Skip to main content
Right of Boom
January 30, 2025

October 12th, 2020

In this video, Chris Sanders and a panel of experts discuss the innovative concept of using deception as a cybersecurity strategy, particularly focusing on intrusion detection honeypots. They explore practical applications for small businesses, emphasizing the importance of deception in shifting the paradigm of cybersecurity defense. The discussion also highlights the need for more focus on small businesses in the cybersecurity industry, sharing insights from Chris's experience and his advocacy work through the Rural Technology Fund.<ul><li>The importance of focusing on small to medium businesses in cybersecurity, highlighting how they have been largely forgotten by the industry despite being a significant part of the economy.</li><li>The concept of intrusion detection honeypots as an effective way to detect attackers within a network by using deception techniques that are low-interaction and cost-effective.</li><li>The call for more advocacy and tailored cybersecurity solutions for small businesses, emphasizing the need for industry-wide commitment to protect these entities against threats like ransomware.</li></ul>

Guests

Andrew Morgan

Video Transcript

All right. Welcome everybody. Week 22, we are joined with our crew, and we actually did an improvement, Annie, didn't we? Uh, don't let Kyle hear that. We've got the lovely Annie Ballou from today, um, as always joined with Wes Spencer, Gary Pika, and ge. Uh, hey, I'm gonna let Wes, why don't you just Yeah. Intro a good friend of yours and then hand it back to me so I can get through our stuff. But I'm gonna let you do the intro here. Yeah. So, uh, Chris Sanders, thanks for joining us today.

We have got, uh, Chris, he's the founder of Applied Network Defense, uh, does some really awesome stuff. If you wanna check out his website, chris sanders.org, so you can go and see all the goodness. That is Chris. Uh, but Chris, more importantly, you and I kind of go way back, don't we? Uh, yeah. Back, uh, to West Kentucky, all the way back to Murray State. Yes. And we're gonna talk a little West Kentucky here in a minute.

Uh, you'll see it slip out in my accent now that I'm with you and, and, uh, oh boy. Yeah. Can, you can't stop it. Uh, but, uh, so Chris and I were, uh, wait, can you start by saying together? Can you start by saying, important? Important. There we go. Sounds Perfect. Fine to me. Yeah, It, me too. It sounds good. So, Chris, thanks for joining us. If you don't know Chris, he's written, uh, several books.

And Chris, why don't you give a just a quick intro on who you are and what you've done in life so far. Okay. Yeah, absolutely. So, uh, I'm from West Kentucky. Um, same as you. Um, you really gotta want to get there, um, to find, to, to get to that part of West Kentucky. But, uh, proud, proud to be from there. And, uh, my first job was actually as the network administrator of the school district I graduated from.

Um, I spent a little time after that working for an MSP, um, in West Kentucky, providing tech support and things like that. So this is the network administration. Um, along the way, I wrote a book called Practical Packet Analysis that got noticed by some folks and landed me a job working for the Department of Defense, um, working as an analyst in a security operations center, catching bad guys.

Eventually started leading and building those working for, for the Army and then the Navy, uh, before going out into the private sector where I worked for, uh, Mandiant big, uh, incident response company many of you may be familiar with.

And then, uh, about a little over three and a half years ago, I left to start my own company, applied Network that smart, focused exclusively on education, whether that's, that's writing books or, uh, teaching classes in person, online, things of those nature focused on security investigations. Very cool. Well, Chris, we are ecstatic to have you. I'm just gonna back up just a little bit. Few quick announcements.

Um, number one, we coming back to the incident response planning workshop that we did with Wes, Chris Laer, Mike Ard, and Gary, the incident response plan is now live and available along with Wes' Business Impact Analysis in the Cyber Nation. Link can be found below. You'll see a little call to action there. It's highlighted in green. Gary, I'm looking on the spot here. Um, do will you guys have it available at True Methods soon to the, uh, BI Business Impact Analysis? Yes, We will. We will.

Right now we have just in our, we have it in our portal for our, for our True Methods members, but we're gonna put it on our public site. Okay. Under re, under Resources. Fantastic. Okay. And the Siren Nation is cranking away. You'll find incredible resources and people in there like Chris Sanders, like Wes Spencer and Gary Pika, um, over 700 in five weeks. Um, and so we are ecstatic about that.

Some other things coming up on the cyber call, we are going to have the Dean of Research, uh, Johannes Ulrich from Sands Institute on the Cyber Nation. We are also going to have, um, uh, Sunil Yu, who is the author of, um, the Cyber Defense Matrix, um, as well. So we are very excited about both those. Yeah, we are gonna have some stellar, um, talent coming onto this show and some other ones that Wes and I are working on as well. Um, Chris, um, just I had to ask a few quick questions.

Oh, and lastly, we're gonna do a virtual, well, in essence, a virtual book signing. Five of you out there today, um, are going to receive, uh, intrusion detection honeypots. So this, I started reading this book this weekend. Some other people were telling me in Cyber Nation, they started reading it as well. And, um, Chris, I gotta tell you, it's a fun book. I mean, most people don't think of cybersecurity, technical cybersecurity books as fun, but kudos to you.

And, um, I'm gonna start off by asking you about one of the things which I loved in the beginning, where if you could kind of just talk about how the, kind of, the chronology of people starting off with, Hey, I got a, uh, virus, so I'm gonna put this technology in, and then walk us through that, because you eventually end with the applicability to small to medium business and how it's forgotten about. So I think it's really interesting, but let me let you tell us a little bit about that. Sure.

And I, I'm, I'm glad you think the book's fun. It was super fun to write. I think there's just a, a, an exciting dynamic about, well, taking it to the attacker when, when they're on your network, they're on your home field turf, and you can have a lot of fun with 'em and use it for, um, to, to get them off the network eventually. Right? So I, I find that to be a very fun thing and something defenders don't get to do a lot.

Um, the, the part of the book you're mentioning is really, it's, it's the very first, it's the introduction. And I kind of talk a little bit about the history of cybersecurity and how it's evolved. And it's this notion that, you know, a business has needs, and the industry tries to respond to those. And the business may be, may say, well, somebody broke into my system. So, well, the industry says, well, well, you have these firewalls, buy a firewall and put that in.

And then the business will go, well, a user got a virus despite this firewall. And the industry says, well, good thing we have this antivirus software. You should buy it and put it in. Well, well, then the business says my antivirus missed something. Well, the industry says, well, how about you buy an intrusion detection system? And the business says at that point, well, the number of logs and alerts are overwhelming, and they don't have enough context.

Well, maybe you need some more centralized logging. Maybe you need a sim, maybe you need threat intelligence. Eventually, maybe you need machine learning. And if all that fails and the business says, this is all way too time consuming, and it's not working for me, the industry says, well, you just need to hire more people. And, you know, that kind of works. It can work. I've seen it work for really large, well-resourced businesses, companies, governments, but that's not most people.

90% of the businesses in America are small businesses. What about them? They've been largely forgotten by the security. That's, That's why we're only doing response plans we gave up on the other side. Yeah. Now It's fair. It's a good thing that I think it's a good thing. Small businesses come around that prevention eventually fails. If an adversary is structured or just wants to bad enough, they're gonna get in.

