Skip to main content
Right of Boom
January 30, 2025

Super Charge your Cyber Skills – John Strand

In this video, cybersecurity expert John Strand discusses the importance of Sysmon logs for incident response and day-to-day troubleshooting. He highlights how Sysmon provides detailed and useful event logs on Windows systems, which are essential for identifying and managing security incidents effectively. Additionally, John emphasizes the significance of accessible training and the need to reduce financial and time barriers to empower more individuals to enter the cybersecurity field.<ul><li>Sysmon, developed by Mark Rasanovich of Microsoft Sys Internals, provides enhanced logging capabilities on Windows systems, offering valuable insights for incident response and troubleshooting.</li><li>John Strand emphasizes the importance of providing accessible security training, removing financial barriers, and creating opportunities for individuals from diverse backgrounds to enter the cybersecurity field.</li><li>The Backdoors and Breaches card game is a tool for incident response training, allowing users to simulate and practice handling security incidents, and identify skills gaps in their teams.</li></ul>

Guests

Andrew Morgan
John Strand

Video Transcript

Welcome, everybody. Happy Monday. And we are at session 1 33. And, uh, it's great to see all of you out there chatting it up. We have an one of our favorites, fan favorites, crowd favorites, uh, favorites in general. Uh, Mr. John Strand with us today who will do an intro momentarily. I just got a few quick announcements.

First off, probably the biggest announcement is, and I'll, and I'll probably say this more times 'cause we, a lot of people are coming in right now, being at the top of the hour, but we will be, um, giving away, right a boom sponsoring five, um, courses, uh, five seats in John's course, uh, next week. This is, uh, uh, I, I I think one of the most critical courses, uh, that John teaches John is teaching it, which makes it that much better.

Um, but, and John's gonna give us a preview into that today, kind of called the supercharging Your Cyber Skills course. Okay, so that's number one. Again, don't hate me 'cause I'm gonna reiterate it again, if you wanna see what the course is like it is in the call to action, the green thing flashing below. Um, I know John's looking, uh, kind of, I, I think naked is, is a good word. Not afraid though. Not just naked. Just naked.

Um, alright, so, um, and then in, I'm putting in the, the chat right now, uh, just a few things. One, one of John's top Red Teamers and an amazing instructor, uh, Bo Bullock, is going to be doing a webinar on top M 365 attacks and credential compromise. If you have not seen Bo, um, this is not to be missed. He is amazing. Um, and so articulate. Um, so that is in there now. Um, it's sponsored by Cyber Fox, um, but it will be Bo um, and I'll get to moderate that with Bo. So it's always awesome.

The last thing I'm going to put in here is, um, the cyber cast, um, that we did most recently. Hadie Matley, um, with Phyllis Ryan Weeks and Wes. And this was on control 16, uh, application software security. And, uh, Jim Manco, John at the end, very animated. Jim Manco is hysterical and, and, uh, and he now has an owas course on your platform, which is very cool. Yes, he does. Alright, so lemme set the stage. There is a poll up.

So, uh, John, we have like hundreds and hundreds of people in the cyber call and we'll get like three people to answer the poll. We still don't know why, 'cause it's always a yes or no. Um, I don't know, maybe I'll start doing like, abstract questions or something and we'll get more people so that, that one's still an anomaly for me. Alright, setting the stage and then we'll do an intro to John.

All right, so, so knowing, and this comes off of John's, uh, write a boom, uh, presentation, which was awesome. Uh, you know, so knowing MSPs and MSPs are on the front line and, um, you know, recently, um, CrowdStrike's report that only 30% of MSP, I'm sorry, only 30% of organizations have MFA fully enabled. Um, and that, uh, by the way, John, only 112% increase in, uh, access brokers in this past year. Um, my suspicion is we will probably have some more activity in 2023.

Is that probably a fair statement to say that, um, access brokers are, are, and, and cloud environments are gonna be under a heavy attack. But, um, so with that, I wanted to, um, give you guys the best opportunity, the best instruction, and the best in the business. And that is Mr. John Strand. John, welcome.

Not everybody knows you, you've become, you know, in the last few years a household name in the M-S-P-M-S-S-P space, but for those that may still not know you, if you could tell a little about yourself. Yeah. Um, I am the owner of Black Hills Information Security. I am also, as Josh just pointed out, I am the card game guy for breaches. 'cause that's how I'm going to be known now for the rest of my life is that game.

Uh, I also own Antis Siphon Security training and I own Active Countermeasures, which is a network security monitoring tool, which is free. You can get the community edition, you can pull it down from there if you wanna play with logs. So there's a lot that, that, that we do in this universe, right? Um, we're giving a tremendous amount back to the community in the form of webcasts going on. Things like this, pay what you can training as well.

If you click that link soc core skills, you can take it for nothing. If you click the link, go to the bottom of it, it says, if you need your educational assistance, click here and it'll take you to a $0 amount because we're really, really trying to focus on making the entire community better. Uh, before all of this, I was a senior instructor with the Sands Institute for 15 years.

Um, I was in the room, uh, when the critical controls were first bantered about, and uh, it's just been a very, very long career so far. And people are wondering where the beard went. The beard goes away in the summertime. Whenever I'm running outside, whenever I'm swimming, whenever I'm snorkeling and surfing, the beard goes away and then it'll be back this winter. So it'll be back this fall. Don't worry, it's fine. Yeah.

John, one thing I do want to say, and I hope everybody takes this into account, pay what you can is not the same as pay pay, you know, kind of like pay what you want. Um, can in the, in the, and the reason I just wanna say that is to be fair to everybody is, you know, can you talk about why you're doing it?

I think it's important to understand what you call the gates and, and don't just sit there and go, I'm gonna give $15 when, you know, you're, you're getting a course that if John was teaching this at SANS is $7,000. They only charge I think 5 95, but, um, 6 95, 8 95 Is what they for a full six Yeah. $8,000 course. Um, so, but, but talk, talk if you could about why you're doing this and, and the importance.

