1 00:00:00,039 --> 00:00:03,369 Welcome to another encore episode of the Backup Wrap-Up. 2 00:00:03,439 --> 00:00:07,739 This very popular episode looks at a three-part series of Reddit posts 3 00:00:08,109 --> 00:00:12,689 from a security specialist who finally agreed to write about ransomware after 4 00:00:12,689 --> 00:00:14,639 a bunch of people asked him to do that. 5 00:00:15,209 --> 00:00:19,169 What he put together ends up being a full ransomware response checklist, 6 00:00:19,339 --> 00:00:22,709 how to stop it from getting in in the first place, how to keep it from 7 00:00:22,709 --> 00:00:27,509 spreading once it does get in, and what to do if you actually get hit. 8 00:00:28,099 --> 00:00:31,379 This is, uh, exactly the process that we built into my latest 9 00:00:31,379 --> 00:00:34,969 book, Ransomware Response and Recovery, which is now available. 10 00:00:35,639 --> 00:00:39,329 If you've ever wondered whether your organization has the right pieces 11 00:00:39,329 --> 00:00:43,639 in place before, during, and after a ransomware attack, I think you'll 12 00:00:43,639 --> 00:00:45,869 get a lot of value from this episode. 13 00:00:46,869 --> 00:00:50,549 By the way, if this is your first time watching or listening to me, I'm W. 14 00:00:50,559 --> 00:00:53,119 Curtis Preston, AKA Mr. Backup. 15 00:00:53,529 --> 00:00:59,469 I've been obsessing over backup, recovery, and now cyber recovery for over 30 years. 16 00:00:59,889 --> 00:01:01,529 If that's your bag, then I'm your guy. 17 00:01:01,929 --> 00:01:06,879 You're not gonna find anyone more, uh, interested in backup than me. 18 00:01:07,229 --> 00:01:11,129 Ever since 1993 when I had to tell my boss that there were no backups of 19 00:01:11,129 --> 00:01:12,799 the database that we had just lost. 20 00:01:13,389 --> 00:01:16,569 Now I've written five O'Reilly books, a blog, and a podcast. 21 00:01:16,729 --> 00:01:20,789 Here, we turn unappreciated admins into cyber recovery heroes. 22 00:01:21,149 --> 00:01:23,129 This is the Backup Wrap-Up. 23 00:01:37,225 --> 00:01:39,445 Hi and welcome to Backup Central's podcast. 24 00:01:39,445 --> 00:01:42,295 I'm your host, W. Curtis Preston, AKA Mr. Backup. 25 00:01:42,655 --> 00:01:46,585 And I have with me, my delayed shipment consultant, Prasanna Malaiyandi. 26 00:01:46,585 --> 00:01:47,415 How's it going , Prasanna? 27 00:01:48,515 --> 00:01:49,025 I'm good. 28 00:01:49,025 --> 00:01:50,405 Curtis, wait, what's delayed. 29 00:01:52,345 --> 00:01:55,915 my, my, my flooring shipment, and I turn to you for. 30 00:01:56,095 --> 00:01:58,705 what I thought you received one. 31 00:02:00,440 --> 00:02:03,880 I did, but . I ordered a big shipment of flooring, and then I ordered 32 00:02:03,880 --> 00:02:07,660 a much smaller shipment and I did that in two shipments because I 33 00:02:07,660 --> 00:02:08,980 couldn't order all of it at once. 34 00:02:08,980 --> 00:02:12,580 And then I had to order like another 10% and the second shipment I received the 35 00:02:12,580 --> 00:02:16,150 second shipment like three weeks ago, I still haven't received the first shipment. 36 00:02:16,720 --> 00:02:22,480 And, I just turned to you for, you know, emotional support in this time of. 37 00:02:22,870 --> 00:02:26,338 Ridiculousness I'm not doing anything until the entire shipment 38 00:02:26,338 --> 00:02:28,338 comes in., it's just ridiculous. 39 00:02:29,238 --> 00:02:30,228 Maybe they ran out of 40 00:02:30,228 --> 00:02:31,128 the raw stuff. 41 00:02:31,698 --> 00:02:32,118 Yeah. 42 00:02:32,178 --> 00:02:32,628 Whatever. 43 00:02:34,893 --> 00:02:36,003 So this is why you're here. 44 00:02:36,003 --> 00:02:37,833 You're here to make me not so angry. 45 00:02:38,163 --> 00:02:40,473 That's why I said you're my delayed shipment consultant. 46 00:02:42,003 --> 00:02:46,803 All I know is it's not in my hot little hands and I'm not doing squat in my 47 00:02:46,803 --> 00:02:48,903 garage until I get the entire shipment. 48 00:02:49,858 --> 00:02:51,148 Just think though. 49 00:02:51,208 --> 00:02:53,818 How about delayed gratification? 50 00:02:53,848 --> 00:02:55,318 Once you finally get the 51 00:02:55,398 --> 00:02:58,128 Oh, This is the ultimate in delayed gratification. 52 00:02:58,158 --> 00:03:01,168 I've never had so much trouble spending money in my life. 53 00:03:01,628 --> 00:03:02,438 You're annoyed. 54 00:03:03,308 --> 00:03:03,728 it'll be 55 00:03:03,918 --> 00:03:04,808 #firstworldproblems. 56 00:03:05,678 --> 00:03:06,608 Take a deep breath. 57 00:03:11,403 --> 00:03:13,383 Yeah, good times. 58 00:03:13,383 --> 00:03:14,253 Good times. 59 00:03:15,013 --> 00:03:20,793 Rate us at ratethispodcast.com/restore, or just click on your favorite pod catcher. 60 00:03:21,058 --> 00:03:25,048 And, uh, click down to the bottom and give us some stars, or maybe even a comment. 61 00:03:25,588 --> 00:03:27,508 Talk about how much you love Prasanna's beard. 62 00:03:27,538 --> 00:03:28,318 I'm good with that. 63 00:03:28,918 --> 00:03:33,268 And how it's so much longer and darker than mine and. 64 00:03:34,453 --> 00:03:36,373 So I see. 65 00:03:38,793 --> 00:03:43,983 I sent you this post that I saw on Reddit, which it's well, it's 66 00:03:43,983 --> 00:03:50,893 actually a series of three posts from a Reddit user called snorkel42. 67 00:03:50,913 --> 00:03:59,483 Don't let his, snorkeling ID fool you the person knows what they're talking about. 68 00:03:59,938 --> 00:04:00,238 Yep. 69 00:04:00,413 --> 00:04:00,953 don't know. 70 00:04:00,983 --> 00:04:02,783 I don't know anything about this person. 71 00:04:02,843 --> 00:04:08,143 Other than that, they have, they post regularly in a subreddit 72 00:04:08,173 --> 00:04:10,243 called security cadence. 73 00:04:10,903 --> 00:04:15,493 but he also posted he or she, I don't know if I mistaken 74 00:04:15,553 --> 00:04:16,753 mistakenly called the person. 75 00:04:16,763 --> 00:04:20,033 He, I apologize in advance for my misogeny, 76 00:04:22,543 --> 00:04:30,492 The, it was about ransomware and they are a specialist in the areas 77 00:04:30,492 --> 00:04:38,647 of security and many people had asked them to post stuff about ransomware 78 00:04:39,067 --> 00:04:45,647 and they had continually said, I don't want to post about ransomware. 79 00:04:45,977 --> 00:04:48,017 And can you imagine why that would be 80 00:04:49,367 --> 00:04:53,807 You're just propagate well, it's ransomware you get hit with, because 81 00:04:53,837 --> 00:04:58,007 there were a bunch of gaps before ransomware got hit and it's better 82 00:04:58,007 --> 00:05:01,637 to address the problem than trying to 83 00:05:01,687 --> 00:05:02,137 right. 84 00:05:02,207 --> 00:05:03,407 sort of the outcome. 85 00:05:04,547 --> 00:05:04,937 Yeah. 86 00:05:04,967 --> 00:05:12,557 So ransomware to this person is the symptom of a whole lot of bad things 87 00:05:12,557 --> 00:05:14,507 that you were already doing or not doing. 88 00:05:14,987 --> 00:05:21,467 And they've spent their career helping to make sure you do those things. 