Skip to main content
Right of Boom
January 30, 2025

RMM Services for Adversaries (Take two)

In this video, Gary, Phyllis, Wes, and Garrett discuss the emerging threat landscape where cybercriminals are leveraging Dark Utilities to offer 'C2 as a Service', making it easier for less skilled adversaries to conduct cyber attacks. They delve into the implications this has for cybersecurity, particularly for Managed Service Providers (MSPs), and the importance of maintaining strong security hygiene and proactive defense measures. The conversation also touches on innovative defense strategies like cyber deception and the evolving tools and tactics used by both attackers and defenders in the cybersecurity realm.<ul><li>Dark Utilities is a command and control service that offers a user-friendly platform for threat actors, similar to commercial software like RMM solutions.</li><li>The discussion highlights the evolution of cyber threats, with ransomware and other malicious activities becoming more accessible to less skilled individuals due to services like Dark Utilities.</li><li>The importance of basic cybersecurity hygiene and behavioral-based detection is emphasized as effective strategies for defending against emerging threats.</li></ul>

Guests

Andrew Morgan

Video Transcript

Welcome to episode 1 0 7, back at it here with the crew. Um, and, uh, wonderful to see you, Gary, Phyllis and Wes saved my, you know, what, last week as I had a time zone mishap with Garrett who will introduce momentarily. Um, uh, I'll do some, uh, intros momentarily because you have, Because you use a Mac. Is that what it is, Gary? Because like, I, oh man. Anyway, um, let's see. There's a poll question up. I have no idea. What's that? I Have no idea. Oh, yeah.

So, um, there's a poll question up if you could take a look at that. Um, and um, Gary, I was just gonna ask from an announcement's perspective, we got Da Ocon coming up in a few weeks. Um, I know you're gonna speak Wes, are you speaking at Da Ocon? Unfortunately not. Okay. I, uh, tried to get in, but I think I was a little too late on the speaking circuit, unfortunately. Well, you got me There. Um, like I have been doing for the past, probably three or four DattoCon. I'm over two days.

I'm doing a session and a panel, but I'm MCing their business executive track. Okay. Um, we'll have six sessions over two days. Really awesome people at it. It's gonna be great. Awesome. Um, how, how many are you expecting, give or take? I, I'm going to guess 2000. Okay. Fantastic. But I Don't, but I don't know exactly. Okay. Good. Good. Alright, let me kind of just set the stage and then we will intro our guest here. Um, alright, so I'm, I'm reading through this.

I'm gonna put the article up momentarily when Garrett, um, does his intro and Phyllis takes over on questions. But, um, really interesting, you know, this article, this, so Talos, Cisco, Talos, um, Wes and you guys did used to do a really nice integration with their threat feed. They a great group of researchers. Yeah. Talos is top shelf. Yeah.

They came across this, um, basically, I'm gonna butcher it, but let's just call it a threat actor, just for lack of a better word here, offering C two as a service. So basically, when you go to the article, and I'm gonna again pull up there, there's screenshots. I mean, it looks like a modern day RMM uh, solution, almost as if you were gonna write the next version of an RMM, how, you know, feature Rich and easy it would be to use.

And so, um, I mean, it offers, and by the way, Gary, they have a phenomenal, uh, monthly recurring revenue model. I think they're up to about 30,000 subscribers. Um, in fact, the article says with tens of thousands of threat actors already subscribed at the low price, dark utilities is likely to attract an even larger crowd of less skilled adver adversaries. So isn't that wonderful to look forward to? Um, so they've got a great business model. Listen, you can't really blame 'em.

It's a, it's a significant tam. Yeah, it's very true. Right? I, I wonder if any of 'em will soon be, instead of state backed, if it's a good business, then it might be PE backed. Yeah. That that's very possible.

Um, so, so, uh, you know, I started thinking, you know, who I'd like to have on and, um, I, I was having conversations with Garrett and, you know, he's got a he'll, as you'll share with you, a really strong background in this area, aside from, interestingly, it looks like, you know, the people that decide to go white hat Garrett, uh, that could easily be, you know, black hat have a strong ProfIn for music like you. Well, it might still be, Et cetera. Um, so I wanted to kind of dig into this.

You've done a lot of research on dark utilities and I think it's a really timely thing. Um, last thing I'll kind of say, Wes, it almost seems like eerily quiet, you know, I know I was talking to Chris LA here and great to see you, Chris is always, you know, you're, you're seeing a lot of the traditional things, but nothing, you know, catastrophic, thank God, but almost eerily eerily to that. Andrew, you're right.

Uh, I did a LinkedIn live on this on Friday, and I was looking into some of the data from chain analysis and Cove Ware. And I would say those are two of the authorities and like the, like the threat actor activity space around like blockchain payments from ransomware actors and a lot of the incident response stuff. 'cause Cova pays the vast majority of ransoms these days. And so both of them are showing a significant reduction in volume in cyber crime.

And so I dove into that just j jump into my LinkedIn feed. For those of you that haven't seen, I'll try to find you a link, but I went through that data and we are seeing an e like an ebb right now in, in activity. I happen to think it's short term. I think it's a lot of politically generated stuff, but one thing that Ware said no chain Alice said that I thought was really good is the, the mantra is shifting a little bit, Andrew.

Like all of a sudden we're starting, like these threat actors are starting to realize, hey, being part of a big outfit may not be as good for me. Um, when the Conti leaks came out and all of a sudden we saw all of their trade craft get exposed, it really shifted the narrative of maybe it's not so good for me as an affiliate to be too deeply affiliated, like one of the major actors. And so are we seeing this diaspora of all these new threat actors going after, like, becoming smaller outfits.

It's interesting to see what's happening Happening. Yeah. Let me get my theso Gary, and, you know, well, Gary No, it's, thank you for sharing that, Wes. That's awesome. Um, Gary, talk to us a little about yourself, your background. It's awesome to have you with us, and I'll have Phyllis jump on in after that. Sure. Uh, hey, thanks so much for having me. Uh, my name is Garrett Gross. I live in beautiful Austin, Texas.

Uh, my most recent experience was building a security operations center from the ground up for an organization with about 1500 users, about 10,000 assets globally. Uh, before that I was a principal engineer on Palo Alto security team for about two months. I'll tell you that story over beers sometimes. Um, before that worked as a product advisor at a couple different security, uh, teams and have a lifetime of, uh, research and development Under my belt. Yeah.