So kind of going back to that, when, whenever I was teaching at like Black Hat and other institutions that were more expensive, um, you would have a room of a hundred people, 150 people, and you, you would have this belief that you were making a large impact in the community as a whole. And I came to realize, especially coming on to this show, there's no chickens and there's no rooster around right now.

Um, at the moment when I first came on, I realized there was this monstrous group of individuals that far dwarfed any other information security individuals that were out there that were not getting the training that they needed. They were incredibly underserved because they didn't have the budgets. Um, they didn't, can't take the time. It's one of the things that blew my mind talking to MSPs. They're like, I can't afford to have people out for a week. I just can't.

So we wanted to meet people where they were, because I do believe that this is one of the most important things that's happening today, is this idea of people are trying to build things and they're trying to make the world a better place. And then we have this whole group of people that are trying to not do those things and knock everything down. And the MSPs are the front lines in that battle.

So being able to help as many people as possible with world class security training is really became kind of my mission, uh, for the past few years. And somebody said, John comes on and the first thing he opens up is, here's not to give me money. Um, it's easy to make money when your goal is not making money. Uh, we do just fine financially, don't worry about it. Uh, but we practice quantum capitalism whenever we do marketing and sales by not going after the sale and not looking at it.

It's in the box, it's the cat and, uh, we, we do just fine. But we found that giving back to the community, the community will continue to give back to us. Yeah, absolutely. Um, okay, I'll say this one more time. For those of you that got came on late, um, the write of Boom is sponsoring five people. Um, and, uh, we'll pick those at the end or during, based on your interaction. So, um, this is a chance for you to speak up, ask questions.

John is gonna take the floor momentarily, but before he does, um, you know, so if you have any people by the way in your team that have hands-on keyboard, that um, uh, you know, can really benefit from understanding the core, most essential cyber skills, um, I would get them into the cyber call soon. 'cause we are gonna give a pri, John's gonna give a primer to what's his training, the training next week. Um, Phyllis, you have a few quick questions for John, so let me let you knock those out.

By the way, welcome Phyllis, it's nice to see you. Um, we're sitting here talking like you don't, you're not even here. I'm sorry fellas, but it's great to have you as always. No, it's great. It's great being here. And hello everyone and hi John. I'm so glad that you're here.

Um, we know that you're gonna provide, um, us some, uh, training or today on the cyber call, but um, before we get going, can you share with us, um, what should MSPs be looking for, um, when they're trying to build their cyber security skills? I mean, is there a place that you should start, you know, what, what is that path that organizations especially MSPs can be taking today?

Well, and, and I think the main answer is what Andrew and I have kind of set out is trying to provide this pay what you can training. Uh, there is a ton of resources online. Uh, John Hammond with Huntress does an amazing job. There's plenty of YouTube videos. Uh, get your team together, do cyber range challenges, uh, hack the box, try hack me.

Uh, if you want something that's a little bit easier that you can work through that has step-by-step guides, look at the holiday hack challenges from Ed Scotus and Counter Hack and its cute little 2D like final fantasy style video game that involves hacking challenges and forensics challenges. And there's actually walkthroughs where you can go through the entire thing and pick up these skills.

So there's a lot of places where people can actually learn to pick up these skills, but I think learning to pick up the skills is one thing. Working in such a way that it impacts towards a goal is another. And that's why I think when you're looking at the skills that your team wants to have, looking at implementation group one, and I also think implementation group two is not that hard, uh, from the critical controls for many, many, many organizations.

Look at the skills gap for getting to implementation group two and truly try to focus on those skills that will get your organization to that level. I hate to say compliance 'cause it seems like such a dirty word, but let's, let's go with it. That'll get you to implementation group two. So when you're setting up your training, look at implementation group two, say, this is what we have, this is what we are missing.

And then work towards that goal and objective with your training, with the certifications that you choose to go after or cyber ranges to develop those skills to meet those requirements or certification points. Oh, I love Phyllis. That's a great answer, huh? I think that's a, I was just say, I think that's a, a great answer as well because what it does is it bounds the problem instead of like, just be better and get more skills. It's like, here's how you can be focused.

And I really like that answer to help folks get focused because there are, cybersecurity is huge and it's like, just like implementing a framework training folks, you know, you also need some guidelines. So I really appreciate your, um, answering and your thoughts. Um, well you're Mr. Back doors and breaches. The car guy. The car guy, You know, and, um, we all know that it teaches MSTs as well as MSPs how to be better prepared, um, to handle incidents.

And I'll tell you, we're so excited you're here because you know, we've, we've asked so many times on cyber call, do you, do you have an incident response plan? Have you walked through it? And for the folks that have answered, um, the answers haven't been that great and um, you know, people really liked your presentation at right of boom.

Um, and so can you just quickly walk us through one role play so we can understand how does back doors and breaches work for or for those folks who haven't, um, haven't played yet. Sure. Alright, so I'm gonna share my screen. This is a great kind of, we into this. Let's go through, right, you should be able to see my screen now, right here. There's three different decks. Don't get too wrapped around the axles.

Um, we're adding more decks as we're bringing in more, I guess diversity and the technology footprint of back doors and breaches. If you just want the basics, you can choose core version two. And this website that I'm at is at play dot backdoors and breaches.com and I will copy that link and it's available once again for, for for free to everybody. I'm gonna put this in the chat like that.

John, will you, um, will you also share after you do a role play how you're kind of morphing it into the training with it? Absolutely. I'll show that next. That's really cool. Yep. So we've got the core version. I'm just going to do that one and then I'll go to demo, uh, do back doors and breaches in just a second. Okay.

So the way the actual physical card game works and the way that the game here works is the same if I'm an incident master, I can develop a scenario that involves an initial attack and compromise card. In this example, it's an insider threat. I can have a pivot and escalate how do the attackers move laterally in the environment. And then I can have command and control and data exfiltration.

