1 00:00:00,000 --> 00:00:04,080 You found the backup wrap up your go-to podcast for all things 2 00:00:04,080 --> 00:00:06,359 backup recovery and cyber recovery. 3 00:00:06,869 --> 00:00:11,190 In this episode, we talk about detecting ransomware with cyber 4 00:00:11,190 --> 00:00:13,860 threats evolving at a breakneck speed. 5 00:00:14,160 --> 00:00:17,640 Understanding how to spot the early signs of a ransomware 6 00:00:17,640 --> 00:00:19,979 attack is more crucial than ever. 7 00:00:20,800 --> 00:00:24,010 We're once again joined by cybersecurity expert Dr. 8 00:00:24,010 --> 00:00:28,600 Mike Sailor, who shares invaluable insights on the subtle indicators of 9 00:00:28,600 --> 00:00:33,940 ransomware activity from performance degradation to unusual network behavior. 10 00:00:34,540 --> 00:00:38,080 We'll explore the role of SIM and XDR tools in early detection. 11 00:00:38,365 --> 00:00:42,715 And discuss why a rapid response is your best defense against 12 00:00:42,715 --> 00:00:44,245 these malicious attacks. 13 00:00:44,785 --> 00:00:48,835 By the way, if you have no idea who I am, welcome to the podcast. 14 00:00:48,835 --> 00:00:51,355 I'm w Curtis Preston, AKA, Mr. 15 00:00:51,355 --> 00:00:56,905 Backup, and I've been specializing in backup and recovery all the way back to 16 00:00:56,905 --> 00:01:02,215 30 years ago when I could not restore a database because our backups were broken. 17 00:01:02,940 --> 00:01:06,930 I, I hated having to tell that to my boss, and I don't want you to have to tell that 18 00:01:06,930 --> 00:01:09,240 to your boss, so that's why I do this. 19 00:01:09,780 --> 00:01:15,690 On this podcast, we turn unappreciated backup admins into Cyber Recovery Heroes. 20 00:01:15,960 --> 00:01:18,150 This is the backup wrap up. 21 00:01:32,342 --> 00:01:33,242 Welcome to the show. 22 00:01:34,262 --> 00:01:38,132 If I could ask you to take a quick second to press that subscribe or 23 00:01:38,132 --> 00:01:42,512 follow button so that you can always get our content, that would be great. 24 00:01:43,292 --> 00:01:47,012 I am w Curtis Preston, otherwise known as Mr. 25 00:01:47,012 --> 00:01:51,122 Backup, and have with me a guy who almost lost his head today. 26 00:01:51,392 --> 00:01:53,672 Prasanna Malaiyandi guys are going. 27 00:01:53,672 --> 00:01:55,802 Persona, we're we're glad that you're alive. 28 00:01:55,832 --> 00:02:01,592 Yeah, I, uh, I escaped without an losing any fingers or my head, 29 00:02:01,592 --> 00:02:04,562 you know, so that's a, it's a good day, you know, I'll take that 30 00:02:04,562 --> 00:02:05,522 anytime of the day. 31 00:02:06,302 --> 00:02:10,322 so why don't you tell the listeners why we had to delay this recording? 32 00:02:10,352 --> 00:02:11,282 What happened to you? 33 00:02:11,492 --> 00:02:16,112 so I was walking by and getting tea before the podcast and I was like, oh. 34 00:02:16,442 --> 00:02:20,402 And I looked up at the ceiling and we have in our kitchen, we have a ceiling fan. 35 00:02:20,882 --> 00:02:22,382 And I was like, huh, that's weird. 36 00:02:22,382 --> 00:02:25,022 What's that blue piece and why does it look a little tilted? 37 00:02:25,022 --> 00:02:29,522 So luckily I got a chair a step stool and I was like, huh, lemme take a closer look. 38 00:02:29,522 --> 00:02:30,572 And I literally touched it. 39 00:02:30,572 --> 00:02:36,272 And then the thing like fell down and was just dangling by the three wires, right? 40 00:02:36,272 --> 00:02:38,552 The ground, the hot, and uh. 41 00:02:40,172 --> 00:02:43,442 I was like, uh, then I had to quickly call my wife and it's very awkward. 42 00:02:43,442 --> 00:02:45,992 Like these are like 30 pounds, right? 43 00:02:45,992 --> 00:02:47,642 And it's hanging above you. 44 00:02:47,642 --> 00:02:50,522 And I was on a short step stool and I was like, how do 45 00:02:50,522 --> 00:02:52,532 I actually unclip these wires? 46 00:02:52,532 --> 00:02:57,152 And it was a whole fiasco with, uh, ladders and step stools and 47 00:02:57,152 --> 00:02:58,892 all sorts of things in order 48 00:02:58,892 --> 00:02:59,462 to be able to do it. 49 00:02:59,462 --> 00:03:01,022 But I have it down, which is good. 50 00:03:01,562 --> 00:03:01,952 Yeah. 51 00:03:02,012 --> 00:03:04,802 And an anxious wife hanging over to the side. 52 00:03:05,552 --> 00:03:08,312 Uh, do, do you think you're gonna be replacing the fan? 53 00:03:08,642 --> 00:03:10,622 Well, like with the new fan or just 54 00:03:10,682 --> 00:03:11,822 it's, it's gone. 55 00:03:11,942 --> 00:03:12,542 It's gone. 56 00:03:12,542 --> 00:03:12,782 It's 57 00:03:12,847 --> 00:03:13,137 Okay. 58 00:03:13,172 --> 00:03:18,512 going to just put a normal like, 'cause honestly lived here for 11 years 59 00:03:18,512 --> 00:03:19,922 now, 10 years, something like that. 60 00:03:19,922 --> 00:03:22,292 And I think we've only used that fan once 61 00:03:22,667 --> 00:03:22,957 Yeah. 62 00:03:23,912 --> 00:03:27,872 It, it, it's funny, you know, it's funny, you, you know, I recently 63 00:03:27,872 --> 00:03:32,132 replaced my ceiling fan with, in the kitchen with a, with just a light. 64 00:03:32,582 --> 00:03:38,162 And what I remember was I, when I wanted to take it off, 65 00:03:38,642 --> 00:03:41,882 I just could not figure out, I. 66 00:03:41,882 --> 00:03:44,942 How to get it out, like what I was supposed to do to get 67 00:03:44,942 --> 00:03:46,412 it out of there properly. 68 00:03:47,012 --> 00:03:50,792 Um, and I wish that it was just hanging by the three wires. 69 00:03:51,002 --> 00:03:56,102 It was like, it was just, I, I just remember that a saal, 70 00:03:56,582 --> 00:03:58,292 uh, was involved at one point. 71 00:03:59,267 --> 00:03:59,627 Yeah. 72 00:03:59,717 --> 00:04:04,517 Well, and the hard part with that is like, it's like it's bulky and then 73 00:04:04,517 --> 00:04:07,727 I saw the fan blades attached and like you can't see anything, right? 74 00:04:07,727 --> 00:04:09,947 Because they hide all the things and it's like, okay, how do 75 00:04:09,962 --> 00:04:10,262 Yeah. 76 00:04:10,337 --> 00:04:13,097 off this trim piece so then I can get to the screws to unscrew it? 77 00:04:13,457 --> 00:04:17,057 But like you said, luckily because my outlet box head basically 78 00:04:17,057 --> 00:04:19,907 detached itself from its support, it was just kind of hanging there. 79 00:04:19,907 --> 00:04:22,607 And so it made work a little easier. 80 00:04:24,107 --> 00:04:24,437 'cause yeah, 81 00:04:24,437 --> 00:04:24,887 Well, we're. 82 00:04:24,977 --> 00:04:26,567 attached, I don't think I could have figured that out. 83 00:04:27,482 --> 00:04:31,742 I am glad that you survived, and I'm glad that for once it's one of the stories from 84 00:04:31,742 --> 00:04:35,912 your house rather than stories from my house that we're featuring on the episode. 85 00:04:36,242 --> 00:04:36,532 Yeah. 86 00:04:37,052 --> 00:04:40,142 So, speaking of stories, we once again have Dr. 87 00:04:40,142 --> 00:04:42,122 Mike Sailor with us. 88 00:04:42,182 --> 00:04:45,332 Our, our, at this point, resident cyber expert. 89 00:04:45,332 --> 00:04:46,982 How's it going, Mike? 90 00:04:47,567 --> 00:04:48,497 That's going well guys. 91 00:04:48,497 --> 00:04:48,767 How are y'all? 92 00:04:50,192 --> 00:04:51,422 Well, we're alive. 93 00:04:55,232 --> 00:05:00,482 But, uh, this week I wanted to jump right into this idea of 94 00:05:00,482 --> 00:05:02,042 ransomware detection, right? 95 00:05:02,042 --> 00:05:05,912 So we, we, we tell people that they should assume breach, right? 96 00:05:05,912 --> 00:05:09,842 That they should assume they're going to be attacked, and, uh, 97 00:05:09,872 --> 00:05:12,692 because statistically speaking, they, they probably will be. 98 00:05:13,562 --> 00:05:16,292 And you've dealt with a lot of these attacks. 99 00:05:16,292 --> 00:05:22,087 So, so, um, I, I, I wanna understand, you know, what, what does. 100 00:05:23,162 --> 00:05:25,202 What does a ransomware attack look like? 101 00:05:25,352 --> 00:05:25,802 Right? 102 00:05:25,982 --> 00:05:31,652 Like, what are the things that people see that are going on that don't like? 103 00:05:31,742 --> 00:05:34,652 If, obviously if you get a, you know, a big thing on your screen that 104 00:05:34,652 --> 00:05:36,602 says, Hey, give us a million dollars. 105 00:05:36,602 --> 00:05:38,552 We're gonna get your, you know, get your files back. 106 00:05:38,882 --> 00:05:41,912 That's one way to know you have ransomware attack, but what other 107 00:05:41,912 --> 00:05:46,202 things happen before that that tell you that you have a ransomware attack? 