But you're rapid seven for quite a bit there, who's nothing to sneeze at. So, uh, Yeah, one of the greatest companies I've worked for, you know, they, I think they've done a great job, um, kind of caretaking the Meta Exploit project, um, the past couple years. So great, great company. Yeah. Um, and right now I, I run a technical sales team for Huntress, which is commonly referred to as sales engineering.

Um, but I was kind of brought on to maybe help reinvent how we support that process because not only are we supporting our users, but we partner with a lot of the service provider community as well. So try to help rethink how they provide, uh, value to their users. Um, and the last part is, I have auditioned for the Blue Man group, but that's all I'm legally allowed to say about that. Which, speaking of Vegas, isn't that your hometown? That's Right. Yeah. That's where I grew up. Yeah.

Very, very So you're the one who actually Yeah, Right. I'm the one that didn't get in. Actually, I've Never really met anyone actually from Vegas. Very true. Yeah. They call us unicorns, actually. I go to Defcon and every year, and that always comes up and yeah, someone always accuses me of being a unicorn. Fantastic. Well, welcome Garrett. It's awesome. Thanks so much. Okay. Phyllis, you want to kick us off here? Yeah, sure. And, um, welcome Garrett.

And if you guys didn't notice, Andrew did put a link, um, in the chat. So Garrett, who, who really is this organization called Dark Utilities, um, and what services do they provide adversaries? They kind of sound like a, a well-run, a well run SaaS RMM solution, um, you know, with good customer service and certainly as Andrew said, a great business model. So what can you tell us about them? Yeah, it's, it's interesting.

You know, I, I absolutely see what Wes was saying about the decline in ransomware payments. I'm not sure that folks are deviating from the big business as, as we'll get into. Um, but what for dark utilities, we're not sure exactly who this is. Um, the attribution from, from my perspective, is weak at best. But Talos seems to think that it's, uh, at least one of the main threat actors is operating out of Europe.

Um, what I found really interesting is they, they seem to have a specialized feature set in disrupting gaming and streaming services, which, um, my bet it's probably somewhat of a younger generation. I know that makes me sound old 'cause I am. Um, but this focus on interrupting multiple smaller streams of revenue is much like how we saw the shift in ransomware actors focusing on a smaller subset of enterprise and then moving to a larger amount of, you know, small to medium businesses.

But, um, back to your point, they do seem to be very services oriented, uh, uh, a really responsive criminal network. You know, they have, they have, uh, support levels. I believe, uh, they use Discord to support their user base, uh, telegram. Um, and as we'll get into it, it's actually pretty affordable. Uh, the, um, distribution of payloads is all gooey driven and it has a very resilient architecture.

Um, and the most glaring thing that actually I was kind of offended by is that they have like platform stats and server health available. I mean, this is a business folks, this is, uh, right. If, if I were a criminal in 2022, Wes, no, I'm not. I found out that software pays comparable to crime. Um, plus no jail time if I were Yeah, yeah. No jail time. Right. Uh, which can be very expensive.

Um, if I were a threat actor in 2022, I would absolutely look at, uh, using this versus running my own CNC threat factory. You know What, I'm always amazed by how well organized adversaries are. I mean, this is like, you know, it's, it's like a well run business, quite honestly. Yeah. It's not operating in the shadows anymore. It's weird. CC Gary, because you've mentioned, is it, is it the fact that it is probably a state sponsored? Is that why they're so well run, Gary, in your opinion?

No, I, I don't know. I can listen. My logic tells me that's part of it, but part of it is it's, and you know, um, Garrett and Wes would know better, but I think these groups have had time to grow and mature. And just like MSPs now, you didn't see, you know, private equity back. You didn't see people with 60, a hundred, 130,000 this maturity. Um, so I think it's, I I feel like it's part of I especially SMB, it is just growing up, right? Mm.

And there's another, between now and the end of the decade, the, you know, the amount of technology and the amount of SMBs and how much they're gonna use it, it's gonna outrun GDP. That means the opportunity for bad guys is gonna outrun, you know, their tam is growing right along with it. That's my logic on it. But I'd like to hear maybe what Garrett has to say. Well, I mean, their marketing is fantastic, guys.

Like, if you look at, I, I don't, I forget which threat actor campaign this was, but when they shuttered their doors, they sent out a message to everyone and said, Hey guys, we won Crime Pays. We netted over $2 billion in this, this threat campaign. And everyone saw that. Everyone has been seeing that for quite some time.

So I liken it just to the, it's extremely lucrative and threat actors are very good at getting their name out and bragging, uh, about how lucrative their, um, their endeavors are now that sometimes has bitten them in the behind a couple times. And, uh, having a little bit too much bravado in forums. But, you know, it's, uh, remains the same. It's out there, it's very lucrative, and it's very obvious that it is.

And to Wes' point, uh, you can see, uh, financial evidence of, of how lucrative it's, So this dovetails nicely into the next question. You know, like you said, it, it's the services providing command and control. Um, why, why choose this over something like a Cobalt strike or some other, um, commercial C two options? Ah, cobalt strike. Uh, I hear co I hear Cobalt strikes are up this year, by the way. I dunno if you saw that, that marketing gaff, uh, done. Anyway, you'll have to dive into that.

Um, yeah, so I think probably because of the feature set that we're talking about, it's, it's much easier to use. Um, you know, I was always of, of the opinion that Cobalt Strike did, did a really great job providing command and control framework to, uh, nubs like myself. But, you know, dark utilities takes it to like a whole nother level. It's already set up. Uh, you just have to sign up with an account, pay your money, deploy the agent, and then you're rocking and rolling.

And if you run into issues setting it up, well that's fine. They've got tech support ready and happy to help you. Which is the part that really blew me away is it's a very fervent and active, like, you know, when, when you look at this from kind of, from an objective point of view, these are folks that are very proud to do what they do, which is very interesting. Um, and you know, like I said, it's, uh, another reason why you would choose this is it's very affordable.

Um, why, why would a criminal enterprise pay money? I mean, why would they pay for Cobalt Strike to begin with? But I dug into that and you'd be surprised at what users are willing to do for good support. I mean, just, just thinking about back in the day, you know, I had to roll probably not to dime anyone out, but probably had to roll your own tools back in the day, and having support for that would've been fantastic.

Um, so I'd say, you know, parting software for a network of a couple users is probably feasible. But when you're looking at gangs, the size of Conti, the size of what we think dark Utilities is, um, supporting thousands of users parting their software, the ROI is probably more in the, let's run the gamble of actually paying for this and getting our, you know, possible, uh, paper trail out there.

