away. So, um, I'll let, uh, let maybe Xavier pick that, uh, uh, at the end based on who asks the best questions or whatever.
And then the other big announcement is Huntress is, uh, signed up to give away you ready 55 0 spots to John Strand's upcoming, uh, training, um, which is the getting started in security and Mitre attack. So you have to register for Hack It. You have to attend hack It, and, um, you have an opportunity. Alright, so enough of the mentions of, uh, stuff, let's get right on into it here. Uh, first off, today, as I mentioned, I'm gonna show this momentarily.
We're doing, uh, a session on threat modeling and specifically four important threat profiles that, uh, Dan, Brian, Ryan, and the team created. Uh, they created them, they released 'em at dacon. They're available either by registering for dacon, uh, Dan, Brian, you want to pop that, if you don't mind, in the registration link in. It's off of that URL too. You can get to it by the one I put in there already.
You can go to their security booth and get these and or I put them all on the Cyber Nation. You can go there as well. Um, so we began discussing threat modeling. Um, and I'm gonna do intros in a second. I just wanna set the stage here. We, wes, you know, we, we started talking about this concept of threat modeling that a lot of MSPs hadn't heard about early this year. We eventually did the threat modeling workshop, ironically, just a few days before the Kaseya July 4th incident.
And the bigger irony is we cho chose the threat actor that actually did the attack, which was Gold Southfield, which is AKA, our evil. Um, and then just lo and behold, they're the ones that struck. So I just thought it was really fitting that, um, we kind of revisit this as we, um, get into, um, uh, what, you know, data and team is, uh, is doing and, and these are becoming more and more relevant to us. So with that, let me start off with some intros.
Let's start off with Dan, if you could tell us a little about yourself, um, and, uh, working with Mr. Weeks. Yeah. Yeah. So, uh, de Garcia, deputy CISO at Datto, uh, kinda do all the things that Ryan can't manage to do in a day, which, uh, he gets through quite a bit. Uh, but, uh, most of my day job surrounds around, uh, managing cyber risk here at Datto, uh, leading our client risk program, third party risk program.
Um, you know, I've worked in financial services, had the, the fortunate pleasure to work with Ryan here for God over it seems like 15 years or so. So we go way back. But, uh, yeah, you know, working at Datto, um, you know, do our best to, to quantify risk and then kind of drive down and mitigate that risk.
And, um, you know, our third party risk program is, uh, is fairly robust at this point, but, um, you know, that took hiring and finding the right people in, in both programs to get to where it is today. So that's the short and sweet for me. Very cool. Dan, welcome. Hey, Brian, tell us a little about yourself. Yeah, so I'm Brian Mill Beer. Um, I joined Datto about six months back, um, the director of threat management.
I'm also building out security architecture and security engineering underneath Ryan. Um, previous to joining Datto, I was at Elastic and I was the, the tech lead for information security there for, for a few years, almost three years. And, um, before that I worked with Dan at MassMutual and Capital and a few other places, some financial institutions. So Very, very cool.
And if, for those of you out there that don't know, elastic is the, uh, we maybe you wanna share the backend for a lot of, of the Sims out there. Fair? Yeah. Pretty much any modern sim uh, if it's not been around for a while, is gonna be based on Elastic for, um, a whole lot of reasons Yeah, we won't cover, uh, but it is awesome. Yep. Very cool. So Xavier, tell us a little about yourself. Hey, my name's Javier Salinas. I'm the VP of threat Ops at, uh, black Point Cyber.
I've, I've been at Black Point since, you know, I was a few of us in a room with a dream, so trying to make the dream come true. I've been there about six years now. Uh, time really flew. Um, previous I was a, uh, networking security nerd. Well, I still am a networking security nerd. I just have to do a little bit more operations these days. Yeah, I get to nerd out at night now if I have the time to do it. But, uh, big, big, big, uh, background in networking. Worked at Tenable for a long time.
Uh, previous to that I was actually in like, um, I worked at Schneider Electric and did a little bit on the like, uh, SCADA side of things, networking, kind of a little bit different type of networking, um, you know, with the BAS systems and HVAC systems for commercial buildings. So it was kind of getting my feet wet and then I figured out, you know, security's the is is where I really like to go and always have been since I was a kid, you know, with my game shark and my PlayStation too.
Uh, always, always liked to hack around things. So, uh, it's a little bit of a background about myself. Thanks. And sorry for butchering. I said Xavier, Javier, sorry about that. Uh, it reads, it reads like Xavier. Yeah. Not the first. Okay. Surprisingly. Can you guys see my screen real quick? Just curious. Yeah, looking good. Yeah. Yep. Okay.
So I'm gonna pull this back off, but I just wanted to share real quick here, what one of these threat profiles look like and the depth in which your team Dan and Brian went through to build these.
Um, this is, uh, a fair amount of work, and I'm gonna let Wes start off the questioning, but, um, you know, uh, you know, we, I I I just re remember vividly, uh, west, I don't know if you remember this, but literally when, um, you know, the, the SolarWinds incident hit and people are like, imagine if that was, you know, one of the rms and Gary said, not imagine if, imagine when, and sure enough, we, we got that wake up call.
So with that, um, Wes, let me, uh, hand the first question off to you and I'll pepper some in with you. Yeah, great. We'll do it. So, um, thanks for joining us, Jen. This is gonna be a, a fun day. Um, I think one of the great things about, um, building threat profiles, we've talked about this a fair amount on the cyber call, um, but we, we have new folks that join us every week. So, um, maybe we'll start here with an off the cuff question. Can you guys talk to us about Dan and, and Brian both?
Can you talk to us a little bit about, um, what, how a threat act, threat profile is used? Um, maybe about how you guys use them, how you ascertain value for them, and then even pivot for me a bit into like how you would recommend an MSP use this, because they may be looking at some of these profiles for the first time and think, what the heck am I supposed to do with this? So, so just open us up into those line of questions for us. Sure. Yeah.
So I, with the threat profiles that we put together, we tried to be a little more complete than you typically see a lot of threat profiles. A lot of big companies that have a dedicated threat intel team, they have other teams that are interpreting those threat profiles. You write and figuring out what to do for, like, what are the risks of your business, what are the defenses you need to put in place? What are detection rules you need to write?
So knowing, knowing, uh, datto's customers, we tried not to put that onus on them and tried to include those things in the threat profile. So instead of just stopping it, Hey, here's a threat actor, here's what they're after, here's the tactics that they use. We tried to add additional features to the profile, talking about like ways to detect them, um, and how to con implement controls that would also help mitigate the risk of the specific threat actor.