89 00:05:21,497 --> 00:05:29,507 But with the, I think two things, one is that obviously the ransomware attacks are 90 00:05:29,507 --> 00:05:32,007 getting to a fever pitch and then two. 91 00:05:32,882 --> 00:05:37,592 There is what we talked about on the previous episode, which was this concern 92 00:05:38,132 --> 00:05:41,732 about Russia and D w we did cover that. 93 00:05:41,732 --> 00:05:41,912 Didn't 94 00:05:41,912 --> 00:05:42,152 we? 95 00:05:42,377 --> 00:05:44,807 Yeah, we cover the Conti ransomware gang 96 00:05:44,892 --> 00:05:45,372 Yeah. 97 00:05:45,522 --> 00:05:46,002 Yeah. 98 00:05:46,037 --> 00:05:46,877 of the previous 99 00:05:47,292 --> 00:05:48,912 yeah, the Krebs on security post. 100 00:05:48,927 --> 00:05:49,287 Yep. 101 00:05:51,062 --> 00:05:56,042 That the concern is that the level of the fever pitch that we're experiencing 102 00:05:56,042 --> 00:05:58,022 might actually go through the roof. 103 00:05:58,022 --> 00:06:01,802 And so they said, Hey, I'm gonna finally, I'm fine. 104 00:06:01,982 --> 00:06:06,962 I'll post about ransomware, but even in their post about ransomware, it 105 00:06:07,472 --> 00:06:12,542 really wasn't that much about ransomware as much as it was about the things. 106 00:06:12,612 --> 00:06:13,212 no, that's not true. 107 00:06:13,212 --> 00:06:13,932 I'll take that back. 108 00:06:13,982 --> 00:06:16,382 it was here is the way ransomware works. 109 00:06:17,627 --> 00:06:21,487 And so I'd say the first one, I'd say of the three series, 110 00:06:21,722 --> 00:06:21,842 Yeah. 111 00:06:21,907 --> 00:06:24,037 The first one was about here's how to prevent it. 112 00:06:25,177 --> 00:06:27,217 Number one, like from getting in. 113 00:06:27,397 --> 00:06:31,147 The second was here's how to prevent it from doing more damage once it's in. 114 00:06:31,627 --> 00:06:33,007 And then the third one, it was okay. 115 00:06:33,037 --> 00:06:33,427 All right. 116 00:06:33,427 --> 00:06:34,177 You're totally screwed. 117 00:06:34,177 --> 00:06:35,347 You've got to reach for your backups. 118 00:06:35,557 --> 00:06:35,827 So that 119 00:06:37,062 --> 00:06:41,532 The one thing I would add to that is he also was careful saying, I 120 00:06:41,532 --> 00:06:45,702 don't want to just focus on the Conti ransomware and provide you steps to 121 00:06:45,702 --> 00:06:49,452 prevent that because there are so many other ransomware flavors out there. 122 00:06:49,452 --> 00:06:51,252 If you build something for just one. 123 00:06:52,147 --> 00:06:53,677 You're not going to be protecting yourself. 124 00:06:53,707 --> 00:06:55,207 Let's take a holistic approach. 125 00:06:55,507 --> 00:06:56,377 And like you said, let's 126 00:06:56,482 --> 00:06:56,962 good point. 127 00:06:56,977 --> 00:06:58,267 you prevent it from getting in? 128 00:06:58,507 --> 00:07:00,697 What, how do you prevent the spread of it? 129 00:07:00,697 --> 00:07:01,777 And then how do you recover? 130 00:07:03,202 --> 00:07:03,562 Yeah. 131 00:07:03,622 --> 00:07:04,342 Good point. 132 00:07:04,882 --> 00:07:10,042 The first one is called breach, I think is how he titled the first article. 133 00:07:10,042 --> 00:07:10,352 Right. 134 00:07:10,752 --> 00:07:18,852 So the phishing basically, they're saying that that is the number 135 00:07:18,852 --> 00:07:20,772 one way that you get ransomware. 136 00:07:21,262 --> 00:07:21,532 Yep. 137 00:07:21,622 --> 00:07:25,012 Someone accidentally clicking an email, opening up something, 138 00:07:25,012 --> 00:07:27,352 letting the attackers in, and they don't even know about it. 139 00:07:27,352 --> 00:07:33,622 So do you prevent your users from clicking on malicious links? 140 00:07:33,822 --> 00:07:34,662 now, it's interesting. 141 00:07:34,662 --> 00:07:36,822 This goes, yeah. 142 00:07:36,852 --> 00:07:37,152 Sorry. 143 00:07:37,282 --> 00:07:43,242 This goes somewhat against what, some of the advice of one of the 144 00:07:43,242 --> 00:07:47,712 guests that we had on the podcast, which was, they basically said, 145 00:07:47,742 --> 00:07:53,412 look, your people are going to click on stuff, stop relying on, I dunno. 146 00:07:53,562 --> 00:07:58,372 I dunno if it's against, but de-prioritized training and 147 00:07:58,827 --> 00:07:59,247 Yeah. 148 00:07:59,362 --> 00:08:01,312 phishing assessments, didn't you think. 149 00:08:02,617 --> 00:08:02,907 Yeah. 150 00:08:02,907 --> 00:08:03,477 So. 151 00:08:03,597 --> 00:08:09,342 This author does say can only help you so much? 152 00:08:09,342 --> 00:08:13,622 I think the couple things though, that he did mention is, you do need some level of 153 00:08:13,622 --> 00:08:18,342 training, but you need to make sure people don't feel like they're being punished. 154 00:08:19,932 --> 00:08:21,422 they do the wrong thing, right? 155 00:08:21,422 --> 00:08:23,042 You want that transparency. 156 00:08:23,042 --> 00:08:26,852 You want to be telling people it's okay for you to say that I clicked 157 00:08:26,852 --> 00:08:30,902 the wrong thing because then the IT team can try to evaluate what's 158 00:08:30,902 --> 00:08:32,792 going on and try to contain it. 159 00:08:33,602 --> 00:08:34,412 sooner they know the 160 00:08:34,627 --> 00:08:35,107 right. 161 00:08:35,342 --> 00:08:37,712 if say someone's afraid because they're going to get in trouble. 162 00:08:37,712 --> 00:08:41,472 They might be fired, It becomes taboo then no one's going to report it. 163 00:08:41,532 --> 00:08:43,032 And that's actually really bad. 164 00:08:44,402 --> 00:08:44,712 Yeah. 165 00:08:44,942 --> 00:08:47,852 they said to prioritize rewarding over punishment. 166 00:08:47,882 --> 00:08:48,662 make it known. 167 00:08:48,662 --> 00:08:50,282 Like you said, that it's okay to call in. 168 00:08:50,282 --> 00:08:56,582 We want you to call in, even if you messed up and then, and they also said consider 169 00:08:56,582 --> 00:08:57,992 doing your own phishing assessments. 170 00:08:58,202 --> 00:09:00,212 I read some of the comments and they talked about 171 00:09:02,282 --> 00:09:02,822 that. 172 00:09:02,852 --> 00:09:06,192 They had a thing where you got some. 173 00:09:07,002 --> 00:09:10,272 You got some, it was some strikes and it was like 10 strikes. 174 00:09:10,272 --> 00:09:15,562 It was like, you could click on 10 malicious emails. 175 00:09:15,852 --> 00:09:17,112 And, and then it was the 10th. 176 00:09:17,112 --> 00:09:20,472 When, and that they actually had a series of escalations where, it started 177 00:09:20,472 --> 00:09:23,122 out, Hey, we really told you thing. 178 00:09:23,522 --> 00:09:24,902 I think you can do both. 179 00:09:24,902 --> 00:09:29,312 I think you can do both carrot and stick, Reward and punishment where yes. 180 00:09:29,312 --> 00:09:31,142 You want to reward people for calling in. 181 00:09:31,142 --> 00:09:36,302 Thank you for calling, I accidentally clicked . And then if the person 182 00:09:36,992 --> 00:09:41,672 clicks doesn't know, because you did a phishing assessment, you do 183 00:09:41,672 --> 00:09:47,822 a series of escalating things where that ultimately you can have a person. 