1 00:00:00,000 --> 00:00:03,280 You probably already own the cybersecurity tools that you need. 2 00:00:03,469 --> 00:00:04,500 That's not the issue. 3 00:00:05,150 --> 00:00:08,889 The issue is that nobody's using them, or certainly not using them correctly. 4 00:00:09,310 --> 00:00:12,659 Today's guest built an entire cybersecurity culture out of that 5 00:00:12,659 --> 00:00:15,379 one realization, one week at a time. 6 00:00:15,939 --> 00:00:19,589 This is the final episode in our Encore series, where we picked the 7 00:00:19,589 --> 00:00:23,269 episodes over the last few years that our listeners really engaged with. 8 00:00:25,139 --> 00:00:29,780 We found this guest schooling people on Reddit with a series of posts, uh, 9 00:00:29,789 --> 00:00:32,119 on what he called a security cadence. 10 00:00:32,679 --> 00:00:36,769 His pitch was to skip the new six-figure product and instead commit 11 00:00:36,769 --> 00:00:42,389 to one small, deliberate security change, uh, and improvement per week. 12 00:00:42,789 --> 00:00:46,519 We get into how that habit turned into a real culture shift at his company. 13 00:00:46,779 --> 00:00:50,289 Plus, of course, we talk about things like MFA, SIM hijacking, 14 00:00:50,679 --> 00:00:54,010 and why he thinks that chasing the latest zero day misses the point. 15 00:00:54,569 --> 00:00:59,089 He goes by his Reddit username of Snorkel42, and he clearly knows his stuff. 16 00:00:59,709 --> 00:01:03,220 If this is your first time watching or listening to me, hi, I'm W. 17 00:01:03,220 --> 00:01:05,309 Curtis Preston, AKA Mr. Backup. 18 00:01:05,749 --> 00:01:08,699 I've been obsessing about backup, recovery, and now cyber 19 00:01:08,699 --> 00:01:10,879 recovery for over 30 years. 20 00:01:11,190 --> 00:01:12,829 If that's your bag, then I'm your guy. 21 00:01:13,239 --> 00:01:16,290 You're not gonna find anyone that cares about that topic more than me. 22 00:01:16,809 --> 00:01:20,789 Ever since 1993 when I had to tell my boss that there were no backups of 23 00:01:20,789 --> 00:01:22,359 the database that we had just lost. 24 00:01:22,879 --> 00:01:26,330 Now I've written five O'Reilly books, a blog, and a podcast. 25 00:01:26,539 --> 00:01:30,529 Here we turn unappreciated admins into cyber recovery heroes. 26 00:01:30,809 --> 00:01:32,779 This is the Backup Wrap Up 27 00:01:36,327 --> 00:01:38,817 Hi, and welcome to Backup Central's podcast. 28 00:01:38,817 --> 00:01:41,937 I'm your host, W. Curtis Preston, AKA Mr. Backup. 29 00:01:42,297 --> 00:01:47,067 I have with me, my ghee deployment consultant, Prasanna Malaiyandi. 30 00:01:48,307 --> 00:01:50,167 uh, Curtis, how's your ghee going? 31 00:01:51,852 --> 00:01:55,662 You know, you may recall it a month or so ago. 32 00:01:55,692 --> 00:01:58,122 I got ghee for the first time. 33 00:01:58,482 --> 00:02:01,242 And, you know, for those that don't know what ghee is, it's 34 00:02:01,332 --> 00:02:02,952 clarified butter specifically. 35 00:02:02,952 --> 00:02:04,722 It's apparently an Indian thing, right? 36 00:02:04,992 --> 00:02:07,362 we did learn that ghee is from Sanskrit. 37 00:02:07,362 --> 00:02:10,002 That means sprinkled, which is interesting. 38 00:02:10,392 --> 00:02:15,042 But the, um, and the thing about it is that it can sit on the counter. 39 00:02:15,762 --> 00:02:19,332 Um, like it's shelf stable so it can sit on the counter and 40 00:02:19,332 --> 00:02:21,042 you made a comment by the way. 41 00:02:21,042 --> 00:02:23,592 I know this because I'm literally editing this episode right now. 42 00:02:24,762 --> 00:02:28,242 And you made a comment that, you know, it can sit there probably for a 43 00:02:28,242 --> 00:02:30,492 couple of months or until you run out. 44 00:02:30,642 --> 00:02:36,252 So I'll just say this, the, uh, the jar, I thought that I was going to 45 00:02:36,252 --> 00:02:38,152 be the only weirdo using the ghee. 46 00:02:38,682 --> 00:02:42,762 Yeah, I am not the only weirdo using ghee. 47 00:02:43,242 --> 00:02:46,482 In fact, if anything, the rest of the house is used the 48 00:02:46,552 --> 00:02:48,012 ghee much more than I have. 49 00:02:48,312 --> 00:02:50,642 And that jar that we bought is close to gone. 50 00:02:51,222 --> 00:02:51,852 So 51 00:02:52,692 --> 00:02:53,532 it's convenient. 52 00:02:53,532 --> 00:02:54,402 It's super easy. 53 00:02:54,402 --> 00:02:55,242 You just keep it out. 54 00:02:55,242 --> 00:02:56,202 You warm it up a little. 55 00:02:56,202 --> 00:02:57,762 It becomes really liquidy. 56 00:02:58,482 --> 00:03:00,222 You put it on warm bread. 57 00:03:00,222 --> 00:03:01,062 You toast that. 58 00:03:01,182 --> 00:03:02,172 super good. 59 00:03:02,562 --> 00:03:04,092 You can also put it in rice. 60 00:03:04,152 --> 00:03:04,662 Warm rice. 61 00:03:04,662 --> 00:03:05,352 It's really good. 62 00:03:05,967 --> 00:03:07,887 Yeah, well, I mean, it's like it's butter, right? 