Because like I said, you know, they, they, they, they're big businesses just like, just like we, uh, work in, I think we should hack them. Can we hack them? I mean, we, we can, like are we allowed to? I, I, I think they're, uh, so lot we Get to work on that, Wes. Well, yeah, and there's precedent of it.

You remember when we were going through all the exchange attacks of the, I forget the name of that threat actor all of a sudden, um, and us, um, was it CISA that actually corrected the vulnerabilities in those remotely and there was a bunch of stink around like, should the US government take action both state side and foreign on some of these things, right? So it's happened, there's precedent. I mean, that really is the mission of US Cyber Command, right?

So just from my history, the head of the NSA has tool had it, he's the head of the NSA as well as the head of Cyber Command, right? And Cyber Command actually owns that mission is, um, we loosely call it the hack back mission. Now, it literally used to take an act of Congress to get that permission at a national level. And so we used, you know, so how effective can you be? You know, I don't know if they've done some course corrections since then. I haven't really, um, researched into it.

But it is, you know, it is something that the government at least has thought about. But of course, There's lot of s literally an act of Congress. Yeah. They, Hey Phyllis, if we give us Like firing a weapon, right? And what was that? Go Again, from a legal perspective, they don't distinguish between hacking back and firing a kinetic weapon in an enemy. Right? That's kind of the confusion.

I actually said this in a different webinar where, um, we have laws around like, like things in the physical world, like a kinetic weapon going into a bank, physically robbing a bank. Do you have a weapon? Do you not have a weapon? But in cyber, we try to apply those kinds of laws to cyber, right? And so then it's, it becomes very confusing and murky. Judges don't understand it, lawyers don't understand it. You know, you look for precedent and stuff like that.

And so, you know, we're working on that internally, even at CIS like, what's it mean to implement a control properly when someone goes to sue you and their information is actually, you know, um, divulged or whatever. So it it is, it is, it is hard, Which is why it kind of freak all of us out when there's some legislation possibly barring the use of penetration testing tools. All of us we're like, cool. What the hell are we gonna do then? You know? Yeah. Well, you can only subscribe.

That's right. That's right. Hey, Phyllis, I was just gonna ask if, uh, we get cyber call up to 5,000, do you think you could get general, um, nakasone from the, uh, US cyber command to join us? We'll see. We'll see. Maybe. Okay. Everyone hands up and chat if you wanna see Phyllis do that. Woo-hoo. That's funny. That's funny. So, you know, I, I love how, you know, not love, love, but I mean, it is impressive. You know, dark utilities has tech support.

They're probably really responsive, you know, of the low, low price, 99 euros per month. Um, you know, we have already 3000, um, sub subscribers. Um, Oh, it's nine, nine euros, Oh, nine euros. It's even worse. Even better. So, you know, what do you think now you don't have to be some, you know, technical guru to write your own malware or whatever. What, how do you think this actually changes, um, you know, how attacks are gonna be occurring? Sure.

Well, and this is, this is something that I think about and talk about a lot. Um, and this starts off, of course, horribly back in my day. Uh, you know, you had to have serious skills to pull this stuff off. You, um, needed to have a pretty decent understanding of how to write, or in my case, how to copy and paste code, uh, horribly. Um, you needed a, uh, an understanding of network and systems architecture. Um, and you need skills and tailored access.

And if for those of us who have that in, you know, trade craft, that's not an easy thing to just pick up, especially back in the day. Um, 'cause remember a few people were even like checking email, you know, back in the day when I was a script kitty. Um, but I would say, you know, um, we've seen kind of an evolution of these tools, this technical prowess in, in tool form.

Um, first one I can think of, and, um, you know, I don't know if I can say this on your call or not, but there's a tool put out by the CDC called, uh, Bo, uh, back in the day. And it provided, uh, yeah, you know what I'm talking about. It provided, you know, access to some not yet widely known Windows exploits, uh, that anyone that could point and click, you know, had the ability to do that.

So, um, we're now seeing, you know, fast forward 10 years ransomware as a service, we're seeing, uh, all the, as a services. So to your point, Phyllis, uh, getting this, this capability in someone's hand, all you really need to know now is how to transact, uh, via Bitcoin. And you can pretty much buy bespoke ransomware. You can buy reconnaissance, you can buy initial access, you can buy a service to facilitate your phishing.

Um, and you know, like the thing about it, back in the day, if you didn't want to get caught after you did all this very cool technical things, you had to know about operational security. You know, you had to know, uh, uh, know how to hide or have a network of people that could hide you. Um, it might require skills that are esoteric, like forgery and, and, you know, uh, laundering money and stuff. So anyway, all of this is a moot point.

Um, when you have a robust supported platform that operates over a peer distributed network, um, and it's payable via anonymous money, you know, it's, it's kind of scary. 'cause all said do is sign up. It's really lowered the barrier to entry, um, big time for cyber criminals. It's crazy. Gary, you always talk about sales entrance barriers, don't you?

Yeah, like I said, it's a good, it's a really, listen, as we learn more and more, what we, again, what we find out is the hard part here is these are now, you know, you know, larger, more mature organizations than most m most all MSPs. And so, um, that, uh, you know, that that changes, that changes the game and our responsibility and what we need to do. Yeah.

And it, Garrett, this reminds me of like, you remember back in like the early 2010s when you had like EC and all those that had like this super script kitty friendly, uh, DOS attacks, like low orbit ion Canada. Oh, yeah. But it was literally as easy as put an IP address or domain, send us Bitcoin off you go. And they took the visa down with that.

It was easier than that because they got all the script kitties to download the low orbit ion cannon, and little did they know that was just a botnet, and that was controlled by a, you know, in some cases by a larger kind of puppeteer. So yeah, it's, I mean, again, we're, we're seeing the same thing. And, and if I had a crystal ball, I, I would say that this is only gonna ramp up like the lull in payments. I'm kind of paranoid.

I almost think like maybe a lot of people are going back to the drawing board to create a competitor for dark utilities before they Mm-Hmm. Start their next threat campaign. I don't know. I don't know. But yeah, go ahead. Gary, you mentioned earlier that, you know, kind of like, it seems like they're starting, you know, in the gaming area, this and that, maybe low hanging fruit, not so sophisticated.

Is there some precedence And, and West, feel free to chime in also, like of threat actors kind of like making, you know, it's like, Hey, let's get our feet wet, make sure everything's working well before you see this potentially escalate into larger attacks, is, if that makes some sense. Yeah.