So your goal also has to be not just prevention, but detection and then responding to that event before something really, really bad happens. I think intrusion detection honeypots are one of the best ways to do that, because they scale down as well or better than they scale up. And that's ultimately the impetus for why I wrote the book and why I started the book off, kind of with that history of the business security industry relationship. That's an awesome perspective.

I think you're hitting, you're hitting a chord with a lot of people. And, uh, we're on this call with a lot of experts, but I've never really heard it described exactly in that way. So that was, uh, that was really good. Well, I'll tell you, I, I, I can't complain claim complete innocence because I mean, I worked for a vendor for a long time and, and I worked for Mandan, and I'll pick on them, but also, also pick on all the other vendors in that space too.

I mean, most of them would say, they describe, they, they subscribe to what I'll call the NASCAR model. Again, the West Kentucky coming out of me. If you're of a more global audience, we'll call it the Formula One model, but I'll call it the NASCAR model. And these, these big cybersecurity vendors, they say, we are gonna build these big 800 horsepower awesome machines that aren't really appropriate for most folks.

But the idea is that the tech we develop will then get commoditized by the, the Fords and the Chevys and so on of the world. The problem is cybersecurity doesn't have a lot of Fords and Chevys. We have all these vendors who want to be, um, who want to be, you know, your Joe Gibbs racing or all your various, um, nas, everybody wants to be a NASCAR team. Nobody wants to, to be Ford and build cars for everyone else. We all suffer for it, Man, Gary, this, this cyber call is built for you.

Not, not a lot of people know that you've got a passion and a lot of expertise in nascar, but that's gonna be saved for another cyber call. Gary. Yeah, I I won't mention that one year I was in the top 0.01% of fantasy nascar. I don't even know what that means. Yeah. So normally I just turn it right over Chris at this point to Wes, but I was so intrigued by your book.

I had a, you know, you mentioned you work for, you know, DOD and, and, and, and one of the other parts, and there's two parts in the book I just wanted to ask you about quickly, and then I'll turn to last, I promise.

But the one part I wanted to ask you about was how you talked about, and again, this is early in the book, guys, if you and gals out there, if you get the book, it's just really great read, but you talk about, Hey, I-D-O-D-I would say, you know, that basically it was the different reactions you got and it was a complete different end of the spectrum in speaking with DOD and Fortune 500. And can you, you kind of run through that?

And again, we're talking about Chris, if I could just put in context, and correct me if I'm wrong, honeypots, a lot of times people think are on the outside of the network and they think about those. You are sitting there saying, Hey, why don't we put this on the inside and get the bad guys in here, right. Well, Yeah. When most folks think of honeypots, they think of traditional research based honeypots, which sit outside the network. They're intentionally vulnerable.

They're really just to collect information about, you know, proliferate proliferation of worms and things like that. What I'm saying is take those, strip them down, slim them down to their very specifically focused things, and then put them inside the network. They're not even intentionally vulnerable. They're just logging interactions so that, you know, when attackers are there, that's the premise of an detection honeypot. Nobody should ever talk to it.

So if someone does, you know, something is on the network that probably shouldn't be. Or maybe a user is doing something they shouldn't. Either way, I want to know about it so that I can, uh, that I can investigate it now, because honeypots have been around for a while and they're using a lot of different ways. There's a lot of baggage associated with the term.

And so in this section of the book that you're talking about, that's what I'm really trying to do, is kind of talk about that bag and how it plays out in many cases. And in my time in the DODI worked for the Army first and then the Navy. And during those times, I also consulted and did things with, with the Air Force and Coast Guard and pretty much everyone else.

Um, and what I found was using, as an example, was, well, when I went to the Army and said, Hey, I wanna deploy honeypots inside the network, well, they said, um, no, they just said, no, not gonna happen, period of sort. So then later on I went to the Navy and said, Hey, I wanna deploy honeypots inside the network. And they're like, well, we like your idea, but let's not call 'em honeypots. Call 'em something else in any documentation you write and then we can do it.

Um, we ended up calling 'em sponges, uh, at the time. Um, now then the Air Force came along and I said, Hey, I want to deploy honeypots on the network sponges. And, uh, the Air Force said, sure, well, haven't you done it already? Right. They, they had no quals with it whatsoever. And now that's not so much to speak to the segmentation or the, or the difference in viewpoints of these three individual branches. As a matter of fact, it's a lot more nuanced than that.

It goes down to specific individual units and their perspective on things. But that's to say that using the word honeypot means diff very different things to a lot of different people. So part of my goal with this book was to basically sit down and cordon off this notion of what an intrusion detection honeypot is, so that you can have more informed conversations with these folks and deploy this technology more effectively.

It's not just the honeypot, it's an intrusion detection honeypot, which is a very specific purpose on the network. Awesome. And then my last thing, because I was just like, it was almost like a catch me if you can, you started to go down this thing called the cuckoo's egg. Um, and it was really just like, I was like, come on, Chris, give us the whole story. So can you just, you know, maybe give people the, the cliffhanger, if you will, of what that is about?

And and maybe you could give us the answer here, Chris. Yeah. So the, the first chapter of the book is, is a brief history of honeypots. And I talk about some of the bags of that term and how honeypots have been deployed. And as far as we know, really, the first, well-documented case of a honey pot being used was by a gentleman named Cliff Sto, um, who's a researcher at, uh, at Berkeley.

And basically this was, this was from the late eighties, and he noticed an accounting error on, uh, on a system he was in charge of. And we're talking about accounting because you had to rent and pay for CPU time back in those those days. And I'm probably causing a lot of like, flashbacks to people that are not good. Great, but I'm sorry about that. But you had to pay for accounting time. He noticed that accounting error, like something wasn't right, they were missing like 50 cents.

So he started digging into it, and he found that he had an intruder on the network, started investigating that. And it kind of led to this, this big long sequence of events where he eventually reveals nation state level activity and, and espionage going on, not just in his network, but in all sorts of military bases, government entities, all these different things that were going on.

Um, at one point during the, the sequence, he needs to keep an attacker in a network for a certain period of time, um, so that they can be traced. Because back then when you trace people, it meant going to a closet and physically tracing the cables, uh, of the phone relay. So he built basically a honeypot, a trove of fake documents designed to lure this attacker in and keep them on the, on the wire for several hours. And that was a key part of the investigation.

I'm not gonna give away the book, I'm not gonna give away the ending Here. And I do, I say that because it's such a great book. Um, and, and the book's called, uh, the Koo Egg by Cliff Stoll. Um, it's a book that's gotten many people into the field. Um, I know, I know several practitioners in the field who have gone to do really great things. And so them, it all started with the cuckoo egg. Um, and it's a real story. Um, cliff is out there.

I actually ended up building and teaching a free online class about this, that you can find on my website. So one of the things you, you may wanna do, especially if you're new to information security, um, that class is free, go to chris sanders.org, there's a training button, click on Cuckoos Egg, and you can read the book in eight weeks sections. And I have exercises and things like that you can do along with it.

So that's a good way to go through the book if you don't just wanna read it and you wanna be a little bit more hands on. Alright, well, with that, Chris, thank you for that time. Wess, the floor is yours. Hey, uh, Chris, I've been itching to ask you one question. Are you ready for this question? No, he's all things, I know him. He winds up like that. He's ready. He's, I I've got an inside joke that I'm gonna bring the rest of this, uh, 2,248 folks, we gotta get to 2250 by the end of this.