63 00:03:08,427 --> 00:03:12,677 you know, all the places you can put butter, you can put ghee. 64 00:03:13,017 --> 00:03:17,967 Um, it's just, it, it, it is interesting for those that have never had it. 65 00:03:17,967 --> 00:03:23,187 It has a slightly different flavor than butter, but it, you know, so there 66 00:03:23,187 --> 00:03:27,597 is a, there is a, I didn't know what my mouth was going, what was going 67 00:03:27,597 --> 00:03:29,067 to happen when I put it in there, 68 00:03:29,487 --> 00:03:31,267 That's funny because I never think about that. 69 00:03:31,267 --> 00:03:34,207 Like to me, like butter and ghee it's like, ah, yeah. 70 00:03:34,417 --> 00:03:34,747 Yeah. 71 00:03:34,777 --> 00:03:38,197 The first time I had, I had ghee, I remember going, huh, 72 00:03:38,287 --> 00:03:40,687 this tastes different, you know? 73 00:03:41,367 --> 00:03:47,587 Um, but what it was, but it was, but it was yummy, you know, so we continue to, 74 00:03:47,587 --> 00:03:49,537 but yeah, I think that jar is almost gone. 75 00:03:49,687 --> 00:03:54,427 So we're going to have to, we're going to have to find the ghee at Costco, which is 76 00:03:55,207 --> 00:03:56,257 like 64 ounce. 77 00:03:56,307 --> 00:03:57,237 like one pound. 78 00:03:57,567 --> 00:03:59,637 Yeah, one pound jars or something. 79 00:03:59,927 --> 00:04:05,087 Well we have a, a back by popular demand guest here. 80 00:04:05,627 --> 00:04:09,497 Uh, he was on the podcast before and. 81 00:04:10,257 --> 00:04:15,787 Is the author of the security cadence series on Reddit, been in IT for about 82 00:04:15,787 --> 00:04:18,367 25 years and in InfoSec about 20 years. 83 00:04:18,787 --> 00:04:25,057 And he is quite the celebrity over there on Reddit because I, you know, 84 00:04:25,087 --> 00:04:30,997 his posts have been incredibly popular with, uh, uh, he's got a, uh, a, uh, 85 00:04:31,207 --> 00:04:32,457 what a, what do they call it over there? 86 00:04:33,602 --> 00:04:38,522 The karma of 35,000, which, you know, if you don't know anything 87 00:04:38,522 --> 00:04:41,942 about Reddit, that's a, BFD, I'll just say that right now. 88 00:04:42,302 --> 00:04:45,482 And we had him previously on the podcast so if you haven't heard that podcast, 89 00:04:45,482 --> 00:04:46,652 you should totally listen to that. 90 00:04:47,292 --> 00:04:49,122 Welcome back to the podcast. 91 00:04:49,172 --> 00:04:50,452 snorkel42. 92 00:04:51,352 --> 00:04:52,312 Good to be back. 93 00:04:52,342 --> 00:04:56,492 And I tell you, so last time I learned what karma meant on reddit. 94 00:04:57,252 --> 00:05:00,867 time I learned what ghee is so good for me. 95 00:05:01,417 --> 00:05:02,657 So, um, 96 00:05:02,657 --> 00:05:06,057 I want to hear about this thing. 97 00:05:06,107 --> 00:05:09,127 You mentioned about security cadence. 98 00:05:09,547 --> 00:05:13,867 What, what started, because that was, that was the, um, that was 99 00:05:13,867 --> 00:05:15,247 the, what, what do you call that? 100 00:05:15,247 --> 00:05:19,897 Uh, the thing before the thing, the, the precursor, the preamble, 101 00:05:19,897 --> 00:05:24,217 the, in the title, um, uh, to the post that we saw that. 102 00:05:24,217 --> 00:05:25,747 So where did that term come from? 103 00:05:26,777 --> 00:05:29,657 So the term came from a previous employer. 104 00:05:29,657 --> 00:05:34,367 I worked at where I was a network engineer, um, and it was a large company 105 00:05:34,367 --> 00:05:36,527 that did not have an InfoSec presence. 106 00:05:36,527 --> 00:05:37,697 There was no InfoSec team. 107 00:05:37,697 --> 00:05:41,417 It was just kind of considered, Hey, all engineers are responsible for security. 108 00:05:42,157 --> 00:05:46,867 Um, and you know, we would, we'd have our occasional shots off the bow in terms of 109 00:05:46,867 --> 00:05:49,567 security, you know, problems or issues. 110 00:05:49,567 --> 00:05:53,377 You know, I, I hesitate to say breaches, but, you know, incidents and when 111 00:05:53,377 --> 00:05:56,407 they would occur and we would all pile into a conference room and we would 112 00:05:56,407 --> 00:05:59,167 talk about what happened and what we should have done to prevent it. 113 00:05:59,767 --> 00:06:03,967 And it would always come down to, well, if we just bought six figure dollar 114 00:06:03,967 --> 00:06:06,697 product X, this would not have occurred. 115 00:06:06,757 --> 00:06:10,417 Meanwhile, in the data center, there were piles of six-figure products 116 00:06:10,417 --> 00:06:13,747 that were completely ignored because those products never run themselves. 117 00:06:14,107 --> 00:06:17,287 And if you're complaining of not having resources to run those products, what 118 00:06:17,287 --> 00:06:20,467 makes you think you're going to have resources to buy and run new products? 119 00:06:21,037 --> 00:06:25,177 So I finally got fed up one day and just challenged the team to, you know what? 120 00:06:25,687 --> 00:06:26,947 We've got plenty of tooling. 121 00:06:26,977 --> 00:06:28,087 That's not the issue. 122 00:06:28,447 --> 00:06:30,607 We just don't have the oomph. 123 00:06:30,637 --> 00:06:32,647 We don't have the motivation to actually use it. 124 00:06:33,007 --> 00:06:36,157 So why don't we set ourselves a goal for six months, we're going to 125 00:06:36,157 --> 00:06:38,617 implement a security change every week. 126 00:06:38,647 --> 00:06:40,627 It could be a big change, could be a really minor change, but 127 00:06:40,627 --> 00:06:41,257 there's going to be something. 128 00:06:42,217 --> 00:06:43,297 Move the ball forward. 