In this situation it's HTTP and I can choose a persistence mechanism, which is a malicious browser plugin, and I can just come up with a brand new session on the fly and it will automatically come up with a new incident every single time that I hit new session. This gives you the capability to start working through your procedures and once again trying to find skills gaps and try to address those skills gaps as quickly as possible. So I'm just gonna stop on this session.

Um, this one is web server compromise, new service creation. DNS is command and control and application Shimming are the techniques that the attackers use. And I can reset these cards 'cause I know what it is, and now I can share my screen with the people that play. Now as the incident master, I set up a little story. We say, well, Bob came in in the morning and noticed that there was a dancing gerbil, um, on his web server. Like goofy, what would your team do?

And these blue cards down below every single one of these blue cards is the steps that you can use to work through that incident, right? So sim log analysis, uh, if you're working with something like perch memory analysis with tools like Velociraptor and Volatility Endpoint Protection analysis, this would be something like, um, uh, CrowdStrike, some type of high-end, nice EDR. These are the different techniques that you can do to try to flip over these cards. So it's all about the conversation.

So we say, well, the first thing that we would do is we check our SIM and see if there's any logs or any alerts associated with dancing gerbils. Well, because it's on this top row, it's a plus three modifier showing the importance of having documented procedures. So if I roll the dice, I click that it was a failure.

Now in this game, traditionally failures are much more interesting to me than when things are successful because now we can ask a question of the people that are playing or your MSP or MSSP teams, why would that fail? How often does SIM log analysis actually fail in our organization? How would we recover? So you would have a conversation about why that would fail, and then somebody may say, well, let's do network threat hunting. We can roll the dice.

That one's 11 plus three means it was successful. And that would flip over a command and control card. As you can see, the command and control card says, detection is network threat hunting and firewall log review. We flip that card over, once again, we have that conversation. So all of this boils down to these blue cards at the bottom can be used to identify and flip over these cards at the top.

And if there's anything at the bottom that your team doesn't know how to do, how would you, how would we do UEBA, how we do network threat hunting? How would we do some log analysis, memory analysis, and so on. Now you've identified a skills gap and all of these can be tied back to the critical controls, um, in a variety of different ways. One of the ones, I think it's Control eight still, uh, log analysis. I'll be talking about that now. Andrew was talking about another website.

Lemme just go here. I can just do this that we stood up specifically for right of boom, and it's still out there. It's called Demo back doors and breaches.com. P is the problem. Let's do this. Don't have a certificate on it. And this one is a little bit more complicated and a little bit different in this one. You have to set up the game, you have to choose your deck. I'm gonna use the core deck, submit that, and then I'm going to go to Scenario Tools and I'm gonna generate a random scenario.

Now, the difference between the demo backdoors and breaches.com and the play backdoors and breaches.com is every single one of these cards down at the bottom has links. Like if you look at Cyber Deception and you say, I have no idea where to begin on Cyber Deception, I can open that up in a new tab and it opens up back doors and breaches. Cyber Deception says, here's an example of how to set up a Honey share Canary token honey user.

So we've got step-by-step instructions from the pay, which you can intro to soc core skills class with instructions on how to set up those things. And then we also have videos on how to do these things as well. So this becomes not just a game, but it also becomes an outstanding resource for you to learn more about the topic at hand. So we've got, you know, how to do memory analysis with volatility three, how to use basic volatility. So it becomes a training engine on top of it being a game.

So if you get to anything you're like, I, I have no idea what I'm supposed to do for endpoint protection analysis where we have a link with some instructions that goes to a lab. We had this really great session with Huntress where they provided a system where people could log into a entrance tres instance and play with an actual incident inside of the Huntress dashboard. And we're gonna be working with some more vendors on this in the future because people seem to like that quite a bit.

So it ties in education and awareness into the game and makes it a lot more accessible for people. Uh, so that is, let me see, that is how you can actually play back doors and breaches. I'll go ahead and close out my screen share. There we go. So let's see if anybody has any questions about that. Yeah, that was awesome, John. And by the way, I put in a, a poll real quick to say, Hey, would you like to see your favorite security tools vendors built into back doors and breaches?

Um, and, and 'cause I I, I could foresee this eventually being one of these things, John, where we can, you know, like, Hey, this is a better EDR than let the let the community, you know, hey, I could do a memory analysis easier with this tool versus this tool. Um, right, Absolutely.

And, and this is why, and it's not, you know, a vendor saying it, it is hands on, but they're getting the teaching, the training and the incident, um, scenario becoming better at what actually is happening on the keys, um, and the role playing. So really cool stuff. By the way, I wanted To share one quick thing, Andrew. We had a couple of people go, were asking Questions. It's your, it's your, it's your, it's your thing. So they were saying, um, one, we can play it with our customers.

You absolutely can. Yes. The other person asked, this is on GitHub. It is. So the actual source code for the entire thing is on GitHub and you can clone it over to another web server and you can change the branding. Instead of it saying Black Hills information Security, you can totally put your own company's logo there. So you can use this as a sales tool, not just a training tool, but a sales tool for your customers as well. So there you go. Cool.

Um, there was a quick question here in, uh, um, from Keith. While, while skills and tech are core to our knowledge base, so much of good security hygiene is based on culture, leadership, integration, workflows, processes. We are not disrupt. And so we're not disruptive to the business customers we serve. Uh, what's the best way to train your staff to understand workflows IE lean manufacturing so we can integrate good best practices with existing process flow?

I think that's what Keith is saying. Just, uh, see if that makes sense to you. It does, and when you're looking at that, you have to look at it in a couple of different ways. All right. So once again, I'm gonna share my screen. Yeah, of course. First way to look at it is when you're dealing, specifically what I'm talking about today is incident response, right?