So, uh, uh, go invite your friends. All right, so here it goes. Like all good things West Kentucky and cybersecurity. There's one missing element to that Venn diagram, and that's meth labs. Yes, I said it. Meth labs. Chris, talk to us about meth labs, cybersecurity and how you would not be here today if it were not for, uh, for a great meth lab. Yeah, well, I, I think maybe not a great meth lab. Maybe a really bad math. So yeah. What is a cybersecurity call without talking about meth labs?

So a lot of people ask me often, um, how did you get started in security or in computers in general? And the answer is that my cousin Billy built a meth lab. And so let me, let me provide a little more detail on that. So, so my cousin Billy, he was kind of a, a wayward sort, um, somewhat of an innovator. He built probably one of the first meth labs in west Kentucky. Um, he wasn't a chemist, he was a redneck chemist. And, um, it didn't go too well.

And he got arrested as happens often when you build a meth lab. Um, so that was bad for him. But what he did, he went to prison. He, um, took a computer class in prison and learned about computers. And so then he went home and was on house arrest. Of course, he's my cousin. He was living with my aunt. We were often at my aunt for various reasons, and they had this computer, and I thought it was really interesting.

And so Billy then taught me some things he had learned about the computer, and that was really my first exposure to, to technology. And, um, a lot of the interest was, you know, the games and things like that and figuring out how to play them. And eventually I learned about the components and the insides. Uh, I was able to, uh, scavenge enough components to, to build my own computer. And the rest is kind of history.

So if my cousin did not, how things Turn out for Billy in life, Not well, uh, not good. No, Billy, um, couldn't really get away from the drugs. He's, uh, he's no longer with us anymore, but, uh, Ah, man. Yeah. Yeah. And, but he, um, I would say, you know, like I said, if he had never built that meth lab and never gotten caught, who knows what I would be doing right now.

So, um, I thank him for his indirect contribution to, to my career and helping get me and my family out of poverty in that way. So, uh, silver lining to every, everything, I guess. Yes, yes. Well, Chris, I appreciate the story and I love everyone's journey into cybersecurity and how they got there. Uh, I don't think most of us have a story, uh, quite like that. So it's good. Let's, let's talk a little bit more about deception.

Uh, my, I guess one of the questions I, I'm itching, like if you think about a lot of our members that are here on the call, the past two, three years, Chris, they've really grown, most of them have grown in their understanding, especially like adhering to cybersecurity framework, looking at identify, detect, protect, respond, recover.

And, you know, you've been at an MSP, you actually worked for one in, in the olden days, and I think most MSPs would agree, you know, up until maybe three years ago, very prevention focused on AV, spam controls, firewall, that sort of thing. And so they've really gotten into, uh, investing in things like detection, response, recu, uh, recovery, all of these things that, uh, I really make a great cybersecurity program.

Do you feel like deception as a technology and a strategy is an offshoot of detection? Or do you think it's something all in its own? I, I think deception could probably be used in a, in a number of ways. Um, I think detection is just maybe one of those ways. It's the one I'm focused on, um, specifically because it, it scales really well.

Um, I mean, and, and when you think about attack and defend, if an attacker is going to break into my network, they know very little about it until they're in there and they get around and they explore. I, in theory, should know a lot about my network. So with that knowledge, I have home field advantage and there should be a way that I'm able to use that. Um, you know, traditional intrusion detection, a little bit of that.

But really, I, I think no way, in no way better can we, we use that home field advantage than leveraging deception techniques. So I think of, you know, deception's a broader thing. It's been around forever. People have been deceiving each other since the beginning of time. Um, but applying that to intrusion detection, that gives us the power that I don't think we've really had.

And again, it's maybe one of the only pure ways to interact with, with human attackers in ways that, um, make use of that home field advantage. It's funny. 20, it took 22 weeks, right? Um, for this to come up. Wes y Yes, indeed. Right. And, uh, you know, I've, I've, we've got a lot of questions coming up around deception and, and how MSPs can best utilize it. And I'll save those, Gary, for you because, and a lot about meth and, and a lot about meth, right? So, Chris, we're down a rabbit hole.

We're down a mess to turn things blue. Yeah, I'm glad that Billy didn't actually teach me anything about meth, anything I know about that. Sure. Okay. So getting back onto, uh, the, the topic. I will say, if you guys have a question for Chris, we see the first one that came in that from Matt. It's a really good one. I'm gonna table that just for a little bit, but that's a great question. If you have a, a question submitted into the q and a, we'll make sure that Chris gets to it.

And, uh, if it's a meth recipe or not, I'm sure he'll be glad to answer. So Chris, I wanna dive into something a little bit more that you said. You know, I, I often talk about how, and you used this quote from Richard Balik earlier, you said prevention eventually fails. That's what he said in the Dow of network security monitoring great book, that's where I cut my teeth in understanding detection for the very first time. And he's right about that.

I mean, we know factually that happens for every organization. Here's the deal though, when you think about detection, you think about the, the, this paradigm. People are always saying, you know, as defenders, we have to be right every single time. And a bad guy only has to be right once to get into a, a network. But that paradigm, Chris shifts the second a bad guy is in the network in that they now have to stay, uh, hidden quiet.

They have to be quick with what they do, but they, they have to be the ones that are now hidden. We only have to be right once to see something and detect and do something about it. And that's where deception technology as a foundation is really built upon. Right. Is this idea of taking that paradigm, shifting it and giving the attacker, and I'm sorry, the defender, an advantage that they never had before. Is that correct? Yeah, absolutely.

I mean, when you think about the attacker, the attacker's counting on really two things. One, that when they get into the network, you're not really watching for them. And even if you are that you are either overtaxed over alerted, there's too many alerts, you don't have enough staff, your technology is not tuned well enough, they're counting on any number of those things being the case. So that even if you're watching, you're just not gonna see them, you're not gonna be able to differentiate.

Chris, in our defense, we have a lot of service tickets to do. We're pretty busy over here. Yeah, fair enough. And, and I mean, I remember those days. I, you know, the, the MSPI worked for, if every, every single thing I had to be I was doing had to be tied to a billable hour, right? And, um, security and proactive security and monitoring doesn't really fit too well, um, in the notion of billable hours most of the time. So, um, it doesn't put us in a great place. Y yes, indeed.

And, you know, I, I guess I'm gonna seed the rest of my time, but I wanna ask one last question to you. Less about meth, more about, uh, deception. And this idea of deception can be, it can take many methodologies, right? For example, our friends at Huntress Nanny can talk about this with what they're doing, canaries, it's really cool what they're doing in that, in that, uh, that mind. Um, but I remember I was at a bankers conference with FS ISAC one time when I was a practitioner.

We, we all had a, you know, a late night just discussion, having fun. And one of the guys that I was chatting with said, you know, what we've started to do? He said, we've started to take user accounts and create fake user accounts and seed them onto dump lists and dark web forums and places like that.