129 00:06:43,777 --> 00:06:46,297 And also during that six months, we are going to just put the 130 00:06:46,297 --> 00:06:47,917 kibosh on talking to any vendors. 131 00:06:47,947 --> 00:06:51,427 So no products are allowed, no solutions are allowed that we don't already own. 132 00:06:52,147 --> 00:06:55,477 Um, and you know, it took some, took some talking and wrangling 133 00:06:55,477 --> 00:06:59,157 people, but eventually folks fell in line and we sat down. 134 00:06:59,167 --> 00:07:01,777 We'd wrote out a list of, you know, here's some things just off the top of our head 135 00:07:01,777 --> 00:07:06,427 that we know we could implement with, you know, very little roadblocks, no impact. 136 00:07:06,937 --> 00:07:09,457 And we just started and we called it our security cadence. 137 00:07:09,457 --> 00:07:13,327 Once a week, we have a security cadence of releasing a security update and 138 00:07:13,327 --> 00:07:17,047 it, you know, it ended around six months in our CIO came to us and said, 139 00:07:17,407 --> 00:07:20,977 listen to what you guys are doing is fantastic, but please don't restrict 140 00:07:20,977 --> 00:07:22,627 yourself to only free solutions. 141 00:07:22,657 --> 00:07:23,737 Like we have money. 142 00:07:23,737 --> 00:07:26,947 If there's stuff you need to keep this ball moving, please ask. 143 00:07:27,427 --> 00:07:29,797 Um, so, you know, it kind of turned the whole thing on its head of, 144 00:07:29,857 --> 00:07:31,387 you know, securing the company. 145 00:07:31,387 --> 00:07:34,267 But also we were no longer begging for resources. 146 00:07:34,267 --> 00:07:37,867 The, you know, the executive leadership was asking us, was begging us to start 147 00:07:37,867 --> 00:07:41,097 spending resources because they saw what we were doing and saw the value. 148 00:07:41,552 --> 00:07:44,432 So, could you talk a little bit, I'm sure at the very beginning 149 00:07:44,432 --> 00:07:45,992 as you're starting this right. 150 00:07:46,022 --> 00:07:49,892 With any new process or new, any new endeavor, it's a little difficult, right. 151 00:07:49,952 --> 00:07:51,932 Sort of getting into what does it mean? 152 00:07:51,932 --> 00:07:53,252 And trying to figure things out. 153 00:07:53,642 --> 00:07:57,272 So what were some of the challenges you guys went through and how did you address. 154 00:07:58,772 --> 00:07:59,042 Yeah. 155 00:07:59,042 --> 00:08:03,052 So I would say the biggest challenge with any sort of security changes, 156 00:08:03,052 --> 00:08:07,652 especially in a large company is just the unknown of what will this break. 157 00:08:08,132 --> 00:08:11,372 Um, because quite often, especially in those early days, what you're changing 158 00:08:11,372 --> 00:08:13,502 are out of the box configurations. 159 00:08:13,862 --> 00:08:17,432 So there's this kind of mentality of, well, it's probably an out of the box 160 00:08:17,432 --> 00:08:20,552 configuration for some reason, or, you know, we don't know what legacy, I 161 00:08:20,552 --> 00:08:24,092 mean, this company that I was working at at the time was started in the 1930s. 162 00:08:24,602 --> 00:08:26,552 Now we don't know what kind of legacy applications are 163 00:08:26,552 --> 00:08:28,142 relying on this technology. 164 00:08:28,712 --> 00:08:33,992 Um, so I would say the first, the biggest thing was to just start 165 00:08:33,992 --> 00:08:37,862 easy, take the really easy ones to get as much buy-in as you can, you 166 00:08:37,862 --> 00:08:38,612 know, sit down to the engineers. 167 00:08:39,502 --> 00:08:42,412 Can anyone think of anything that would break by doing this? 168 00:08:42,412 --> 00:08:43,612 And you will get some feedback. 169 00:08:43,822 --> 00:08:43,942 Yeah. 170 00:08:43,942 --> 00:08:44,632 But who cares? 171 00:08:44,692 --> 00:08:45,712 It's not going to fix anything. 172 00:08:45,742 --> 00:08:46,102 Okay. 173 00:08:46,552 --> 00:08:47,122 That's fine. 174 00:08:47,582 --> 00:08:48,862 Let's just do it anyways. 175 00:08:49,312 --> 00:08:53,212 Um, and then start, you know, slowly ramping it up and 176 00:08:53,212 --> 00:08:55,252 taking little bite-size chunks. 177 00:08:55,252 --> 00:08:58,702 And if you look at the security CA cadence, Reddit posts, that's exactly 178 00:08:58,702 --> 00:08:59,692 how I've been approaching them. 179 00:08:59,692 --> 00:09:04,702 You know, I've started off with just really easy things to do and things 180 00:09:04,722 --> 00:09:09,232 I would not expect, um, to break many enterprises, you know, I tried to 181 00:09:09,232 --> 00:09:12,472 make it very clear in those posts of, you know, everyone's environment is 182 00:09:12,472 --> 00:09:17,332 different and be careful, but you know, I've called out certain items of this. 183 00:09:17,332 --> 00:09:20,752 Isn't going to break anything, just do it, you know, please just, just do it. 184 00:09:21,727 --> 00:09:27,967 I do remember in your, the trio of posts that you did that were around 185 00:09:27,967 --> 00:09:31,807 ransomware, you, you had a, there was a phrase that came up a lot. 186 00:09:31,847 --> 00:09:34,957 It's escaping me at the moment, but it was like, turn this on 187 00:09:34,957 --> 00:09:36,877 and then customize as necessary. 188 00:09:37,357 --> 00:09:37,777 Right. 