184 00:09:48,112 --> 00:09:51,662 And this was discussed in the comments, not necessarily that you 185 00:09:51,662 --> 00:09:55,742 would fire somebody that, that keeps doing this, but you might say, okay, 186 00:09:55,742 --> 00:10:00,182 this person cannot be trusted with a straight internet connection. 187 00:10:00,552 --> 00:10:00,822 Yup. 188 00:10:01,192 --> 00:10:03,562 All email from this person will be monitored. 189 00:10:03,982 --> 00:10:04,342 Yeah. 190 00:10:05,302 --> 00:10:08,992 They can only open email that's straight from our Exchange server 191 00:10:08,992 --> 00:10:10,042 or whatever stuff like that. 192 00:10:10,397 --> 00:10:13,377 So phishing was sort of one way that people get in. 193 00:10:13,377 --> 00:10:17,817 But I think once they're in whichever mechanism it is, it's okay, how 194 00:10:17,817 --> 00:10:19,857 do you detect that someone's in? 195 00:10:19,857 --> 00:10:21,507 And I think Curtis, this is what you're going to say, 196 00:10:21,507 --> 00:10:23,437 About this notion of droppers. 197 00:10:24,567 --> 00:10:26,577 Yeah, I actually didn't know this part. 198 00:10:26,607 --> 00:10:33,697 That's I was fascinated that basically that the actual phishing results in a very 199 00:10:33,697 --> 00:10:39,667 small piece of software whose job it is to install the actual piece of software 200 00:10:40,182 --> 00:10:40,422 Yeah. 201 00:10:40,837 --> 00:10:42,337 and that he calls out a dropper. 202 00:10:43,032 --> 00:10:43,332 Yep. 203 00:10:44,272 --> 00:10:49,822 and so the idea is understand that's the way it works, that a piece of 204 00:10:49,822 --> 00:10:53,572 code gets dropped in, and then that piece of code executes, and the only 205 00:10:53,572 --> 00:10:58,462 purpose of that piece of code is to download the other piece of code. 206 00:10:58,732 --> 00:11:01,112 And so they said that you could stop that. 207 00:11:01,322 --> 00:11:05,182 You could say, you can't run arbitrary pieces of code 208 00:11:05,767 --> 00:11:06,037 Yep. 209 00:11:06,472 --> 00:11:11,592 in locations that are directly accessible by the end user, you know, 210 00:11:11,662 --> 00:11:12,352 Or you could restrict 211 00:11:12,497 --> 00:11:13,042 and 212 00:11:13,327 --> 00:11:15,817 are allowed to run on a laptop for instance, 213 00:11:15,972 --> 00:11:16,272 yes, 214 00:11:16,282 --> 00:11:21,082 Whitelisting, I think whitelisting is it, I think it's the, the best. 215 00:11:23,102 --> 00:11:25,822 The best way to stop stuff like this. 216 00:11:26,242 --> 00:11:29,722 It's also the highest touch because it means that every new 217 00:11:29,722 --> 00:11:32,632 application that anybody has to install, they have to get approval. 218 00:11:33,582 --> 00:11:33,882 Yep. 219 00:11:34,865 --> 00:11:38,838 think it's a way to guarantee legitimate applications have gone through some sort 220 00:11:38,838 --> 00:11:42,918 of validation process, security review, et cetera, before it's being allowed 221 00:11:42,918 --> 00:11:45,268 to be deployed in your environment 222 00:11:46,313 --> 00:11:52,073 And then the next thing it talked about was that a random file running should 223 00:11:52,073 --> 00:11:57,313 not be downloading files from the internet, That it should only be HTTP and 224 00:11:57,313 --> 00:11:59,293 HTTPS is downloading from the internet. 225 00:11:59,773 --> 00:12:02,606 And He said with exceptions, SFTP for example. 226 00:12:04,136 --> 00:12:10,706 So he talked about, again, accessing that also possibly blocking bizarre TLDs right. 227 00:12:10,706 --> 00:12:12,716 And unnecessary locations. 228 00:12:12,716 --> 00:12:15,876 You could just simply say, listen, we don't have anything to do with Russia. 229 00:12:16,336 --> 00:12:19,476 Why would we download anything from Russia? 230 00:12:19,836 --> 00:12:22,236 And if there is somebody in our company that needs to download stuff 231 00:12:22,236 --> 00:12:23,506 from Russia, they will be accepted. 232 00:12:23,806 --> 00:12:29,656 That was a very running theme I heard was lock down everything and allow exceptions. 233 00:12:30,161 --> 00:12:30,371 Yeah. 234 00:12:30,941 --> 00:12:33,741 And, it was going to bring up two things. 235 00:12:33,741 --> 00:12:36,891 One was what's a TLD for our listeners? 236 00:12:37,356 --> 00:12:39,066 Oh, top level domain. 237 00:12:39,066 --> 00:12:42,396 That's like.com or dot ransomware. 238 00:12:43,866 --> 00:12:44,586 There is no dot 239 00:12:44,586 --> 00:12:45,096 ransomware, 240 00:12:45,096 --> 00:12:45,426 but. 241 00:12:46,431 --> 00:12:50,331 And was it you, or was it one of our guests who were, who was talking about 242 00:12:50,331 --> 00:12:54,321 how they worked at a company that completely locked down their network 243 00:12:54,321 --> 00:12:59,451 and the network admin would never let them do their backups and everything 244 00:12:59,566 --> 00:13:00,346 no, that was me. 245 00:13:00,801 --> 00:13:01,161 Okay. 246 00:13:01,276 --> 00:13:01,726 was me. 247 00:13:01,876 --> 00:13:02,236 Yeah. 248 00:13:02,446 --> 00:13:02,866 Yeah. 249 00:13:03,116 --> 00:13:10,376 that was, I was a client of mine where they had internal firewalls and that's an 250 00:13:10,376 --> 00:13:14,466 example of, going to the extreme of, now you're preventing core business functions, 251 00:13:14,661 --> 00:13:14,991 Yeah, 252 00:13:15,696 --> 00:13:16,116 right? 253 00:13:16,821 --> 00:13:17,121 but 254 00:13:17,226 --> 00:13:20,766 they also talked about local firewalls, Which is what we were just talking 255 00:13:20,766 --> 00:13:27,336 about, that the, and we're going to get to that more in the next section is, 256 00:13:28,866 --> 00:13:31,566 so they're just looking, he's looking 257 00:13:31,566 --> 00:13:35,856 for ways to stop the dropper from getting yeah, exactly. 258 00:13:35,866 --> 00:13:36,046 Yeah. 259 00:13:36,746 --> 00:13:40,436 thought was an interesting point I'd never thought about is he does have a point 260 00:13:40,436 --> 00:13:44,276 about they block newly created domains. 261 00:13:44,851 --> 00:13:48,821 Which I thought that had been dormant for a while and then are now active, 262 00:13:48,851 --> 00:13:51,731 which I thought was very interesting because it's something I had never 263 00:13:51,731 --> 00:13:53,261 thought about, but it totally makes sense. 264 00:13:53,261 --> 00:13:57,591 Usually when you get ransomware, These actors, they spin up domains and they 265 00:13:57,591 --> 00:13:59,331 start communicating, using that domain. 266 00:13:59,331 --> 00:14:02,641 So yeah, you could have a policy to just block these domains. 267 00:14:02,641 --> 00:14:05,161 So they can't actually reach back out to the 268 00:14:05,436 --> 00:14:05,916 Right. 269 00:14:06,721 --> 00:14:10,361 to be able to download from the dropper, the actual exploit. 270 00:14:10,361 --> 00:14:10,971 code 271 00:14:12,501 --> 00:14:12,821 Right. 272 00:14:12,821 --> 00:14:16,786 And, and they said they weren't aware of anything. 