We know bad guys chatter specifically looking for triggers in our sim if we see something odd, like, hey, we, there's no Max Smith, whatever that exists as a user account in our bank, if we ever see that hit somewhere, we know somebody's brute force and we know automatically that thing is is nasty, it's not good. And we can use that to do some additional correlations.

And I thought, like when I first heard something like that, my mind was like, why do we not think about like this strategy from a defensive detection driven, whether you want to call it honeypots or whatever, from a deception perspective, we should be able to use these things to push pain back to a bad guy.

And so, Chris, I'm curious, can you give us some examples of deception that we could use or we could think about or just things that, uh, would be useful for a defender when it comes to deception? Yeah, and I'm gonna present a scenario to you and, and just consider that an attacker is targeting the network and they manage to get access to, let's say an end user workstation.

And maybe they've sent a phishing email, the users click something, they've gone to a website, some blah drop by download, who knows? But they've got access to a system. And let's think about this from the attacker standpoint. What is the attacker going to do 99% of the time? Great scientific stat, they're gonna do one of three things. They're going to attempt to steal credentials so they can get administrative access and then do other badness.

They're going to pillage the system and look for documents or things that are of value to them, or they're gonna go ahead and scan the network and try to see what other systems they can move to. That is what an attacker's gonna do most of the time. I know this because I spent a couple years doing penetration testing myself, and I kept good notes. And what I found was when I got access, these were the things I was doing every single time.

Uh, and I've also investigated a lot of these cases where I see this happen. So take those three scenarios, stealing credentials, opening documents, and scanning the network. Each of those is an opportunity for deception. Um, opening documents, probably the easiest one. If I know an attacker is gonna be looking for documents on my system and opening them, why don't I just give them one? Why don't I make a file called passwords xls and place that on there?

The attacker is just gonna think it's a file. They're either gonna open it directly or they're gonna pull it off the network and open it directly. When they do, there's gonna be a, basically a string in there that's gonna call out to a web server that I own, and I will know that they've opened it and I'll know where they opened it from. I'll have the IP address at that. So that's the document scenario. Let's say they're gonna scan the network.

If I know they're gonna scan the network and see what is on that same network segment, well, I can put something else on that network segment too. So I can just put a, a fake listening service. And it can be really simple. It doesn't have to be a real system. It can be netcat listening for something. It can be something purpose built, like an open SSH server, whatever. When they scan it and they interact with it, nobody should be doing that.

I've already whitelisted all my authorized scanners, so I know it's not that when they scan it, nobody should be doing that. So now I know that they're on the network. The final scenario, I think this is maybe one of the coolest, if they're gonna steal credentials, probably the most popular way to do that is to try to extract them from memory using a tool like minica or something like that from LSATs. Well, if they're gonna do that, why don't I just give them credentials?

So at that point, I can run a process based upon take credentials, inject those into memory, then when they dump those credentials, they'll get them. When the attacker gets the credentials, what are they gonna do with them? I try to use them so I can set up active directory to monitor for any use of these credentials. They're not real credentials. They're not gonna let 'em log in. So I'm monitoring for failed attempts for the specific username when they do it.

I know they're there, I know they're where they're coming from. So right there, those three techniques, you've already encompassed most of the things that the attacker is going to try to do right from that system right off the bat. All incredibly easy to set up all very low rates of false positives. And you mentioned once the attacker gets on the network, they have to be right every time. That's really true.

Now they just have to do one of those things that we know they're there, let alone if they do all three. Listen, when we get to the end, I'm sorry. When you get to the end, can you tell us how many people ordered your book during this? Uh, I don't know myself because I, I'm thinking a few people are ordering your book right now. It's, it's Gary. It's a great read. Yeah. And speaking of, I'm sorry, go ahead Annie. I didn't mean to interrupt you.

Oh, I just wanted to ask, so do you normally recommend that a lot of these alerts that come out of these honeypots go into a sim or some other tool to provide that sort of alerting? How does that architecture sort of work? Yeah, so I, I would say, I say to most folks, if you already have a mechanism in place for getting alerts, like a sim by all means, yeah. Put that in. That's what you wanna do, is just integrate it into your existing format.

And, and most, I mean, any tool you set up and all the ones I discuss in the book book, I tell you to get logs from them. And then it's just a matter of integration.

If you don't have something like that, particularly for small businesses, I recommend using something like just send them to something like a, a SIS log or an NX log forwarder and send it to like a publicly available service, like a Zapier or if this, then that and have it send you, once you get it there, you can do a number of things with it. You can have it send you an email, you gotta it send you a text message, you can dump it into a Slack channel at that point.

It, it's kind of whatever you want to be. And you can do that in an encrypted, secure manner. Um, for small businesses, that's gonna be a little bit more preferred, but if you're a bit bigger and you have stems, or you're a service provider and you have that just integrated into the existing, Yeah.

So Gary, I'm gonna turn it over to you and I, I'll just say, uh, as I close, that's a, that's exactly what we would do at Perch, for those of you that are wondering, that's how, that's how we would do it. We would just have an event notification, pick that up and, and alert. So this, I love this conversation. I love that we're getting into this. I love that MSPs are interested and, uh, itching to kind of get into all of this. I love what, uh, Doug, I think it was said.

Yeah, he is like, how do I get started? So there's some practical ways, Doug, get the book, check out some of those examples and start hammering away. Uh, Gary. Yeah. So first off, this is really awesome. Like, I'm really enjoying this conversation. It's like each week we're peeling back the onion on something else, right? We have different people on in addition to our panel. And, um, and this is a great one.

Why do you think, like, this seems like low hanging fruit, something that everyone can do when so many of us, like it's MSPs, we're spending so many times on so many complex things. Why do you think sometimes it's hard just to like, to think through, like you just said, okay, it usually falls into three categories. What if we did this, how likely would it be? Like, why, why, why hasn't this become something that, like the standard operating procedure for every small business or every MSB?

It's a great question. I think it's a couple things. Um, I, I first wrote about this concept of intruding section pots in 2013 in a book I wrote called Applied Network Security Monitoring. Uh, I dedicated a chapter to it, and it was really just kind of broad and high level at the time, nobody was doing it, and I couldn't find, I mean, I was doing a little bit of it, and there was a little bit of it in the DOD, but I couldn't find anybody who had talked to me about It.

It might've been the name of the book. So you must've got a marketing person to help you out with this one. Yeah, yeah. Well, I, the, uh, the book sold and everything, it's just that, that part of it. And, and people were like, well, this is cool, but I just, I don't know how to do it. And there wasn't a lot of tooling available either. Yeah. And that, that was a big part of the issue. So people didn't wanna talk about it. I mean, it's deception, right?

It's inherently, and it's deception, and it's about your security and, and just people are very cagey when you wanna talk to 'em about that. I still experience that when researching this book. Um, part of it too is just nobody ever wrote any of this stuff down. Nobody ever did it. And then, I mean, one of my favorite quotes is, the difference between science and screwing around is, is writing it down. Um, and same as for engineering and security in some ways.

And, um, people just, nobody ever created a Word document, um, and then, you know, put the string in it and, and then had it to where it would alert and then would send you this, this notification, and here's where to put it. Like, people were kind of doing that, but nobody really wrote it down in a structured way. Like, here's a way to think about this, and here's a way to do it. Here's a link model for it. Um, that really changed really, probably around 2016 people started doing that more.