189 00:09:37,807 --> 00:09:42,667 That, that, that, you know, that you can't, that no one solution does, uh, you, 190 00:09:42,667 --> 00:09:47,887 you can make a general rule for example, and then you're going to find somebody 191 00:09:47,887 --> 00:09:51,067 that needs, that thing turned on the thing you just turned off, you're going 192 00:09:51,067 --> 00:09:55,147 to find somebody that needs, that turned on and then you can turn it on for them. 193 00:09:55,597 --> 00:09:56,047 Right. 194 00:09:56,137 --> 00:09:57,907 Um, and, and that's okay. 195 00:09:59,392 --> 00:09:59,712 Yeah. 196 00:09:59,742 --> 00:10:04,132 So one of the catchphrases are one of my guiding lights in InfoSec is to never 197 00:10:04,132 --> 00:10:05,782 let perfect get in the way of being good. 198 00:10:06,162 --> 00:10:07,222 I call it out a lot. 199 00:10:07,372 --> 00:10:14,312 And part of the reason why I lean on it so heavily is it's often a. Uh, voice of 200 00:10:14,352 --> 00:10:17,022 dissension that you get from folks when you're trying to talk them into things 201 00:10:17,022 --> 00:10:21,072 like, oh, well that won't solve this one edge case, so let's not do it at all. 202 00:10:21,672 --> 00:10:24,532 Um, and you know, when it comes to security, security, it's all about 203 00:10:24,552 --> 00:10:29,562 layers and it's all about catching the attacker and yeah, there, this may 204 00:10:29,562 --> 00:10:32,622 not solve all of your problems, but it might be the alert that gets generated 205 00:10:32,622 --> 00:10:33,822 that tells you that they're there. 206 00:10:34,212 --> 00:10:42,012 Um, you know, and so it is definitely a strong, um, demand I make a people of, 207 00:10:42,402 --> 00:10:45,522 you know, if you can only do this for one system, great, it's better than none. 208 00:10:46,242 --> 00:10:49,482 Um, and yeah, so there there's something to be said about going 209 00:10:49,482 --> 00:10:51,882 slow and implementing slowly, but there's also something that I said 210 00:10:51,882 --> 00:10:55,702 about implementing broad and then backing off where you need to. 211 00:10:57,327 --> 00:10:57,687 Hmm. 212 00:10:57,897 --> 00:10:58,287 Yeah. 213 00:10:58,527 --> 00:10:59,127 Yeah, exactly. 214 00:10:59,397 --> 00:11:00,627 I would say that. 215 00:11:01,912 --> 00:11:06,122 When you, when you try the latter, when it, when I was thinking about your, 216 00:11:06,122 --> 00:11:10,972 your initial, this, the six months program that you had, the farther 217 00:11:10,972 --> 00:11:14,122 you got into that six months, and the more complicated things that you were 218 00:11:14,122 --> 00:11:18,802 doing that were potentially riskier, if you will, to the environment that 219 00:11:18,802 --> 00:11:24,202 you could potentially impact someone's ability to do their job, the more 220 00:11:24,262 --> 00:11:27,532 you're going to need support from above. 221 00:11:28,012 --> 00:11:28,372 Right? 222 00:11:28,402 --> 00:11:32,002 Like, I, I, I told, you know, I told them to do this. 223 00:11:32,332 --> 00:11:34,732 We're sorry that it broke, you know, we'll 224 00:11:35,077 --> 00:11:35,197 Yeah. 225 00:11:35,932 --> 00:11:37,432 we turned it off for now. 226 00:11:37,732 --> 00:11:41,212 We didn't realize that by pushing this one button was going to make everyone in 227 00:11:41,212 --> 00:11:43,462 the company not be able to log in ever. 228 00:11:43,882 --> 00:11:46,102 Uh, we've turned it off until we figured that out. 229 00:11:46,132 --> 00:11:46,432 Right. 230 00:11:46,432 --> 00:11:49,102 Don't don't go, don't go beat, snorkel out. 231 00:11:49,997 --> 00:11:52,127 And maybe that's also where you get some of those early 232 00:11:52,127 --> 00:11:53,807 wins before you take on those. 233 00:11:54,017 --> 00:11:57,407 So you get sort of the buy-in from upper management that, Hey, 234 00:11:57,437 --> 00:11:58,577 they are doing the right things. 235 00:11:58,577 --> 00:11:59,837 They are making improvements. 236 00:12:00,907 --> 00:12:02,467 Yeah, absolutely. 237 00:12:02,582 --> 00:12:02,912 Yeah, 238 00:12:03,517 --> 00:12:08,907 One of the, the biggest allies of InfoSec people that they forget about is the CFO. 239 00:12:10,437 --> 00:12:12,627 The CFO is the person when you're doing these sorts of things that you 240 00:12:12,627 --> 00:12:15,387 want to have in your back pocket to be able to go have that conversation of, 241 00:12:15,387 --> 00:12:17,817 Hey, where is our money actually made? 242 00:12:18,417 --> 00:12:23,097 Because I want to know, Hey, what, what divisions of this company aren't really 243 00:12:23,097 --> 00:12:24,417 contributing that much to the bottom line. 244 00:12:24,417 --> 00:12:27,207 Cause those just became my test case the things that I'm really 245 00:12:27,207 --> 00:12:27,957 not sure about. 246 00:12:28,557 --> 00:12:31,617 Let's take them down because that's not going to, you know, that's not going 247 00:12:31,617 --> 00:12:33,507 to ruin our end of quarter numbers. 248 00:12:33,587 --> 00:12:35,267 So they're going to start this off as a retailer. 249 00:12:35,267 --> 00:12:36,107 So that was obvious. 250 00:12:36,197 --> 00:12:39,377 Don't take down the stores under no circumstances do you take down the stores. 251 00:12:39,377 --> 00:12:39,627 Right. 252 00:12:39,652 --> 00:12:40,072 Right. 253 00:12:41,187 --> 00:12:41,707 but legal? 