108 00:05:46,232 --> 00:05:49,052 Is it is a ceiling fan if a ceiling fan starts to fall? 109 00:05:49,052 --> 00:05:50,162 Is that, is that, 110 00:05:50,237 --> 00:05:50,537 I think, 111 00:05:50,612 --> 00:05:50,942 is that. 112 00:05:50,957 --> 00:05:53,897 I think before Mike, before you jump into that, Curtis, maybe it might be a 113 00:05:53,897 --> 00:05:57,377 good idea just 'cause I think listeners may not be listening to every episode 114 00:05:57,377 --> 00:06:01,397 in order, it might be a good idea to say like, why Mike is on the podcast 115 00:06:01,397 --> 00:06:03,287 and why he's the expert in this area. 116 00:06:03,707 --> 00:06:03,947 Right. 117 00:06:04,247 --> 00:06:04,727 Well, 118 00:06:05,027 --> 00:06:07,727 talking about ransomware detection, or Mike, maybe you wanna cover that. 119 00:06:08,382 --> 00:06:09,432 yeah, go ahead, Mike. 120 00:06:11,487 --> 00:06:16,557 Uh, certainly, so happy to, happy to, uh, comment on all of those things. 121 00:06:16,617 --> 00:06:21,867 Uh, I think my experience over the last probably at least 20 years, uh, responding 122 00:06:21,867 --> 00:06:28,437 to incidents both at, know, uh, personal, uh, at the personal level, uh, whether 123 00:06:28,437 --> 00:06:32,067 it's a family member or somebody referred. 124 00:06:33,392 --> 00:06:38,252 someone to us to, to help with a, a problem, uh, or a corporate, uh, level. 125 00:06:38,252 --> 00:06:43,082 And, and that's, you know, school districts, banks, um, normal business 126 00:06:43,082 --> 00:06:47,672 enterprise that, uh, have incurred some, uh, some cyber incident. 127 00:06:47,792 --> 00:06:47,822 Uh. 128 00:06:48,232 --> 00:06:52,162 We, we've seen quite a bit of, uh, variety of incidents, uh, 129 00:06:52,462 --> 00:06:53,752 especially around ransomware. 130 00:06:53,752 --> 00:06:57,802 There's, there's a hundreds of different variants of ransomware. 131 00:06:57,862 --> 00:07:01,162 Uh, there's the more popular ones that we've probably seen more often 132 00:07:01,162 --> 00:07:06,082 than the others, and there are some consistent themes and, uh, you 133 00:07:06,082 --> 00:07:08,272 know, potholes and lessons learned. 134 00:07:08,272 --> 00:07:13,282 And, and, uh, when, when someone that's seen it before, uh, shows up 135 00:07:13,282 --> 00:07:16,522 to help put out the fire, we know where to where to put the water first. 136 00:07:16,832 --> 00:07:20,402 Uh, what not to put water on, uh, when to ask for help and who else 137 00:07:20,402 --> 00:07:22,082 to, uh, who else to involve in that. 138 00:07:22,082 --> 00:07:22,442 So, 139 00:07:22,802 --> 00:07:23,312 So, so 140 00:07:23,377 --> 00:07:23,697 happy 141 00:07:23,747 --> 00:07:23,957 know? 142 00:07:24,002 --> 00:07:24,152 of. 143 00:07:26,492 --> 00:07:26,792 Go ahead. 144 00:07:26,792 --> 00:07:27,242 Finish. 145 00:07:27,437 --> 00:07:27,707 Yeah. 146 00:07:27,947 --> 00:07:31,412 to share, to share my experience and some stories. 147 00:07:31,742 --> 00:07:31,952 Yeah. 148 00:07:32,012 --> 00:07:35,342 So unlike me who's a YouTube person, you're actually 149 00:07:35,342 --> 00:07:36,782 like, grounds on the boots. 150 00:07:36,782 --> 00:07:40,682 Someone who's actually lived and does, does this on a like day to day basis 151 00:07:41,642 --> 00:07:42,392 Uh, absolutely. 152 00:07:42,392 --> 00:07:44,162 And, uh, you said grounds on the boots. 153 00:07:44,162 --> 00:07:44,912 And the first, the 154 00:07:45,002 --> 00:07:45,212 Yeah. 155 00:07:45,272 --> 00:07:45,392 I 156 00:07:45,547 --> 00:07:45,722 on the 157 00:07:45,812 --> 00:07:45,902 thought. 158 00:07:46,742 --> 00:07:47,642 Boots on the ground. 159 00:07:47,642 --> 00:07:47,822 Yeah. 160 00:07:48,332 --> 00:07:50,852 Uh, well, and, and first thing I thought of is that needs to 161 00:07:50,852 --> 00:07:52,292 be a t-shirt at a coffee shop. 162 00:07:52,292 --> 00:07:56,042 I think that would be good, uh, because I'm a, I'm an avid coffee 163 00:07:56,042 --> 00:07:58,532 person, so that made sense to me, even though you said it that way. 164 00:07:59,552 --> 00:08:00,242 But absolutely. 165 00:08:00,242 --> 00:08:01,232 I've, I'm, uh. 166 00:08:01,622 --> 00:08:06,002 Uh, in addition to being hands-on, you know, years ago in, in rebuilding 167 00:08:06,002 --> 00:08:08,882 machines and actually, you know, type it in commands and running 168 00:08:08,882 --> 00:08:13,532 tools, uh, to today, I'm more of what they consider a, a breach coach. 169 00:08:13,832 --> 00:08:17,522 Uh, so you've had an incident, uh, and I'm just there to, to try and herd the 170 00:08:17,522 --> 00:08:23,342 cats and give up updates in a, in a correct and, and less stressful manner. 171 00:08:23,732 --> 00:08:27,422 Uh, be the one there that, that's already had my hair burned off while 172 00:08:27,422 --> 00:08:29,312 everybody else is running around on fire. 173 00:08:29,792 --> 00:08:30,332 Uh. 174 00:08:31,637 --> 00:08:39,827 So d uh, Mike, uh, during the pre-call, you uh, had mentioned how different. 175 00:08:40,547 --> 00:08:45,167 Like a ran like ransom, how different ransomware is from other malware, 176 00:08:45,167 --> 00:08:48,857 and I think that's probably a good place to start before we talk about 177 00:08:48,917 --> 00:08:50,957 what an attack actually looks like. 178 00:08:52,187 --> 00:08:52,577 Sure. 179 00:08:52,607 --> 00:08:55,457 Well, you know, malware in general, just bad software. 180 00:08:55,517 --> 00:08:58,847 Uh, you know, it's, it's intended to do nefarious things or, 181 00:08:58,877 --> 00:09:01,727 or trick us or steal from us. 182 00:09:01,877 --> 00:09:06,797 Um, and, and there are elements of, of malware that are consistent 183 00:09:06,797 --> 00:09:08,507 across different types of malware. 184 00:09:08,507 --> 00:09:10,697 It's like info Steeler, malware. 185 00:09:11,087 --> 00:09:14,417 Uh, harvesting malware that, you know, captures your keystrokes 186 00:09:14,417 --> 00:09:15,707 or looks for certain things. 187 00:09:15,707 --> 00:09:18,347 There's malware that just does reconnaissance. 188 00:09:18,797 --> 00:09:24,947 Uh, and so when you think of really bad malware, it has the worst of 189 00:09:24,947 --> 00:09:27,437 all these elements, uh, combined. 190 00:09:27,497 --> 00:09:33,017 And effective ransomware these days really does. 191 00:09:33,107 --> 00:09:33,617 Uh. 192 00:09:34,967 --> 00:09:37,097 Perform in different phases. 193 00:09:37,427 --> 00:09:43,367 So the first phase is it wants to gain access to, to whatever it's infected. 194 00:09:43,367 --> 00:09:48,347 So that computer, your, your smartphone, that server, whatever it might be. 195 00:09:48,707 --> 00:09:51,797 And then it wants to figure out, well, what do I have access to? 196 00:09:52,757 --> 00:09:56,237 so was it a, a particular user, user account that. 197 00:09:56,612 --> 00:09:58,862 Allowed it to infect this device. 198 00:09:59,162 --> 00:10:02,672 Uh, what does this device then, and, and that user profile have 199 00:10:02,672 --> 00:10:04,562 access to across a network? 200 00:10:05,042 --> 00:10:10,982 Uh, what type of, um, software or files are on this machine? 201 00:10:11,162 --> 00:10:15,002 For example, there is a specific ransomware that only 202 00:10:15,002 --> 00:10:17,012 targets point of sale systems. 203 00:10:17,432 --> 00:10:21,392 And so if, if it infects my laptop, it's gonna determine whether my 204 00:10:21,392 --> 00:10:23,312 laptop is a point of sale system. 205 00:10:23,312 --> 00:10:24,392 And if it is not. 206 00:10:24,782 --> 00:10:29,042 It's gonna look for a way to spread to the next system, and once it does, 207 00:10:29,042 --> 00:10:31,592 it will clean itself off of my laptop. 208 00:10:32,072 --> 00:10:33,392 So as if it were never there. 209 00:10:34,562 --> 00:10:38,132 And then it will continue doing so until it finds a point of sale 210 00:10:38,132 --> 00:10:39,992 system and then it will deploy. 211 00:10:39,992 --> 00:10:44,342 Its, its ransomware, you know, whatever, additional software 212 00:10:44,342 --> 00:10:47,072 and, capabilities it has. 213 00:10:47,522 --> 00:10:52,232 But there's those first few phases of what, what do I have access to? 214 00:10:53,372 --> 00:10:58,562 And what, um, what can I, you know, what value, uh, aligned with my 215 00:10:58,562 --> 00:11:03,932 ransomware campaign, uh, does that bring me, that then, uh, triggers 216 00:11:03,932 --> 00:11:05,762 a whole slew of other things. 217 00:11:05,762 --> 00:11:09,272 Like, okay, so I found I found a point of sale system. 218 00:11:09,482 --> 00:11:10,922 Do I still have internet access? 