So a lot of things may be going into that as well. The term honeypot having a lot of baggage associated with it. The notice, most people think still that honeypots are just these things that sit outside the firewall and so on. Um, that's what honeypots can be, but it's not all that they can be. So it's kind of a influence of things there. But I think a lot of it just goes down to people only one to talk about it and write it down.

And, you know, I I, I, as far as I know, written the first dedicated book on the topic, I hope I do not write the last dedicated book on the topic. I hope some, you know, I'll continue to write about it. I hope others will pick it up and carry the torch and write more about it too. I, I think that's different about what I'm hearing from you, Chris, is that the things that you're advocating or pushing are very focused and actionable types of honeypots.

Like, for example, the credentials thing, right? If you see those credentials being used, there's action that you can, can take out of it. Whereas the traditional honeypot that I am used to thinking about is one where you're just sitting there and you're just waiting to see what I can potentially find or discover. And I think that's the big difference. Well, I mean, e especially as the size of the business decreases, nobody has time to to, to do research, right?

I mean, you need people to do that for us. And that's kind of what I hope I've done, at least some of is prepackaged this idea and here's every step you need to make it happen and just put it in air and set it up and don't think about it ever again until it alerts. Um, we need more of that. And, and that, that idea and that concept has not really been compatible with most intrusion detection in the past.

Yeah, I think there was one of the, the comments of somebody who was using honeypot said that they have, um, a piece of hardware that's sitting there, but they're not, they're accustomed to not normally getting alerts. So when one actually does appear, then it's something that you can chase after. And, and it's scalable in that way. And that, I think is a key part for our, our MSPs and our SMBs or small Business. Well, I tell you, it's true too.

Like, I mean, I, I run IDS on my home network just because I'm a nerd. I do. Um, and like I kind of pay attention to that. But I also run numerous, um, numerous types of intrusion detection honeypots, and I've got some of them, for instance, that also alert me when the power goes out or when the network pick, because if they go down, it means someone could have attacked it, and you wanna know that. Um, and that, that does happen.

I mean, especially in a home, because I don't have these things all in battery backups, right? So if the, if my network connection goes down and I, I get the alert from the honeypot before I get it from anything else, and that every time it kind of freaks me out. So I, I eventually built in stuff where it would detect if it was because the internet was down and so on. But honeypot alerts are, are highly, highly actionable.

So you want people to kind of like step back and pause when they see them. 'cause it means something's worthy of investigation is going on. Yeah. Otherwise you're spending all your time trying to tune all of the policies and rules, and you're not actually spending the time creating or following up on the alerts that you get. So. Exactly.

And again, smaller businesses don't have time for all that, that is most businesses, most businesses that people work at in this country and many of the others. Two, How much of your time at the MSP, which is different right? Than being in a small business? 'cause you're dealing with multiple environments, how much, and you see what they're up against, right? You're responsible for 10, 20, 30, 50 in my first MSP 180 customers, right?

Um, how much did that influence how you look at this, knowing what you were up against when you were in a, you know, a, a business like the people that are on today? It certainly defined a lot of the lens through which I saw this. I mean, it, it really defines the lens through a lot of what I see most of cybersecurity, because I grew up in a small town filled with primarily small businesses. My parents worked for small businesses.

Um, all my customers at the time through the MSP were small business. I'm a small town person. Um, and, and now, you know, even, even, you know, everything I do, I see through the lens of small business and having the experience was certainly helpful to that. But also then going to, to big business, going to DOD, which is the biggest business in some ways, um, going to the vendor who really didn't care about small businesses, I was struck by how little the industry does for small business.

When I say this, I mean it, the cybersecurity industry has forgotten and left behind small business. They did it a long time ago. That ain't gonna work. It ain't gonna work for America. It isn't gonna work for the world. Um, we need advocates who think about small business and design security solutions from them or for them. Um, this is particularly of issue now, now that ransomware has really, I mean, ransomware is the biggest threat to small business that's really existed on a security level.

Um, because it can bankrupt these businesses. And I mean, the government's shown how little they think about small businesses. Just this, the last, in the last week, department of Treasury put out guidance that said, if you pay ransom, um, that may fund sanctioned entities, we are going to punish you whether you knew it or not. And let me tell you, you're not gonna know it as a small business. Right?

So now you're having to trust the government's attribution on these things, which is a little bit of a, of a hinky science. Um, they're saying, yeah, you can probably pay a hundred thousand dollars, which will hurt you, but allow you to continue your business. But if you do it, we're gonna find you a million bucks and put you out of business and we can't protect you nonetheless. Right? So basically decisions made without thought of small businesses.

Um, there's just so much of that going on, and we just need more advocates and more people talking about that stuff. Yeah. I decided very early on I was gonna be one of those people, Like when you say small businesses were left behind, you're also saying like, MSPs were left behind Andrew, all the really, the top vendors and products that around security for MSPs, they didn't exist that many years ago.

In other words, used to be able to go into a solutions pavilion and, you know, other than, you know, a a a couple endpoint things, nothing. There was nothing. Mm-Hmm. Right. Yeah. Yeah. Well, I mean, I, I, I guess about How far behind that is of the enterprise and, and Right. You know, Gary, you're hitting on it.

I mean, I think, you know, what we've discovered in over the past three years and what we're seeing, you know, the, the, the, the part, Chris, that's, I, I would say that that is a positive is, you know, the group that's on this call involved in the cyber call and the cyber nation is, is really evolving rapidly. We've got some very evolved MS.

P to, to MSPs, but yeah, Gary, I mean, look, you know, three years ago, and you know, you and I did some stuff and we asked, you know, I was started working with perks three and a half years ago, right? Ask about security frameworks, ask about security controls, and oftentimes you were getting blank stares. Um, and so we've had to help compress Chris really, um, 20 years of enterprise security in the last few years. And it's, it's been daunting to say the least. Yeah. And we still have, right?

We, and that's why we keep coming back to two big hurdles every week, right? And one of them is having to change the business model of taking the part of this that is not just tools and services, but that is the proactive labor. Like 70% of it is discipline and building it into the pricing model, and then being able to have that value conver that value conversation. You know, because if we don't change the business model, that's why we keep coming back, Wes right?

To it somehow every week we end up having to touch on that because it's an obstacle that, that enterprises don't have. They just have to go get more budget. That's all they have to do. That's simple to do. Yep. We have a much more complex business proposition to solve before we even get to the great ideas that we have to do like this. Yep. And, and MSPs are the, the gateway and the key to securing the s and b sector. And Chris, that's one of the things I I appreciate the most about you.

You understand this both from your background as an MSP practitioner in the old and old and olden days, but also Chris, we haven't even talked about the site, the, the rural, um, defense fund that you have as well, the nonprofit. And, and, and that's another further evidence of how much you care about this and understand that as well. Can you just spend 30 seconds talking about that nonprofit and, and why it's important? Yeah. So I started a nonprofit in 2008 called The Rural Technology Fund.

And it started out basically just as a scholarship fund. You know, I mentioned I come from West Kentucky. There weren't a lot of resources for, for kids who were interested in technology in places like that, particularly at that time. Um, it's getting better, but, uh, there wasn't a lot available for me. So I, you know, once I was able to achieve some success in my career, I started scholarship fund to give scholarships to basically kids from rural areas pursuing technical careers.