254 00:12:41,707 --> 00:12:43,097 Go for for it, 255 00:12:43,257 --> 00:12:43,497 Yep. 256 00:12:44,197 --> 00:12:47,277 I don't know how legal would feel about that. 257 00:12:47,277 --> 00:12:50,037 But yeah, no, I understand what you're saying basically. 258 00:12:50,277 --> 00:12:53,067 So w every change that you made, you don't have to roll it out. 259 00:12:53,067 --> 00:13:00,327 Company-wide you, you put it into places where you felt that it would do, you know, 260 00:13:00,327 --> 00:13:04,557 hopefully the change would have a minimal impact, but if it did have an impact, 261 00:13:04,887 --> 00:13:09,417 it would have a minimal impact to the company, because it only made legal, not 262 00:13:09,417 --> 00:13:11,037 be able to do something for a day or two, 263 00:13:11,727 --> 00:13:12,417 Absolutely. 264 00:13:12,867 --> 00:13:15,177 which is a very different thing than no one can log into the 265 00:13:15,177 --> 00:13:16,707 cash registers for a day or two. 266 00:13:16,817 --> 00:13:17,537 Absolutely. 267 00:13:17,717 --> 00:13:21,137 In retail, taking down the chain is the worst thing you could possibly do. 268 00:13:21,947 --> 00:13:22,907 Yeah, exactly. 269 00:13:22,907 --> 00:13:25,517 So for the record, I actually started in retail. 270 00:13:25,517 --> 00:13:28,937 I, I worked a hundred years ago. 271 00:13:28,997 --> 00:13:34,847 I was a shoe salesman at a, a chain called Kenny shoes, which no one. 272 00:13:35,777 --> 00:13:40,997 Under 25 even know exists, but you know, it used to, it was the parent 273 00:13:40,997 --> 00:13:42,557 company that created Footlocker. 274 00:13:42,557 --> 00:13:47,087 So Footlocker is still around, but Kenny shoes was its own store. 275 00:13:47,087 --> 00:13:50,207 And I worked in, uh, retail. 276 00:13:50,207 --> 00:13:54,307 So I know I also worked at some, some what we now call big box stores. 277 00:13:54,307 --> 00:13:58,277 So I know what it's like to be at the receiving end of that. 278 00:13:58,277 --> 00:14:01,787 And when, uh, when corporate, when corporation changes things 279 00:14:01,817 --> 00:14:04,757 and then poof, you know, you, you suddenly can't do your job. 280 00:14:04,787 --> 00:14:05,687 That's unacceptable. 281 00:14:06,417 --> 00:14:11,037 So you went through this exercise, you had this process of, um, 282 00:14:11,757 --> 00:14:16,497 going for six months, doing a security update or roll out a week. 283 00:14:17,127 --> 00:14:22,137 And then you started writing about this small things that people can do 284 00:14:22,137 --> 00:14:24,927 to improve their security posture. 285 00:14:25,677 --> 00:14:27,207 And where did you go from there? 286 00:14:27,207 --> 00:14:30,027 Like, did you think you would keep writing this long because 287 00:14:30,777 --> 00:14:34,227 how long have you been posting on Reddit for your security cadence? 288 00:14:34,737 --> 00:14:36,927 So I, I only started it in January. 289 00:14:36,927 --> 00:14:38,967 I did it as a new year's resolution. 290 00:14:39,117 --> 00:14:41,277 Um, and it, the idea came to me. 291 00:14:41,277 --> 00:14:43,077 I was on a, on a different podcast. 292 00:14:43,107 --> 00:14:47,337 Um, and we were talking about InfoSec and we were talking about a term that I 293 00:14:47,337 --> 00:14:52,257 believe Wendy Nader from duo security, uh, coined, which is InfoSec poverty. 294 00:14:52,887 --> 00:14:56,487 Um, and it's basically in reference to companies that just don't have the 295 00:14:56,487 --> 00:15:01,677 resources to have dedicated InfoSec people or InfoSec tooling, and how, 296 00:15:01,797 --> 00:15:04,617 you know, it's not really fair to expect these companies that just 297 00:15:04,617 --> 00:15:07,687 don't have those resources to really be able to stand up against you know, 298 00:15:07,687 --> 00:15:09,547 the modern era of security threats. 299 00:15:10,057 --> 00:15:14,407 Um, so on this podcast we were discussing, you know, what do, what can we as InfoSec 300 00:15:14,407 --> 00:15:16,807 professionals do to help those companies? 301 00:15:17,227 --> 00:15:20,287 Um, and it's been kind of living rent free in the back of my brain 302 00:15:20,287 --> 00:15:21,577 since I was on that podcast. 303 00:15:22,087 --> 00:15:25,237 Um, so as I was approaching the new year, I was like, you know what, I'm just going 304 00:15:25,237 --> 00:15:30,187 to hop on Reddit, starting in January and make that weekly post and see if 305 00:15:30,187 --> 00:15:34,207 I cant' help um, you know, some of the folks in the sysadmin sub Reddit, which, 306 00:15:34,447 --> 00:15:38,437 you know, the sysadmin subreddit, they have the, um, the flares for everyone. 307 00:15:38,677 --> 00:15:41,047 And there's a lot of them that list themselves as Jack of all trades. 308 00:15:41,287 --> 00:15:44,497 And those are those sysadmins that are working in smaller companies. 