Um, and we also selected threat threat actors that were known to target MSPs or, um, or the supply chain of s piece. Yeah, generally internally, um, you know, this is part of the risk process, right? Um, the threat intelligence group creates, uh, a number of profiles. Uh, we actually break down internally, uh, for groups. So we, we, we have general commodity, uh, type, uh, actor method breakdowns. We try to do, um, uh, MSP focused.
But to be, to be honest, that's really hard to peg because it's a multi-industry, uh, problem. Um, then we do, uh, peers of DA software peers, uh, you know, companies in the channel. And then we do our own, you know, targeted intelligence from that. We derive, uh, really what our list of threats, what we call a threat event library, uh, from that threat event library, we start to come up with the risk scenarios we need to be worried about. Uh, ransomware is in the mix.
If, um, uh, you know, if there's, uh, some kind of, uh, criminal, criminal game activity that, uh, we need to be aware of that, uh, you know, we need to look at our controls factually creates this baseline set of scenarios for which then we quantify and do our analysis on. Um, later in the, in the analysis, it actually gets to be a little interesting because it's not enough to say, all right, well, do you have a firewall? How good does that firewall work?
Uh, there's an aspect, uh, something that we're striving towards over the next year is something called control validation. And, and this allows us to take a look at the profile, take a look at the individual tactics being used, um, uh, and, uh, the tools at the end of the day, and how well we are able to detect or prevent them from being, uh, operational in the environment. And then we use that to assess how well we're doing based on that scenario, uh, and then derive a risk from that.
So, uh, you can go pretty crazy, uh, in terms of, uh, trying to map that stuff out, but at its simplest level is what Brian left out. There's some intelligence that comes in, you make sense of that. Does it apply to me, uh, what mitigations exist? And then you do the need both take care of the mitigations and then, uh, you know, kind of start that process over. Got it. And, and I have to think like, this is relatively young and new for the industry, right?
Like, I mean, it seems like a lot of security discussions in the channel for many years have been, you know, what's the best vendor X for solution Y or whatever, you know, and then there's a bunch of subjective fields that go on inside of it, right? Um, and, and we've gone through this journey going through like, what's a framework? How do we map controls to that framework?
And then once we have those things in place, then we can begin some of these things of understanding like what Ryan talks about on cyber call all the time, of like, not just knowing yourself, but knowing your adversary, right? And then knowing your adversary then gives ground to knowing the battlefield as well. And I think sometimes we miss that step of knowing the adversary. And so I love that we're talking about all of this. Um, Javier, maybe a question for you to just jump in a little bit.
You know, how do you approach threat management and, um, you know, do you, do you use threat profiles at all? Or, um, what's your approach to this? Oh, absolutely. Um, uh, I kinda get a little bit of a cheat code because, you know, we're a security software company and we run, you know, lot services on, uh, thousands and thousands and thousands of segregated networks that have risk profiles all over the place.
I think you really hit on a good note, and I probably, Ryan and you guys have pounded this in, like, everyone's looking for that like go-to Security stack, but it's not, it's not that easy. It's, it's more of what, what works for you? You know, are you, what, what vertical are you in? You building management, you're, you know, there's certain things and different threat actors are really, you know, pounding different ones, and it's not really a cut and dry, uh, way to do it.
But yeah, with the threat management, that's, that's kind of the name of the game, right? For us detecting, uh, certain adversaries and what tools they're using.
So, uh, usually, you know, since we have, you know, we're threat hunting constantly all the time, we're seeing odd stuff and we're able to look at it and be like, you know, this is a, uh, you know, uh, after, you know, so and so after re installs cobalt Strike, they like to run this, or, you know, after, you know, Conti, uh, exploits your firewall, they like to do this, you know, we kind of really get this good profile built together in these groups, and then we can build, you know, of course, rules around it and everything.
They like to kind of help out, you know, the, uh, the greater good of all our clients. So I get a little bit of a cheat code being, you know, being in the industry and having so much data, uh, with it all. I don't have to realize so much on Google. But there, there's a lot of good stuff, um, especially, um, you know, a good, a good cheat code and figuring out a lot about, um, what operators are doing these days is reading like DFA reports.
Um, they, they, they will, they will lay out a lot of things that aren't just talking about malware, but talking about, you know, the whole, uh, breach as a, uh, a whole thing. Um, so, you know, it's kind of a little bit of a, a cheat and I, I'm getting some insights on, on some how these operators work. Hey, Wes, can I just ask a quick question here? Yeah, of course.
So to maybe to Brian and, and, and Dan, um, 'cause I remember this vividly, um, the July 4th weekend, and, you know, granted it was not datto's company, but talk about the work that starts to get spun up in a company like yours that says, Hey, wait a minute, they attacked our vertical. They attacked the same LOB line of business application that we offer to our clients. What was it like to go through that adversary emulation for you guys?
'cause you guys looked under the kimona pretty hard, and I'm asking this to you so that maybe we could draw an analogy. Um, and maybe Javier, you can take that, this part of, Hey, if you're client, you're an MSP, and let's just say, you know, e motech just hit a, you know, the threat actor used a mote to hit a bank. You know, you, you wanna be going to your banks and going, Hey, this is a, this vertical is getting hammered right now. Let's look at our defenses.
So Dan, Brian, you want to take that first? I'll let Brian take the front half. Uh, I was on paternity, but uh, certainly had some work to do even even in the beginning of August from that. So, Brian, why don't you kick things off here. Yeah, I know. I mean, it's something, I think you alluded to it earlier, um, Andrew, it's something that was on Ryan's mind too, right? Where it was like, these things have been happening, and he was like, oh, imagine if that's us.
So while we definitely, it gave us, you know, a lot of buy-in from folks to say like, Hey, yeah, this is a threat. This is something that's out there. It's definitely something that we had been talking about and preparing for internally for a while. It wasn't just like, Hey, this thing happened, now we need to react to it.
Um, I think a lot of the stuff that, that Ryan and our, um, application security team touched on at DA Ocon last week really highlighted some of the things that we were doing, trying to get into BS I, um, getting our products bcim certified to show that, you know, it's not just are we doing code reviews, but like looking at our whole security stack top to bottom and making sure we're, we're implementing strong security controls along, you know, at every step of the way.
Um, and one of the threat profiles that we have here, the A PT 29 1, that's one of the ones that, that focuses on that supply chain kind of thing. So we definitely looked at tactics that were used and, and the different attacks. And, and back to what Javier was saying, like those incident response or those D reports are, are great to read through.