219 00:11:10,922 --> 00:11:14,672 And if I do, I'm gonna reach out and download the next, the next 220 00:11:14,672 --> 00:11:18,362 piece of malware I need specific to the point of sale system I found. 221 00:11:19,022 --> 00:11:19,712 And so. 222 00:11:20,117 --> 00:11:24,227 A lot of times that initial malware, ransomware infection is a very, what we, 223 00:11:24,257 --> 00:11:27,797 we call a thin or light, uh, payload. 224 00:11:27,917 --> 00:11:28,907 It's not very large. 225 00:11:28,907 --> 00:11:30,707 It doesn't draw a lot of attention. 226 00:11:30,707 --> 00:11:34,757 It doesn't do a whole lot other than determine whether it, it, 227 00:11:34,877 --> 00:11:39,017 it has access to whatever this ransomware actor is interested in. 228 00:11:39,287 --> 00:11:42,107 And then it'll phone home and say, Hey, I've got, I've got the goods. 229 00:11:42,137 --> 00:11:46,187 Send the, send the next, send the next payload and we'll get started. 230 00:11:46,367 --> 00:11:49,397 For that first phase, I know we're talking about ransomware detection. 231 00:11:49,697 --> 00:11:52,607 Is there anything you could really do to detect, I know you said it's a 232 00:11:52,607 --> 00:11:54,947 very lightweight, thin shim, right? 233 00:11:54,947 --> 00:11:56,237 That gets installed, deployed. 234 00:11:56,237 --> 00:11:58,907 Are there things people can do to detect at that phase? 235 00:11:59,612 --> 00:12:02,942 There are and, and there are some symptoms, uh, ransom. 236 00:12:03,182 --> 00:12:07,022 These, these first few phases are different from, uh, one ransomware 237 00:12:07,322 --> 00:12:11,882 variant to, or even just malware in general, from one variant to another. 238 00:12:12,352 --> 00:12:17,692 But they're, they do consume resources and, you know, to, to do reconnaissance, 239 00:12:17,692 --> 00:12:19,732 to, to do a system inventory. 240 00:12:20,062 --> 00:12:22,702 There will be a change in resource utilization. 241 00:12:22,702 --> 00:12:27,742 CPU may go up, memory may go up, drive io may go up, network IO may go up. 242 00:12:29,242 --> 00:12:35,962 And so if you have the ability to monitor those things, uh, and, and it 243 00:12:35,962 --> 00:12:39,892 may not be much, but you know, set some thresholds that say if my system resources 244 00:12:39,892 --> 00:12:41,962 go above whatever it is, let me know. 245 00:12:42,317 --> 00:12:45,707 That may be because you're watching a movie, but at least you know it's because 246 00:12:45,707 --> 00:12:50,867 you're watching a movie I'm typing, you know, a new chapter to my book, 247 00:12:51,287 --> 00:12:53,627 and then all of a sudden my CPU spikes. 248 00:12:53,657 --> 00:12:56,717 Well, I'm not doing anything that would justify that. 249 00:12:56,717 --> 00:12:59,807 So let me go look at what processes are running and, and so on. 250 00:13:00,227 --> 00:13:03,887 Well, for the normal person or even the normal technical person, you know, I 251 00:13:03,887 --> 00:13:08,957 could go look at Windows processes and not know what 95% of those are, but I 252 00:13:08,957 --> 00:13:10,907 could potentially kill that process. 253 00:13:11,762 --> 00:13:14,912 maybe dig into where, where, well, what spawned that process? 254 00:13:14,912 --> 00:13:17,222 Where's that file and what folder is it in? 255 00:13:17,222 --> 00:13:20,912 And when did, what's the time and date stamp that, that that happened? 256 00:13:20,912 --> 00:13:22,292 And was that something I did? 257 00:13:23,192 --> 00:13:27,302 some things you can do, um, investigatively and you'll, it's 258 00:13:27,302 --> 00:13:29,282 probably a learning process as you do it. 259 00:13:29,702 --> 00:13:32,372 But then there are other tools, like that's, that's kind of what 260 00:13:32,372 --> 00:13:34,292 Black Swan Cybersecurity does. 261 00:13:34,292 --> 00:13:38,282 We monitor environments and in, in our monitoring, we create a. 262 00:13:38,657 --> 00:13:42,407 Behavioral baseline by user, by device, by network segment. 263 00:13:42,767 --> 00:13:46,157 And as weird stuff happens, it flags to us. 264 00:13:46,802 --> 00:13:50,402 Because it's simply deviated from normal behavior before 265 00:13:50,402 --> 00:13:51,962 it becomes a security problem. 266 00:13:52,292 --> 00:13:57,002 So then we can call the client or the tech support person or the whoever 267 00:13:57,002 --> 00:14:01,322 it is and say, let's dig into this and figure out, uh, if this is, uh, 268 00:14:01,442 --> 00:14:06,272 if this is legitimate activity or, or what can we tie it to from a user. 269 00:14:06,302 --> 00:14:08,882 Maybe some user clicked on a link or downloaded a file, and 270 00:14:08,882 --> 00:14:10,712 that's what led up to this. 271 00:14:10,712 --> 00:14:14,522 And so there, there are, there are tools out there and it ranges from. 272 00:14:14,912 --> 00:14:18,872 You know, put your toolbox together and run, run script one and look at, 273 00:14:19,232 --> 00:14:23,192 you know, report B and tie all that stuff together, which is kind of time 274 00:14:23,192 --> 00:14:28,892 consuming, but low cost, no cost, uh, to, to more of the elaborate 275 00:14:29,012 --> 00:14:34,202 capabilities of hiring a, a managed service to, watch over all that stuff. 276 00:14:38,402 --> 00:14:38,852 Hang on. 277 00:14:39,392 --> 00:14:40,832 I'm not sure where I wanted to go from there. 278 00:14:41,222 --> 00:14:41,732 Nevermind. 279 00:14:41,762 --> 00:14:42,242 Nevermind. 280 00:14:42,512 --> 00:14:43,682 I'll um, 281 00:14:44,087 --> 00:14:44,807 Well, well back 282 00:14:44,822 --> 00:14:45,242 uh, 283 00:14:45,707 --> 00:14:50,807 back to the kind of the, the, the attack progression and this, this lines 284 00:14:50,807 --> 00:14:52,457 up with the Mitre attack framework. 285 00:14:52,457 --> 00:14:56,207 You know, reconnaissance is always first, and then how do we, I. 286 00:14:57,002 --> 00:14:58,712 Maintain our access. 287 00:14:58,712 --> 00:15:00,122 'cause that's, that's second part. 288 00:15:00,122 --> 00:15:03,062 Once I've infected you, I wanna make sure that if you've determined I've 289 00:15:03,062 --> 00:15:06,512 infected you and you try to clean me off, I'm still infecting you. 290 00:15:07,322 --> 00:15:10,562 so once you reboot, I'm, I'm still there, and I'm gonna be there until 291 00:15:10,562 --> 00:15:12,212 you throw this computer out the window. 292 00:15:13,052 --> 00:15:15,062 Uh, and so persistence is next. 293 00:15:15,062 --> 00:15:18,062 And then, uh, you know, some of the other, other phases. 294 00:15:18,062 --> 00:15:20,102 And as, as that. 295 00:15:20,762 --> 00:15:24,752 Attack progresses through the Mitre attack framework, and it, it's 296 00:15:24,752 --> 00:15:28,232 all mapped out regardless of, of the attack who's doing the attack. 297 00:15:28,232 --> 00:15:33,422 It, it falls into these categories, these phases, and as that phase progresses, 298 00:15:33,782 --> 00:15:41,552 resource and network and, um, symptomatic, uh, identifiers will always increase. 299 00:15:42,002 --> 00:15:45,392 So the more activity, the further along that attack framework they get, 300 00:15:45,422 --> 00:15:48,902 the more identifiable, uh, it is. 301 00:15:49,382 --> 00:15:50,132 And so. 302 00:15:50,177 --> 00:15:50,237 Um, 303 00:15:50,777 --> 00:15:54,437 Hey Mike, you, you threw out the Mitre Attack framework. 304 00:15:54,437 --> 00:15:56,957 Not everybody, uh, is gonna be familiar with that. 305 00:15:56,957 --> 00:15:57,827 You want to talk about that? 306 00:15:58,727 --> 00:16:06,407 so Mitre, which is an organization, um, a framework within which, and there, and 307 00:16:06,407 --> 00:16:11,807 there's like seven phases, within which every attack sequence can be mapped. 308 00:16:13,157 --> 00:16:15,767 And so almost every attack starts with reconnaissance. 309 00:16:15,977 --> 00:16:18,497 Uh, what do, what did they gain access to? 310 00:16:18,587 --> 00:16:20,897 All the way through, like data exfiltration. 311 00:16:21,317 --> 00:16:24,377 Uh, so they've, they've got access to your stuff and they're stealing it. 312 00:16:25,847 --> 00:16:31,457 and so the, the attack framework is simply a way of, of identifying not only, 313 00:16:31,667 --> 00:16:37,037 uh, where an attack is, but how far did it go, and based on those attributes, 314 00:16:37,097 --> 00:16:39,257 then how big of a problem did we just. 315 00:16:40,367 --> 00:16:43,757 you know, how big of a, how big of a, a, an issue is this. 316 00:16:44,237 --> 00:16:48,227 Um, but it also then allows you to align your response to those 317 00:16:48,227 --> 00:16:50,477 different phases of the framework. 