273 00:14:18,386 --> 00:14:21,721 Where that you can do this for free, but there are tools that are 274 00:14:21,721 --> 00:14:23,551 available to help you do This right. 275 00:14:23,791 --> 00:14:24,031 There's 276 00:14:24,151 --> 00:14:25,841 remember, what are the D D. 277 00:14:28,261 --> 00:14:29,251 what were the initials? 278 00:14:29,611 --> 00:14:30,491 The DNS 279 00:14:30,541 --> 00:14:31,621 DDI. 280 00:14:32,491 --> 00:14:34,471 yeah, And I think that goes to some of that as well. 281 00:14:34,471 --> 00:14:38,221 Where it's like, Hey, if you have some of those controls in place, can now 282 00:14:38,251 --> 00:14:41,251 prevent unauthorized access to domains. 283 00:14:41,251 --> 00:14:42,691 They should not be having access to. 284 00:14:45,236 --> 00:14:45,866 Exactly. 285 00:14:46,119 --> 00:14:51,874 And then they started talking about preventing lateral movement inside. 286 00:14:51,874 --> 00:14:57,574 Think about the ways that people need to move within your organization and 287 00:14:57,904 --> 00:15:02,884 allow that, but block all other movement, Lateral movement between servers and I 288 00:15:02,884 --> 00:15:07,714 think, again, going back to that company, that was a perfect example of, they had 289 00:15:07,714 --> 00:15:13,234 blocked all lateral movement between all servers and I couldn't get my job done. 290 00:15:13,999 --> 00:15:16,699 They're only problem w and they should have done that. 291 00:15:16,789 --> 00:15:21,299 And, they were forward thinking in that regard, but you do need 292 00:15:21,299 --> 00:15:24,069 to allow exceptions for things like backup, That is definitely a 293 00:15:24,069 --> 00:15:26,049 server to server lateral movement. 294 00:15:27,979 --> 00:15:28,249 Yeah. 295 00:15:28,369 --> 00:15:30,229 And it's also other simple things. 296 00:15:30,229 --> 00:15:32,539 Like one of them was your favorite topic, right? 297 00:15:32,569 --> 00:15:34,549 Locking down RDP and SSH. 298 00:15:34,909 --> 00:15:35,479 yes. 299 00:15:35,759 --> 00:15:36,899 then lock it down. 300 00:15:36,949 --> 00:15:40,369 SMB is the same way as well for vCenter, right? 301 00:15:40,639 --> 00:15:42,649 Figuring out what actually needs access and what. 302 00:15:43,634 --> 00:15:45,764 to be available to the internet. 303 00:15:46,424 --> 00:15:48,914 And one of the points he made is you should just assume that 304 00:15:48,914 --> 00:15:53,834 your inner internal network is as hostile as internet access. 305 00:15:54,204 --> 00:15:57,714 So once an exploit happens, you can't trust anything internally. 306 00:15:59,539 --> 00:16:03,469 They were also, I, I didn't necessarily agree with this one here. 307 00:16:03,469 --> 00:16:06,019 And that was it's time to kill monolithic file servers. 308 00:16:06,069 --> 00:16:08,919 Now I don't have a problem with the file server. 309 00:16:08,919 --> 00:16:12,049 It's just, I think when they mean monolithic file server, they're just 310 00:16:12,049 --> 00:16:16,219 saying a file server where everybody in the company can access all the data. 311 00:16:16,219 --> 00:16:17,539 I would agree there 312 00:16:17,934 --> 00:16:18,234 Yep. 313 00:16:18,559 --> 00:16:19,819 that's doing that, in a 314 00:16:19,819 --> 00:16:21,709 company of more than three people is 315 00:16:22,154 --> 00:16:22,934 isolate to 316 00:16:23,179 --> 00:16:23,449 yeah. 317 00:16:23,504 --> 00:16:24,404 that need access. 318 00:16:24,404 --> 00:16:28,304 You use ACLs, make sure the people who need access have access and 319 00:16:28,304 --> 00:16:29,764 then monitor who's accessing what. 320 00:16:31,364 --> 00:16:36,179 So they made a specific example of just because accounts receivable gets attacked, 321 00:16:37,319 --> 00:16:38,879 something shouldn't happen to payroll. 322 00:16:38,979 --> 00:16:42,239 these are both finance functions, but they're separate financial functions 323 00:16:42,249 --> 00:16:44,349 and they should have their own areas. 324 00:16:45,024 --> 00:16:45,264 Yeah. 325 00:16:46,409 --> 00:16:51,449 and this is another one that I harp on is about protecting privileged credentials. 326 00:16:52,199 --> 00:16:52,889 And 327 00:16:53,029 --> 00:16:53,389 don't just 328 00:16:53,609 --> 00:16:54,299 he says, 329 00:16:54,619 --> 00:16:55,879 on your forehead, Curtis. 330 00:16:58,009 --> 00:17:03,159 They recommended implementing, things like LAPS, which I had to look up, which stands 331 00:17:03,159 --> 00:17:05,799 for local administrator password solution. 332 00:17:06,609 --> 00:17:10,089 setting a different random password for the common local admin account 333 00:17:10,089 --> 00:17:11,469 on every computer in the domain. 334 00:17:13,229 --> 00:17:15,089 So you don't use one password for everything. 335 00:17:16,679 --> 00:17:21,498 And then MFA, I think every system, every privileged account needs to have 336 00:17:21,498 --> 00:17:24,468 MFA and, I'm sorry, that's a pain. 337 00:17:24,768 --> 00:17:29,798 I, I use it all the time, but it what is 338 00:17:30,758 --> 00:17:33,408 but wait, why do you need a privileged account? 339 00:17:34,578 --> 00:17:35,028 You should. 340 00:17:35,928 --> 00:17:36,438 Here's the thing. 341 00:17:36,438 --> 00:17:40,278 Most times you should probably not need privileged accounts, so you do not need 342 00:17:40,278 --> 00:17:41,958 to access your privileged accounts. 343 00:17:42,768 --> 00:17:44,948 Agreed, but they have to exist. 344 00:17:44,948 --> 00:17:46,538 And so you have to lock them down this way. 345 00:17:46,598 --> 00:17:50,228 I think what you're saying is MFA, shouldn't be that big of a deal for you. 346 00:17:50,228 --> 00:17:53,258 If you set up modern administration. 347 00:17:53,793 --> 00:17:54,153 yeah. 348 00:17:54,603 --> 00:17:57,003 And you should rarely be using that. 349 00:17:57,963 --> 00:18:01,133 And then very last on the list and I would have put it first, it's just 350 00:18:01,133 --> 00:18:02,843 me and that was patching your stuff. 351 00:18:03,623 --> 00:18:05,573 How many times does that come up on the podcast? 352 00:18:05,783 --> 00:18:06,413 When we talk about 353 00:18:06,503 --> 00:18:06,833 Yeah. 354 00:18:06,943 --> 00:18:07,833 Yeah, exactly. 355 00:18:08,943 --> 00:18:12,093 So the next one is about. 356 00:18:13,268 --> 00:18:15,518 It's okay, so you got some ransomware. 357 00:18:15,518 --> 00:18:18,188 Let's talk about the things that they're going to try to do. 358 00:18:18,398 --> 00:18:24,878 The very first thing they listed was deleting of shadow copies. 359 00:18:24,968 --> 00:18:31,028 And so I, and really shadow copies are basically like he's talking 360 00:18:31,028 --> 00:18:32,348 about windows shadow copies. 361 00:18:32,348 --> 00:18:32,528 right? 362 00:18:32,528 --> 00:18:33,308 Like VSS. 363 00:18:33,408 --> 00:18:33,678 copies. 364 00:18:33,738 --> 00:18:34,128 Yup. 365 00:18:34,778 --> 00:18:40,128 And so there is a tool here, which I had never heard of called raccine. 366 00:18:41,258 --> 00:18:45,938 And it stops you from deleting shadow copies. 