'cause you understand how those bad actors came into environments, what they did once they were there, and kind of helps you review what you're doing and make sure that you're covered. Yeah, yeah, I mean, we, we modeled the scenario back in Q1, uh, and, you know, knowing the data that we had available, then we had some, some sense of, uh, threat event frequency, as we call it, the amount of time that you're gonna see the event happen.
We also had an idea of our resistance strength, uh, to the type of attack. And, um, you know, it's just not, can you stop it, but how do you detect it or how do you respond? Which are the other things that people don't necessarily understand, play part in your total risk and total exposure.
Uh, so, um, you know, coming back into the office, uh, my team actually was doing a post-analysis where we actually completely modeled, uh, the attack, uh, you know, tactic for tactic, uh, and then took a look at things that, uh, we had in our backlog that we had yet completed. Uh, and while, uh, we, we stepped through that process, it did allow us to prioritize some, some, some things that, uh, made little more sense, but we didn't necessarily weren't scrambling.
I think one, one thing, if you're reacting, uh, if, if every day is a fire in the office 'cause of some new vulnerability that came in, uh, you're not in a great spot when it comes to your operations. Uh, it should just be, oh, we got another one. All right, well, here's the process. You guys do this, you, you do that, uh, you know, mitigations come out if mitigations come out.
But it shouldn't be something that's like a, a five alarm, uh, every time, you know, new breaches in the headlines, you really need to move beyond that, uh, and, and get to a spot where it's just more of an operational cadence and you're, you're really just doing your due diligence as it's coming through. So, but, uh, x what are you thinking? Yeah, yeah. You really gotta have that assume a breach mentality, you know, nothing's a hundred percent nothing's ever guaranteed.
Um, you know, you gotta really take, you know, uh, and into, you know, like what, what, you know, systems you have, what you're gonna deal with, you know, if this does happen, 'cause likely, you know, it can't happen and it will happen. So, you know, your backups, there's a lot more into it than just detection. Like, uh, Dan said, you know, there, there's a response side of it and response as in like, how do I get back up? How fast can I get back up?
How, you know, how much time can this customer afford? And then you can build your, you know, your, your, your, uh, thought process and, and your, and your frameworks around, uh, that, and like you said, it, you know, vulnerability, man, that's the huge one, I would say. I mean, daily, almost hourly. You know, WW we have clients getting hit with common vulnerabilities, whether it's the FortiGate one, whether it's the exchange one, whether it's the other exchange one, uh, it, it's constant.
So, you know, um, I, I think that's really under, um, under thought about part of a MSP security stack is vulnerability management, because it can seem intimidating. I get it. But, you know, um, it's really something that you want to get down and, and kind of get into, into the cycle and into your things because it's, it's not that hard once you kinda get the cadence down, just like Dan said. So, Wes, I'm gonna, I'm gonna hand it back over to you, but maybe I could do it this way.
Ed El Gado asked a really great question, uh, in, in, in the question section about, Hey, so what about cloud? Um, you know, kind of asking you, Wes, and maybe hit it over to the team. Is it Cloud Security Alliance? Is it oasp? Like, what, what resources, um, and, you know, what do you guys think about when it comes to that? So I would, um, yeah, go check out the q and A for the audience listening, if you want to kind of clue in what we're talking about here.
So, ed, I would even take that one step further and say, um, I wouldn't EI wouldn't even think we're closer and closer to defending cloud environments. I think we're already there. Um, and there's a lot of reasons I would point to that. One is all of the cloud providers, all of them that are reputable, have a shared responsibility model. Uh, and what that's saying, clear clearly from them is, here are the things you're responsible for.
And turns out there's quite a bit that we are responsible for. It's nice for me not have to worry about a fire in the server room anymore. It's nice for me to know that they're gonna rack things up correctly into the right IDFs, et cetera, et cetera.
But, um, from a data security perspective, a process flow perspective, the applications that run on top and all the things that, you know, are, uh, from, as Javier, as you just mentioned, from a vulnerability management perspective, all of these things are clearly in front of it for us. Um, and so why don't we expand that question a bit from Ed, 'cause it's a really good one, and I'll turn it over to Dan and Brian first. Um, what do you think about cloud environments?
And we're starting to see some of that being rolled into, um, how threat actors operate. Um, you know, clearly in the channel, you know, the, the RMM is still the target of choice, um, but you know, RMMs are now hosted and, uh, there's certainly a lot of data that's present and valuable inside of, um, office 365, Google Apps, AWS, et cetera. So, riff on that for us a bit on how you guys are thinking about that.
And, um, if, if you're seeing threat actors begin to target some of this, just give us some, some, some thoughts here. Yeah, there, there's kind of two, uh, two immediate things that jump to mind. One, uh, the cloud has standardized a lot of the IT operations and orchestration in a way that's actually just easier to defend and manage.
Uh, even built into most of the cloud platforms, there's checklist and things that you can run and, and free tools to really, uh, at least have your attack surface be minimized. The other thing is you can run anything you want on it. So it doesn't necessarily solve all those problems that you get from application, uh, you know, depending upon if your ias up paths up, or, uh, even if you're doing functions as a service, right?
Everything above that line, you still have a responsibility for, which means you can still screw up in some way and introduce some vulnerability. Uh, so, uh, it's, it's kind of both worlds, but, uh, your position is better because you, Amazon's gonna charge you for everything, so at least you're gonna know that you have those assets somewhere running. Uh, I think in general, uh, the open source community has been really good too to the cloud services.
Uh, and when we think of everything outside of SaaS, right, like you can probably head up GitHub, you can probably find very quickly, uh, a number of signatures that you can run that will help you assess whether, uh, uh, you know, your postures in a poor spot when it comes to, say, Azure or AWS On the SaaS side, uh, it's even more simplistic, right? I mean, there's, there's APIs most for most of the major platforms. Um, again, there's, uh, crowdsource rules.
You can find that that can kind of make sense of some of the, uh, alerting that kind of comes out of the, the platforms. But, uh, platforms like Microsoft 365 have done a good job. The only, the only thing that Microsoft has a problem with is getting in the way of Microsoft itself, right? And, um, tons of consoles and things. And that's where tools for MSPs actually start to normalize that and, and, and make it easier.
So I think on the tooling side, we're getting there and, uh, you know, some folks on the call here have some great solutions that help, uh, satisfy the gaps and including data at this point. So, Yep. Yeah, it's good. Brian, anything you wanna add to that? Yeah, I know, I mean, I know you mentioned the Cloud Security Alliance. I think they're great for giving those guidelines.