Because naturally you're gonna have lower technical prowess, folks getting access to this tool, so they're not gonna go for the gusto and use this to launch some sophisticated, you know, sec, you know, multi-stage attack, like you're saying. They're probably just gonna use it to dos their friend's, you know, Twitch stream, which interestingly enough is like a very viable attack vector these days, you know? Right. All right, very cool.

So Tali mentions that, um, dark Utilities uses the interplanetary file system. Mm-Hmm. Quite honestly, after I read the blog, I had to look that up as well. But this helps make them resilient, um, to content, um, change or, um, law enforcement. Can you give us a little explanation about what IPFS is? Yep. So, uh, same here. I had never heard of it, so I did a bunch of research on it. Um, and it's pretty interesting.

Um, again, I'm probably gonna date myself again, but I draw a lot of parallels to like early, uh, peer-to-peer file sharing, like Kaza, Napster and stuff. Um, but modern day would good parallel would just be like Torrance. Um, but the interesting thing about this is when you use IPFS, the, the files are broken up into random, uh, size chunks. Uh, they're encrypted. Um, they're sent to a, a very large number of distributed instances. It's not, not a one-to-one or one to many.

It's kinda like a random shotgun approach. Uh, not random. 'cause of course there's math involved. Um, and then each chunk gets a unique, uh, fingerprint. It's called a, a content identifier so that you can find this later, much like Torrance. Um, but the thing that makes it very different, and I I found a lot of similarities in early worm activity.

When someone looks the file up, they reference all the nodes that store this content identifier that automatically down downloads that chunk, caches that copy of the chunk to your local file system, and therefore you automatically become an, uh, another node. So it's almost like a self propagating peer-to-peer file network. Um, which is interesting.

So because, um, because each chunk gets this unique identifier, if you were to say, add a new version of the file, um, that gets added to IPFS, the file gets new CIDs for only the changed parts. Mm-Hmm. So what does that net you? It gets you two immediate benefits. Um, what you store in this file system is automatically resistant to any kind of tampering or any kind of censorship. 'cause you have a, a blockchain like lifecycle reference of how this file has evolved.

Um, but for the frugal felon, uh, you keep bandwidth and storage costs down too because you're only, uh, storing the changes, you know, so the net net of this is that this is designed, designed specifically to thwart, uh, monitoring activity or any kind of taking of this service down. You, you would not be able to cut the head of this dragon off. Wow. Awesome. Thank you for that detailed explanation. Wes. This is super interesting. Does everybody agree with that?

Yeah, I think it's, I mean, keep in mind I'm this like security nerd that's deep into crypto, and so I see IPFS, I'm like, I know what that is. Like I, it, it's this weird Venn diagram where it all converges for me and like this weird nerd, uh, uh, collision. So I'm into it. Carrie, Crypto meaning cryptography, not crypto money, right? I I'm talking cryptocurrency, baby. Okay. Like the new term that like, everyone's like cryptography, crypto's never meant that before.

So let's, We, we both we're both interested, but for the opposite reasons. Right? I like, I'm interested on a macro level. You're interested on a micro level. Yes, yes. Yeah, exactly. And I happen to be crypto poor now, so, you know, whatever. Uh, yeah. All right. So Garrett, let's Talk real quick.

Not not to hold things up, but, um, the only good thing about, um, a lot of, uh, young crypto dudes, uh, you know, taking a little hit in the while it is, it's, um, it's bringing down the price of watches. Yes. Turns out a lot of that money was being spent on watches and driving up the market. So really, Gary, almost Now, the watch market is tied to, uh, Bitcoin. So now's the time to buy, huh? Yeah, today I learned, this is awesome, and I know you're a man of your watches.

That's what is a that's what Andrew said. I, I get a free submariner for participating in this, this panel. This is fantastic. Yeah. Gary's got 10 of them. Just, Just Reach out. He's probably got 'em on his jackets, you know, All on one arm. Yeah, exactly. Alright, Garrett, let's jump back in. I got a question around, let's get practical. Uh, do you have any experience on like the SOPs, like standard operating procedures of how, like people get access to an environment through this?

I mean, is it really just click button, get ransomware? Or like, what, what does the SOP look like? I mean, yeah, that's, it could be anything really. Uh, just looking at the assumed skills of these attackers, or maybe they're shrewd business decisions, it's likely something low brow and pedestrian, like, just like you said, like a wide net phishing campaign.

But, um, this could just as easily be used in later stages of a targeted campaign or, um, even on the heels of some purchased, uh, initial access. Um, what I found interesting though, is because of the lightweight nature of the client side deployment, it's just a small PowerShell script that could be embedded in anything. Um, your options are, are almost endless.

Um, something cool that Thalus pointed out was that they're offering ARM 64 and arm V seven one as architectural deployment options, which, if you know anything about that, that opens the door for compromising network devices, phones, uh, IOT devices like cameras, which is a very attractive attack vector because, um, the primary building, uh, component in IP cameras is, I don't know if you knew this is Swiss cheese. It's just riddled with holes.

Um, very, I mean, early IP cameras were just riddled with exploits. In fact, I, I don't remember where I read this. I wanna believe this was official documentation, but, um, the initial install docs for HD Moore's, uh, network discovery tool Rumble now called Run Zero. Um, they, they suggested that you could ex install the Explorer on an IP camera just because of how lightweight the agent was. So I would, uh, expect that because we're seeing stuff like arms B seven one, arms 64 right now.

Um, they're likely exploring other lightweight, you know, uh, zero day like deployment options that we just may not be looking out for or that everyone's not looking out For. Just real quick, is it, if I could, interesting Garrett there in, um, the Sands, you know, storm center's, uh, morning, uh, uh, podcast Johannes referenced that, um, there was this, uh, vulnerability found in ring cameras.

And, you know, um, he, he goes on to talk quite a bit about like, what you could do if you compromise the camera. It's pretty frightening, uh, things that I wasn't even thinking about, but Well, 'cause that's not normally in your initial scope of assessment, especially if you're starting out looking at an environment. I mean, that would be like second or third stage, but certainly not the first. Yeah. Wes, Back to you. And Yes, I laughed at my own joke. I know that that's, yeah.

And they're saying We didn't give enough reaction to your Swiss cheese Joke. It was pretty good. Yeah. Yeah. It was a little over my head initially. I'll, I'll admit. Uh, yeah, it's fine. It's all good. Okay. So, uh, now that we understand SOPs, like it's, they've made it crazy simple. Yeah. What about on the defender's side of the house? If I'm an MSP and I'm looking for this, or even flip this to you at Huntress, let me ask it from that perspective.