And the reason why I, I really think that that's a great question is a lot of people when they look at, especially training, they try to create flow charts. Like, if we're dealing with an incident, this is what we're going to do and then we're going to do this, and then we're going to do that, and then we're going to do this, and then we're gonna close out the incident. And in military doctrine throughout, like, like most all of history, that is a really incredibly bad idea.

Whenever you're in a confrontational situation with an adversary, anytime you set up flowcharts, then you're working in flowcharts making the assumption that the adversary is going to move in a predictable manner and that doesn't work. One of my favorite quotes from Dwight Eisenhower is, plans are useless. Planning is indispensable. So what is the differences between those two? Especially when it comes to ir?

Well, the plan would be step by step by step what is supposed to happen, whereas planning is you have a whole bunch of individual discreet things that are at your disposal. So when we're playing this game, it isn't so much like what is the plan, but what are the individual procedures that exist in your organization that you can use and you can leverage and your team is trained in to be able to handle that instant.

So at no point do I say this is how you string these things together, because that's a bad idea. But rather you need to understand that e everybody in your team needs to be trained on how do we do endpoint analysis, how do we do firewall log review, how do we do UEBA and SIM analysis in our environment? So you're not looking at it as a very detailed plan on how to deal with something. 'cause the adversary's not gonna move the way that you expect them to.

But rather these should be the Lego bricks that you can use to address any incident that hits your organization. If you want kind of a mental model of a Lego movie, absolutely love the first Lego movie. Second one, not so much. But the first one is great. And one of the cool things about the Lego movie is they're constantly taking Legos and they're building things on the fly that help them solve problems.

So when you're looking at these procedures, these should all be individual Lego blocks that exist in your organization. Little individual, discreet, quantifiable areas of training and skills that your organization has that you can assemble to deal with in the incident. There you Go. Yeah, that's great. Um, and then John, the other one from Ben is, am I correct in assuming this is back to the get hub, you can make your own decks? Yep.

You could mod, he's like, could you, so could someone modify them so they could do IR for things non iot related? I'm not sure. Yeah, Absolutely. Yeah, all the art is there. You can pull it down, you can make your own cards, you can add them all in. It's pretty much all available. Yep. Yeah. Very cool. Alright, fantastic. Um, alright. Um, so keep the chat coming. This is fantastic. Um, let's just see, uh, on the polls, John just bel just shy of 40% of MSPs that have answered.

Again, like I said, we only get a fraction of an answer.

Um, I won't be as harsh as a Gary Pika comment, but, um, but, but I think it's pretty amazing that oh, almost 40% now of the people on here have taken a course, uh, with you or some or someone at antisi and that's saying something in the, in the short period of time somewhere, what was it, several thousand now have gone through collectively MSPs, we have, We take MSPs outside, like, I don't know what, we haven't broken it down for a while because you and I found out that's really hard 'cause people register with their personal email.

Uh, since we've started doing this, we've put through, uh, my class has had about 25 to 30,000 security professionals through it. And Chris Bruton is about 35,000 security professionals as well. So we're, we're talking just a monstrous amount of people and that once again tells me there's so much pent up demand, not just for security skills, but there's a huge number of people that have the, the ability to be able to come in and do computer security. They just don't have a on-ramp, right?

They don't have a degree, they don't ha they can't get certifications. One of the things we talk about a lot is I have people that are truck drivers for some reason we have a huge number of truck drivers that can get into podcasts and they just listen. And then they've transitioned into information security. Um, we've had a number of people, parents that have worked two jobs, uh, kind of minimum wage jobs just to make ends meet, being able to transition into computer security.

And we're trying to make that, make that number as big as we possibly can. Very cool. And yes, an overwhelming number. We have one contrarian here that would not like to see their favorite security tools and vendors built into back doors and breaches. Um, that'll, that'll be an interesting one of the why you wouldn't, but, uh, hey, it's great to always have different flavors and different, uh, perspectives. Absolutely. Okay. Um, so John, let me, let's see. I have one other thing here.

Let me just take a look. Uh, Well you're looking for that. I got a question. Yeah. Um, Jeff said it, write a boom. John alluded to an EDR he thought was really, really good. He declined to state the vendor at the conference. Um, yeah, I'll state it. I I will not rip on any vendors. I need to make that very clear. I don't like to say negative things, uh, about people because it's just like my opinion man.

Um, but uh, the, the two that we see a lot and we really work to get around and make sure that we're on point for our Microsoft Windows defender is absolutely phenomenal and Microsoft's doing a great job. And the other one that we see quite a bit is CrowdStrike. Uh, CrowdStrike hasn't quite gotten the penetration in the MSP space yet. Uh, but in larger corporate America and corporate just in general, they're everywhere. And that used to be silence was the gold standard.

Silence got bought by Blackberry and not saying that they're bad, it's just CrowdStrike has really been upping their game Yeah. Um, over the past couple of years. So There you go. Yeah. And I think, I think this could be the year we see CrowdStrike, really, I mean, not only did they state it in their, like, you know, in their earnings from the CEO that they would be coming down market. Um, but um, you know, just stay tuned.

We might know a thing or two, um, that we won't say, but it'll be interesting to see, uh, what's happening in the next, um, uh, next, uh, few we months here with CrowdStrike. Yeah. Uh, coming down market. So one of the questions specifically about this, Eric brought up a point, tools don't matter, it's the concepts that matter. And that's Why I couldn't agree more. And I agree 110%.

Uh, what we are trying to do, like we said with uh, like bringing in interests or other vendors is I, you know what, let's bring the vendors in. Uh, if we can create training step-by-step and they can put it into a platform somewhere, then I think it creates an environment where MSPs can try Sentinel One, they can try CrowdStrike, they can try Microsoft, even though Microsoft probably won't answer my phone calls.