367 00:18:46,388 --> 00:18:48,428 He said it stops everybody from deleting them. 368 00:18:48,488 --> 00:18:52,848 So just realize that if you've got some regular thing that regularly deletes 369 00:18:52,868 --> 00:18:58,908 shadow copies, it'll break that, but it looks it's something on github. 370 00:18:58,928 --> 00:19:00,798 So it's, it's an open source tool. 371 00:19:01,248 --> 00:19:06,693 And just reading that briefly, I think many backup tools when you're backing up 372 00:19:06,693 --> 00:19:09,693 windows applications uses shadow copy. 373 00:19:09,693 --> 00:19:12,723 So be careful if you are using that because you may not 374 00:19:12,723 --> 00:19:13,803 be able to do your backups. 375 00:19:14,138 --> 00:19:15,758 Yeah, that's a good question. 376 00:19:15,788 --> 00:19:19,868 I would differentiate between shadow copies made just for the purposes 377 00:19:19,868 --> 00:19:22,248 of backups and shadow copies that are made and then left there. 378 00:19:22,268 --> 00:19:23,868 I don't know if there's like a different. 379 00:19:24,468 --> 00:19:28,218 I know that when you make a snapshot, you say why you're making the snapshot. 380 00:19:29,003 --> 00:19:29,273 Yeah. 381 00:19:29,628 --> 00:19:33,108 but agreed that this is not something that you're just going 382 00:19:33,108 --> 00:19:36,168 to download and just implement, 383 00:19:36,703 --> 00:19:36,943 Yeah. 384 00:19:37,878 --> 00:19:39,228 might break all your backups. 385 00:19:39,538 --> 00:19:41,908 what it might do is it might allow you to create that snapshot, but 386 00:19:41,908 --> 00:19:44,098 then it leaves all those snapshots around and let you delete them. 387 00:19:44,421 --> 00:19:46,521 and you might get an error on your backup because you can't, 388 00:19:46,611 --> 00:19:47,751 it can't delete the snapshot. 389 00:19:48,311 --> 00:19:48,581 yeah. 390 00:19:49,421 --> 00:19:51,941 your production could run out of space and then your app dies. 391 00:19:54,521 --> 00:19:55,451 And then what's the next one 392 00:19:56,111 --> 00:19:56,621 here? 393 00:19:56,716 --> 00:19:59,956 the next one is common theme for us. 394 00:19:59,986 --> 00:20:04,846 when we talk about ransomware, less about the actual encrypting of data. 395 00:20:04,846 --> 00:20:08,866 It's the fact that these ransomware actors, especially the Conti group, 396 00:20:08,896 --> 00:20:13,726 they like to exfiltrate your data and steal sensitive data, and then hold you 397 00:20:13,726 --> 00:20:15,616 hostage and be like, Hey, you want to pay? 398 00:20:15,616 --> 00:20:18,696 Then you have to pay twice once for the decryption key. 399 00:20:18,696 --> 00:20:20,446 And then once to make sure we don't publish your data. 400 00:20:21,196 --> 00:20:22,826 sometimes they will still go and publish your data. 401 00:20:23,966 --> 00:20:24,326 Right. 402 00:20:24,346 --> 00:20:28,026 So in this post, he talks about how can you make sure you 403 00:20:28,026 --> 00:20:30,786 can detect data exfiltration? 404 00:20:32,196 --> 00:20:37,296 And he talks about everything from, if you have, if you understand network 405 00:20:37,296 --> 00:20:39,636 patterns, you could look for anomalies. 406 00:20:40,116 --> 00:20:42,456 can also look at other tools. 407 00:20:43,766 --> 00:20:47,936 To see when data is actually being read and sent. 408 00:20:48,686 --> 00:20:50,576 there's some interesting tools that he talked about. 409 00:20:50,576 --> 00:20:54,926 One that I never thought about, which was this mechanism called, 410 00:20:55,296 --> 00:20:57,876 from things called Canary tokens, 411 00:20:58,571 --> 00:20:58,811 right. 412 00:20:59,106 --> 00:21:02,226 it basically creates a false file. 413 00:21:02,911 --> 00:21:07,111 And any time someone accesses it, it generates a token and sends it home. 414 00:21:07,411 --> 00:21:09,211 And then it'll send you an email, say, Hey, by the way, 415 00:21:09,211 --> 00:21:10,381 someone accessed this file. 416 00:21:10,831 --> 00:21:11,551 So you can 417 00:21:11,621 --> 00:21:12,041 Right. 418 00:21:12,331 --> 00:21:15,361 get notified of, Hey, someone's accessing something, which they 419 00:21:15,361 --> 00:21:17,101 probably normally never should be. 420 00:21:17,851 --> 00:21:18,601 Because most of this 421 00:21:18,611 --> 00:21:18,731 Yeah. 422 00:21:19,171 --> 00:21:23,581 software and data exfiltration, it's just programmatically reading, like 423 00:21:23,581 --> 00:21:27,881 scanning folders, reading files, Trying to figure out what to send. 424 00:21:29,066 --> 00:21:34,026 And they mentioned both commercial solutions and open source solutions. 425 00:21:34,026 --> 00:21:36,576 Like the one you mentioned, they also mentioned something called, 426 00:21:36,606 --> 00:21:42,236 Zeke, which, And that it analyzes NetFlow, but there are commercial 427 00:21:42,236 --> 00:21:44,036 tools, which we've mentioned on here. 428 00:21:44,086 --> 00:21:47,096 and I'd like to get, I'd like to get more of those companies on here. 429 00:21:47,846 --> 00:21:51,506 And their recommendation was the same as mine, which is looking 430 00:21:51,506 --> 00:21:54,836 for something that uses behavioral analytics to determine what is, 431 00:21:54,836 --> 00:21:56,636 and is not a normal file transfer, 432 00:21:57,246 --> 00:21:57,546 Yep. 433 00:21:57,746 --> 00:22:00,926 should be able to spot a massive, exfiltration attack.. 434 00:22:03,226 --> 00:22:11,501 And then the response against encryption, they talked about the EDR 435 00:22:11,501 --> 00:22:14,561 XDR, which is I had to look that up. 436 00:22:14,591 --> 00:22:18,521 I was not in my, so this is what, 437 00:22:18,571 --> 00:22:19,051 did we say? 438 00:22:19,051 --> 00:22:19,531 that meant, 439 00:22:19,821 --> 00:22:21,201 detection and response. 440 00:22:21,941 --> 00:22:22,421 Okay. 441 00:22:22,661 --> 00:22:26,291 The idea is that if you've got, if you've got the money to put something 442 00:22:26,291 --> 00:22:34,151 on each laptop that basically looks at and stops, massive file modifications, 443 00:22:34,181 --> 00:22:35,771 it would detect and stop those. 444 00:22:35,821 --> 00:22:38,701 And then same thing with the honeypot. 445 00:22:38,701 --> 00:22:43,341 I liked the idea with the creating an entire separate file server that has 446 00:22:43,391 --> 00:22:47,291 all the same file names, but just with junk data, watch for anybody doing 447 00:22:47,291 --> 00:22:48,681 anything there and then report on. 448 00:22:49,251 --> 00:22:49,461 Yeah. 449 00:22:49,701 --> 00:22:53,061 And the interesting thing is when he was talking about honeypots, I didn't 450 00:22:53,061 --> 00:22:55,101 know, this is, he was like, oh yeah. 451 00:22:55,101 --> 00:22:59,241 And then to make it more realistic, you, there are a couple things you can do. 452 00:22:59,271 --> 00:23:04,566 You can map those device shares to actual endpoint devices. 453 00:23:04,566 --> 00:23:07,926 So they show up there because if I'm a ransomware program and I'm just 454 00:23:07,926 --> 00:23:11,176 looking at all the devices attached, I don't know if it's real or not. 455 00:23:11,206 --> 00:23:14,716 And the question came up, Hey, how do you hide it from your end users? 