What does, what does Huntress do to look for presence of, uh, this activity? Well, I'm not gonna speak for huntress on the threat ops team, um, but I, I would say that we don't, we don't have a lot of data out there in, in terms of, uh, signature based stuff. I know Talos included a a list of IOCs, which are some, some file hashes, maybe a couple domains, but, But you're subject to change upon will, They're subject to, I mean, I mean, like, I would guarantee they would change.

Um, so I'd say, And, and where they're useful is like regression analysis. You wanna go search for history. Yeah. Okay, keep going. But, but as far as like, you know, you're, you're heading in the same direction, like you could look forensically at, at how prevalent that's been, but if you're looking proactively, um, you know, you're gonna have to just update your controls.

And I'm not saying don't rely on signature based things, but update your EDR, make sure it's covering what you want covered. Um, but I would rely on, you know, hunting and behavioral based things, uh, looking for anomalous activity in addition to, you know, bat uh, batting down the hatches in your, your existing controls, which I could go on about basics, but DNS obviously, uh, email security firewalls, you know, training your, your basic, uh, security hygiene.

But yeah, it's, so back, Back to hygiene then. In other words, because this is so new and emerging, we might not see the presence and activity of the kit itself, but we might see the aftermath of it. I might see, you know, lateral movement. I might see some kind of like, uh, privilege escalation just goes back to the basic hygiene things that have always been tried and true. A hundred percent. And so, and that's a great point. So they have seen dark utilities used in some known malware samples.

So you will hopefully identify it and, you know, post exploit, uh, after, after you get popped. But as far as identifying it, like we can look out for cobalt strike, I, I don't know that we're there yet. But again, I would double down on, um, you know, SSO and MFA training your people, um, naming and shaming and phishing simulation. Like, I'm a big proponent in that, like, you know, let's, let's get people through that. Um, password management.

I mean, this is kind of like when we, when, I mean, every time we see a a, a new zero day come about, it's like, well, we don't really know what this looks like, so let's revert back to what we know, which is just basic security hygiene. Okay. Is the kit itself, is it mostly focused around the exploitation or does it actually have, like, actions on objectives, capabilities like ransomware?

Does it deploy its own brand of ransomware, or is it mainly just about compromising and getting access and then you still have to figure out the outcome on objectives yourself? I mean, I see this as a, just a next stage cobalt strike. It's a C two, um, platform. Uh, it, from what I understood, it doesn't provide any kind of initial access. I think they just have PowerShell, uh, scripts to provide the install.

They do have a, a crypto miner based off Monero, which is pretty slick because again, the chances of your average person writing their own crypto miner are slim to none. But there's a DOS engine, which, or a denial service engine, which is probably their, their main weapon.

Uh, I'm not sure on the bespoke ransomware, but I mean, again, that's a trivial point where if they didn't, you could just go get that at a very low cost if, if not free, but your, your mileage may vary when using free ransomware. Not like I have been burned by that in the past, but, you know, maybe look under the hood before you start, uh, experimenting with that. Okay. That's good. So, uh, summarize, I got one last question for you before I flip to Gary, but so summarizing, it's new.

We don't know a lot about it. It's certainly worrisome because they've made the supply chain even easier on the threat actor side. Um, but we still come back to the basics of good hygiene, good visibility, going after the things that we normally do for anomalous activity, uh, presence of hunting on my, on my network to look for things that might be anomalous.

That kind of puts me in my happy place a little bit as a defender to say like, at least it's in my territory of defense, you know, going back to Ryan Weeks, his whole, you know, defend your, your own turf and, and, you know, protecting your own house becomes, I can, the same things that have always held true are still here today. Right. That's kind of a summation of what we talked about so far, Garrett. Yep. Yep. Okay.

I mean, if, if you wanted to be able to identify this, I would say that you'd have to have your own 24 7, uh, research and response team. Uh, it's, it's just not to me, in my opinion, just not feasible for your average, uh, entity to have the capabilities to identify this, this type of activity. So, well, I, if I translate that and how it impacts, uh, us and our customers, what we need to do basically stays the same. Uh, just becomes more important because this increases the chances, right?

Um, because it widens distribution and effectiveness that, um, that our, if not when, may come sooner than later, right? Yeah. I mean, I In the lottery go up, What's that? Our chances of winning the lottery go up. That's right. And, and this, this, to me, I mean, it's, it's very significant, but I don't see this as like a, a huge, uh, step. I just see this as another bolster of this rising tide of, of it's just gonna get easier.

Like I said, I would expect folks, because this is so novel, to be inspired by how novel it is and go out and build a, a better dark utilities, uh, uh, platform. One that maybe, uh, doesn't require, you know, the, any kind of scripting expertise. I mean, I, I don't know, but if you had asked me five years ago, how do you make Cobalt strike easier? I I don't know what I would've said, like a point and click gooey is all I can think of.

I'm, I'm just picturing that there's like, um, you know, down the line, there's just a DattoCon for dark tools where they're well organized that they can all come and have a booth and Oh, if you think that doesn't exist already, it it absolutely does. It's just not in, you know, meat space. Yeah. Yeah. Is that like MEET space or MEAT space? It's called humanware. Yeah. Yeah. Sorry. Yeah. I didn't wanna miss another Swiss cheese joke or any type of food stuff, Garrett.

No, I'm just Exactly Didn't wanna assume here, Wes. All right. One last, one last question for you, Garrett. Yeah. Yeah. Uh, so we're thi things like this are forcing MSPs to even go faster. To Gary's point in the maturing my security capabilities, my messaging, the right packaging and pricing, because as we consumerize threat activity, we, we open the doors and we widen those doors to even more. And so, you know, this just becomes more prevalent, right?

So do MSPs, are they gonna, are you seeing any that are coming down this journey being like, we're gonna take this even one step further and we're gonna hire some really good security, like Jason Slagel level in-house talent that are like leveraging great tools, like, uh, Andrew in the notes, I know you had mentioned Rita, for example, from Black Hills, which is an awesome tool.

Are you seeing MSPs kind of grab and seize onto some of these like deeper defender, enterprise level defender tools, whether open source or, or, uh, or, or enterprise, or is that still kind of like, that's probably not happening from the majority of us. We're gonna outsource that to like, really qualified vendors, or we're just not gonna do it at all? What are you seeing? Yeah. Uh, interesting, interesting question.