Uh, but we can have all these vendors that are willing to come into a platform and it's not necessarily the core concept of the class, but it's something that people can try and see what actually fits best in their environment.

The other thing that I think we're missing on that, on that thing, and then I'm gonna stop and get off this really really quick, is a lot of vendors are in these weird echo chambers where they have their own r and d people, they have their own salespeople and they're constantly just kind of repeating and parroting back the exact same thing. Their CEO, their COO, their CFO, their CMO says. And it becomes an emperor's new close thing.

And my hope is whenever we can bring vendors into, like we did with Hunters, which I thought was great, we can get people to come in and say, this is cool, but it would be cooler if it had this. And we can start getting that feedback out of the executive echo chamber and maybe some of these vendors will make their products better. Yeah. I think that's the exact great reason is, is that to have that feedback Mm-Hmm.

So that vendors can actually hear from organizations that are using their tooling and hopefully, you know, build in some automation and all of that Yeah. That, um, that everyone needs so badly. And I just wanna say one more thing. I also really like, um, you know, what I liked about your story, about how you're training folks from all walks of life, from all ages is that when we talk about, um, trimming down or um, filling the cyber education gap, we often focus on college Yeah.

And things like that. And so I love the fact that you're out there, um, on the front lines, um, bringing in a new model that, you know, college is not for everyone. People have had different jobs for different reasons, and it doesn't mean that they're not capable, they just didn't have the access. And here you are giving them access. So, um, I applaud you and I love that. And I also think it gets into the diversity issue. Yes. 100. Yep.

And this is gonna sound horrible and, and it's gonna make people cringe, but one of my problems that I have with the whole diversity concept is whenever we're talking about groups and trying to bring in specific groups, we automatically exclude other groups.

And like for example, we have Pacific Islanders at Black Hills Information Security, we have people that are Native Americans, and traditionally those are marginalized groups that don't get as much, uh, like, like play because they just don't have that large of a percentage of the population.

And there's a lot of other things, like you talk about, um, for some reason we have three women or have had three women, um, at Black Hills Information Security that have raised their kids and they decided to reenter the workforce. They didn't know where to go, and they came in through what we were doing here at Pay What You Can Training. And they were able to get the training, get an on-ramp to get a career, whereas traditionally that path wouldn't have been there for them. Right.

It's really, really, really hard for a lot of these different groups. So when you're looking at barriers, most of the time the barriers are financial. Like whenever we're talking about most barriers, not all of them, they're absolutely barriers in finances and financial ability by doing the pay, which you can thing. And this gets into the quantum capitalizing, uh, capitalize, uh, uh, what is it? I just completely capitalism thing.

When you're dealing with that and you completely reduce the barrier to entry for cost down to zero, then all of a sudden those gates disappear. And it doesn't matter what your creed, sex, religion, anything like that is anymore background anymore. It's that that financial barrier is destroyed. And I think that that's the only way that we can open up inclusion in this workforce to have the greatest diversity.

So now the people that have the skills and have the will and have the desire, regardless of their background, are now invited to come play and get involved. That's what we needed to do more than anything else.

So, like I said, it's a little weird, but I think that, uh, I think it, you know, you, we all know people that for whatever reason, either they didn't go to college, like you said, maybe they got pregnant, maybe they had a family member that got sick, maybe they had something in their, like they screwed up when they were 17, 18 years old and it precluded, precluded them. Maybe their family didn't have the financial ability.

We know people with a variety of different reasons that are brilliant, they just don't have the opportunity and we're giving them the opportunity. I love it. Thank you. And John, the other thing before I let you know, I want you to take over and give a, give the supercharge course here. But, but the other thing that I think is really critical, it's not just the bringing down the financial gates, but for MSPs and MSPs, it's also the gates of time. Like Yeah.

So if you could just describe like how you do a course, because again, an MSP as you said, can't just say, sure, take my engineer out of the office for, you know, five full days and don't worry about it. That's not a reality for MSPs. No, It, it, it's really not. So a couple of things on that timing, uh, a little bit of inside baseball that people don't know. We have a 50% drop off and attendance from the first day.

The reason why we get on and we tell people it's recorded, it's here in Discord, you can come and you can take it at your leisure. And we have a huge number of people on the other side of the planet. Yeah. Um, we were talking like India and Singapore, Malaysia, Philippines, all of these different areas. We literally have people like a couple of, one person I've hired in New Zealand, I might have two people from New Zealand now I'm not sure that are there. And I'm like, why are you here?

It's 2:00 AM go to sleep, come back. So I think that creating a schedule for the pay what you can training is really, really, really important. But I also have noticed a lot of MSPs look at it and they say, this is available to you. Right. Go do it. And they're seeing certain employees that take advantage of it after work and they have certain employees that maybe aren't disinterested and they're not forcing everyone through.

And it makes it available for the people that wanna learn these skills to have those skills as well. That's awesome. Good stuff. Alright John, let me, uh, in the interest of time, and I'm gonna keep an eye here for some more people. I've got a few written down that are gonna win one of five, um, cla one, one of five seats in your class next week. Um, again, if you wanna learn more about what the class is, it's in the, uh, call to action below.

Um, but John, take us through a little bit around, you know, the key concepts, whether that's, you know, I I I love how you talk about, you know, even things like Windows and the next command line, how you would teach a a a a core a a, you'd be teaching in sand and you'd start off and these security people that are very bright didn't have the basics. And, and wasn't that the genesis of a lot of this? That was the genesis of a lot of this.

Actually the full genesis was I had a cyber deception class. I love to teach and I had a bunch of students that are like, cyber deception and all of this stuff is great. Do you have a core security? Just, just what are the 10 things that we need to do to make an attacker cry? I'm like, I can do that. So we jump right into this class and immediately people were like, this is great. I don't even know how to get to a command line. And then we created the soc core skills.