309 00:15:44,497 --> 00:15:47,057 And they're, you know, if it plugs into the wall, that's their job. 310 00:15:47,662 --> 00:15:50,572 Um, and you know, those companies are exactly what InfoSec 311 00:15:50,572 --> 00:15:52,252 poverty is calling out of. 312 00:15:52,282 --> 00:15:55,012 You know, you have these brilliant sysadmins who are heavily 313 00:15:55,042 --> 00:15:58,252 overburdened, and they just don't have the time to focus on this. 314 00:15:58,792 --> 00:16:02,272 Um, and they just kind of need someone to say, Hey, you know, this week, why don't 315 00:16:02,272 --> 00:16:05,962 you disable this one thing that comes out of the box in windows and you do not need, 316 00:16:05,962 --> 00:16:08,692 and it creates a massive security risk. 317 00:16:09,082 --> 00:16:13,822 Um, yeah, so I started in January and I have a nice long list, 318 00:16:13,942 --> 00:16:15,952 uh, in one note of post to make. 319 00:16:15,952 --> 00:16:19,342 And you know, every every week around Wednesday night, I just pull one 320 00:16:19,342 --> 00:16:20,782 up and I write a quick blog post. 321 00:16:21,682 --> 00:16:21,862 Yeah. 322 00:16:21,892 --> 00:16:24,742 Cause you can't, you can't schedule Reddit posts, Right. 323 00:16:24,952 --> 00:16:25,192 I don't 324 00:16:25,482 --> 00:16:25,752 Right. 325 00:16:25,752 --> 00:16:27,512 You can, uh, you can put them in drafts. 326 00:16:27,512 --> 00:16:28,362 So I write them 327 00:16:28,362 --> 00:16:31,272 Wednesday night and Monday morning I remove it from draft, 328 00:16:31,852 --> 00:16:32,092 got it. 329 00:16:32,692 --> 00:16:32,872 Yeah. 330 00:16:32,872 --> 00:16:35,242 that was Paul's InfoSec weekly, I believe. 331 00:16:35,242 --> 00:16:37,582 Was it the podcast where you were, right, right. 332 00:16:38,152 --> 00:16:39,292 Yeah, Shout out to them. 333 00:16:39,832 --> 00:16:46,312 Um, so, uh, so you said you started in January, So, you're what, uh, 334 00:16:46,762 --> 00:16:49,372 like eight or nine posts in on that. 335 00:16:50,062 --> 00:16:55,402 And did this, this, uh, this, what do you call it? 336 00:16:55,402 --> 00:16:56,512 Um, or maybe like 10. 337 00:16:56,542 --> 00:16:56,872 I don't know. 338 00:16:56,962 --> 00:16:57,682 I can't do math. 339 00:16:57,712 --> 00:16:58,132 Anyway. 340 00:16:58,382 --> 00:17:05,392 This is, um, the ransomware posts were, where did that fall into that? 341 00:17:06,592 --> 00:17:08,122 You know, the 342 00:17:08,302 --> 00:17:12,682 yeah, it's a fun question because literally, since I started this since 343 00:17:12,682 --> 00:17:15,472 post one, I've had people messaging me on Reddit saying, Hey, could 344 00:17:15,472 --> 00:17:16,672 you do something about ransomware? 345 00:17:17,182 --> 00:17:19,762 Um, cause it's you know, it's a top of mind topic, especially for the 346 00:17:19,762 --> 00:17:21,922 smaller orgs, that's the big boogeyman. 347 00:17:22,582 --> 00:17:26,762 Um, and I've been honestly kind of Mr. Miyagi'ing it in terms 348 00:17:26,782 --> 00:17:29,422 of, well, everything I'm posting really has to do with ransomware. 349 00:17:29,422 --> 00:17:30,382 You just don't realize it. 350 00:17:30,952 --> 00:17:33,052 Um, but when. 351 00:17:33,382 --> 00:17:36,822 reference by the way not sure if everybody listening will understand that 352 00:17:36,822 --> 00:17:38,952 reference, But, very nice reference. 353 00:17:40,277 --> 00:17:44,087 But, yeah, so my expectation was I haven't, you know, a list of posts that 354 00:17:44,087 --> 00:17:46,247 eventually I was going to say, Hey, you know, if you've been messaging me 355 00:17:46,247 --> 00:17:48,017 about ransomware, go read these posts. 356 00:17:48,047 --> 00:17:49,397 This is what I was driving at. 357 00:17:49,907 --> 00:17:53,537 Um, but then, uh, when Russia invaded Ukraine and the Conti ransomware 358 00:17:53,537 --> 00:17:57,587 groups, uh, came out and said that anyone that takes up arms or, 359 00:17:57,587 --> 00:17:58,787 you know, it goes against Russia. 360 00:17:58,817 --> 00:18:03,107 We're going to come after I got flooded with people saying, no, really, please. 361 00:18:03,107 --> 00:18:03,857 We need something. 362 00:18:04,217 --> 00:18:06,647 So hence the title, the, okay, fine. 363 00:18:06,707 --> 00:18:07,367 Let's talk about 364 00:18:07,677 --> 00:18:07,917 Yeah, 365 00:18:08,477 --> 00:18:11,837 Um, so I decided, yeah, it was time to just at least take 366 00:18:11,867 --> 00:18:13,727 a truncated approach to it. 367 00:18:13,916 --> 00:18:18,086 How did you approach because ransomware is such a huge topic, right? 368 00:18:18,126 --> 00:18:21,566 I know Curtis, you and I, we talked about it, but just sort of your 369 00:18:21,566 --> 00:18:24,656 thought process behind like the series that you wrote and how do you 370 00:18:24,656 --> 00:18:26,846 get such a dense topic out there? 371 00:18:26,846 --> 00:18:31,136 Because there are so many different ways that ransomware can attack you 372 00:18:31,136 --> 00:18:35,456 and so many different, uh, crews out there with different methods. 373 00:18:35,456 --> 00:18:38,786 So how do you sort of generalize it, especially, like you said, 374 00:18:38,786 --> 00:18:42,746 for those people who don't have the time to research and follow up 375 00:18:42,776 --> 00:18:45,086 everything related to InfoSec, right? 376 00:18:46,186 --> 00:18:49,496 So I giggle when you say dense. 