Um, I know that was when I was at Elastic, that was definitely something that we, we, we were a member of the Cloud Security Alliance. I was on quite a few of the different groups where we talked about new controls and how to measure controls, and, and as Dan mentioned with the APIs, a lot of these large SaaS providers, whether it's Datto or Elastic or whoever, it gives you that insight into how you're configured. That's a lot harder to get if you're running things on-prem.
Um, so a lot of that tooling that lets you measure things and say like, is this encrypted? Is this properly controlled from an access perspective? Like, those things you can ask through API and, and, um, like Dan said, there's a lot of open source solutions out there that that'll tell you, you know, that things are in good order. Yeah. Got it. And, um, Javier, you know, one part of the question from Ed that, uh, we haven't touched on much is the automation piece, right?
So we've talked about this on the cyber call before, whether it's like API automation, and you know, we have data flow between two different, uh, platforms. Um, understanding what the implications are in those APIs, that's a critical piece. Um, I think we're also starting to realize from a defensive countermeasure perspective, we lack the automation tools ourselves, um, to make life easier to reduce attack surface footprint, um, to reduce the cost of human error.
We have all of these challenges in automation in the cloud as well to address. What do you think about all that? Any, any thoughts? Yeah. Uh, you secur securing clouds, it's not, it's not an easy thing. Um, you know, mainly it kind of boils down to, you know, coming from, you know, a software security company. You know, uh, developers aren't security pros. Um, so you can't really push that down onto them. So they need the oversight and the, the oversight, you know, comes in.
There's a lot of open source tooling and, and automation. And, um, one of the best things that I've seen implemented was, uh, automation. Like, um, that runs over all your repositories that looks for, um, secret like secrets items in there, like SSH keys, API tokens and stuff. And, and, and being a cost, it's a, it's like a bot that's automatically, constantly, will, will search through all your repos for these secrets.
Uh, that's, that's the type of automation I think's super powerful because a lot of these, a lot of these things come from that kind of stuff. You know, the developer, you can't give a developer sometimes don't, might not know what they're doing, or you get an intern and, you know, some developer gives them an API key that has too much access, you know, you know, it happens, it's fine. The good thing is just being proactive about it.
Um, because, you know, you don't want to be reactive once that EPI key gets out there, or if someone steals your repos and finds all your secrets inside your repos, you know, um, you gotta treat those things as almost being open source, even though they're closed source, you know, someone could get access to these repos, um, and look at those things. So that's the type of automation I think is really important.
Um, you know, software security side, uh, and also comes down to, like Brian was talking about, just, you know, keeping a constant audit on, on your cloud surface. Um, you know, it only takes one, it only takes one accidental click to open up RDP or open up SSH with, you know, a, a weak key. Um, you know, and you, you know, we, you know, we run in AWS there's 700 and something security policies.
They're all over the place, you know, uh, and I think another tip too, I'll have, if I don't wanna talk too much on this, is making sure that you, you're treating like your infrastructure as code, um, and, and, and the most, and not really having any manual way into it. Like, you know, having code, the, like, you know, Terraform and Ansible and all these other things, you know, making sure they're the only ways things that can be deployed and kind of take that power back.
And it makes everyone happier. The developers think they're cool, security thinks it's awesome because it's codified, um, and you don't get any surprises. Uh, so that's, that's another tip. Yeah.
The, the, the thing from a risk perspective that I like most about, um, and I, we get to see the different products at Datto who have come through acquisition and others that have different methodologies that they use, and some of the, um, some of the groups that use infrastructure as code, uh, you actually get quicker remediation times.
And if you think about it, if you're orchestrating your work and you're making changes through, through code, it's very easy to make adjustments, uh, in, in that code and push it out. Uh, where if you think of a standard build, config, manage type, uh, lifecycle, uh, oh, I gotta test this, I'm not quite sure how this is gonna work. Uh, you know, things can be changed quite quickly as infrastructure is code.
So you get to be a little more nimble, and the tech debt that you do have, um, actually gets to be managed a lot more easily. Uh, so it's kind of a side benefit that is often missed. So, um, for the audience today, I'm gonna share something I thought was pretty interesting. Uh, so Joe Penn and Terry had an article that he produced a couple weeks ago. I actually spoke with him about it. I thought it was really intriguing.
I'm gonna pop it here into the chat, um, about the future of where like the channel is going and needs to go.
And a lot of it is in this idea of RPA, it's this idea of, um, you know, it, Javier, a lot of what you just said a minute ago of human error, reducing the costs and the, um, the footprints of human error, like we mentioned before, whether it's your, you know, regular users that click on something, open something, visit something, do something that's out of band that takes a while for us, we may have, we may have shortened the detection gap. We still lack a response.
Um, whether it's just remote like, or it's, it's routine it work of like provisioning and deprovisioning. Like, we have these gaps that really do lead to challenges that we have in today's environment.
So, um, I don't know that I have any direct commentary other than I would encourage you guys in the audience to check that article out and just know that wins of change are coming and new things are happening, um, because we're starting to see, as we mature in security, um, we sort of increase in, and I wish Gary was here, but we're increasing in costs of what we talked about last week, the reactive, um, hours per endpoint management. I love that, that, uh, metric.
So, um, check that article out. I think there's a lot there. Um, Dan, maybe a question for you, and this is, this goes directly into what we were just talking about from Steven as well in the chat, is, you know, we spend a lot of time talking about traditional security, but what are devs like, and, and maybe if you wanna explore a little bit what DevSecOps is and, um, maybe resources that you guys use to make sure that security is of priority among your devs. Yeah.
You know, uh, it's, it's interesting, and I think we touched upon it earlier in the call where, uh, folks outta college, they didn't necessarily have, uh, depending on where the program and what the focus on the program, security is kind of an afterthought. Um, uh, and what's interesting, um, data with our, our BM initiative, it kind of brings focus a number of things, but one, um, are, are the debs aware of the tools that they have available? And we look at their pipeline process.
Um, well, I guess the first step, understanding the threat landscape, and we have these wonderful threat profiles, but there are are other forms of intelligence that these teams need to get and receive. And, and, and some of that comes in the form of direct vulnerabilities, pen tests, things that are found after the fact.
But there's also some preventative, um, intelligence that allows them to make smarter decisions on how they're gonna approach their solutions, uh, assuming they have a sense of what they need to do. Uh, it's understanding the tools that they have to, to use, and that's where, uh, design level application security patents come into play.
And these are, um, ways of doing things within the application that are reusable, uh, that, uh, are secure in nature, that have been blessed that, that way you're not recreating the wheel every time, like a, you know, a IDP to s, you know, IDP to service provider kind of, uh, workflow. And, and that pattern from an authentication standpoint is just an example. Um, from that, you know, you're making these changes and, uh, there should be some review process.