Um, it evolved pretty dramatically since that, um, now we kind of work with teachers to give them the things they need to teach kids about STEM type education. So we work with classrooms. We give them things like Raspberry PIs, Arduinos to teach coding. We sponsor competitive robotics teams. We put 3D printers in schools. Um, all these places where, um, teachers are certainly starting to recognize the value of STEM careers and the transformative power that those can have.

Um, we give them things they need to be successful. So we've been doing that now for, again, since 2008. We've managed to put technology in the hands of over a hundred thousand kids in all 50 states. And it all started in, uh, in Mayfield Kentucky. Isn't that awesome? And if anyone catches that vision and wants to get involved, Chris, how can they get involved with that? Uh, take a look@ruraltechfund.org. There you go. Rural tech fund.org. We'll post that into the chat.

Uh, but yeah, I wanted to make sure we had a plug for that too. 'cause that's important. Yeah. And listen, long term we're trying to deal with the short term, the current providers, what's happening, but long term, just in general, whether it's cybersecurity or under what's happening right now with the biggest systemic threat to our world, uh, which is big data, right? And, and the use of it, um, like a whole generation's gonna have to get trained.

Um, 'cause they're gonna have to solve this, right? We're, we're gonna put our finger in the d**e and just try to keep businesses, you know, rolling along. But it is a much bigger systemic problem. So I, I, uh, kudos, uh, kudos on that. Well, Well, thanks. I mean, it's, it's, it's a, a thing that needs attention at, at all sides, both in, in workforce and labor development. We need people, we need an increased level of diversity. And that comes in a lot of ways.

Uh, both cultural, ethnic diversity, cognitive diversity. Um, people from rural areas think differently than people from urban areas, right? Uh, we have all these different fountains of cultural wealth and things that we can pull from. So creating a more diverse workforce is, I think, a key to that. That's kind of the long term vision. Um, but then the short term vision too, we need people advocating for other people.

Basically, when I, when I say, you know, I'm focused on small businesses, I think of that as I'm focused on people because pe again, the majority of people work for employ or impacted by small businesses, and that's everywhere. That's the operating system vendors. It's Microsoft who does, they've gotten better, but they do very little to make things secure.

Um, and with detection and response in mind out of the box, it's with your big vendors, like the one I used to work for in many of the other ones who don't, you know, if it's not a six, five or six or six or seven figure deal, they don't want it because their cost of their research and development and the cost to onboard customers is way too high. Um, it's a full industry commitment that needs to be made, and we just don't have enough people talking about it. And it's even in legislation.

Um, the government and lawmakers just don't really, I mean, we, we could get it. That's a whole nother deal. They just don't really listen to, to folks. Like the folks I think that are on this call right now, It's funny, this whole industry got built because of Microsoft, right? Like that's what changed everything because their products weren't always, usually weren't finished. They created more problems, they solved, and we got to solve 'em and take care of 'em.

Like all that complexity literally created the channel. And it was all great until recently when those things now can put us or our customers at risk. Now it's not as that then it's not as great. Yeah. Well, should we transition over to Annie here in the final stages? Um, Annie, you could, yeah. Yeah. If you could Again. Yeah. Well, thanks for coming, being with us. Maybe, um, we'll will, what we'll try to do here, um, take like five, six minutes if you would, Annie.

Um, we'd like to, um, have a little bit of time for the winners Mm-Hmm. Uh, for Chris to announce those. And I'll also, if you all are listening when we announce those, I'm gonna put my email in the chat. Please send me your address because we need to get you the book. So, and lastly those books, uh, Wes, thank you. Uh, perch is sponsoring those and I know we at the Cyber Nation and Gary are also going to kind do some additional giveaways and Cyber Nation and some other things.

So we appreciate all your work that You're, I just wanna say it's, it's Perch Huntress True Methods and Cyber Nation that are all co-sponsoring. Okay, fair enough. Fair enough. Alright, so Andy, let me let you take it over. Yeah. Um, well, one of the questions I, I had was, uh, I know you mentioned you had, um, experience with the DOD, um, and how it's just vastly different to how the SMB handles security and how the SMB is largely ignored.

But do you also feel like with your experience in the DD that there are lessons that could also be applied to the s to the MSP or the SMB as well? Um, you know, I, I think, I mean, the biggest thing I kind of hit on this that I think I learned in my time at DOD was just kind of, again, how much, not how much non DOD and non-defense and small business and things like that were, were ignored.

Um, I got a, a lot of firsthand experience with the red tape that comes along with, with DME and government type work. Um, it is not much different than the red tape you have in small business in many ways. There are just many more layers of it and much more complexity, uh, to it. I would say that oftentimes the standard of evidence to put things into, um, into play in small business is much lower than with DOD. But I think that can sometimes be a, a, a good thing.

Um, you just have to prove that can, you know, often save the business money, um, things of that nature, you know, prevent huge losses later on. And that's often pretty easy to do. I think sometimes with security, with DOD you often have to prove other things, um, political things, et cetera. It, it, it's a big deal. So they're very different. It's hard to draw a lot of conclusions from DOD that can directly apply.

Um, it certainly shaped my lens of how I see the world and how I apply some of the work I do when I do work with small business customers and, and edgy and have them in my class and so on.

Um, if not, just to see like what another part of the world looks like When you, when you think about like, um, you, you were talking about evidence and like, um, um, like a sort of a trail, you know, for the SMB, if they were to do some of these honeypots and then they do get alerts, but then those alerts get lost. Is there any potential opening for, uh, liability or anything like that?

If, if they don't do anything with the information that they receive, um, and is there, is that something they need to potentially think about or consider when, um, when, you know, implementing some of these honeypot um, uh, ideas that you have? Sure.

I mean, there's the notion of if you have no ability to, you know, and this gets said a lot, I don't, I'm not saying I necessarily agree with that, but there's this notion of you have no ability to respond to intrusions at all, and you're just not going to, then you shouldn't collect the data. That's what a lot of people will say. I think that's problematic for a lot of reasons, not the least screws over your customers.

Um, but, um, you know, I, I think there's certainly liability involved even at the big business level. We see this a lot. Um, people will have IDS set up and it turns out they had an alert that reference the bad thing that was happening, and they just ignored it or didn't see it for, for various reasons. Um, that can probably have some, some, you know, particularly for, for publicly traded companies that can have some, some fallout in that regard.

But also cyber insurance, um, can, sometimes they can say, well, you knew about this thing and did nothing about it. I'm not seeing documented cases where people have been denied claims for that sort of thing. Mm-hmm. Then again, I'm not sure I would because that information is not publicly disclosed. If it's not Publicly. Yeah. I I would say if you're not gonna look at it, probably don't set it up as a general rule. Yeah. I mean, may maybe I, I just think it's a flawed statement.

It's a flawed question in that way, just because like, you should just look at it, right? I mean, that's like, and, and you have to ask yourself if, you know, ideally you don't have your own security people, you don't have your own cisman. You, you have a, you have someone who you can lean to for tech advice and, you know, it's say if you're gonna rely heavily on information systems for your business, security is a part of that.