So it, it's easy as an instructor to basically say, well, my students are dumb and if they're not smart enough, if they're not at this level, it's easy. You, they just shouldn't be here. Man, that is so exclusionary, right? And there's so many people that are technically brilliant, but they've never been exposed to a specific technical concept. So SoCore skills was the basics, right?

Then you move up to core security technologies, like the top 10 things you have to do plus backups, and then you get into cyber deception. So really it's, it's kind of that arc from the beginning all the way to get people ready for my cyber deception class that I love to teach. Yeah. Is What we're doing. So, so let, let's, uh, you wanna share your screen a little bit, John, you wanna just talk through it? Yeah.

Aaron, while you do that, Aaron brings up a point about, there's a flip side of the coin. Employers often don't do a good job izing training. Someone at the first rite of Boom stood up Aaron an employer and who's a big advocate for training his people. And he is like, you know, so many MSPs out there I hear. And these, uh, you know, one of the things is, you know, if we train our people, what if they, you know, we train our people all this good stuff and what and what if they leave?

And, and he said, you know, my answer to that is, what if we don't train our people and they stay? Uh, which I think is one of the best quotes I've ever heard. Um, yeah. So I think it's just great. Yeah. All right. So Andrew, you gave me a, you gave me a bit of a difficult task. Oh, okay. You said when, when we were coming into this, you were basically like, Hey, is there just something that you think is so core that every MSP needs to be doing it, but they're probably not doing it?

And normally I'd pick up like network threat hunting, and I could talk about that a little bit, but I really wanna focus and I wanna talk about if an incident occurs, the logs on your endpoints that you absolutely need to have is essential for an incident, but also day-to-day troubleshooting. 'cause a lot of what MSPs do are trying to figure out what did the user do? What's going on with the system? How is this working? What problems are we running into?

And the answer to a lot of those problems are having the right logs come into your sim, the right logs that you're getting as an analyst. And specifically I'm gonna be sharing with you, uh, sson. So let me go into the event logs on a Windows system. You should be able to see my screen. If you can't, Andrew, let me know. Well, we can see it. Great. Absolutely. All right.

So we're gonna go into standard Windows event logs right now, one of the things I like to talk about in the class is Windows event logging. The way that Microsoft set it up is basically the equivalent of giving a monkey a whole bunch of psychedelic drugs and then asking that monkey to develop a logging system with vague hand paintings on a cave of what a logging system would entail. So if you're looking at, we got like a credential manager credentials, were read, okay, that's great.

We enumerated credentials a bunch of times. Okay, that, what does that actually mean? Um, special privileges were assigned to a new login. What, what does that actually mean? It's, it's, it's, it's insanity. Like Microsoft event logs are horrible. On the application side, if we're gonna look at the application logs, you would think in the application logs there would be logs for applications that started. And that's not quite what you're seeing here, right?

Duplicate definition of policy found policy name a, a D block, a a D workspace, joint default priority equals 100. What does that even mean? Right? Uh, so we have all of this stuff and it's horrible. And this is what's being fed into a wide variety of different sims and log management solutions that are out there today. And they're bad. Like, they're just absolutely horrible.

I remember when I first got into computer security, one of, uh, one of the people that was so patient and helping me, his name was Mark Brunick. And I remember going through the Windows event logs and I'm like, they've gotta be broken. And he is like, no, that's literally the way the event logs read. I'm like, they, they have to be broken. Mark, this is absolutely horrific. He goes, no, this is the way it is.

And I remember getting depressed for a period of time and thinking this is the best that we're going to get because we're always talking about event logs. Event logs from Linux systems, event logs from network devices, event logs from firewalls, and the event logs themselves are garbage for windows by default. Now, a number of years ago, a gentleman by the name of Markovich, uh, from Microsoft SIS Internals, he was the original founder of NT Internals, which got bought by Microsoft.

He developed something called Sisson. And Sisson is what you would get for the event logs on a Windows computer system if somebody actually knew what they were doing in creating those event logs. Now you have to install and you have to run Sisson and you have to use a config. And I'd recommend looking at Swift on securities configuration or Olaf Hard Togs, Sisson Modular for the configurations for sysmon. But if I go to Microsoft and I go all the way down, keep going John.

I just have a question while you're finding it. Yep. When you got depressed, was that the point where you took the psychologic, psychedelic drugs, figured of there was a monkey involved and then you got happy again? No, whenever it comes to that, I don't need drugs, I am drugs. That just comes naturally to me. Okay.

So when you run cisman and it takes literally like five seconds to get it running on your systems, you get these event logs which are absolutely amazing event logs because now we're actually getting full event logs of what is going on in the system. So now I can see that DLL host XE ran on this particular computer system and it gives me the hash value of that. You can see that I started, uh, WMM, sorry, MMC, um, you can see the full path to which it executed, what was the parent image.

And I can just kind of go down through these things. And you can see Edge was updating. There was a connection out to Amazon where I'm updating a bunch of things in S3 where can see that WPA web proxy, auto detection fired as well. Um, what is the other one? Here we go. Trusted installer. My system has been sitting for a while. Uh, so I'm trying to find, trust me. But now we're actually getting the individual logs that matter on this computer.

So like I said, I have malware running on this computer system. So let's actually do something with that malware. So what I'm gonna do is I'm gonna hide my screen share 'cause it's in the bottom and I'm gonna open up a simple shell on the system and I'm gonna do net users. All right, so now my back door is fired, right? My interpreter session and now I'm running net commands on the computer system and if I refresh, I should be able to see that command.

In fact, right here you can see that the net command was invoked on this computer system. And if we start at the beginning, we get the U talk time, which is the only time that matters. The process id, the image, the full path to the image who wrote it, the net command, it's written by Microsoft. This is the full command that was ran was net one users. It was executed by me or my user account, A DHD.