And depending upon what's changed and the criticality of the underlying component, uh, you need to make sure that it's secure. And there are workflows that kind of kick up for security architecture to take a look, understand the component change was, and, uh, just you, you need someone with a deeper security eyes just kind of doing a peer review.
It's not to say that that person's creating or engineering the solution for you, it's just, Hey, uh, I want you sanity check on this new, new piece of code. And then pushing that beyond, uh, goes into your static analysis, your dynamic analysis test suites, uh, that kick back to the developer kind of rinse and repeat until you're able to do some, uh, QA and out out the door, right?
So, uh, dev SecOps is bringing in and, and pushing that work sooner so that it's not deployed and running on a server, uh, but earlier in that development process, and then making sure the appropriate touchpoint securities baked in, um, in past life as a collaboration architect. And one of the things you learn is, uh, people, people and user experience especially, um, they don't wanna go outside their normal workflows.
So a lot of security tools are actually built into their workflow, so they don't even feel it's like frictionless at the end of the day, and the least amount of friction you can apply to a developer's, uh, development lifecycle, but still make sure you have a secure outcome. That's what secure, you know, that's like, what a winning picture for me at the end of the day. That, that's good stuff. Um, and, and I love seeing that culture change.
You know, sometimes I get frustrated when I hear, oh, DevSecOps, if I hear that one more time, it's just a buzzword. But there really is a mantra and a philosophy and a, um, a way of doing things. And I love a lot of what you said there, Dan, especially around reducing friction, giving them the tools that they need, embedding those processes and culture into your secure design process. That's really good. Um, Andrew, you wanna talk about the poll you just popped up?
Yeah, if I can take myself off mute. Yeah. Just real quick, I put, I put a poll in there just to get a sense, um, you know, are you guys looking at pro threat poll profiles? Have you, um, you know, considered, you know, who attacks not only yourself, but your customers, especially if you're in, you know, high targeted verticals.
Um, obviously banking, being one, healthcare, um, you know, we talked a little bit about that most recently on the cyber call as well with Conti and their focus, um, on, on healthcare. So yeah, if you could just let us know, that'd be awesome. How's that? Yeah. And, and I'm surprised to see some of the yeses. So here's my challenge to you yeses. Will you pop us in to the comments, um, like how you're using it or give us some feedback of why you're a yes?
Because Andrew, I had to guess that we were like 90% nos and we're almost 50 50 on yes and nos. So that really shocks me. I'd, I'd be curious if someone wants to chat about, or even wants to join the call and talk about it a little bit, I'd, I'd be interested to know. Um, so give us some feedback while we're waiting. Let's jump back into one of the threat profiles for a minute. Brian, I'm gonna queue you up for a question. So let's start with a PT 29. Yep.
Let's talk about, um, what's important for MSPs to know about with them. We know they're state sponsored, so, so information is of, of high value to them, but, um, is there, talk to us about the supply chain, um, considerations inside of all that, why you guys picked a PT 29. Give us some feedback here. Sure. Yeah. So a PT 29, we, I touched on it a little bit earlier.
One of the main reasons we picked it is 'cause it's known to, um, like we knew the whole solar, um, the solar storm or whatever the act, whatever they called it in the media, right? There was the Sunburst, I think sunburst. There you go. Yeah. So there was that whole, that whole thing, and it really was focused on MSPs, a lot of it. And, and we felt like it was relevant to Datto and, and, um, and our security posture.
So we were looking at it internally and we thought it would be great to expose that, that out to our customers so they would understand, Hey, here's an actor that's out there that's targeting your customers primarily, right? And how what controls are, are, are available to help defend against it. Last question, if I could follow up.
What was interesting is, um, just maybe rhetorically to the, to everybody out there, but Dan, Brian, you know, did anybody ask you guys about, Hey, does data run SolarWinds? 'cause this is where the third, you mentioned earlier about third party, right? Dan, about, and, and, and, uh, ax, I'd love your thoughts on this too, like, did any MSPs go, Hey, by the way, do you guys run Orion internally? So go ahead, Dan. Yeah.
So, uh, you know, when the SolarWinds and then, uh, I think Solar Gate in, in January kind of kicked off, and both of those events within a few days of the news breaking, we had RFIs out to every one of our tier one critical vendors, which a data we tier our vendors in the buckets most restrictive or most sensitive access data. You know, you're in our tier one bucket all the way down. Uh, so, uh, we, we mass email out to all, all the folks that, that have 'em answer a quick questionnaire.
Uh, we got some surprising results and some, uh, not so surprising results, uh, from our, our, uh, customers. What was most surprising is not one MSP reached out to us and asked if we were impacted, uh, which scared the hell out of us. Uh, we actually have a blog post that we created, uh, in response to that, in which, uh, third party risk, I'll try to pull it up. Um, Jaime, my team kind of created in just a way of breaking down third party risk as an MSP, uh, some basic easy tips.
Uh, but yeah, not, not one MSP unfortunately reached out to us. Uh, it's something we preach. We wanna make sure that, uh, they understand. Uh, we, we sat down with five six MSPs when we did a case study two summers ago. And, um, we asked in their meetings, we're going through nif, CFF, uh, CSF, and asked, well, hey, third party risk. Do you do any, any, any questionnaires like, well, what are we gonna do? We're just a, a small shop in so and so, and like, you're ghetto.
No one's gonna listen to us. And we're like, like, you absolutely need to be grilling your vendors, especially your critical vendors. It doesn't matter who they are. Uh, so, uh, yeah, I'll send the, I'll share the link in a moment here, but, um, you know, they're very much a surprising, uh, uh, non, uh, ask from partners when it came to those two events. Xavier, I don't know if you had a different experience. No, I think the poll is, uh, two nos on that.
We didn't get asked once, Uh, if we were Running Orion or Solar Ones. I, I agree. Um, I, we, I'd have to go back and look among MSPs to see who a, if any, asked us that at Perch. Uh, but I will tell you, we had enterprise, some enterprise ask us, and I think you we're all kind of identifying a gap here is like, what does that third party risk management look like? Even if you assume it's a no, it's a still a wise thing to say a yes.
And, um, I realize that enterprise, and I think all of us come from some larger enterprise that are on this call today. So we all kind of know the mechanisms that are in place, and some of them have quite large, like, I have third party risk management teams and this is what they do. Um, but it's a gap and it's a challenge and it is something you have to keep an eye on, um, and keep your own vendors to the, to the, um, to, to hold them to the fire a little bit, right?