And if you can't afford at least a, a tiny bit of that, and I think these are, and honeypots are one of those things that are very cost effective, then maybe you're not ready to play the game. Right. You're, you know, right. You're not, you're Not ready. Well, I totally agree with that. I mean, I think this circles back to that whole idea of keeping it really focused and keeping it really actionable so that you can really stay on top of it.

Um, I mean, I'm, I'm not trying to plug hunters too much, but when we were doing our ransomware canaries, um, that was something that was really important to us. Uh, and ransomware, canaries can be extremely noisy, especially when they're on endpoint machines because the users, you know, they can poke around, they can potentially find them, they'll change them, they'll create alerts, um, around those.

And so having someone who is actually looking at the potential alerts and you know that they're looking at them is, is a big deal. Um, you know, I, I remember a quick story, uh, when I first got to my second MSP, uh, I, I'm talking to one of the service people and uh, the phone's going buzz. And I'm like, Hey dude, I, that thing's blowing up, man. Maybe you check it. He is like, nah, don't worry about it. It's just alerts. And I said, what do you mean? He's like, yeah, they come in.

I can't look at every alert. I went, I'm like, okay, people, we got work to do. You know what I mean? We got, we got work to do. You might, let's turn 'em off except for the five that we need, right? And let's turn the other 95 off. 'cause now we're missing those five. So I think that speaks to what you're saying here, and that's really in every area of how MSPs run a like tickets, alerts, sensors, all of these things, you're, you have to get to the actual result on 'em.

So Annie, that's an awesome point and applicable in the real life of every MSP. Yeah. And kind of with the ones that you mentioned a couple, but are there any, uh, favorite deception techniques that you like or you like to see? Or when they trigger it gets really exciting. You're like, oh, I got one. I I got the hacker.

Yeah, so I mean, I, I think probably one of my favorites, just 'cause it's the easiest, it's where it's to recommend most people start with honey documents that's taking word, Excel, PowerPoint, whatever office document and embedding, um, the code in it that makes the call out to another website when opened, uh, make, you know, passwords, ls, there's a number of things you could potentially call them to get them opened. Um, and you can, you think there's a number of ways to hide those.

You don't want legitimate users clicking on those. So I talk about a take book where you can create, uh, map drives to servers that are actually invisible and explore, because a lot of times attackers are gonna compromise a system. They're gonna do it at command line level. So the drives will show up in the command line, but not in explorer, um, for, for whatever protocol. So the attacker sees that, they browse to it, they open the file and so on.

Um, I think it's a really, I like this one just because it's so easy to sit up once you read about it and learn about it, you can have it set up and working in, in 10 or 15 minutes. Oh, that's interesting. 'cause the user probably wouldn't be poking around or clever enough to poke around to find it. But ha a hacker absolutely would try to find, yeah, absolutely Know there's, there's somewhere with honey documents, like a user could find 'em and trip them. But that's, that's not a big deal.

One of the benefits of, of most honeypot deception is they're really easy to investigate if it is a false positive. So if user double clicks and open it, or lemme just say it's, from my perspective, I get the alert that it was open on this system and I know that it's, you know, Steve's system. I'm just gonna call Steve and say, Hey, did you open this document? You know, no worries if you did, it's not a problem. I just need to know.

And they'll be like, yeah, like, okay, well this is a false positive and I can tell them, by the way, just ignore that document from here and out. You know, it's there. Don't worry about it. It's a security or it's a system administration thing. Um, leave it there. And you, you can also put protections them to make sure they don't get deleted and things like that. Um, so really easy to investigate in that regard. Um, and I, I like them for a lot of reasons and that's one of them. Yeah.

That's Very cool. So, so let's this, let, let, let's get, sorry for the feedback. Um, Chris, I think we got five winners. We do. You let me know if you've got 'em. I do. Okay. So let's go through the winners one by one. I am gonna put my email address in the chat please. If you are called, send me your address. I'll get those over to Chris, we'll get you some books. Again, Gary, uh, true methods, Huntress Perch, thank you so much for, uh, for sponsoring this.

Um, and then we've got some questions for you Chris. So I know everybody's chomping at the bit for their questions to be answered as well. So lemme put my email in Chris and you take it away for some winners. Alright, number one, we have John Roberts. John Roberts, I know Roberts. Then we have James Ober house. Okay. We know We have Tim Fornet. Ha ha Tim, congrats. Frequent Our frequent viewer Tim. Good to see that We have Stewart Waltz. Stewart, I know Stewart. And we have Trevor Anderson.

Oh, you got some, uh, some technical prowess there. Very, very, very cool. My email is in, um, uh, my email is in chat going up quickly, andrew@thecybernation.com. Shoot me an email. Mike, Mike says they're all fake users. It was a honey pot. That's very, very, uh, very well said. Gary or Mike. Alright, um, Wes, do you want to Yeah, um, MC the questions? Yes. Let me, let me Mc the questions. 'cause the first one's a good one, by the way, to the winners.

Uh, we do expect that, uh, you're gonna have some five star reviews coming in Chris, on Amazon. So, uh, watching for it, uh, I guess it won't be an authenticated purchase, but whatever. Alright, so Chris, this first question from Matt, I know Matt really well. It's a really good one. You can probably see it if you click on the ask a question at the bottom. So he is asking you, Hey, what are the ramifications here?

If a honeypot setup incorrectly, it's compromised, you know, does that have some ramification back to us? And doesn't that increase the organization's liability since they knowingly set up to an attack? A a And I think Chris, this is a bit of an ambiguation of the term honeypot because a honeypot doesn't just have to be a server sitting on the edge that a bad guy is gonna find. So for example, at Perch, we have a vulnerable automate server that we collect intelligence from.

We're intentionally attracting bad guys to that. But this is a, you, you can do honeypots inside the network that aren't necessarily attracting anybody. It's not gonna attract undue liability. Right. Can you elaborate? Yeah. So any honeypot, one of the characteristics we use to define it is the notion of interactivity. So basically, what degree of interactivity does it provide to the attacker who's interacting with it? Intrusion detection honeypots are generally very low interactivity.

They're very focused. We're not building like dedicated systems or dedicated vulnerable systems. I'm not just putting a, a version of an unpatched Windows XP out there inside my network and, and letting someone compromise it. It's not that at all. It's generally always software or some type of data. So it's very, very specific low attack service.

So if we're regulating a service, it's built specifically for a honeypot, like I talk about in the book, uh, a tool called Cowie, which emulates SSH the attacker can log into it and issue commands, but it's not actually really SSH they can't, you know, they can't get any further. They can't pivot to anything else from it. Could they theoretically exploit the software? I mean, all software theoretically can be exploited. The chance of that happening are, are very, very low.

'cause it's kind of built, again, with this in mind, um, I show you how to use a tool called netcat to set up listeners where an attacker thinks they're interacting with a web server, but it's not actually a web server. Um, whatever data they send just kind of gets dumped in, into a log file or into nowhere. The ability to to exploit or compromise that is, is pretty much non-existent. Um, for all intents and purposes and even for the things like the documents, like it's a Word document.