318 00:16:50,627 --> 00:16:52,787 So in reconnaissance, what's my response? 319 00:16:52,787 --> 00:16:54,977 Well, maybe just passive for now. 320 00:16:55,277 --> 00:16:56,897 What is doing this reconnaissance? 321 00:16:56,897 --> 00:17:01,487 Is it normal like internet, uh, pings just to see if a website's 322 00:17:01,487 --> 00:17:03,197 alive that could be reconnaissance. 323 00:17:03,917 --> 00:17:07,992 or is it something a lot more active, uh, where they're doing port scans and. 324 00:17:08,867 --> 00:17:10,127 some active enumeration. 325 00:17:10,127 --> 00:17:14,537 What, you know what, um, I, I pinged this IP and I've, I've 326 00:17:14,537 --> 00:17:17,027 determined these ports are open and they're responding a certain way. 327 00:17:17,027 --> 00:17:22,667 So now I know it's a Windows seven or, or Windows 2018 server, uh, running, 328 00:17:22,667 --> 00:17:24,137 you know, whichever patch level. 329 00:17:24,137 --> 00:17:26,837 And so that's active reconnaissance and that's a no-no. 330 00:17:27,707 --> 00:17:31,577 so what's doing that and can we address it now versus, uh. 331 00:17:32,402 --> 00:17:36,392 Waiting until that progre, that attack progresses into one of the other phases, 332 00:17:37,172 --> 00:17:41,132 which could get a little more, uh, complicated as far as responding to it. 333 00:17:41,162 --> 00:17:46,322 But then you would have kinda your playbook lined up with what phase of the 334 00:17:46,322 --> 00:17:49,952 framework, what phase of the attack are we in, and here are the tools and things 335 00:17:49,952 --> 00:17:52,742 we should, be applying at this point. 336 00:17:52,982 --> 00:17:55,832 Uh, and some of those are management decisions, like cut the hard 337 00:17:55,832 --> 00:17:58,382 wire, you know, uh, it's that bad. 338 00:17:58,712 --> 00:17:59,222 Uh. 339 00:18:00,047 --> 00:18:02,087 But you would want all that stuff kind of mapped out and 340 00:18:02,087 --> 00:18:03,917 planned out, uh, ahead of time. 341 00:18:03,947 --> 00:18:07,187 And that's kind of, you know, I think we touch on that in a different episode 342 00:18:07,187 --> 00:18:10,907 and being prepared for, for game day and having your, having your team on 343 00:18:10,907 --> 00:18:14,057 the same page and, and knowing what to do when certain things happen. 344 00:18:14,927 --> 00:18:19,067 Do you ever see, like, this is fascinating to me, by the way. 345 00:18:19,247 --> 00:18:23,507 I haven't dealt a lot into the security side, so it's kind of cool and it reminds 346 00:18:23,507 --> 00:18:25,967 me a lot of TV shows to some extent. 347 00:18:26,327 --> 00:18:30,947 Uh, the question I had though is I know that you could try to stop an 348 00:18:30,947 --> 00:18:32,357 attack early on, like you said, right? 349 00:18:32,357 --> 00:18:35,537 If you detect it early on, you could probably stop it before harm comes. 350 00:18:36,242 --> 00:18:41,222 But at the same time, if you don't know what they're after, isn't that also 351 00:18:41,222 --> 00:18:45,692 kind of a downside because they might figure out a different attack vector to 352 00:18:45,692 --> 00:18:47,672 come back back at you through, right. 353 00:18:47,672 --> 00:18:52,052 So is that some of the risk trade-offs that happens at like a 354 00:18:52,052 --> 00:18:55,412 business level that the business sort of needs to make that decision? 355 00:18:56,357 --> 00:18:57,017 Absolutely. 356 00:18:57,017 --> 00:19:00,497 And that's the, so there's, there's value in, in exactly what you said. 357 00:19:01,097 --> 00:19:04,112 Um, you know, if I had, if I had a thousand things to protect. 358 00:19:04,937 --> 00:19:09,437 And I only had a thousand dollars to protect them then without knowing 359 00:19:09,437 --> 00:19:12,407 the value of all that stuff and what I really need to protect, 360 00:19:12,407 --> 00:19:16,337 and I'm gonna give a dollar of a protection to all thousand things. 361 00:19:17,297 --> 00:19:21,677 if business says out of these thousand things, 10 of them are the most 362 00:19:21,677 --> 00:19:25,487 critical for us to maintain business operations and continue making money 363 00:19:25,487 --> 00:19:29,417 and make sure the lights are on tomorrow, then I'm gonna reallocate. 364 00:19:29,792 --> 00:19:33,812 Proportionately that a thousand dollars of security funding to 365 00:19:33,812 --> 00:19:36,242 protect primarily these 10 things. 366 00:19:36,572 --> 00:19:42,122 And then some, maybe, uh, diluted version of, you know, decent cyber 367 00:19:42,122 --> 00:19:48,452 hygiene to the other, you know, 990, uh, because they are layers between 368 00:19:48,572 --> 00:19:51,962 bad guys in the outside world and these 10 things that we care about. 369 00:19:51,962 --> 00:19:57,272 So we need some tools and, and capabilities on those other 990 things. 370 00:19:57,932 --> 00:20:01,442 But I'm gonna focus most of my, my resources on the, 371 00:20:01,682 --> 00:20:03,212 the, the jewels, if you will. 372 00:20:03,647 --> 00:20:03,857 Yeah. 373 00:20:04,742 --> 00:20:09,422 and that's just part of what we would consider a business impact analysis. 374 00:20:09,422 --> 00:20:11,132 Where's the, where's the critical stuff? 375 00:20:11,132 --> 00:20:15,872 Well, the other part of that analysis would be what is the financial impact? 376 00:20:16,352 --> 00:20:20,642 What is the business and operational impact if these things are infected 377 00:20:20,642 --> 00:20:23,492 or, or compromised or unavailable? 378 00:20:23,792 --> 00:20:25,382 Is that a thousand dollars an hour? 379 00:20:25,382 --> 00:20:26,882 Is it a million dollars a day? 380 00:20:26,882 --> 00:20:26,942 I. 381 00:20:27,437 --> 00:20:32,837 How, and then how many, how fast do I have to to get things back up and running? 382 00:20:33,197 --> 00:20:36,347 Because, you know, let's say we, we, we lose those 10 things to 383 00:20:36,347 --> 00:20:42,077 ransomware and the bad guys want $7 million, uh, to help you recover that. 384 00:20:42,767 --> 00:20:46,037 Well, the business could go, all right, so they want 7 million. 385 00:20:46,037 --> 00:20:48,107 We've got 5 million in insurance. 386 00:20:48,557 --> 00:20:51,827 Um, insurance says they'll cover it. 387 00:20:51,827 --> 00:20:53,297 So we're out 2 million. 388 00:20:54,857 --> 00:20:58,937 If we don't recover this within a week, we're out 10 million because 389 00:20:58,937 --> 00:21:00,707 that's how much money we're gonna lose. 390 00:21:01,457 --> 00:21:07,457 then the IT guys and, and all of our subject matter experts are telling me 391 00:21:07,457 --> 00:21:12,077 that we can rebuild this whole thing for 10 million or maybe 9 million. 392 00:21:12,077 --> 00:21:15,887 So do we do it on our own and invest in X, Y, Z? 393 00:21:16,157 --> 00:21:17,987 Do we pay the bad guys who. 394 00:21:18,902 --> 00:21:20,432 no guarantee there either. 395 00:21:21,362 --> 00:21:24,812 or do we just suffer through it for a week and we're out X dollars while we 396 00:21:24,812 --> 00:21:28,022 try to rebuild it and recover on our own? 397 00:21:28,922 --> 00:21:32,222 So that's, that's the business side of ransomware and some of these 398 00:21:32,222 --> 00:21:36,122 cyber breaches that it, and subject matter experts like my, we're just 399 00:21:36,122 --> 00:21:41,822 giving business intelligence for them to then make the decision. 400 00:21:41,822 --> 00:21:44,402 Paying the ransom should never be an IT decision. 401 00:21:44,402 --> 00:21:44,462 I. 402 00:21:45,452 --> 00:21:45,842 guy, the 403 00:21:45,902 --> 00:21:46,172 Yeah, 404 00:21:46,412 --> 00:21:47,702 said, we're not the one going. 405 00:21:47,702 --> 00:21:48,572 Yeah, pay the ransom. 406 00:21:49,202 --> 00:21:53,012 We're giving the business, the executive team, the information 407 00:21:53,012 --> 00:21:54,272 they need to make that decision. 408 00:21:54,572 --> 00:21:54,782 Yeah. 409 00:21:54,842 --> 00:21:55,112 Sorry 410 00:21:55,292 --> 00:21:55,592 agreed. 411 00:21:55,622 --> 00:21:56,852 we went off on a tangent, but. 412 00:21:57,962 --> 00:21:58,532 That's all right. 413 00:21:58,622 --> 00:21:59,132 That's all right. 414 00:21:59,882 --> 00:22:00,752 Um. 415 00:22:01,637 --> 00:22:05,687 So, so, so let's, let me get a sort of what I, what I think would be an 416 00:22:05,687 --> 00:22:07,097 interesting part of this episode. 417 00:22:07,097 --> 00:22:12,382 Not saying this, this wasn't interesting, but a, a, a fascinating part is you, 418 00:22:12,387 --> 00:22:14,327 you, you've seen a bunch of attacks. 