And here's the hash value associated with it and then the parent process associated with it as well. So now we're getting actual valid, just amazing useful information from our Windows computer system and it just, I don't want that to run. There we go. And I now have visibility. In fact, I can jump jump into this even further and I can see how this all came about. I can see that, trust me, XE right here. The parent image invoked cmd XE trust me is my malware.

And now you can see it invoked CMD exe and then CMD exe, lemme scroll back up here. CMD EXE opened up the net command and net users was executed. So now we have that visibility into what's actually going on on this computer system. Now I mentioned this is very, very useful when we're talking about computer security because you can see the execution, you can get the hashes of all the things that you, you see executing on the computer system.

You can also see network connections, event ID three, uh, with some Sisson configurations. And now you have great visibility into what that system is actually doing. This is very valuable in an incident. If we ever get into an incident, many times our customers are giving us the standard Windows event logs. And like I said, those are bad. They aren't very good event logs and they're not very useful in an incident.

So with CIS monologues, I can get the logging fidelity of this process begat this process, which made this network connection at this time by this user. And here's the hash associated with it, which is golden for incident response. And the reason why I'm bringing it up here is we help a lot of MSPs and MSPs for IR activities. And this is the number one ask for my IR analyst for incident response. They're always asking, is it possible for these organizations to enable SIS bond logs?

And then we can import ingest and we can do analysis on them. But also from a day-to-day troubleshooting perspective, there's a lot that's really useful here, right? So I have these DNS queries, I'm currently uploading, uh, to S3, a large amount of data off of this particular computer system. And I can see those DNS queries and I can see where that data is going. I can see that there's a query, wild West Hackfest, John s3, us dash west dash one amazon aws.com.

That's not malware, but it's a great troubleshooting entry. 'cause now I can see the DNS queries that are being made off of that computer system as well. So this is great, not just for ir but also just general troubleshooting on someone's computer system. If a piece of software is not working or a driver isn't installing properly, the sysmon logs will actually help you do that analysis in a lot more efficient manner rather than playing the game of 20 questions with one of your customers.

Like, you got this malware on your system. Were you surfing porn? No, I wasn't. I wasn't actually. No, No, no. Uh, are you sure? No, I wasn't. What about Ling right here? This will actually give you that level of visibility. So if you're just gonna do one thing from this, honestly, if you could just start using sysmon in your environment, that would greatly help for IR and just troubleshooting as well. Oh, recommended configs. I'm gonna put those in the chat.

I think Andrew's got some questions. Lemme get you some configs while Andrew keeps Up. Yeah, yeah, yeah. Oh, uh, Isaac, I'm really glad to hear that. Um, uh, John, I'm normally in the background that people are saying, you know, listening to the cyber call kind of in the background, but now that you're on, you've actually brought it to the foreground. So we've actually upped our, so I, the good news is when you're here, people will listen.

The bad news is when you're not here, we'll go back to basically being background music, Background music. I don't know, I, I I, I like just listening sometimes to the archives and just kind of going through it because I'm trying to learn this space. Yeah. Because it's, it's definitely a different set of dance crab dances than the information security space for sure. And I just shared in the chat, swift on securities configuration at GitHub and Olaf Hard Talks, uh, cisman Modular at GitHub.

And, and just so you know, like you're Isaac, you bring up a great point. Like this is, you know, when, when, if you haven't taken one of John's courses, I mean, this is a glimpse into it. He's so in, you know, he's so engaging and he brings it to light. I mean, not that that's a true gift, right? That an instructor can literally, you know, for, you know, four days and four hours and you're gonna be doing labs at the same time, right?

John, in the course, and, and by the way, for, for the people that either sign up, if you don't win, uh, today, um, there, you know, if you pay a certain amount, you get the range right John, for a certain period of time as well. Um, yes, We do have a full cyber range and it's a great way to kind of level up your skills and share those skills with coworkers as well. Yeah.

And that, by the way, I'm gonna ask a question or two that I'm seeing here, but that, that's kind of the vision guys in gals of where we want to take this. Where if you picture like back doors and breaches, whether you're playing it internally by yourself with a client, um, would be, okay, we have this incident, then maybe we don't know this procedure. Well, let's just take that assumption. Okay, great. We, you link John, right?

We link into some training that is at your hand, you can listen to a quick video, three, five minutes. Um, and then from there, John, they would be able to eventually go into a lab or arrange right, to validate can they actually do that skill Yes. Or do they need to brush up on that skill? Is it, isn't that kind of the vision of this? That's the vision, right?

And, and I think the cyber range, and we're working really hard, the cyber range you have to pay, I think it's like $200 and then you get access to the cyber range and we're working really, really, really hard to find people that wanna support, make it available to everybody. Yeah. But it's not an issue of just doing the labs, but it's applying those labs in specific real, real world style scenarios. And that's why the cyber range is so important. Yeah.

And, and again, folks, you know, in John's credit, as you know, like someone said early on, John, you come on and basically say, tell me how I not to give you money, the range, obviously there's hard costs and ongoing costs, hence why he has a certain, you know, even still nominal gate to get access to that because there's a lot of computing power going on there. And we have people a lot, Andrew will say, well, why don't you just spin, spin up Azure instances for your students.

That is a great idea. There's Microsoft Labs, it works great for it, but a lot of these solutions don't scale to a thousand to 7,000 people. Yeah. And when you're looking at the costs of, you know, it's like it's only, it's only $15 a day if you have 7,000 people go through, that's not just like a small cost to absorb. Yeah. So, uh, that's why we're doing, once again, we're working with, with a number of different things to try to make it more accessible. Yeah, absolutely.

So Carl asked John, should sysmon be turned on only on servers? Nope. All systems. It all systems. Got it. And, and with, uh, Olaf Hard Ho Sysmon Modular or you're looking at like, uh, like, uh, swift on security, um, the logs are not overwhelming. Uh, so we currently have, I wanna say I think in one of our, well, it's not our largest environment, our largest environment's doing a petabyte of logs a day.