377 00:18:49,496 --> 00:18:51,936 Cause one of the other pieces of feedback I get quite frequently 378 00:18:52,006 --> 00:18:53,206 is that my posts are too long. 379 00:18:53,566 --> 00:18:59,146 Um, but yeah, so my take on ransomware is that companies tend 380 00:18:59,146 --> 00:19:01,606 to focus on the exact wrong spot. 381 00:19:02,176 --> 00:19:06,736 Um, and I apologize for coming on to a backup, um, related podcast 382 00:19:07,006 --> 00:19:10,726 and say that most companies focus on backup and that's, that's 383 00:19:10,796 --> 00:19:11,186 No, no. 384 00:19:11,596 --> 00:19:11,956 effort. 385 00:19:11,956 --> 00:19:13,516 That's the, that's the thing that 386 00:19:13,516 --> 00:19:15,886 hopefully saves the company when everything else has 387 00:19:15,886 --> 00:19:17,536 just gone poorly for you. 388 00:19:18,226 --> 00:19:19,316 And don't Don't worry, snorkel. 389 00:19:19,336 --> 00:19:21,916 We have the same opinion as well, or at least I do, right. 390 00:19:21,916 --> 00:19:22,186 That 391 00:19:22,486 --> 00:19:26,536 it's just a last resort, but you should really be protecting yourself upfront. 392 00:19:27,546 --> 00:19:31,836 Um, and so the thing that comes, that happens every time, there's a major 393 00:19:31,836 --> 00:19:37,176 ransomware breach, um, is, you know, it hits the media and everyone starts talking 394 00:19:37,176 --> 00:19:38,646 about the indicators of compromise. 395 00:19:39,006 --> 00:19:41,886 It loves talking about indicators of compromise because it's easy to deal 396 00:19:41,886 --> 00:19:43,476 with, you know, how did they get in? 397 00:19:43,476 --> 00:19:44,196 I was an email. 398 00:19:44,196 --> 00:19:45,696 Well, where did the email come from? 399 00:19:45,696 --> 00:19:46,746 What was the subject? 400 00:19:46,786 --> 00:19:48,996 Did it link to something, where did the link go to? 401 00:19:48,996 --> 00:19:49,926 What did it download? 402 00:19:49,926 --> 00:19:52,476 What was the hash of that downloaded and on and on and on and on. 403 00:19:53,076 --> 00:19:56,316 And because it's easy then to go into your controls and, oh, we're going to put in 404 00:19:56,316 --> 00:19:58,716 our spam filters to block that address. 405 00:19:58,716 --> 00:20:00,876 We're going to block that domain. 406 00:20:00,876 --> 00:20:05,466 We're going to put in our, uh, endpoint security tools to block that 407 00:20:05,466 --> 00:20:07,986 hash, but it's all pointless, right? 408 00:20:07,986 --> 00:20:09,516 Because that breach is done. 409 00:20:09,666 --> 00:20:11,376 That entire infrastructure has been burned. 410 00:20:11,436 --> 00:20:12,876 There was nothing left of it. 411 00:20:13,236 --> 00:20:16,236 So, you know, you're, you're reacting to something that's no longer exist. 412 00:20:17,036 --> 00:20:21,926 But when no one ever asks is, wait a minute, how did you know Susie 413 00:20:21,926 --> 00:20:26,946 in accounting downloading this attachment lead to their entire VMware 414 00:20:26,966 --> 00:20:28,376 infrastructure getting encrypted. 415 00:20:28,976 --> 00:20:33,716 And that's, that's the real takeaway from every single ransomware breach of, you 416 00:20:33,716 --> 00:20:37,196 know, it's one thing to come in and, you know, the accounting system, one person 417 00:20:37,196 --> 00:20:38,756 in the accounting system is encrypted. 418 00:20:39,476 --> 00:20:40,886 It's another thing entirely to come in. 419 00:20:40,886 --> 00:20:44,426 And yeah, the entire network has gone now and we don't have any data. 420 00:20:44,966 --> 00:20:48,656 Um, and that's really where the security cadence posts come in. 421 00:20:48,656 --> 00:20:52,466 And w what I try to focus on, especially in the first post of this 422 00:20:52,466 --> 00:20:53,696 is what I would be doing right now. 423 00:20:53,696 --> 00:20:57,926 If you are waking up to a world where Russia has invaded Ukraine, and you're 424 00:20:57,926 --> 00:21:01,016 all of a sudden, greatly concerned that ransomware group's going to 425 00:21:01,016 --> 00:21:04,736 come after you, these are the things to start off with, and it isn't 426 00:21:04,736 --> 00:21:06,716 necessarily preventing ransomware. 427 00:21:06,716 --> 00:21:09,746 It's preventing ransomware from being able to do anything significant. 428 00:21:10,316 --> 00:21:14,756 Um, and the nice thing about those controls is it translates 429 00:21:14,756 --> 00:21:16,286 to way more than just ransomware. 430 00:21:16,781 --> 00:21:20,741 Which is another issue that I think smaller companies particularly have 431 00:21:20,741 --> 00:21:23,051 when they're dealing with InfoSec, as they put their blinders on and 432 00:21:23,081 --> 00:21:26,921 very specific attack types, like how do we protect against ransomware? 433 00:21:27,161 --> 00:21:28,421 Oh, we get good backups. 434 00:21:29,051 --> 00:21:33,341 Well, how about, how do we protect against any sort of extortion attempt? 435 00:21:33,401 --> 00:21:37,271 You know, we, we had the lupus group or excuse me, Lapsis 436 00:21:37,561 --> 00:21:38,581 Yeah, I think it was locked system. 437 00:21:39,181 --> 00:21:39,511 Yep. 438 00:21:40,421 --> 00:21:43,331 I had been talking about all week and I just blanked on there anyways, you 439 00:21:43,331 --> 00:21:49,661 know, going after Nvidia and Okta and Microsoft and LG, really their playbook 440 00:21:49,661 --> 00:21:51,461 is the exact same as a ransomware group. 441 00:21:52,211 --> 00:21:54,371 You know, ransomware only exists, not because they care 442 00:21:54,371 --> 00:21:55,181 about encrypting your data. 443 00:21:55,211 --> 00:21:56,921 They've went to extort you for money. 