419 00:22:14,837 --> 00:22:22,547 What are some of the like, weird things that we're going on that ultimately, um. 420 00:22:23,777 --> 00:22:25,937 You know, ended up being ransomware attacks, right? 421 00:22:25,937 --> 00:22:29,387 It's like they see this weird thing going on, and then eventually what 422 00:22:29,387 --> 00:22:32,082 they figured out was, oh, well, it's because we have ransomware. 423 00:22:32,172 --> 00:22:35,142 because always what I hear, sorry Mike, before you continue, always what I hear 424 00:22:35,142 --> 00:22:38,682 is like, oh, all of a sudden I couldn't access files because they were all 425 00:22:38,682 --> 00:22:43,152 encrypted, or things like that, which is like way, I'm guessing further downstream. 426 00:22:43,452 --> 00:22:43,812 Right? 427 00:22:43,812 --> 00:22:47,952 And I'm sure you have a lot of interesting stories about, hey, this, this, or this. 428 00:22:49,862 --> 00:22:50,822 Uh, you are right. 429 00:22:50,822 --> 00:22:55,682 It, it, it's, it's usually never, uh, a phone call with someone saying, I was 430 00:22:55,682 --> 00:22:59,642 in the middle of doing X, Y, and Z and all of a sudden I, I, things changed. 431 00:23:00,062 --> 00:23:02,072 It's, it's rarely ever that. 432 00:23:02,477 --> 00:23:07,067 And bad guys know this, so if, if bad guys tip their, their hand 433 00:23:08,777 --> 00:23:10,877 when people are at the console, 434 00:23:13,307 --> 00:23:16,397 the response to that is, is gonna be pretty immediate. 435 00:23:17,132 --> 00:23:17,482 Right. 436 00:23:17,567 --> 00:23:19,157 want, don't want that. 437 00:23:19,187 --> 00:23:26,087 They want, they want your response to be delayed to some degree, hours, days. 438 00:23:26,867 --> 00:23:31,757 they also want to be conscious and even considerate in some cases. 439 00:23:32,807 --> 00:23:37,937 sure that you can, some to some degree have the ability to recover with minimal 440 00:23:37,937 --> 00:23:41,747 impact because they want you to, they want to, they want to be your friend. 441 00:23:41,747 --> 00:23:43,997 They want, Hey, I did this on a Friday. 442 00:23:44,177 --> 00:23:48,797 So you've got the weekend to recover, and so if by Monday you decide to 443 00:23:48,797 --> 00:23:50,567 pay the ransom, everything's fine. 444 00:23:51,707 --> 00:23:52,007 Right? 445 00:23:52,007 --> 00:23:56,267 So ransomware attacks usually trigger Thursday, Friday, 446 00:23:57,117 --> 00:23:57,417 Yeah. 447 00:23:58,322 --> 00:24:00,542 It's usually not in the middle of the day. 448 00:24:00,572 --> 00:24:03,212 It's usually first thing in the morning or in the middle of the night. 449 00:24:04,022 --> 00:24:07,652 it's when you come to work and you notice your computer's useless. 450 00:24:08,312 --> 00:24:11,612 It's when the middle of the night, uh, your, your batch 451 00:24:11,612 --> 00:24:13,862 processes, your batch jobs fail. 452 00:24:14,642 --> 00:24:17,972 And they know that a lot of organizations, well, I'll just check 453 00:24:17,972 --> 00:24:19,292 on it in the morning when I get there. 454 00:24:19,712 --> 00:24:20,072 Right. 455 00:24:20,837 --> 00:24:25,787 so they've had hours to, to de to plan and deploy their ransomware 456 00:24:25,787 --> 00:24:28,097 to do as much damage as they can. 457 00:24:29,507 --> 00:24:30,827 Uh, so there's that part. 458 00:24:30,827 --> 00:24:34,757 And then Curtis asked about some of the things that we've seen and 459 00:24:34,757 --> 00:24:38,237 we've seen, we've seen quite a, a few different interesting things. 460 00:24:38,327 --> 00:24:41,747 Uh, and one of the things I'll touch on too is, uh, initially 461 00:24:41,747 --> 00:24:43,367 you asked, well, how do we notice? 462 00:24:43,367 --> 00:24:44,417 Notice these things? 463 00:24:45,107 --> 00:24:46,487 How do we know if we have ransomware? 464 00:24:46,517 --> 00:24:50,567 Well, you'll notice, uh, a small degradation in performance. 465 00:24:50,957 --> 00:24:53,567 If you are watching a movie as an example, if you're streaming 466 00:24:53,567 --> 00:24:55,577 something, you might see some glitches. 467 00:24:56,597 --> 00:24:57,467 and you're like, that's weird. 468 00:24:57,467 --> 00:24:58,787 I've got fiber to my house. 469 00:24:58,787 --> 00:24:59,117 Why? 470 00:24:59,147 --> 00:25:00,077 Why is it glitching? 471 00:25:00,737 --> 00:25:01,907 well, it's not the internet. 472 00:25:01,907 --> 00:25:06,797 It's, it's, it's the resources on your computer being consumed by other stuff. 473 00:25:07,037 --> 00:25:10,607 So there's some symptomatic stuff that, that's observable. 474 00:25:11,207 --> 00:25:14,147 Well, then on the, um. 475 00:25:15,722 --> 00:25:18,722 Network behavior side, especially if you're a, uh, 476 00:25:20,732 --> 00:25:23,222 a public sector entity, like a school district. 477 00:25:24,032 --> 00:25:27,842 are information sharing and analysis centers called ISACs. 478 00:25:27,872 --> 00:25:34,502 There's a multi-state There's, uh, the state of Texas has its own called DIR. 479 00:25:35,747 --> 00:25:39,452 if you're in a specific sector like financial sector, there's 480 00:25:39,452 --> 00:25:41,432 a finance, a finance isac. 481 00:25:41,432 --> 00:25:43,592 There's one for healthcare credit unions. 482 00:25:44,237 --> 00:25:50,447 Auto dealerships and they all monitor the organizations that belong to their isac. 483 00:25:51,287 --> 00:25:55,757 And so in the state of Texas as an example, they might call a school district 484 00:25:55,757 --> 00:26:01,787 and say, Hey, we are seeing ransomware traffic coming out of your network. 485 00:26:01,967 --> 00:26:02,357 You need to 486 00:26:02,572 --> 00:26:02,842 Hmm. 487 00:26:03,557 --> 00:26:04,307 Just a heads up. 488 00:26:04,907 --> 00:26:06,857 Well, and that's, that's pretty common. 489 00:26:06,947 --> 00:26:08,357 Uh, the majority of. 490 00:26:09,422 --> 00:26:14,552 The majority of notifications to the help desk about something weird going wrong, 491 00:26:14,672 --> 00:26:16,862 going on is usually made by a third party. 492 00:26:18,392 --> 00:26:23,642 It's just the way it's, uh, we're so focused on operations, uh, and, and 493 00:26:23,642 --> 00:26:25,412 keeping the lights on and the fires out. 494 00:26:26,222 --> 00:26:28,292 very rarely do we see these weird things. 495 00:26:28,622 --> 00:26:33,092 And so those, those third parties, whether it's law enforcement or an ISAC or a 496 00:26:33,092 --> 00:26:39,872 customer or somebody working from home, it's usually somebody else notifying 497 00:26:39,872 --> 00:26:41,252 us that weird things are happening. 498 00:26:42,122 --> 00:26:46,082 And so as ransomware progresses, uh, and there's different, and we 499 00:26:46,082 --> 00:26:50,042 touched on this initially too, there's different types of ransomware attacks. 500 00:26:50,132 --> 00:26:52,652 There's the type that attacks just you as a user. 501 00:26:53,702 --> 00:26:57,452 Whether you're, you know, grandma at home or you're just working from home and 502 00:26:57,452 --> 00:27:02,252 you've got this, this hybrid workstation where it's business and some personal 503 00:27:02,252 --> 00:27:05,042 stuff, uh, or just business, but. 504 00:27:05,387 --> 00:27:08,747 We're working from home as kind of as an individual, and so we get infected 505 00:27:08,747 --> 00:27:13,067 outside of the, the normal organizational network, the corporate network. 506 00:27:13,067 --> 00:27:17,657 We're, we're working off of a wifi at the library or a coffee shop or 507 00:27:17,657 --> 00:27:22,277 at home, and so we don't have the same network perimeter protections 508 00:27:22,277 --> 00:27:24,287 that we might have at, at, at work. 509 00:27:24,917 --> 00:27:29,597 Well, those, those attacks focus primarily just on this laptop, this endpoint. 510 00:27:31,082 --> 00:27:33,242 And it's, it's kind of a one dimensional attack. 511 00:27:33,242 --> 00:27:34,652 You're not connected to anything else. 512 00:27:34,652 --> 00:27:38,852 It's just gonna do what it does here, and there's something valuable that 513 00:27:38,852 --> 00:27:40,502 you're willing to pay a ransom for. 514 00:27:41,402 --> 00:27:45,662 Well, then the, the attacks at work on the corporate network, the organizational 515 00:27:45,662 --> 00:27:48,722 network, are a bit different in that the bad guys want to do enough 516 00:27:48,752 --> 00:27:52,202 reconnaissance first to see what they have access to, and then make that, 517 00:27:52,892 --> 00:27:57,932 that ransomware, that infection as broad as possible all at the same time. 518 00:27:58,427 --> 00:28:05,177 So in most cases, they will compromise an account, try to es elevate to a, an admin, 519 00:28:05,567 --> 00:28:07,757 uh, or equivalent account power user. 520 00:28:08,837 --> 00:28:13,847 find your domain controllers and then script a deployment package to put 521 00:28:13,847 --> 00:28:17,537 malware on all your computers, all your endpoints, all at the same time 522 00:28:17,542 --> 00:28:21,347 with a trigger to start infecting and encrypting all at the same time. 523 00:28:22,277 --> 00:28:26,507 And so we had, we had one, uh, it was a, it was a pretty large company, 524 00:28:26,597 --> 00:28:30,107 uh, headquartered in Dallas that has projects all over the country. 