So right now, I think we're, and just to, I know I'm not here to plug Huntress, but like we're being really successful on the Hunts side, being able to have a threat ops team and then, uh, research all the data that our users are collecting, and then use that to kind of force multiply our efforts. I'm not sure that we're at the point where it makes sense. And, and this is where I'm totally ahead of my skis.

I'm not sure that it makes sense business wise to have a threat ops team at the MSP level at this point. 'cause I'm not sure that you're really getting that.

Uh, again, saying things that I don't even know what they mean, that return on investment, um, I, I, um, I see MSPs again, focusing probably on partnering with vendors that have that capability, and then f figuring out a, a way business wise to create an offering that is affordable, that is usable by their, uh, by their user base, rather than focusing on bringing that, that functionality in house. Now, if you want to use Rita, uh, I think that's a, a fantastic example.

In fact, I really wish John was on here 'cause I'm not gonna do a, any justice on this. Um, but I'll give it a shot. Um, if you don't know about Rita, uh, it's a, a really cool analytics engine that sits on top of, uh, bro, IDS, which is a open source, uh, host, IDS, um, it uses what all dub, um, sorcery driven math that I don't really understand. Um, and it, it brings kinda like the, the needles and the hay haystack to the top.

It, it identifies what they call perfect beaconing, which I think is really cool. Um, 'cause, you know, if, if anyone who's ever used a, a SIM or an IDS knows, they, they don't really work that well. And especially in a small team, um, that ROI, again, that comes up, um, you spend a lot of time fiddling around with that. So Rita is something that I think, actually it's a great point.

Um, maybe an MSP could use that, especially in a, uh, maybe an interim, uh, between the, you know, detection to the response time. They can start looking for, um, kind of needles in that haystack. So, Andrew, so I don't wanna go, sorry, go ahead. Yeah, that makes total sense. Andrew, you work with John, um, as much as anyone, I know John Stern as much as I know. Are you seeing MSPs using Rita? Are you having conversa and or other similar kinds of tools? What are you seeing, um, on that House?

Yeah, no, that's great. I mean, so the, some more advanced ones are starting to look at his commercial version of it, Wes, which is active countermeasures, because, you know, again, I think it's maturity thing and, and, and, and I think, you know, on both sides, right? You know, they're used to dealing with big enterprises that use either Rita and or active countermeasures. Um, but yes, I do see some of the more mature MSPs looking for solutions now, um, for Beacon. Absolutely. Okay.

That, that's a really good point. 'cause Rita is, I mean, it makes, uh, a whole mountain of data very, very easy to use. But I, I still probably wouldn't say that it's approachable for most folks that are in a, uh, in an MSP, especially the ability to use that in a, a kind of effective manner to deliver a service to their users. Um, now John May, uh, disagree with me and say, well, we're developing active countermeasures just for that reason.

And, and I would say that he's right 'cause uh, that that ability to see that exploded view, as John likes to call it, um, that is the key for us to, to find things these days. 'cause I think SIM and IDS is just a, a waning return. Yeah, well, well, if you think about it, I mean, there's a very small handful of really large scale right? MSPs that you see out there that probably still use third parties, but they have, you know, 4, 5, 6, 7, 8 people right? On a security team.

Um, then you have some mature MSPs that understand security, but they're gonna have to outsource. They can't have the time, the process, uh, or attract the talent right. Pool, you know, that they need, right? But still, if we add those two up, I'm saying that's a very small percentage of the marketplace. So now you have masses.

And I don't know, I think Garrett, some of it you might, you deal with a lot of people with this, but even when they're using, you know, outsourcing and using vendors and tools, they sometimes don't even have, you know, the process or the, uh, expertise or the bandwidth to even act properly, right? Mm-hmm. On it, that and that, I think that's a big risk. Well, we see a lot of supplementing of services too.

In fact, I've been a user of these supplemental services where you kind of build in a path to self sustainability. 'cause like you're saying, even if you have access to these tools or this data or whatever, you may not know what it's like to use this in a business setting or use this in the context of an incident response or something like that. So I think you're right.

It's probably prudent to, even if you want to take on these functionality to look at a, a kind of waiting in the, you know, the shallow end a little bit and, and build a path from totally manage to that function in-House. And then just to kind of dovetail off that, I would also concentrate on just a specific function, rather than saying something like, well, I wanna bring penetration testing in-house.

You know, you should focus on one very specific thing that you would like to assess, bring that in-house, and then move on to the next capability. Much like anything else, Gary, can I just say something that you just said? Because I, I, I really gotta give you kudos. Um, so Sunil Yu does, uh, it was one of his RSA talks. Wes, you remember this when he's like, and this is for enterprises, and he is like, you know, raise your hand.

Tell me like what became shelfware in your organization and, and Wes, like, sim and those types of solutions were Amongst it. It was Id s and sim Were they the top two? Yeah. I actually presented on this just a week ago, using some of the Sun's data from that study. Yeah. Did, Can I, can I interrupt real quick? Yeah. I think Phyllis is waiting for us to readmit. No, she's, she's here. She's Here. Okay. I can see her. She's just, sorry, she's off camera and, and on mute.

We're We're we're getting dogged in the comments. I, yeah, no, no. She's acknowledging that She's either her dog's going crazy. Uh, we can, we can all you wanna all guess on what it might be? Um, no, she's here. I can see her right down there. Sorry. Um, but yeah, we, wes, um, it was really interesting. I'm glad you mentioned that Gary, and, and I, Wes, I think the punchline was when he asked like the why again, it became people and process West, right?

It was, it was lack of those things, even at the largest of large where you see everything becoming shelf or garage. So I'm, I'm Glad you So you're saying Andrew? Yeah, I think what Andrew's referring to is sometimes when I'm doing a live presentation in front of MSPs, you know, there'd be two plus hundred people in a room. And I'll always say this, how many people here, you know, feel good about security, and all the hands go, some of the hands go up.

How many here feel like, you know, they're really, they're a proactive MSP and all the hands go up. How many people here have at least one role in their company that isn't assigned tickets, alerts, or has to bill hours and very few hands go up. I'm like, well, who's being so proactive then? Like, you know, where's it, where's it happening? Uh, speaking of dogs may just opened the door and came in. Nice. I love it. He just opened the door themselves. Yeah.

And he just sat himself on my, on my couch. It's hilarious. Um, so I wanna talk for a minute. Um, I got a few different questions in the time we have left, and I wanna leave time for, you know, for some, some, if people have questions, I, Phyllis Phyllis, they thought we were like, dogging you or something here. I dunno. Meanwhile, hello. I know I was gonna do occupy Andrew.