I think it goes back to that know your battlefield thing we touched on earlier, right? Like, your vendors are part of your battlefield. So like, you need to have a strong understanding of who's providing critical services to you and, and watching the news. And as important as it is for you to know how all these things and these different threats impact you, it's equally important to understand how they impact your critical vendors. Absolutely. Good stuff.
Okay, so let's peel out some more from a PT 29. Um, anything else you wanna add, Dan? No, no. Brian, uh, if you wanna continue rolling through the, the readout, uh, Yeah, I mean, I think, I think we touched on most of the important stuff and why we had highlighted it, right? It's all about third party, third party management, understanding your, uh, your supply chain and, and where the, uh, where your critical vendors are.
And, and we as Datto consider ourselves a critical vendor to, to our MSPs, which is why we, we came out with the, with the profile, a lot of the tactics, um, that they use, you know, as an a PT, there's not a lot known about what they're doing. 'cause their whole goal is to stay low and slow and, and remain undetected, and they don't really want to give away what they're doing, where, you know, other, other threat actors like organized crime. It's more of a smash and grab kind of thing, right?
Where you're, you know, they're not really trying to hide what they're doing, they're just looking to make a quick buck. So, you know, we filled this in with as much information as we could, could find that was available. But, you know, anytime you see a PT in the name, uh, that intelligence is usually pretty few and far between as far as the details of the techniques they're using. Wes, i, I, you know, Brian, uh, the, i i, I just again, encourage everybody to read these.
It, it reads like a, a a like a really cool, like I know it's factual, but it's like you, the way you guys put it together reads like this, you know, incredible like novel and, and, and mystery. You know, like their way they, uh, hide their beaconing or the intermittent of their beacon. It's really fascinating, unfortunately fascinating how they do things.
Um, Wes, uh, as you move into lock bit, I don't know, you came on, uh, Javi Javier was saying, so maybe you just to, to get to him on this too, that something they just literally saw and, uh, left all their tooling behind as well. So just, just wanted you to keep that in mind, Wes, as you, as you go through lock bit. Yeah. Okay, cool. Yeah, Javier, make sure you queue me up on that.
Um, one other thing I'll, I'll call out too on the threat profiles that I think you guys need to look at in the audience is the detection opportunities or solid gold. Um, and they give you actual finite things to look for and conversations to have and questions to ask both your own internal teams and those that provide your security services. I'll give you an example.
Just looking again at a PT um, 29, um, detection opportunity too is here, if you guys don't have it, it's, it's uh, the on Mitre attack. It's signed, uh, binary proxy execution from like run DLL 32. For example. You should go ask your endpoint, your edr, you should go ask your, um, sim um, you guys give us visibility in those things. Can we see this happening? Is anyone reviewing this? Do we have a process to handle when we have an alert with one of these that come through?
And do we have the education and knowledge to be able to handle that accurately? Like Dan, that's a good thing to have in place, Javier, wouldn't you agree? Like these are things that we can go through these detection opportunities and use these defensively in our own organization, right? Right. Even at the Casea attack, they're using a Microsoft defender to side load, to malicious DLO. Um, yeah, yeah. Being able to answer those questions, you know, uh, of those things. Absolutely. Yeah. Yeah.
Cool. So let's jump into, um, lock bit. Uh, Brian, take us through Lock Bit Town. Yeah, sure. So lock bit we selected specifically.
'cause after, after this stuff that happened over the summer, a lot of the, uh, the reval stuff started to, you know, they, they were taken down initially and there was a, there was a power vacuum and we saw, um, more and we saw more lock bit and that's why we, we looked at the, uh, the two threat profiles we picked here for Wizard Spider and Lock Bit to try to get more visibility out there.
Lock Bit was one where when we looked on the Mitre attack framework, there was nothing published out there. So we went through and tried to map the tactics and, and give more visibility into, um, into this attacker. 'cause it's definitely becoming more, more prevalent. Brian, Brian, were you guys surprised about that because that it wasn't in Mitre attack?
A I, I mean, I remember also hearing an interview with John Hammond over at Huntress, um, saying he was highly concerned about Lock bit with that, that that void of, um, you know, post Casea. So I mean, I think, I think with, with uh, MITRE, you know, a lot of that stuff comes from the community. So like we took this information that we collected and we submitted it, so we're working with Mitre to try to get that published.
But a lot of this stuff, it's just having, you know, folks having the time to put the information together and, and get it over to the Mitre team, so, you know, so everyone can take advantage of it. Yeah. And, and I think that's just it right there.
I know some folks from Mitre in, while they're fully responsible and capable of keeping an attack up to date and fresh and understanding what new tactics need to be aligned and understood, it's a plethora of work that I think we vendors need to help out with in terms of producing back to them data that you, we can say, we've analyzed this and, and here it is free for the community to use.
And I know that's partially the goal of what you guys are doing, Brian, with that, but, um, yeah, I think that's really wise and, and that doesn't shock me that Mitre is, you know, overwhelmed and certainly doesn't have the time to get into these things. So we, we can help with this. Yeah, Super. They're really easy to work with too, to get, to get this information out there.
So like, it was, it was a piece of cake to, to get information to them and now we're just reviewing and working through the details before we publish, before they, uh, they publish it in. And these ransomware as a service ones too, are tricky because like, you know, they've got threat actors and they've got ransomware and they kind of land in between, right?
So like figuring out, do you put 'em in the threat actor group or do you put 'em in the, in the ransomware family group is is a little tricky too with some of these foot locked it right Saying, saying Mitre is, uh, pragmatic is probably an understated comment.
So, uh, you know, their canonical model isn't quite aligned to, uh, to, you know, the ransomware as a service model, which is, uh, unfortunate because there's a lot of good intelligence that should be shared that, uh, just doesn't have a home in their model right now, so. Right. Yeah, that's for sure. Yeah, like in the case of Lock Pick too, uh, going back on onto them, you know, um, we kind of saw that the, the Conti uh, operators, their tool set got leaked not that long ago.
And that's always been the biggest interest to, uh, me and, and our, and our sock at Black Point is, uh, because that's the best, that's the best time you have to catch these ransomware operators is when they're in and then they put their tool sets down and they're trying to spread their access, that's they're gonna get in no matter what. You know, you can really count that out, you know, they're gonna, they're gonna bypass the, they're gonna get in, you know, what can you do after that?