456 00:23:14,746 --> 00:23:16,966 Because you don't want your end users clicking on it as well. 457 00:23:17,416 --> 00:23:20,956 And there are registry commands in Windows, so you can actually hide them. 458 00:23:20,956 --> 00:23:24,176 So your users don't actually see those drives. 459 00:23:25,576 --> 00:23:28,786 And instead he suggested you actually bookmarked. 460 00:23:29,701 --> 00:23:35,161 Shared drive letters with these honeypot shared drives because ransomware, 461 00:23:35,451 --> 00:23:38,451 programs are either going to start from a and work alphabetically or 462 00:23:38,451 --> 00:23:42,711 start from Z and come backwards, to see what drives are available. 463 00:23:42,711 --> 00:23:44,151 And then they'll just start looking that way. 464 00:23:45,261 --> 00:23:47,601 so put a honeypot at a and put a honeypot at z. 465 00:23:48,371 --> 00:23:48,701 Yup. 466 00:23:50,491 --> 00:23:50,821 I like 467 00:23:53,101 --> 00:23:53,431 it. 468 00:23:53,481 --> 00:23:56,381 were some really interesting things that he talked about. 469 00:23:56,481 --> 00:23:58,251 And we can only cover a little bit here. 470 00:23:58,251 --> 00:24:02,931 I just would highly recommend anybody that's interested in this, which should 471 00:24:02,931 --> 00:24:06,501 be everybody go read this thread. 472 00:24:06,741 --> 00:24:08,331 It's really well-written thread 473 00:24:08,871 --> 00:24:09,411 It's like how to 474 00:24:09,591 --> 00:24:09,891 and. 475 00:24:10,101 --> 00:24:11,211 and how to protect yourself. 476 00:24:12,596 --> 00:24:13,256 And then 477 00:24:13,256 --> 00:24:14,156 we get to the 478 00:24:14,601 --> 00:24:14,821 Yeah. 479 00:24:14,851 --> 00:24:15,451 Your favorite Curtis. 480 00:24:15,451 --> 00:24:15,541 Yeah. 481 00:24:15,541 --> 00:24:16,406 Get up on the third? 482 00:24:16,406 --> 00:24:16,616 one. 483 00:24:16,666 --> 00:24:18,316 Sorry, what is the third one about by the way? 484 00:24:19,431 --> 00:24:21,571 Oh, the third one basically it's you've been infected. 485 00:24:22,161 --> 00:24:22,901 What are we going to do? 486 00:24:22,901 --> 00:24:26,681 Worst case scenario you've been infected and it's spread, and now 487 00:24:26,681 --> 00:24:28,031 you need to reach for your backups. 488 00:24:28,511 --> 00:24:32,401 So they mentioned go to the incident response plan. 489 00:24:32,491 --> 00:24:35,521 And of course that assumes that you have one, which we've said 490 00:24:35,521 --> 00:24:37,171 that you need to have one, right? 491 00:24:37,386 --> 00:24:37,536 Yep. 492 00:24:37,661 --> 00:24:41,551 we've mentioned repeatedly that a ransomware attack is 493 00:24:41,551 --> 00:24:44,851 not the same as a disaster. 494 00:24:45,121 --> 00:24:48,491 There are elements that I'd say a disaster is a subset of. 495 00:24:49,636 --> 00:24:54,296 typical DR response is a subset of a ransomware attack response. 496 00:24:56,006 --> 00:24:58,796 Think people get confused because in the end you're trying 497 00:24:58,796 --> 00:25:00,586 to do the same things, your 498 00:25:00,666 --> 00:25:00,786 Yeah. 499 00:25:00,886 --> 00:25:01,276 up. 500 00:25:02,026 --> 00:25:05,896 But I think the steps and the number of people, the different types of 501 00:25:05,896 --> 00:25:09,556 people involved are significantly different between just a normal 502 00:25:09,556 --> 00:25:11,236 DR. Versus a ransomware recovery. 503 00:25:12,516 --> 00:25:16,596 simplistically to me, the biggest difference between, responding to 504 00:25:16,596 --> 00:25:20,626 a ransomware attack and a disaster, it'd be the equivalent of if you're 505 00:25:20,626 --> 00:25:25,616 doing a DR and you've had a flood step number one is drain the data center, 506 00:25:26,756 --> 00:25:27,176 right? 507 00:25:27,716 --> 00:25:29,456 Get all the water out of the data center. 508 00:25:29,946 --> 00:25:33,776 a ransomware attack is you're trying to drain the data center while you have 509 00:25:33,776 --> 00:25:37,356 a person standing there with a fire hose, it's filling up your datacenter. 510 00:25:37,646 --> 00:25:37,916 Right? 511 00:25:38,186 --> 00:25:42,236 that's the difference between a disaster recovery and a ransomware recovery is that 512 00:25:42,536 --> 00:25:44,576 they are actively still attacking you. 513 00:25:45,026 --> 00:25:48,566 And you're actively experiencing the disaster at the same time as 514 00:25:48,566 --> 00:25:50,606 you're trying to recover from it. 515 00:25:51,886 --> 00:25:56,271 And so they've got a good thing here on what should be 516 00:25:56,271 --> 00:25:58,131 in an incident response, right? 517 00:25:58,131 --> 00:26:01,341 Some things you have to have in your incident response plan 518 00:26:01,551 --> 00:26:04,191 got eight things about right. 519 00:26:04,191 --> 00:26:08,881 Procedures and policies and an incident firm. 520 00:26:09,466 --> 00:26:15,196 you need, you basically get professionals, retain them now, right? 521 00:26:15,496 --> 00:26:19,726 Oh, by the way, I just gotta throw out a really hilarious thing from, 522 00:26:19,806 --> 00:26:21,426 my granddaughter Lily yesterday. 523 00:26:23,256 --> 00:26:30,276 So we have a friend, a mutual friend that was in a car accident a while back. 524 00:26:30,276 --> 00:26:33,876 not seriously injured, but injured enough that there is a 525 00:26:34,156 --> 00:26:36,421 lawsuit that our, that's going on. 526 00:26:37,021 --> 00:26:42,601 And Lily said, she, she mentioned that I couldn't, she couldn't pick 527 00:26:42,601 --> 00:26:47,011 her up because, she was with her, she was with her lawyer and then she 528 00:26:47,011 --> 00:26:51,801 looks at me, we were just walking and then she's do I have a lawyer? 529 00:26:54,041 --> 00:26:56,781 I was like, no, I don't think you have a lawyer. 530 00:26:56,901 --> 00:26:58,251 You don't need a lawyer right now. 531 00:27:00,386 --> 00:27:01,126 but you're right. 532 00:27:01,126 --> 00:27:02,926 Most people don't even think about that. 533 00:27:02,956 --> 00:27:07,666 Like even in like everyday, like normal situations, it's if I, God forbid 534 00:27:07,666 --> 00:27:09,286 get arrested, Who am I going to call? 535 00:27:09,286 --> 00:27:09,466 It's 536 00:27:09,516 --> 00:27:09,906 Yeah. 537 00:27:09,936 --> 00:27:15,396 And so w what they're saying here is, go find who you're going to hire 538 00:27:15,756 --> 00:27:16,956 and get them on retainer. 539 00:27:17,371 --> 00:27:18,391 Ghostbusters? 540 00:27:18,426 --> 00:27:19,116 going to call? 541 00:27:19,866 --> 00:27:22,716 And, and they got a policy, oh, a policy. 542 00:27:22,716 --> 00:27:26,766 This is interesting policy for informing partners and customers and the media. 543 00:27:26,916 --> 00:27:27,306 Right? 544 00:27:28,716 --> 00:27:30,246 Decision-makers right. 545 00:27:30,276 --> 00:27:30,936 All of that stuff. 546 00:27:30,966 --> 00:27:33,126 This should all be decided upfront. 