I was gonna, Yeah, one thing that I was thinking is, as you're going, going through this, um, I read somewhere, I'll give you two stats. I read somewhere that the average MSP has like 17 tools right? In their stack, and some percentage of those, a lot of them are agent based now, right? There's a lot of agents. Um, I can tell you the MSPs between two and 20 million that we work with in our peer group, um, they have about 30 tools, right? Average about 30 tools.

So I was thinking about just securing your tools alone, right? I i is a whole nother thing that you have to deal with. Yep. Well, thinking about m and a, think about when you, you know, acquire a company or merge, and now you've got totally different systems of applications that use permissions in totally different ways. You might have two Slack environments and they've got integrations with your code repos in totally different ways.

So yeah, I mean, uh, that, and then agents kind of, uh, either duplicating efforts or maybe they're gonna act in interference with one another. Um, can't speak much about it, but I worked for a software company where EDR was a very difficult proposition because the thing that we produced was in direct competition with the EDR. So, um, that rendered EDR almost useless in looking at very specific, uh, attacks that we had come across the wire.

So first question I had for you is, um, the platform, it supports, um, different forms of DDoS attacks. Yeah. Can you tell people more about that and why, in some scenarios that might be a better option, uh, for, uh, a threat actor than ransomware? I mean, as a denizen of the internet, I'll say, why not both? Um, I, I'd say use one and then follow it quickly with the other. Um, but really, i, i, I would say it depends on the target.

Um, if my target is a large business, um, ransomware's probably gonna work nine outta 10 times. They have a lot to lose if their environment goes down. Um, and they probably have a cyber insurer, or at least some kind of like, you know, ransom fund, which by the way is the worst idea ever to have a ransom fund. Um, so they're prepared, uh, it's built into their, their BCDR plan.

I mean, it's, it's kind of part of it, but what if my target is a lucrative eSports team that's sponsored by a country that I don't like? Well, I can't just ransom a couple of their gaming PCs, because as anyone who's a gamer knows, I mean, those things light on fire all the time. You just, you just get another one going.

Um, but if I can take down their, uh, streaming content, I can, I can doss their Twitch account or, you know, dos their discord or something like that, well then that renders them completely incapable of doing business. It's gonna tank their customer sad. It's gonna, um, you know, if you can man in the middle and impersonate them, that's even worse. You could broadcast obscene content or things like that. So, um, but, but seriously, why not both?

Because if I were on the offensive, I would absolutely do both, uh, one after the other, hit 'em as hard as they can while they're down and make sure they're dead. So does this platform make it easier in from that standpoint for people that may not have, um, use that tactic in the past? Absolutely. Yeah, because the agent is multifunctional and it doesn't, it doesn't really have a single purpose, and likely they'll be expanding the purpose. So who knows, uh, what it could be used for.

And, and, uh, in the future, it could be a, a very viable, uh, initial stage, you know, acting as a dropper to download more tools. You could act as a, uh, who knows a tools compiler for new functionality. It could introduce some polymorphic aspects to where it just changes on the fly.

Um, yeah, I, I, I see this as the, the new way of attack, uh, methodology where the agent is just kinda like, multipurpose, kinda like what we see in the, Yeah, I mean, look, if you think about it as you said, you know, it's like there's this evolution, but if we look at like, you know, just think about like what RMM did for MSPs. Absolutely. It, it took, it wasn't like overnight, but it, it was the building block of changing things.

So this, this is kind of like the equivalent, like same thing now we're seeing, like with some of the RPA stuff, right? It's Starting today, but as, as a defender, I, I kind of want to see the silver lining and, and hope that, you know, much like taking an RMM down, uh, maybe this large network of, you know, interconnectivity. We can elucidate some sort of way to, you know, like David and Goliath. Um, bring the time down. Yeah, I don't know. So the, uh, the choice is discord, right?

For user authentication. Can you tell us your opinion on that and what's the reasoning there? I mean, again, I think it's probably a, a speaking to the ease of use, familiarity. Um, again, I'd imagine the bulk of their user base probably already uses Discord. So there's no, um, there's no learning curve. Um, but also this plays into their desire to offer good support. I mean, you've, they've probably got a support team in one of the Discord channels, um, next to your off dialogue.

So, you know, it's, it's a good old single pane of glass, right? Um, but also I think it probably makes it harder to shut this whole thing down because you'd have to take Discord down to, to stop them from logging into the service. Uh, as well as, you know, if you wanted to, like, a common tactic would be to shut the, um, cut the head off, you know, uh, prevent the threat actor from communicating with the rest of their organization. Um, but you can't do that with Discord.

You would at least have, you would have bought some time to where you could then communicate out your secondary method of communication, whether that's a Telegram group or, you know, whatever. Some other, maybe Just a couple people. Someone said here, what's Discord? Maybe just give a high level for people aren't are aware? Oh, yeah, yeah. So Discord is, uh, it's a really great app. Uh, it's, it's like a chat app. Um, it's integrated with a lot of, uh, streaming, a lot of gaming.

Um, I use it for a multitude of different, I'm not gonna say all the things that you use it for, but a multitude of different things. Gaming, uh, interfacing with professional groups. Uh, DEFCON is actually over Discord. So the virtual side of DEFCON is all over Discord. Uh, so it's a very, very malleable platform that has a lot of kind of, um, uh, engagement, uh, type feature set. So again, would be great for a vendor trying to make a, a name for themselves and offering good, uh, user support.

Um, so for a second there, you talked about, you make your Swiss cheese joke on IP cameras, but I, I wanna just maybe just circle back because mm-Hmm. Um, this platform does help people, like with mobile devices, IOT Maybe just talk for a minute about like, how does that expand, like the, the attack surface? Yeah, sure. So I, I, I, I think I touched on it earlier, um, these architectures, these, uh, I mean, just like a programming language, it may not be approachable to, to a lot of users.

So if you had a specific target that had a bespoke architecture, you'd have to learn about that architecture before you could write code for it, or even steal code and, um, you know, retrofit it to that.

But if you've got someone that just offers, like I said, this multifunctional agent that will have functionality added to it later, and you're already developing it for these, uh, newer, lightweight, uh, protocols or platforms or whatever, I just think, again, it, it opens the door for a larger technical prowess being available to a, a, a smaller subset of, of maybe not so technical users.