525 00:28:31,037 --> 00:28:33,287 dollar projects, multimillion dollar projects. 526 00:28:33,887 --> 00:28:39,827 And, um, they infected 2,800 machines all at the same time, within four hours. 527 00:28:41,007 --> 00:28:41,087 Hmm. 528 00:28:41,387 --> 00:28:42,437 So Friday morning, I 529 00:28:42,682 --> 00:28:42,862 Wow. 530 00:28:43,037 --> 00:28:46,517 think it kicked off at 4:00 AM And so by the time people 531 00:28:46,517 --> 00:28:47,927 came to the corporate office. 532 00:28:49,217 --> 00:28:52,577 machine, 80% of their environment was encrypted in four hours. 533 00:28:53,072 --> 00:28:57,647 And they didn't notice anything before that the 2,800 machines were encrypted. 534 00:28:58,757 --> 00:29:00,947 And even though this is a pretty large environment, they only 535 00:29:00,947 --> 00:29:03,257 had three or four full-time. 536 00:29:04,577 --> 00:29:07,637 IT staff, had a, an executive it. 537 00:29:07,847 --> 00:29:11,057 I'm not sure if he was the CIO or director of what his title was. 538 00:29:11,837 --> 00:29:16,072 Uh, but in this particular case, and then, you know, kind of working backwards, you, 539 00:29:16,077 --> 00:29:21,227 you get the phone call, we need help, you show up, assess the current situation, and 540 00:29:21,227 --> 00:29:23,087 you work backwards to how did this happen? 541 00:29:23,537 --> 00:29:26,057 And we're, so we're starting to piece together, you know, 542 00:29:26,057 --> 00:29:27,737 that was the domain controller. 543 00:29:27,857 --> 00:29:30,047 You know, there was a script, there was all this stuff. 544 00:29:30,347 --> 00:29:31,967 Well, how did they get to the domain controller? 545 00:29:31,967 --> 00:29:33,227 Will they use this account? 546 00:29:33,227 --> 00:29:34,427 Well, how'd they get that account? 547 00:29:34,667 --> 00:29:37,037 And so you're working backwards to patient zero. 548 00:29:37,847 --> 00:29:40,757 And it was actually the, uh, the backup administrator. 549 00:29:41,882 --> 00:29:42,752 Uh, who, 550 00:29:42,782 --> 00:29:43,862 backup Bob. 551 00:29:44,282 --> 00:29:48,902 who, who had worked at this company forever and never taken a vacation 552 00:29:49,892 --> 00:29:55,022 some three or four months ago, uh, while he was looking for vacation 553 00:29:55,022 --> 00:29:59,342 stuff, got infected and they had 554 00:29:59,412 --> 00:29:59,532 Hmm. 555 00:29:59,822 --> 00:30:05,462 to his account for months while also watching him plan his vacation, which 556 00:30:05,462 --> 00:30:09,362 then they lined up their attack with, so he left for vacation Wednesday night. 557 00:30:10,352 --> 00:30:15,122 They, they conducted this attack, uh, Friday morning, and so we actually 558 00:30:15,122 --> 00:30:20,072 were considering him as a suspect as part of this, uh, ransomware. 559 00:30:20,492 --> 00:30:20,882 Right. 560 00:30:21,242 --> 00:30:28,712 we started seeing, uh, several years ago threat actors have been propositioning 561 00:30:28,712 --> 00:30:35,852 internal privileged users to help them their ransomware in exchange for a, 562 00:30:35,852 --> 00:30:37,862 a percentage of the, the monies paid. 563 00:30:39,542 --> 00:30:39,962 But in this 564 00:30:39,962 --> 00:30:40,322 Yeah. 565 00:30:40,322 --> 00:30:43,712 case, they, they had access through a, a network vulnerability, 566 00:30:44,612 --> 00:30:47,222 um, several months prior. 567 00:30:47,522 --> 00:30:52,832 Um, that, uh, um, additional access through the backup administrator account. 568 00:30:53,312 --> 00:30:57,392 And then in this case, the business decided to pay the ransom because 569 00:30:57,392 --> 00:31:00,512 they, these large multimillion dollar projects were at stake and they 570 00:31:00,512 --> 00:31:03,662 wanted to make sure that they got their data back and could continue. 571 00:31:04,397 --> 00:31:05,927 Uh, working on these things. 572 00:31:06,377 --> 00:31:10,937 Uh, so they paid the ransom on a Monday and the very next day, the threat 573 00:31:10,937 --> 00:31:16,187 actors, uh, messaged them back and said, you know, for another $80,000, 574 00:31:16,187 --> 00:31:17,537 we promised to leave you alone. 575 00:31:17,957 --> 00:31:21,437 And it was because they had, they had, you know, I talked about persistence. 576 00:31:21,737 --> 00:31:26,057 Well, they knew that we were gonna clean all the ransomware off, but they 577 00:31:26,057 --> 00:31:31,007 had also configured, um, two dormant back doors that would've allowed 578 00:31:31,007 --> 00:31:33,257 them to regain access to the network. 579 00:31:33,962 --> 00:31:34,892 At a future date. 580 00:31:34,952 --> 00:31:38,312 Well, we had found those over the weekend and made sure everything 581 00:31:38,312 --> 00:31:39,722 was, was clean and tight. 582 00:31:40,142 --> 00:31:42,932 Um, no, no ability to get back in. 583 00:31:42,932 --> 00:31:45,542 So we told them, you know, we told them not to pay the ransom 584 00:31:45,542 --> 00:31:48,092 to begin with, but did it anyway. 585 00:31:48,482 --> 00:31:52,892 And then the, the next day when they said, you know, you pay some more money, we, 586 00:31:52,947 --> 00:31:54,512 we, we will promise to leave you alone. 587 00:31:54,512 --> 00:31:57,092 We told them that we took care of all that and they didn't need to do it. 588 00:31:57,092 --> 00:31:57,302 So. 589 00:31:58,877 --> 00:32:04,577 So a, a question that I have, uh, Mike, is with all of these things, 590 00:32:04,577 --> 00:32:12,377 especially during this reconnaissance phase, surely a good SEIM tool 591 00:32:13,132 --> 00:32:13,552 Mm-Hmm. 592 00:32:15,197 --> 00:32:17,537 see this stuff going on. 593 00:32:18,227 --> 00:32:20,327 Right, and, and can detect it. 594 00:32:21,107 --> 00:32:22,637 Surely that's the case. 595 00:32:22,637 --> 00:32:26,477 Tell me, I'm, and I know that nobody installs them. 596 00:32:26,627 --> 00:32:26,897 Right. 597 00:32:26,897 --> 00:32:27,587 I understand that. 598 00:32:27,587 --> 00:32:31,067 Like, it, it's a, it's an expense for that, that a lot 599 00:32:31,067 --> 00:32:34,277 of companies don't install them and that, and it doesn't matter. 600 00:32:34,277 --> 00:32:35,927 But my question is, what's that? 601 00:32:36,317 --> 00:32:37,372 Or configure them properly. 602 00:32:37,667 --> 00:32:37,997 Right? 603 00:32:37,997 --> 00:32:40,877 Or they've configured 'em because they got too many false positives 604 00:32:40,877 --> 00:32:42,437 and they've, they've ified it right. 605 00:32:42,812 --> 00:32:43,757 You, you're, you're right. 606 00:32:43,757 --> 00:32:46,952 Uh, and, but I think there's a misconception there, uh, that, 607 00:32:46,982 --> 00:32:48,902 that these tools are too expensive. 608 00:32:48,902 --> 00:32:50,582 They, they used to be very expensive. 609 00:32:51,452 --> 00:32:54,902 And really it's, it's the labor that's the most expensive part. 610 00:32:54,902 --> 00:32:58,082 And that's why working with a managed security service provider 611 00:32:58,862 --> 00:33:00,392 is a much better approach. 612 00:33:01,022 --> 00:33:05,312 you're not paying one for one labor, you're, you're paying a, 613 00:33:05,402 --> 00:33:08,372 a disproportionate amount of, of labor because their labor is 614 00:33:08,372 --> 00:33:09,812 spread across all their clients. 615 00:33:10,652 --> 00:33:14,912 And so, SEIM products back in the day for sure, uh, and there were open, they're 616 00:33:14,912 --> 00:33:17,192 still open source SEIM products, but, uh. 617 00:33:18,287 --> 00:33:21,887 to, to you guys' point you, you've gotta configure those, uh, well then 618 00:33:21,932 --> 00:33:27,077 if, if you're not in the, the sim, if you're not experienced in, in how 619 00:33:27,077 --> 00:33:31,157 to configure a sim, then you could be missing the, the, the point there too. 620 00:33:31,157 --> 00:33:32,207 You could be missing a lot. 621 00:33:32,207 --> 00:33:37,907 So, back to the experience and expertise of an MSSP, uh, to do all that for you. 622 00:33:38,237 --> 00:33:40,997 So I think there's a misconception about price. 