So that's where I've always had the biggest, like going back to threat management and, and threat profiles. It's always been the biggest interest to me is what do these operators do once they get in? And it's kind of interesting that you brought up a threat profile for Lock Bid because we just, we just stopped one over the weekend. Uh, a lock bid operator, we able to isolate him off the device before you can remove his tools. So we were able to see exactly the tools that he had on there.
So I can give you a little sneak peek into, um, what they, what they do down to the actual tools that they're using. Uh, I'll map it to the MI framework too. I have it written down here. So for initial access, of course they like to use exploits and open RDP. Uh, a lot of this stuff comes from info stealers. So info stealers will steal information off your computer. Someone will go out and sell it, they lock Pitt will go buy it.
Um, that's always, that's, that's pretty much a lot of the ransomware mos. So once they get in, like I said, they're gonna get in their persistence for this case. And what we've seen before with Lock Pitt two has always been any desk and achi there two programs. Achi can create like a fake VPN right into the network onto that device. Uh, then any desk is kinda like TeamViewer, uh, that was the, that's their two persistence methods they love to use. And what they just used, uh, in the last one.
And then they have big, and this is where they get caught. The, they're, they're, they get into defense evasion and discovery. This is where they get caught 'cause they like to dump down. This operator dumped down every tool, even the generated ransomware all at once. So it wasn't the best idea to do that. It wasn't going low and slow. You dumbed down every tool and try to install everything he could because he was having trouble with the av. Um, so what they run is they run slow.
So to bypass av they like to run things like Process Hacker and PC Hunter because it comes with a signed kernel driver that lets you operate kernel level and to disable, uh, kernel level drivers like your av. So they'll use ones and, and in this case they will, I try to use one called Yar, um, which is one I don't think I've really ever heard of. Uh, it was a Chinese operator, it was a Chinese one like in GitHub. And a lot of these tools revolved around Chinese tools that use.
So I thought that was kind of interesting. And they used another one called PC Hunter, which is another one to same thing. Uh, they also installed your uninstaller. I was like, why did I, I, we couldn't figure out why they installed your uninstaller, why Oh, UR Uninstaller, no idea why they installed that. Maybe they're really having trouble. Maybe they thought maybe if I just like uninstall Davy, that I'll get by.
And they masked a lot of this stuff, uh, as OneDrive executable names like OneDrive setup, XE OneDrive, xe. Uh, so it shows you, they kind of mask 'em a lot. They named, they named, uh, pc hundred four XE and Lucy Root xe. They name 'em weird names because they don't get 'em like that. But you know, it's, that's, it's a little novelty. And then they used a classic, uh, it's a scanner for the network called NSV two Scanner.
And what they do with that, it's a, it's a tool that Chinese apps like to use a lot. It scans for hidden shares and shared activity. So they're trying to find all your shares so they can exfil your data, uh, with a tool called arone. That's the one that they had on there too. Uh, it was arone. It's very common. They'll use arone. They'll sync it to Mega Sync, they'll sync it up to sometimes private SFTPs. Um, so it kind of goes around that, that, that the tools that they're using.
And it kind of shows here that these are all off the shelf tools. None of these is magic here. Like one of these is a third party tool. It's all except for Y Dark, which I've never heard of, which now I have, um, those ones that I've seen and heard of before, um, used to, you know, their, their M mo really is to, you know, get in, turn off the av, uh, find all your shares, xFi your data, and then deploy ransomware.
That's really how that's, that's the timeline almost on every single one of these. So I thought it was very interesting that you guys had a lock bit one, and then we just stopped a Lock pick operator and got all his tool sets. Um, so now we can do that, that type of thing. And it kinda shows too, like a lot of these, a lot of these tools will come in. Here's a tip for the MSPs.
Um, a lot of avs will, will say that these are suspicious, uh, or pua potentially unwanted applications or suspicious tools, and they call 'em hack tools. Um, and it might not seem like it's a big idea. Sometimes they come in as like low warning ones. But I really highly suggest everyone to really look at these. 'cause we find a lot of detections off of these.
Um, 'cause they're, you know, technically are hack tools and their tools use are operators, but it might not seem like they're bad from the AV alert. So if anyone's out there is getting hack tool alerts really look deep. Um, because those are gonna be the ones, and if anyone out there is using these tools like any desk and achi and all, I doubt anyone's using your run installer and, and White Ark or KPort Scanner.
But, um, you know, I, I would move away from them to different tools and then, you know, set up your awareness for these tools because these are the tools the operators are really getting into. Um, if you can, so you can be aware that, you know, a lot of these are common ones. So I thought that was very interesting. You know, uh, kind of relevant information that we caught from a, a locked bit operator. Don't always catch 'em in the, in the act all the time.
Usually we catch 'em before they do anything. Usually we catch 'em when they put down Cobalt strike and then they leave for a while. That's usually our 90% detection on, on those ones. It's not often that, uh, you know, they, we'll get 'em after they put their tools down, um, which is probably a good thing. I'm unfortunate for my threat ops, but good for good for our customers. Um, Question for you.
When, when you guys come across, uh, these ransomware as a service, they have a set package, they're dropping, but the tools that they use and methods that to breach into environments are different.
You find that, uh, you know, whether they're locked bed operators or going back over time, you know, Regal or any of the others are, are there certain shared tools that they use or is it really the individual criminal, uh, gangs that are, are behind each of the, the campaigns all have their own ways and, uh, of going about way, uh, you know, the actual initial access and, and the lateral movement?
Like how much variation across the individual, uh, affiliates is the word I was looking for, uh, that, you know, do you see a lot of variation? That's a good question. Uh, I don't see a lot of variation based around, um, network scanners. They like to use soft perfect network scanner. I would say 80% of the groups like to use soft perfect network scanner, uh, or advanced port scan or advanced scanner. These are very common ones that we see with these operators that they like to use.
Some of 'em are unique. Um, we actually had one the other day. I, I couldn't attribute it 'cause it was a little early, but it was a Cobalt strike Shell code written in Golang. It took me a minute to reverse Golans not the easiest thing in the world to reverse. I found out that kinda actually goes back to APT 29. I think one of their backdoors is some burst ones or no Beum or something. What was written in Golan. Yeah. Um, it's a tricky one.
It was, it had a zero detection rate because it's just not s have a little bit of trouble with the way go compile. It's, it's, it's kind of nerdy run times and all that, but, um, it's not fun to reverse either. Um, so yeah, we, we, we got one at that. I thought that was very interesting. I've never seen that before. Usually, um, you know, it doesn't happen like that a lot, but a lot of 'em use Cobalt Strike as their initial act. I would say a majority of 'em.