So like SCADA and iot, I mean, I don't want to give anyone any ideas, but like, you know, you start opening the door to that kind of stuff and the, uh, the attack surface expands exponentially. Um, so I think that's, that's probably one of the things that scares me about that, is that they are looking to make this, uh, expandable and extensible and maybe even the ability to write your own modules in the future. I don't know. I don't know, Wes. That's not something we talk a lot about here.

Right. And I don't think, um, when you think about iot, I I don't think that, um, I I don't on in terms of securing it, I, I don't think that for MSPs it's high, high on the list. What's your experience? I mean, yeah, there was a heyday in like the pre, you know, maybe 20 18, 20 19 era. You guys remember Garrett, you remember, um, the Mariah Botnet? Absolutely.

Um, my friend Bryon Medlock did a ton of like, chasing and, and going after, um, uh, uh, that botnet and then it just seems like it's, it's fou fallen into passe. You're right, Gary. Like we don't really talk about it. And it's super scary when you consider it's a foot, it's a foothold, a very easily accessible foothold. Um, that's cloud enabled that's right behind all your defenses. Like that's super scary when you think about iot for sure. Yeah.

And a lot of things that get connected to, uh, get connected to the network that maybe the MSP, if they don't have procedures in place, they don't even know about it. Right? Well, I would say They get put in by other, other types of vendors that come in, like, you know, like you said, a security vendors low voltage vendor, a a, a AC vendor security vendor.

The more esoteric the technology in my opinion, the more likelihood there is for some kind of middleware to have to be developed to where you don't really understand what's happening in the middle of there. Like, so, you know, you're talking about IOT and things like that.

Well, if you can write connectors for that, um, you don't necessarily have to be able to program and whatever that language is, you just have to be able to interface with that top level tech and again, makes that available to someone who maybe shouldn't have that available to Them. Andrew, I think, I feel like we're adding to the MSPs to do list every week here. I have a question though. Do you think it's because like, are MSPs not supporting the organizations that are using iot?

'cause it's very prevalent and talked about like in healthcare and then, um, you know, also, like I do a lot with the SLTs. We talked about LA that last week, and they're very concerned because all the parking meters are, um, you know, online kind of like IOT devices for them. And there are all these things now, um, that the, that the localities and the cities are using just so they can track.

I think we're only gonna see more and more of that again as smaller countries start to enable, um, the ease of use of going and collecting data on gas meters or something like that. Like that, that ability to interface with that remotely is just gonna go up. And then as we see in dark utilities, uh, who knows, they might have a connector for that someday to where you can go and, you know, turn off all the gas in a certain area pretty easily. Go ahead Andrew, you're on mute. Andrew.

Andrew, you're on mute. I was gonna say, wow, Yian. So we are in for a real treat here. I know we last few minutes, but Giannis, I wanted to, uh, have you introduce yourself as you know, you know, the former, um, if you ever, you guys ever heard of UBS, I mean, this is the former CISO for UBS. He's a rockstar in Europe, uh, in terms of a CISO and consulting. And I'm Grateful just for the UK that was Yeah. Oh yeah. Worldwide. But he's actually one of the top consultants to ISC squared.

He, they're, they fly him over on like a Lear jet. But, um, Giannis, you had a great question. This Is not a good intro. Great intro. Tell us a little about yourself. And I love your question on deception. Um, my name's Giannis Palu. I, uh, about 25 years ago or so, said to my parents, I wanna go do a PhD in what was information security. We call it cyber these days. Uh, really passionate about our discipline.

Volunteer for IC squared, elected to the board of directors as a volunteer, um, come from a technical background, years of pen testing, um, exploit writing. Um, had to hang up the keyboard to become a ciso and currently consulting, um, virtual CISO business is booming as some of you have Yeah. Reverified in this talk. So I asked a, uh, a question on chat, which I think got me, uh, to be here on the panel with you guys. Yes, exactly. You know what a really interesting, um, discussion.

And I spent, you know, as a hobby, um, the complaints of my family and wife and friends. I spent a lot of time studying, uh, cyber deception last year. Read up all the books. Um, and actually we tried with a couple of clients to industrialize the adoption.

And that late last discussion that you guys had just before I joined where we were discussing adversarial techniques versus the defenses, uh, organizations have got me thinking would we even, you know, bring in a topic like cyber deception where we know a server and just to give a brief intro for our audience, right? Cyber deception, um, the adversary will get in and what we want to be able to do is obfuscate as much as possible, hide, uh, the server structure.

So, you know, if it's a Windows server, it doesn't have like a program files directory. Um, if it's a like a a Linux box, right? Or AWS Linux or whatever, it doesn't have a, a user s bin and the normal file structure is just completely, uh, all over the place. Plus that's very solid techniques. So that's cyber deception. And just one short sort of 22nd description, and I'm not doing it justice. Uh, there's authors out there and people doing great work in it.

Uh, so would we bring in cyber deception to the adversarial defenses that were being discussed? Yes. No. And if so, for what reason would we bring it in? I, I, so first of all, sorry I got lost. I now have access to dark utilities, Andrew. I'm in it right now, including their telegram. Oh, Probably lost you and your good friend Chris Sanders does a hell of a job on cyber deception. I'll have to have 'em back.

We, Yeah, that's what I was about to say is we so Yani, it's great to have you on and I think there's so much to say about this that we're already a minute over, but we, Chris Sanders, we had him on and he talked about, uh, deception. I know that Huntress is doing some deception stuff with their canaries, which is really, really cool. And it's a no-brainer. Um, if I were to go start a company, I would, it would be so fun to do a deception company.

One of my friends is Gadi Evon, who is the CEO of Rio. It's just like an enterprise play on deception. And they got bought by somebody. I forget who, Yani. But, um, I, I mean there's definitely a play in deception as a defender's tool set, and we're not really beyond what Huntress is doing on, um, canaries. We're not doing enough with it. So it's a worthy discussion for sure. Yeah. Well I know we went over Garrett, so good to have you with us. It was really, thanks so much for having me.

Yeah, no, you were awesome. It was a real thoughtful decis uh, discussion. Um, Giannis, thank you for, uh, allowing me to pull you up. Um, it was a real honor having you on with us. Thank you for sitting in. Um, Phyllis is always great to have you. I know Gary had to leave. Um, Wes always my friend. Great to see you. It was a great, I hope everybody enjoyed today. It was, uh, I thought a really fascinating discussion and somewhat frightening of how easy things are getting for threat actors.

So until next Monday, I'm wishing you all a fantastic week and look forward to seeing you all back here, um, next week. And thanks. Take care everybody. Thanks so much. Bye all. Thanks all. Bye bye-Bye.

Related Videos