Um, but one of our environments is 30,000 and it's not overloading S3 or Amazon or anything like that, but it is about, it is tuning it and Olaf Hardman Modular will help with that. Cool. And John, I, I see Matt Lee out there. Um, I don't know if you can Oh, hey Matt. Yeah, I don't know if you can confirm or deny yet for PAX eight beyond, or, or, or can you, can you confirm or deny June you're Gonna be there in one way or the other?

Yeah, and just it's, it's, it, it's, we're trying to set up schedule and unfortunately it's not schedule for, uh, like work it's schedule around family and Andrew and you, Matt, you all know, it's like, Hey guys, I need, I need to make a decision. They're like, yeah, we're gonna get on that this weekend maybe. So we're, we're working on it. So yeah. So we'll, we'll be talking, we'll Be there in some fashion or another. Yeah. And we'll have Matt on at some point to talk as we get closer.

So just to, By the way, super excited about Pax eight being in Denver. That is going be That I was gonna say at least that helps with the family piece, right John? So PAX eight is, um, as you guys probably know, Rob Ray is there now and Matt obviously there. And, um, there's gonna be a security track. We're gonna have a day where John is gonna be doing a tabletop and, and a lot of this, ideally he's there, but one of his people will be there and then there'll be some sections around that.

I think what's gonna happen is someone in my family's gonna start talking about religion and politics and I'll just disappear in the morning and I'll be gone all day and I'll be back that evening and they'll be like, where'd you go? I'll be like, I went on a walk to Denver to A cool, yeah. I mean, look, that's very, very close by, isn't it, John? Oh, it's, it's for me, it's a 45 minute flight. Yeah. So it's very, very close as well. Yeah.

Um, Matt, is there any chance you could put the Pax eight link in there for the folks that are might be asking about beyond? Um, and just so you know, the security track isn't listed yet. It will be there. Um, Keith says, so as we design our staff training, what's the daily weekly slash weekly allocation that provides for quality education and absorption of knowledge?

IE two paid hours a week, you know, like, Ooh and I, and I've seen things like that where I think it's really cool that when people, you know, do that. But again, John, there's no right or wrong just what, what, what your thoughts Are. So, alright, so I'm gonna give you motherhood and apple pie and I'm gonna give you a reality, at least as how I see it. Motherhood and apple pie. We all get together on Fridays and we do brown bags and we all work together.

We hold hands and we skip off into the sunset. Um, or another of motherhood and apple pie is find a company that wants you to do training and they will pay you the time to do that training. That's awesome too. I, I find that that doesn't work. Um, so if you have an employee, let's say hypothetically, uh, when I went to Northrop Grumman, I got my master's degree in I think a year, um, which Northrop Grumman completely changed their, their tuition reimbursement because of me.

Uh, they were like, no, we can't spend that much money within a 12 month period. They change things out. But everything I did for that was on my own time after work. Northrop Grumman paid for it for the classes, but I wasn't getting four hours off a day to go to classes at night. Like I still had to work, right? And I, um, I, I have employees, same thing. They want to go go do training, I'm absolutely gonna support them going to training.

They're going to get their salary to go do that training, but then the actual practice and getting the certification, I'm not gonna pay for them to get that certification. So my point on all of this is, and this is a bit blunt, people only value things in so much as they are willing to pay for it. And that can be time and that can be money. So I strongly encourage you, let's go ahead and get your employees in to take the training.

But if they wanna do cyber range, if they want to do it after hours, that's kind of on them. Because I have found if you force people to do something, they tend not to take that initiative and run with it. Whereas if they're like, you know what? I went home and I spent like another two, three hours on this and I had such a good time, I did the cyber range.

That sets off a signal flare to me as an employer to say this is absolutely someone that I need to invest more time and more effort into making a security rockstar on my team. So like I said, it's it, the motherhood in Apple pie is the company should pay for everything. The reality is that the people need to take the initiative and they're the ones that get to keep that knowledge for the rest of their life. So there has to be a little bit of skin in the game on both sides. Awesome.

Um, okay, so being that there's about two and a half minutes left, if I get back to the questions, I will, but in the meantime I want to call out, um, the winners. So listen up. Um, I'm gonna put my email in here. Okay, so the winners, uh, are Ben Jones, Ann Westerham, Mark Moore, Wes Johnson, and uh, Eric br. Um, so, uh, if um, you guys could, uh, just send me a quick email, I'll get that over to John and, and their team, um, right, like I said, write a boom, sponsored this.

We've already paid for those passes as of this morning. Um, for you, uh, folks, um, just gimme a quick, I see Ben has acknowledged it. Um, did the other people here as well. So that would be Ben, Eric, Ann, um, mark and Wes, can you just acknowledge if you're still here and Yes. Good. Just email me, um, mark, email me. Okay, cool. So, um, with one minute left, um, uh, we'll bring you on to next time to prepare. So you have a week Wes. Um, alright, um, John, in closing. Thank you.

Uh, thank you so much for coming on. Phyllis, I don't know, went off into the sun somewhere. She lost her video. She said she was running into video issues, so Oh, is she? Yeah. Oh, okay. Um, so we'll be back next week, uh, on Monday. But John, thanks a million for coming on. I'm really excited about your class next week and, uh, anything closing that you'd like to, uh, to leave us with?

No, like I said, if you all have had people that have already gone through it, I, I, I think that that's amazing. Uh, but let's, once again, let's get some more people into it. There's so many people in this industry as a whole that could use this and there's so many outstanding people we'd like to come in and start doing it and it security with us all. So find those people. Let's get 'em in, let's get 'em in 'cause we need more security people and uh, it's a great job.

So let's get 'em rolling In. Awesome. Thanks again John. Appreciate all the partnership, uh, that you give all your time, your effort and your energy. Um, and until then next week everybody have a fantastic one. We'll talk soon. Take care later everybody.

Related Videos