So there's a big shared tool set, but you know that that's not as hard, easy to fingerprint sometimes as the other tools ar clone, it's probably the most common one they exfil data with. Um, I would definitely, definitely keep an eye on any arone activity going on in your network. Um, and then any desk for persistence, though, I think, I think that software network scanners, advanced network scanner, our clone and any desk are very, very common across multiple, multiple, uh, operators.
One of the interesting things too, we saw in lock bit was, um, as we were researching through to write the profile up, they were one of the only ones we came across where they're known to use insiders for their initial access. So they're known to like target insiders, try to grab a CIS admin, someone that wants some extra cash and either have credentials created or provide credentials or open doors.
Um, but there was lots of stories around insiders granting access, the initial access for Lock It. Wow, interesting. Really interesting. Uh, hey Ax, I have a, I have a question. Um, mm-Hmm. Knowing what you just laid out, um, let's just take, you know, looking for shares. I mean, do you guys do any type of recommended deception for your clients? Um, um, or It's not deception? Yeah. Yeah. It's, yeah, we don't do it. Not, not, not huge in deception, um, uh, the players and all that.
Um, it's an interesting field, I think. I think it's a, I think it's a field that's yet to be utilized correctly, and maybe that's a better way to put it. Uh, I think it has a lot of value. It just needs to be tapped into a little bit better than, um, some of the current ones. Um, I have, yeah, There's a few, there's a few niche players that do some pretty cool stuff, but overall, right, a lot of it's just like stuff you could do yourself. Yeah. I see.
I saw one person that, not to digress too much, but I saw one company one time, they launched a, they launched a bunch of debugger sounding executables. So malware thinks that a bugger's running and that goes away. I was like, okay, well I guess that works. But it was a little, little, little, uh, weird, but it works. But that was, Yeah, there's, there's a couple of flavors, right?
There's like the evasion techniques, Uh, and there's a GitHub, uh, project skeleton is in the name, but, uh, you can, you can Google that and that, that prevents malware from executing thinking it's in a sandbox. Uh, but there's also the other where, you know, it's a vulnerable service that's set up that just is like, please inviting, please hack me. Right? The problem with that model is it's gotta be one of the more interesting thing on your network.
So if you haven't gone through and baseline your environment and, and kind of have a good vulnerability management, it's gonna be just another tree in the forest, right? It's gonna be really hard, uh, for it to look attractive and then for it to serve its purpose. Yeah. So, uh, it's, it Is, You know, um, it's Interesting that you mentioned that too. Oh, sorry. Oh, go ahead boys. Oh, I was about to say that we, uh, uh, I have, we have multiple, multiple sandboxes running out there.
'cause what we do is we catch something, we like to detonate it in the sandbox, but making it look like a real live network is hard. We see a lot of times that they'll patch our, they'll call our bluff. They'll, they'll look for like how many computers are in the computers, OU and active directory and things like that. And they'll bounce out if it's really low. Um, so yeah, it's really hard to do.
Uh, it's the point you mention that, but I have gathered, I've, I've tricked many of 'em together, their tool sets, uh, that way. But, uh, it's not easy to make a sandbox or some type of de detection deception network to where it doesn't really show your hand. So, uh, one thing we ought to do at some point, I'm gonna pop a LinkedIn profile here and he's gonna wonder why 400 people all went and checked him out simultaneously. But a friend of mine is Gati Evon.
He was the co-founder of Symia, um, which then sold, and now he does something awesome at Citibank. I forget what, um, but Gadi ran, uh, he created a company that does deception. There was a number of these that all kind of spun up around that time and some still alive when he got acquired. Um, and I think there'd be value in having Gadi come on the call at some point and really talk about how, how deception can work from the enterprise sense.
And Gadi is very, very outside the box thinking, you know, I've heard him say, um, like, we should be way more creative in our deception capabilities than we currently are. He said, for example, he said, I know one bank that I work with, and they literally feed, um, into, um, uh, like, uh, like paste men in places like that, fake credentials that do not exist, um, and then have their sim trigger on those things. He's like, why not? We have all the advantage here.
So we, we feed into sources that we know, uh, bad guys consume, just to see if we see something related, and then we can use that as pivot points for research. I'm like, Gabby, that's freaking brilliant. Uh, why does nobody do that? And, and I know why we don't do it in the channel. Who's gonna do something like that? Like, that's really hard. So, uh, I'd love Andrew at some point to bring Gadi on and we could do a talk specifically on a lot of this. Yeah.
What's interesting, Wes, as we wrap up here is, uh, Strand's next course after this upcoming one is on deception. And he lays out if you ever watched him on YouTube, some really, you know, I think easy ways to, to do deception for, for the channel. But, um, anyway, um, Sorry. No, no, go Outside of deception too, like the blog That, that you had shared in the beginning about attack emulation.
I think that's one thing that people don't do well today, is you get all your tools set up, you build everything, and you're like, okay, I'm good because I've turned these things on. But running the tools, like we talked about in that blog post to help you, and there's open source ones out there to help you validate that your security controls are actually working the way that you intended when you built them is, is really important in to, to some of the other things we've talked about today.
Yeah. Uh, that your article is awesome and, uh, I know we gotta revisit some adversarial emulation West back here again. Uh, maybe have at Tonic Red back, uh, and you, Brian, and the team. It'd be a lot of fun. Um, Wes, any, uh, closing thoughts here? So I, I just wanna thank, by the way, Dan, Brian, and, and Javier for coming on. You guys made this awesome. I I think we can give those guys the week off next week too. What do you think, Wes?
Yeah, just, just to let 'em know that, uh, Wes said you guys can just take the next week off as well for such a great job, my friends. And they should be fine with that, right? Uh, but no. Yeah. Javier, thank you Brian. Um, thank you very much. Yeah, and Dan, of course, thank you my friend. Um, this is great. I do want you guys to all as homework, go check out the threat profiles, take a peek at them. We didn't, we only got into two of 'em and I suspected we wouldn't get all the way through.
Um, but you know, I love what you guys are doing and bringing visibility into our adversaries so that we can then align our own battlefield and our own selves, um, against that. I think that's wise and that's an intelligent way to go around what we call threat informed defense. So really good. Um, so we'll just end it there. And Andrew, thanks as always my friend for, uh, popping this thing together. Yeah, we'll look, yeah, Brian, Dan, Javier, thanks a million. You guys, you guys are fantastic.
We'll, uh, we'll look forward to seeing everybody next week. Again, if you want the PR threat profiles to places either register, dataCon, go to the das booth or hop into Cyber Nation and I posted them in, uh, one of the most recent posts. So make it a great day, everybody. Take care. Thank.