623 00:33:41,027 --> 00:33:42,287 Uh, I, it's very affordable. 624 00:33:43,562 --> 00:33:46,052 today than more affordable than it have ever has been. 625 00:33:46,352 --> 00:33:49,112 And whether the client wants to own the license or or not, 626 00:33:49,112 --> 00:33:50,582 that's a different conversation. 627 00:33:50,582 --> 00:33:52,052 But to your point, yes. 628 00:33:53,042 --> 00:34:00,332 new next gen security incident and event management tools, sims, um, are 629 00:34:00,332 --> 00:34:03,182 capable of identifying weird stuff. 630 00:34:03,842 --> 00:34:09,992 Uh, and so our sim, as an example, does use, it's UEBA user 631 00:34:09,992 --> 00:34:11,492 and event behavior analytics. 632 00:34:12,212 --> 00:34:15,482 it uses machine learning to develop a behavioral baseline 633 00:34:15,482 --> 00:34:17,522 by user, by asset, by network, 634 00:34:19,622 --> 00:34:26,312 And so for example, if Curtis does something 10 times a day, or his machine 635 00:34:26,312 --> 00:34:32,192 does, and tomorrow it does 10 or a thousand, get flagged as the behavioral 636 00:34:32,192 --> 00:34:37,142 anomaly before whatever that activity is evolves into a security incident. 637 00:34:38,252 --> 00:34:39,722 So if you got ransomware. 638 00:34:40,637 --> 00:34:46,007 That new file or even a file that maybe it, it, it looks like it's, uh, 639 00:34:46,037 --> 00:34:50,837 something that's been ed on your machine forever, but it starts doing something 640 00:34:50,837 --> 00:34:52,787 that your machine isn't normally doing. 641 00:34:53,537 --> 00:34:55,487 get, we'll see a flag for that and. 642 00:34:56,717 --> 00:35:00,557 In our experience, we'll also be able to determine, well, is that behavior 643 00:35:00,557 --> 00:35:05,597 consistent with symptoms of ransomware or, or some other type of malware? 644 00:35:06,347 --> 00:35:09,107 and then we can get on the phone and talk about, well, what did 645 00:35:09,107 --> 00:35:10,757 you just do or what have you done? 646 00:35:12,857 --> 00:35:18,197 On that note too, uh, I mentioned how organizations are typically, how 647 00:35:18,197 --> 00:35:20,447 they identify ransomware or malware. 648 00:35:20,747 --> 00:35:22,007 One of them is. 649 00:35:23,777 --> 00:35:28,037 You get a call at the help desk today that a user says, Hey, about two weeks 650 00:35:28,037 --> 00:35:31,157 ago, I, it, it just kind of occurred to me, it's really been bothering me, but 651 00:35:31,157 --> 00:35:35,717 about two weeks ago I did this thing and you know, it's really been bothering me. 652 00:35:35,717 --> 00:35:37,247 So I just thought I'd tell you now. 653 00:35:38,027 --> 00:35:39,257 happens quite a bit too. 654 00:35:39,257 --> 00:35:42,227 And so when you start looking at that user's machine and, and their, 655 00:35:42,287 --> 00:35:45,197 their email and yep, sure enough you clicked on ransomware and it's 656 00:35:45,197 --> 00:35:46,607 somewhere in this environment now. 657 00:35:46,607 --> 00:35:48,017 So now we gotta go track it down. 658 00:35:48,737 --> 00:35:49,187 Uh. 659 00:35:49,697 --> 00:35:53,177 Yeah, there's any number of things and a SEIM tool too, you can populate 660 00:35:53,897 --> 00:36:00,377 with, for example, if, if, if Mike got ransomware and we can determine the 661 00:36:00,377 --> 00:36:05,597 type of ransomware it is, we can then go do research on the, the, the, at 662 00:36:05,597 --> 00:36:07,487 the characteristics of that ransomware. 663 00:36:07,517 --> 00:36:10,757 I can now put that in the SEIM tool and it can look across your entire 664 00:36:10,757 --> 00:36:15,617 environment for other, um, other occurrences of those things during, to 665 00:36:15,617 --> 00:36:17,357 try and get ahead of the next infection. 666 00:36:18,287 --> 00:36:18,767 Um. 667 00:36:19,667 --> 00:36:22,517 But really SEIM is just part of the solution. 668 00:36:22,517 --> 00:36:27,257 You've also have, you also have to have a good protection, anti-malware, 669 00:36:27,677 --> 00:36:32,537 and those two things need to play well together the SEIM can identify the weird 670 00:36:32,537 --> 00:36:36,737 stuff, but then it has to be capable of telling the anti-malware on the, the, 671 00:36:37,187 --> 00:36:41,417 the computer what to quarantine and clean and, and do all this automatically 672 00:36:42,437 --> 00:36:44,267 because I've been preaching this forever. 673 00:36:45,197 --> 00:36:47,807 Response is the most important thing. 674 00:36:48,197 --> 00:36:51,677 You're gonna get attacked, you're gonna get infected, it's gonna happen. 675 00:36:51,887 --> 00:36:55,907 The only thing that's gonna save you, or at least mitigate the impact is how fast 676 00:36:55,907 --> 00:36:58,067 you can identify it and respond to it. 677 00:36:59,387 --> 00:36:59,627 Is 678 00:36:59,777 --> 00:37:00,167 so 679 00:37:00,377 --> 00:37:00,497 Is it. 680 00:37:00,497 --> 00:37:05,777 making sure that your tech stack really plays well together so that your response 681 00:37:05,777 --> 00:37:08,267 is, is as effective as it can be. 682 00:37:09,212 --> 00:37:14,687 Is it too soon to bring up the C company, the company whose name starts with the C? 683 00:37:15,977 --> 00:37:16,667 CrowdStrike. 684 00:37:17,127 --> 00:37:17,417 Yeah. 685 00:37:20,162 --> 00:37:21,032 It is not, 686 00:37:21,212 --> 00:37:21,632 too soon. 687 00:37:22,352 --> 00:37:22,922 it's not 688 00:37:23,567 --> 00:37:26,897 I, I, well, I will say, well, we don't have, we don't have much 689 00:37:26,897 --> 00:37:31,067 time left, but uh, if we can cover them quickly, I suppose. 690 00:37:32,162 --> 00:37:36,242 so CrowdStrike's a great, uh, endpoint protection tool and it, it has some 691 00:37:36,242 --> 00:37:40,082 really good capabilities as far as interacting with Sims as an example 692 00:37:40,082 --> 00:37:41,552 where the SEIM says weird stuff. 693 00:37:41,807 --> 00:37:46,127 Hey, CrowdStrike, go do this thing, clean that, that, uh, that machine. 694 00:37:46,367 --> 00:37:51,617 But I think it's also an interesting time to add that those endpoint, uh, that, that 695 00:37:51,617 --> 00:37:55,307 anti-malware stuff, that, that system, that, that software that's running on 696 00:37:55,307 --> 00:38:00,887 your system, it's collecting all this contextual data that's then feeding up to 697 00:38:00,887 --> 00:38:04,007 a SEIM and it's, it's the ability of that. 698 00:38:04,772 --> 00:38:07,442 That software on the endpoint, that CrowdStrike as an example. 699 00:38:07,442 --> 00:38:11,102 It's the, it's the, it's the ability of CrowdStrike to collect this good 700 00:38:11,102 --> 00:38:16,532 contextual data then gonna allow the SEIM to, to build a good baseline 701 00:38:16,532 --> 00:38:19,862 and, and really quickly determine where the deviations from normal are. 702 00:38:20,642 --> 00:38:22,352 in a lot of cases, the sim. 703 00:38:23,387 --> 00:38:27,917 Is gonna detect that behavioral anoma anomaly before CrowdStrike will, 704 00:38:28,367 --> 00:38:32,777 because CrowdStrike is still kind of, is very rules based when this 705 00:38:32,777 --> 00:38:34,397 and this and this and this happened. 706 00:38:34,397 --> 00:38:35,567 That's a security problem. 707 00:38:35,567 --> 00:38:38,027 CrowdStrike does really good at addressing security problems. 708 00:38:38,507 --> 00:38:42,107 CrowdStrike does not currently do really good at saying, Hey, that's never 709 00:38:42,107 --> 00:38:45,887 happened before, or That's happened a heck of a lot more often than it used to. 710 00:38:46,242 --> 00:38:47,742 That's what the SEIM does. 711 00:38:47,792 --> 00:38:52,122 But then the SEIM and the, and and CrowdStrike, as in this case, 712 00:38:52,392 --> 00:38:54,162 have to play really well together. 713 00:38:54,162 --> 00:38:56,682 So when the SEIM says That's weird, Hey, CrowdStrike. 714 00:38:58,787 --> 00:39:01,277 Put a pause on that, put a pin in that, put it, put it in 715 00:39:01,277 --> 00:39:03,947 quarantine, put it in timeout until we figure out what's going on. 716 00:39:04,577 --> 00:39:08,597 And we see that a lot in, um, organizations, especially it 717 00:39:08,597 --> 00:39:09,887 where we're rolling out updates. 718 00:39:09,887 --> 00:39:13,427 We're installing new software or third party things like your 719 00:39:13,427 --> 00:39:17,477 financial system or your dealer management software needs to update 720 00:39:17,477 --> 00:39:19,157 something that the SEIM is gonna go. 721 00:39:19,157 --> 00:39:19,457 No. 722 00:39:19,457 --> 00:39:20,567 Oh, that's weird. 