547 00:27:33,156 --> 00:27:34,626 You should be deciding that now. 548 00:27:34,806 --> 00:27:36,186 I don't know how many times we can say that. 549 00:27:36,716 --> 00:27:36,956 Yep. 550 00:27:38,246 --> 00:27:39,896 And then they talk about restoring your data. 551 00:27:40,656 --> 00:27:41,766 Restoring your data. 552 00:27:41,816 --> 00:27:41,996 we 553 00:27:42,166 --> 00:27:45,166 And I think how they said alright, three posts in and we 554 00:27:45,166 --> 00:27:46,666 can finally talk about backups. 555 00:27:46,746 --> 00:27:47,016 Yeah. 556 00:27:47,176 --> 00:27:48,226 It's interesting here. 557 00:27:48,256 --> 00:27:51,146 And he talks about, the typical call-out is that ransomware's 558 00:27:51,146 --> 00:27:52,286 going to target your backups. 559 00:27:52,506 --> 00:27:52,776 Yep. 560 00:27:52,886 --> 00:27:55,646 And so you need some sort of immutable backup solution. 561 00:27:55,886 --> 00:27:59,156 he does also talk and I know Curtis, you're probably going to 562 00:27:59,156 --> 00:28:01,076 have concerns with this, right? 563 00:28:01,076 --> 00:28:05,196 That you don't have to be offsite to protect your backups properly. 564 00:28:06,396 --> 00:28:11,826 He mentions that you could use strict network segmentation or other mechanisms 565 00:28:11,826 --> 00:28:17,406 to ensure separation, which would protect you in the case of ransomware, but 566 00:28:17,406 --> 00:28:19,506 may not protect you from all disasters 567 00:28:19,946 --> 00:28:20,186 yeah. 568 00:28:20,376 --> 00:28:20,976 could occur. 569 00:28:21,576 --> 00:28:21,946 Agreed. 570 00:28:22,116 --> 00:28:26,056 and, and I don't, I don't have an issue with that, Obviously, I'll say obviously 571 00:28:26,056 --> 00:28:28,046 I work at a service-based backup company. 572 00:28:28,046 --> 00:28:30,986 And we see that as the easy it's easy peasy. 573 00:28:31,166 --> 00:28:32,396 All our backups are off site. 574 00:28:32,796 --> 00:28:36,356 I'm not against, you know, as a backup expert, I'm not against onsite backups. 575 00:28:36,656 --> 00:28:40,256 There's a lot of good reasons for an onsite copy, but I completely agree 576 00:28:40,256 --> 00:28:47,006 with this person that you have to protect that onsite copy from attacks. 577 00:28:47,036 --> 00:28:53,516 And there are a lot of very common backup designs, incredibly common backup designs 578 00:28:54,116 --> 00:29:00,586 that do not that the default installation of those products do not protect you. 579 00:29:01,016 --> 00:29:01,416 Right. 580 00:29:01,416 --> 00:29:05,101 And I, and I'll, I don't wanna, I don't wanna pick on our friends at 581 00:29:05,101 --> 00:29:08,191 Veeam, but that's a perfect example. 582 00:29:08,451 --> 00:29:11,611 The guys from Veeam came on here and they explained to you, if you 583 00:29:11,611 --> 00:29:15,301 listen, if you haven't seen those episodes, go back and listen to them. 584 00:29:15,671 --> 00:29:19,891 Uh, about, you know, when they talked about the, the Conti ransomware attacks 585 00:29:19,891 --> 00:29:24,811 and how you can configure your Veeam backups to protect against that. 586 00:29:25,411 --> 00:29:30,511 My concern is that most of their customers are not listening to this podcast, by 587 00:29:30,511 --> 00:29:31,681 the way, they're more than welcome. 588 00:29:33,161 --> 00:29:37,421 All 700,000 Veeam customers are more than welcome to come listen to the podcast. 589 00:29:37,931 --> 00:29:41,421 But if you just do the default installation and you don't take their 590 00:29:41,421 --> 00:29:45,971 recommendations on how to further protect your data, it's no different 591 00:29:45,971 --> 00:29:47,621 than any of the other products, right? 592 00:29:47,621 --> 00:29:48,131 So 593 00:29:49,016 --> 00:29:49,226 Read 594 00:29:49,301 --> 00:29:51,041 you've got to stop doing that. 595 00:29:51,251 --> 00:29:53,591 Read the manual, read the best practices. 596 00:29:53,951 --> 00:29:55,091 Call Rickatron. 597 00:29:55,271 --> 00:29:57,971 Rickatron'll sort, you out and. 598 00:29:59,051 --> 00:30:00,151 So he talks about that. 599 00:30:00,191 --> 00:30:02,181 He also talks about testing, your backups. 600 00:30:02,421 --> 00:30:06,531 I'm editing right now, like literally in I'm in the middle of editing 601 00:30:06,531 --> 00:30:10,611 the podcast, the episode of the restore test gone horribly wrong. 602 00:30:11,051 --> 00:30:11,651 backup. 603 00:30:12,151 --> 00:30:14,751 It's going to be a great episode. 604 00:30:15,711 --> 00:30:16,551 The. 605 00:30:18,156 --> 00:30:19,476 Yeah, Schrodinger's backup. 606 00:30:19,566 --> 00:30:20,226 Exactly. 607 00:30:20,376 --> 00:30:22,986 That's going to, if, yeah, if you haven't heard that episode 608 00:30:22,986 --> 00:30:24,036 go back and listen to it. 609 00:30:24,036 --> 00:30:24,276 it's a 610 00:30:24,276 --> 00:30:24,786 great, 611 00:30:25,496 --> 00:30:26,126 episode. 612 00:30:26,231 --> 00:30:26,711 of the article 613 00:30:26,756 --> 00:30:27,236 And 614 00:30:27,311 --> 00:30:27,521 to it, 615 00:30:27,566 --> 00:30:27,896 then he, 616 00:30:28,211 --> 00:30:28,571 Yeah. 617 00:30:29,836 --> 00:30:30,916 yes, he does. 618 00:30:31,406 --> 00:30:32,446 did he actually refer to Shrodinger's 619 00:30:32,446 --> 00:30:33,176 backup Schrodinger's backup 620 00:30:33,416 --> 00:30:33,596 Yeah. 621 00:30:33,676 --> 00:30:34,836 HInging your company's 622 00:30:34,946 --> 00:30:35,456 and this one? 623 00:30:36,096 --> 00:30:38,646 backup thought experiment is a terrible idea. 624 00:30:38,886 --> 00:30:39,666 Don't do that. 625 00:30:40,816 --> 00:30:41,296 Nice. 626 00:30:43,426 --> 00:30:45,766 and then why don't you talk about the decryption part? 627 00:30:46,466 --> 00:30:46,826 Yeah. 628 00:30:47,006 --> 00:30:48,656 So I guess the final part right. 629 00:30:48,656 --> 00:30:50,876 Is you've been hit with encryption, right? 630 00:30:51,716 --> 00:30:52,676 now what do you do? 631 00:30:52,706 --> 00:30:55,736 And most cases, it's. 632 00:30:56,936 --> 00:31:00,176 You can try to get, if you're lucky, there might be a free 633 00:31:00,176 --> 00:31:01,736 decryptor out there for your data. 634 00:31:01,766 --> 00:31:03,926 It's just going to take a very long time. 635 00:31:04,796 --> 00:31:08,756 And if you do pay the ransom and you have to understand that paying the ransom may 636 00:31:08,756 --> 00:31:11,936 be illegal to some of these groups, right? 637 00:31:11,966 --> 00:31:13,586 They'll give you back a decryption key. 638 00:31:14,066 --> 00:31:15,326 Hopefully it'll work. 639 00:31:15,356 --> 00:31:16,916 It's not, it's in the ransomware. 640 00:31:16,916 --> 00:31:19,496 Group's best interest not to cheat you there, but you're 641 00:31:19,496 --> 00:31:20,996 taking a risk there as well. 642 00:31:21,866 --> 00:31:22,736 And then finally, 643 00:31:23,076 --> 00:31:23,196 Okay. 644 00:31:23,516 --> 00:31:26,156 Once you've actually decrypted your data. 645 00:31:26,156 --> 00:31:28,046 You've gone back up and running. 646 00:31:28,526 --> 00:31:31,106 There's nothing that prevents them from either coming back 647 00:31:31,106 --> 00:31:34,166 and attacking you again, if you haven't fixed anything right. 