I mean, they can open it, but they're not gonna use that to pivot. So everything again is very, very low interactivity. It's very purpose built. So it's not like someone, again, someone's not going to compromise a full system and use that to pivot around in the network. That's a, that's a different type of honey Potty. All that net cat talk reminds me of Professor McLaren's labs on Net Cat, you remember that?

He just all kinds of wicked stuff of like rerouting SSH through net cat and reverse shell proxies. And I say the reason it's the Swiss Army knife of, uh, of network security. And, and that's why it's, it's actually in the book. It's the first honeypot I have you build. Um, it's not the easiest one, but I'll have you build that one first just to see, you know, what this looks like. And I, and I love that it's so hands on that that's what's so good about it. Alright.

And, and then a follow up from Mark. So Mark kind of added to this inside the question just talked about liability, the, the whole CYA conversation, that sort of thing. Do you think there needs to be conversations with clients around deception technology before you deploy it? And do you need an approval process or does it need to be have T's and C's around all it before you offer?

So I get to ask this a lot and I talked to a couple different lawyers when I wrote the book because I wanted to get some legal perspectives. And generally the way I have, the way I've narrowed in and focused on intrusion detection honeypots here, most of them really didn't see any reason that, that you need to have specific Ts and Cs around, um, around intrusion detection honeypots the way we're using them.

There are certain manifestations of them where you would, um, but if you keep it simple, like small businesses would focused on the minimal amount of interactivity. It's not really something to where it's really no different than a normal intrusion detection system in terms of the data you're collecting and the things, um, that you're doing. Um, it's easy to take some of these things too far. Um, and obviously I would recommend you not do that.

I mean, one of the things, you know, I recommend taking a Word document and putting that u RL in it where it'll call out to your web server. Um, you could put other things in there if you know the attacker's gonna ex spill it, you could put code in there that's gonna run and do bad things on a system. Don't recommend doing that for a number of reasons. Um, so you gotta just kind of be smart about it from that perspective.

Um, if a customer, you know, wants to understand what detection you're putting in their network, by all means have the conversation. You know, you don't need to hide anything. Um, this is not something I think folks need to be kg about when discussing. Uh, they often are 'cause it's inherently deceptive. But, um, I would not let the over complications of those things get in the way of people doing it because it's effective.

And again, it's, it's just really another form of intrusion detection, um, with even less than a footprint. So Gary, it sounds like some of it is the simplicity of it is really what the power of it is. I Would agree. Yeah. So Gary customers could use this or MSPs could use this in the sales process with their clients.

Then just once they have good mastery over it and they understand what they're doing, they could actually use this in some cases just to explain deeper what they as an Ms P do going above and beyond. Right Gary? Yeah, absolutely.

And even some of the concepts that we, uh, every week you keep hearing about when you talk about, you know, prevention, detection response, just when you start talking in concepts and you introduce ideas like this immediately at a conceptual level, uh, you're explaining a command over what's happening in a way that chances are my experience, they're probably not getting from a current vendor. And so when you establish that kind of credibility, the same reason why we talk in frameworks, right?

Concepts, frameworks. They make things black and white and people can understand them quickly without having to give 'em a bunch of technical jargon. And when that happens, we want to make conceptual sales. Wes, for value, not detailed technical sales. Well, I wanna give, I wanna give you a framework right here as well. It's called see, think, do you control what the attacker sees? You control what the attacker thinks, then you effectively control what they do.

If you know they're gonna be on a system in the network, put things where they will see them, make those things look like they have value either by blending in with other valuable things or standing out from them. Yeah, you do those two things, they will interact with it and you win. That is the premise for the whole game. Okay, so, so Gary, I just wanna extrapolate on what Wes said to you. And I could see this happen and I've had a good fortune work with you for many years.

Like, hey, look, there's, there's three things, you know, you just take it in the sales process, but hey, there's three things that we know attackers do. And let me tell you about just an example of a process we put in place and the, and the discipline we have around that right. Documents, this, that and you, you've now like, put that wedge in place, fair, you know, again. Yeah, absolutely. Like just the way, uh, just the way Chris explained it.

Hey, you know, uh, every m MSP's gonna walk in here, they're gonna tell you all the things they're doing, so you never, so you never have a breach. Uh, I am here to tell you, we do more than most everyone can get breached, right? So let me tell you what they're not talking about. And then again, this fits in with the same conversation you'd have about where you are with ir, right? Right.

It's the same, I I put it in the same kind of category where you're painting this, you know, this deep thought, this kinda deep process that is really well, really well thought through. And even like, of all the things you said today, and you said a lot of great things, Chris, when you said is, Hey, I thought about it and, and I thought about all, you know, my time and what happens when a bad guy gets in, they do three things. Here's why we look at those three things.

Like you summed it up in a really simple way. That's how you get credibility with prospects and customers. Yeah. So I know we're at the top of the hour, um, this was fantastic. Um, in closing, Chris, would you, I don't wanna put you on the spot, so I'm gonna ask it as a question, but would you consider coming back either, you know, in a collaborative, we've done these really cool collaborative webinars with true methods and perch, um, and, and, uh, we've had ir people on, et cetera.

But would you consider coming on and, and we could even kind of do kind of, hey, this is how to, you know, create a honey pot around a document, this is how to, would you, would you consider that, um, in the upcoming webinar that we could do something like that? Yeah, absolutely. Glad to come in and, and do a demo.

I've got demos of all these things set up 'cause I use them to build the book and I'm building a, an online class version of the book that'll be out by the end of the year, uh, where I include all these things as well. So I'm glad to come back, uh, maybe about the time that class is released and, uh, we can, uh, run a couple demos through and show everybody what the stuff looks like hands on. Because sometimes it's nice. It's not just to read about 'em, but to, to physically see it as well.

We position it right. We'll get 800 people. Yeah, yeah, yeah. Absolutely. Good stuff. We'll hold you to that Gary. Um, anyway, so in closing, uh, Annie, any closing comments from you or thoughts? Uh, no, this was really great information, really insight insightful. I learned, I learned a lot actually. Uh, and I have a different understanding, appreciation for honey honeypots. So thank you Chris. Yeah, me too. You Gary. Yeah. First off, great job today.

Um, yeah, listen, I, I, if there's MSPs that are out there and they're not taking time to listen, what's happening, uh, an hour a week, uh, here. And I want to, again, I want to command you, uh, Andrew, in the work that you do in getting the guests and, and preparing this and uh, making it easy for, uh, for Wes and I and the rest of the panelists. So thank you. Yeah. My, it's my pleasure Wes. Hey, super quickly 'cause we're two minutes over. Bingo. Chris, thank you for joining.

Means a lot to me personally that you came on and joined the 2000 or so folks that are on here. Thank you guys for joining. Chris sanders.org, you see that in the chat. Also rural tech fund.org. Check out both of those and then also Chris is available for training. So if you wanna get a group together, your MSP and do some really awesome training, Chris is available for that. Uh, I can think of. No one better. I mean it's Sand's quality. Uh, he's a Sand's guy, right?

So Chris, thank you for joining. Hey, thank y'all so much for having me. Uh, I love talking to this audience specifically. Um, awesome call. Y'all are awesome. Thank you. Thanks everybody. Awesome. Week 22. See you next week. Take care everyone. Thank you.

Related Videos