723 00:39:21,347 --> 00:39:25,607 And you're gonna hear it from it or, or the end user going, Hey, my, my install 724 00:39:25,607 --> 00:39:27,767 paused, or it didn't work, or whatever. 725 00:39:27,797 --> 00:39:28,667 And Well, that's good. 726 00:39:29,057 --> 00:39:30,677 It's, it's working the way it should. 727 00:39:31,012 --> 00:39:31,302 Yeah. 728 00:39:31,457 --> 00:39:31,697 Yep. 729 00:39:32,162 --> 00:39:35,162 Yeah, it would've, it would've been nice if, if a, if a SEIM tool had 730 00:39:35,162 --> 00:39:39,722 said, Hey, uh, uh, that file you just pushed out is zero length. 731 00:39:40,202 --> 00:39:42,692 Uh, you might might wanna take a look at that. 732 00:39:43,097 --> 00:39:43,757 right. 733 00:39:43,967 --> 00:39:47,027 And so, well that's a whole other story and a whole other ball of wax. 734 00:39:47,027 --> 00:39:48,227 But that's right. 735 00:39:48,332 --> 00:39:48,722 yeah. 736 00:39:49,757 --> 00:39:50,327 um. 737 00:39:50,732 --> 00:39:53,342 In this case, it was an involuntary patch. 738 00:39:53,372 --> 00:39:55,652 You, you didn't have a choice of, of not 739 00:39:55,667 --> 00:39:56,027 Yeah. 740 00:39:56,252 --> 00:39:56,852 installing 741 00:39:56,957 --> 00:39:57,197 Yeah, 742 00:39:57,542 --> 00:39:59,522 it, it, it messed things up. 743 00:39:59,522 --> 00:40:03,272 But if you had a good incident response plan with a playbook that says when 744 00:40:03,632 --> 00:40:07,862 these certain types of things happen, and they can be categoric things 745 00:40:07,862 --> 00:40:09,212 like, my machine stopped working. 746 00:40:09,212 --> 00:40:10,772 I've got this blue screen of death. 747 00:40:11,042 --> 00:40:12,092 I don't know what to do with it. 748 00:40:12,452 --> 00:40:14,312 Uh, well, there's a playbook for that 749 00:40:14,477 --> 00:40:14,777 Throwing 750 00:40:14,822 --> 00:40:15,002 we. 751 00:40:15,197 --> 00:40:17,507 so, so if you're not. 752 00:40:18,407 --> 00:40:18,827 and, 753 00:40:19,007 --> 00:40:19,577 So if you're, 754 00:40:19,697 --> 00:40:24,227 to call and, and here's where the, the extra machines are or the images 755 00:40:24,227 --> 00:40:27,317 that we need to re, re-image machines with or whatever the case was. 756 00:40:27,317 --> 00:40:29,267 We've thought through this and here's our playbook for it. 757 00:40:29,267 --> 00:40:31,127 And that needs to be part of your incident response plan. 758 00:40:32,087 --> 00:40:34,997 so basically not Delta Airlines apparently. 759 00:40:35,572 --> 00:40:35,792 Yep. 760 00:40:38,077 --> 00:40:38,297 Oh. 761 00:40:38,792 --> 00:40:39,012 Uh, 762 00:40:39,792 --> 00:40:40,012 But 763 00:40:40,152 --> 00:40:40,572 anyway. 764 00:40:41,232 --> 00:40:42,412 By, by the way, it's funny. 765 00:40:43,122 --> 00:40:43,412 Yeah. 766 00:40:43,517 --> 00:40:44,057 What was that? 767 00:40:44,222 --> 00:40:47,402 credit, having a good virtual environment with your snapshots 768 00:40:47,402 --> 00:40:48,332 and all those things that 769 00:40:48,482 --> 00:40:48,902 Yeah, 770 00:40:49,292 --> 00:40:51,032 that saved the other airlines, 771 00:40:51,902 --> 00:40:52,442 yeah, 772 00:40:52,817 --> 00:40:56,012 or, or in some cases, some of the airlines had different operating 773 00:40:56,012 --> 00:40:57,632 system environments and all that too. 774 00:40:57,632 --> 00:40:58,772 But the, the virtual 775 00:40:58,862 --> 00:40:59,462 yeah. 776 00:40:59,612 --> 00:41:01,472 able to, to, uh, 777 00:41:01,682 --> 00:41:02,132 It was just, 778 00:41:02,342 --> 00:41:02,912 snapshots 779 00:41:03,092 --> 00:41:08,552 it was funny, I, I, last week I flew to Atlanta for, you know, the company that 780 00:41:08,552 --> 00:41:10,682 I worked for and for the first time. 781 00:41:10,997 --> 00:41:12,977 No one asked me, why didn't you fly Delta? 782 00:41:16,832 --> 00:41:17,042 Well at. 783 00:41:17,057 --> 00:41:17,327 Oh. 784 00:41:17,327 --> 00:41:20,207 Anyway, well, well listen, we gotta finish up here. 785 00:41:20,267 --> 00:41:27,007 Um, so what I'm, what I'm hearing from you is it does sound like a, a good SEIM 786 00:41:27,007 --> 00:41:31,997 tool is, um, SEIM tool versus XDR tool. 787 00:41:31,997 --> 00:41:33,647 Uh, just a quick thought there. 788 00:41:34,127 --> 00:41:36,167 Um, you know, 'cause I know there's both. 789 00:41:36,482 --> 00:41:40,622 so, SEIM is a little limited in, in its traditional ability. 790 00:41:40,652 --> 00:41:43,412 It's a, it's traditional ability to ingest data. 791 00:41:44,132 --> 00:41:48,002 So, uh, in SEIM tools typically don't have that automated response. 792 00:41:48,002 --> 00:41:49,112 They call it soar. 793 00:41:49,262 --> 00:41:52,322 The, the, the orchestration of automated response. 794 00:41:52,712 --> 00:41:56,642 So SEIM tools, that's usually a bolt-on a third party or, or extra. 795 00:41:56,972 --> 00:42:00,333 But SEIM also does just tra traditional SIS log and. 796 00:42:01,307 --> 00:42:03,377 firewall log, you know, that kind of thing. 797 00:42:03,647 --> 00:42:09,737 Open XDR or XDR, uh, XDR is better because it's, it's primarily, 798 00:42:09,737 --> 00:42:13,367 it's, it's more of an open source approach, but XDR is that extra. 799 00:42:13,367 --> 00:42:19,577 Well, now I can adjust, uh, cloud and third party tools and I OT devices and OT 800 00:42:19,577 --> 00:42:23,057 device scada, uh, you know, smart stuff. 801 00:42:23,537 --> 00:42:28,937 Um, so it's, it's the evolution of sim, um, not just in its ability, 802 00:42:28,937 --> 00:42:30,407 but it's also, its its scope. 803 00:42:30,887 --> 00:42:36,017 Uh, so in in cyber uh, ingestion, we talk about north, 804 00:42:36,017 --> 00:42:37,607 south, east, and west traffic. 805 00:42:37,907 --> 00:42:40,757 So North and south is in and out of your environment, and east and 806 00:42:40,757 --> 00:42:42,767 west is, is within your environment. 807 00:42:43,097 --> 00:42:47,357 And as we, as, as a lot of environments start to migrate, either, either totally 808 00:42:47,357 --> 00:42:51,497 to the cloud or some hybrid on-premise cloud architecture, it's really 809 00:42:51,502 --> 00:42:56,327 important to to, to have a, a platform that's capable of, of expanding with 810 00:42:56,327 --> 00:42:59,237 you, uh, both in scope and capability. 811 00:42:59,627 --> 00:43:03,827 And, uh, so our platform is actually an open XDR platform. 812 00:43:04,217 --> 00:43:08,477 Um, it connects to just about anything that has a data, uh, a data feed. 813 00:43:09,567 --> 00:43:09,807 Cool. 814 00:43:10,907 --> 00:43:11,247 All right. 815 00:43:11,397 --> 00:43:16,207 Well thank you again, um, Mike, for joining us. 816 00:43:17,297 --> 00:43:20,087 As always, anytime happy to be here 817 00:43:21,137 --> 00:43:25,967 Persona, I, I am still glad to see you alive and not decapitated or 818 00:43:26,297 --> 00:43:26,417 or 819 00:43:26,597 --> 00:43:27,527 any, um, 820 00:43:27,632 --> 00:43:29,072 you were gonna make fun of me too. 821 00:43:29,072 --> 00:43:32,882 I know that you were like, ah, excuses, excuses. 822 00:43:33,527 --> 00:43:37,757 because again, normally this is me, not you that's doing the stupid stuff. 823 00:43:38,147 --> 00:43:42,077 Um, why am I seeing the outlet box for my thing at least? 824 00:43:42,167 --> 00:43:44,237 Did you, did you install this fan? 825 00:43:44,507 --> 00:43:44,837 Nope. 826 00:43:45,167 --> 00:43:47,357 Okay, well then, well you guys, because that would be me. 827 00:43:47,592 --> 00:43:47,882 Yeah. 828 00:43:47,897 --> 00:43:50,777 the one who installed the fan improperly 20 years ago, and 829 00:43:50,777 --> 00:43:51,887 then the fan is coming down. 830 00:43:52,457 --> 00:43:57,887 Um, and as I look at the air conditioner that I've installed up over there. 831 00:43:58,217 --> 00:44:01,607 Um, all right, well, thanks again to our listeners. 832 00:44:01,847 --> 00:44:03,527 We would be nothing without you. 833 00:44:03,797 --> 00:44:05,447 Uh, that is a wrap. 834 00:44:08,357 --> 00:44:13,037 The backup wrap up is written, recorded, and produced by me w Curtis Preston. 835 00:44:13,607 --> 00:44:15,077 If you need backup or Dr. 836 00:44:15,077 --> 00:44:18,707 Consulting content generation or expert witness work, 837 00:44:19,007 --> 00:44:20,987 check out backup central.com. 838 00:44:21,707 --> 00:44:24,827 You can also find links from my O'Reilly Books on the same website. 839 00:44:25,487 --> 00:44:29,477 Remember, this is an independent podcast and any opinions that 840 00:44:29,477 --> 00:44:33,377 you hear are those of the speaker and not necessarily an employer. 841 00:44:34,307 --> 00:44:34,997 Thanks for listening.