648 00:31:34,166 --> 00:31:35,696 Or the next group coming back. 649 00:31:35,726 --> 00:31:39,386 Cause that's another common thing is one group gets in encrypts your data. 650 00:31:39,386 --> 00:31:42,236 Another group figures out a different mechanism because they 651 00:31:42,236 --> 00:31:43,766 know now that you're willing to pay. 652 00:31:44,246 --> 00:31:46,016 And so they might come after you as well. 653 00:31:49,141 --> 00:31:49,471 So 654 00:31:49,581 --> 00:31:50,391 And then. 655 00:31:50,581 --> 00:31:52,861 decrypted, it's not the end of the story. 656 00:31:54,406 --> 00:31:58,076 And then the there's a what's next and all of these words, and this is a 657 00:31:58,076 --> 00:32:00,986 really long series of posts, which I highly recommend you go look through. 658 00:32:01,646 --> 00:32:05,756 There's one part where they typed in all caps, and this is it right when 659 00:32:05,756 --> 00:32:10,046 you're done, whatever you did restore, pay the ransom, whatever it is. 660 00:32:11,156 --> 00:32:15,446 It's not over, you clearly have a serious gap in your defenses. 661 00:32:15,446 --> 00:32:17,126 You need to find these and fix them. 662 00:32:17,306 --> 00:32:21,656 And then this is all caps and you need to understand that those gaps are bigger 663 00:32:21,656 --> 00:32:26,066 than just whatever the initial breach vector was as highlighted in parts one 664 00:32:26,066 --> 00:32:29,726 and two of this series, there are several opportunities to stop a ransomware 665 00:32:29,726 --> 00:32:32,036 breach before it gets to this point. 666 00:32:33,146 --> 00:32:34,556 there, there was some other. 667 00:32:35,756 --> 00:32:40,116 It was another one that I read, somebody, they said, if I was at a company that had 668 00:32:40,176 --> 00:32:41,806 a highly, I think it was actually in here. 669 00:32:42,076 --> 00:32:47,296 If I was at a company that a highly publicized breach does this hurt my 670 00:32:47,296 --> 00:32:51,736 chances of getting a job and the author of this article didn't think so, because they 671 00:32:51,736 --> 00:32:53,716 basically said you now have experience 672 00:32:54,201 --> 00:32:54,471 Yep. 673 00:32:54,826 --> 00:32:55,276 and, 674 00:32:55,281 --> 00:32:57,771 was actually at the end of this article is where he wrote about that. 675 00:32:57,771 --> 00:32:58,011 Yeah. 676 00:32:58,381 --> 00:32:58,821 He's yeah. 677 00:32:58,886 --> 00:32:59,216 right, 678 00:32:59,511 --> 00:33:03,171 you should actually show that you've gone through this because for a lot 679 00:33:03,171 --> 00:33:04,881 of people it's just theoretical. 680 00:33:05,241 --> 00:33:06,771 They've never experienced it. 681 00:33:06,771 --> 00:33:07,611 It's like you Curtis. 682 00:33:07,661 --> 00:33:11,471 I can sit here and talk about like how to back up your data, how to restore 683 00:33:11,471 --> 00:33:13,481 your data, ideally how it should be done. 684 00:33:13,851 --> 00:33:16,941 But I've never cut my teeth in a production environment, trying to do a 685 00:33:16,941 --> 00:33:21,281 restore with people, yelling at me over my shoulder or watching over my shoulder. 686 00:33:22,011 --> 00:33:22,381 Right. 687 00:33:22,381 --> 00:33:24,371 You have, and I think that's the difference, right? 688 00:33:24,371 --> 00:33:25,751 Is you 689 00:33:25,881 --> 00:33:26,031 Yeah. 690 00:33:26,081 --> 00:33:28,391 that experience because trial by fire. 691 00:33:29,991 --> 00:33:33,951 Yeah, I, you just reminded me of, and I know I've told this story before, but not 692 00:33:33,951 --> 00:33:35,361 everybody's listening to every episode. 693 00:33:35,871 --> 00:33:39,771 My, one of my favorite restore stories was back at my first big job. 694 00:33:39,801 --> 00:33:45,171 And we had somebody in the NOC that was coordinating the various things that 695 00:33:45,171 --> 00:33:46,641 were happening of this big restore. 696 00:33:48,081 --> 00:33:50,331 And we had another guy that was in the data center that 697 00:33:50,331 --> 00:33:53,391 was actually doing things and. 698 00:33:54,651 --> 00:33:58,651 He was talking to the person who was on the phone in the NOC. 699 00:33:58,791 --> 00:34:00,911 And he didn't know that he was on speaker. 700 00:34:01,746 --> 00:34:06,116 And so he said, he's oh, so you know where you are. 701 00:34:06,136 --> 00:34:07,036 I'm in the NOC. 702 00:34:07,086 --> 00:34:10,356 He goes, oh, so I suppose you have Tom and Tom standing on 703 00:34:10,356 --> 00:34:11,766 your left and right shoulder. 704 00:34:12,186 --> 00:34:15,876 And he was referring to our boss's boss and our boss's boss. 705 00:34:16,116 --> 00:34:19,746 And, the, that would be Tom Thomaides and Tom Lackey. 706 00:34:20,046 --> 00:34:25,806 And they were indeed standing both on his left and right shoulder. 707 00:34:26,136 --> 00:34:29,376 And they said that when he said that, oh, so you have Tom and Tom standing 708 00:34:29,376 --> 00:34:30,456 on your left and right shoulder. 709 00:34:30,736 --> 00:34:33,186 He said they just both took one step back. 710 00:34:35,361 --> 00:34:36,141 but it's true, right? 711 00:34:36,141 --> 00:34:39,321 It's a stressful thing everyone's watching to make sure it goes perfect. 712 00:34:40,461 --> 00:34:42,591 And, we wish you all the best of luck. 713 00:34:43,161 --> 00:34:46,331 I continue to be concerned about our friends over there in the Ukraine. 714 00:34:47,021 --> 00:34:49,601 And, we wish them the best of luck and. 715 00:34:50,996 --> 00:34:55,076 You should also be concerned about the potential ramifications that 716 00:34:55,076 --> 00:35:00,476 all of that has on continued further attacks on your data center and read 717 00:35:00,476 --> 00:35:05,516 this article, read every word of this article, not just this summary and, 718 00:35:05,596 --> 00:35:05,886 Read the three 719 00:35:06,126 --> 00:35:10,386 read all three parts and we'll put links to it in the show description 720 00:35:10,386 --> 00:35:12,036 so that you can easily find it. 721 00:35:12,036 --> 00:35:15,156 Cause finding stuff on Reddit is not necessarily easy. 722 00:35:15,726 --> 00:35:19,496 Thanks again Prasanna for your wise, shipping advice and, a 723 00:35:19,506 --> 00:35:21,286 good commentary on this as well. 724 00:35:21,426 --> 00:35:21,486 Yeah 725 00:35:21,606 --> 00:35:21,706 well. 726 00:35:21,991 --> 00:35:24,511 anytime Curtis and I hope I know, normally when we talk about 727 00:35:24,511 --> 00:35:26,311 ransomware, you get very depressed. 728 00:35:26,641 --> 00:35:29,671 So I, it feels like this isn't a depressing article. 729 00:35:29,911 --> 00:35:31,891 It feels like here are things you should be doing. 730 00:35:31,891 --> 00:35:32,311 So 731 00:35:32,761 --> 00:35:33,181 it feels 732 00:35:33,186 --> 00:35:34,536 Here are things that you should do now. 733 00:35:35,281 --> 00:35:35,521 Yeah, 734 00:35:36,331 --> 00:35:37,441 Yeah, absolutely. 735 00:35:37,591 --> 00:35:39,211 all right, thanks to the listeners. 736 00:35:39,401 --> 00:35:42,221 we'd be nothing without you remember to subscribe