444 00:21:57,401 --> 00:22:02,411 Ransomware shifted, shifted recently to exfiltrating data because people had 445 00:22:02,411 --> 00:22:04,871 good backups or had restoration methods. 446 00:22:04,991 --> 00:22:06,041 We'll find let's steal the data. 447 00:22:06,041 --> 00:22:08,051 Cause we never really cared about encrypting the data. 448 00:22:08,081 --> 00:22:10,091 We just needed that incentive to get you to pay. 449 00:22:10,871 --> 00:22:15,631 Um, so when you take a step back and look at how attacks function 450 00:22:16,046 --> 00:22:19,526 from the ground up and started going at the common denominators. 451 00:22:20,036 --> 00:22:23,906 You, you really don't care about what the actual end objective is any longer 452 00:22:23,936 --> 00:22:27,686 because the controls are there to make sure that they never made it past sending 453 00:22:27,686 --> 00:22:32,396 that initial email, um, or, you know, tacking this particular vulnerability you 454 00:22:32,396 --> 00:22:35,366 had exposed to the perimeter for a week. 455 00:22:36,416 --> 00:22:39,206 Because those vulnerabilities will constantly be evolving. 456 00:22:39,206 --> 00:22:39,506 Right. 457 00:22:39,536 --> 00:22:41,906 And so you kind of need a generic. 458 00:22:42,731 --> 00:22:46,571 Protection scheme, if you will, rather than something tailored for a particular 459 00:22:46,571 --> 00:22:48,401 ransom group, but that comes after you. 460 00:22:49,371 --> 00:22:50,301 Yeah, the rent 461 00:22:50,911 --> 00:23:00,081 A ransomware attack is it's the conclusion of, you know, what, like you 462 00:23:00,081 --> 00:23:03,831 got infected, but the ranch, I don't know if I'm saying, I'm not saying this 463 00:23:03,831 --> 00:23:08,751 right, but It's I want to say it's the symptom, but it is actually the infection. 464 00:23:09,261 --> 00:23:09,741 Right. 465 00:23:09,771 --> 00:23:11,061 But that 466 00:23:11,141 --> 00:23:12,041 not the cause. 467 00:23:12,051 --> 00:23:14,631 The problem is what allowed them to get there in the first place. 468 00:23:15,271 --> 00:23:16,651 You're absolutely right. 469 00:23:16,651 --> 00:23:21,121 And it's, it's interesting that it is a multi-tiered product at this point. 470 00:23:21,121 --> 00:23:25,141 There are, there are groups out there that sell you the initial breach. 471 00:23:25,891 --> 00:23:29,341 Um, so if you and Conti is one of the groups that are suspected of doing this, 472 00:23:29,341 --> 00:23:33,361 that they don't do the initial breach, they buy the breach, they buy someone 473 00:23:33,361 --> 00:23:37,261 who already has the foothold and then use that foothold to do the actual encryption. 474 00:23:37,941 --> 00:23:38,301 Hmm. 475 00:23:38,401 --> 00:23:43,711 And so you have this entire life cycle of, you know, third-party vendors 476 00:23:43,711 --> 00:23:45,391 that lead up to the final breach. 477 00:23:45,421 --> 00:23:45,811 Right. 478 00:23:46,291 --> 00:23:50,851 Um, you know, you know, Conti may be purchasing someone else's exploit kits, 479 00:23:51,031 --> 00:23:52,501 um, someone else's encryption kits. 480 00:23:52,861 --> 00:23:54,631 So you're exactly right. 481 00:23:54,631 --> 00:23:57,631 That there's the initial breach. 482 00:23:57,661 --> 00:23:59,521 That's really your first opportunity. 483 00:24:00,041 --> 00:24:02,551 And when you get to the point where things are encrypting, so many other 484 00:24:02,551 --> 00:24:03,841 things have been missed by that. 485 00:24:04,751 --> 00:24:07,601 That at least if you get to that point, you know, you have 486 00:24:07,601 --> 00:24:10,271 a lot of great opportunities to prevent it from happening again. 487 00:24:10,391 --> 00:24:14,111 Cause you should have learned so much up to that point of, oh my gosh, they 488 00:24:14,111 --> 00:24:17,711 got the phishing email through my end user is able to download this thing. 489 00:24:17,711 --> 00:24:21,461 They were able to click this link to this weird domain that was stood up yesterday. 490 00:24:22,031 --> 00:24:25,331 Um, they're able to execute a program after they downloaded it off the internet. 491 00:24:25,391 --> 00:24:28,481 I mean all these different controls that had to go poorly just to 492 00:24:28,481 --> 00:24:29,891 get to that point of encryption. 493 00:24:31,921 --> 00:24:38,131 Uh, speaking of phishing, I did see something like this is just a couple 494 00:24:38,131 --> 00:24:41,431 of days ago and they were, and, and again, I, I don't remember exactly 495 00:24:41,431 --> 00:24:45,841 where I saw it, but it was like, it was saying that phishing had surpassed, 496 00:24:46,861 --> 00:24:52,071 uh,, that it now become the number one method of attacking companies versus 497 00:24:52,571 --> 00:24:57,261 I guess, uh, a standard exploit, I guess, would be number two, right? 498 00:24:57,311 --> 00:25:02,091 A standard sort of direct hacking attempt the phishing had become the number one. 499 00:25:02,091 --> 00:25:02,721 I don't know if you, 500 00:25:03,601 --> 00:25:03,871 No, 501 00:25:04,071 --> 00:25:05,781 sounds like you saw that as the number one. 502 00:25:06,521 --> 00:25:07,031 Yeah. 503 00:25:07,421 --> 00:25:09,191 Actually someone that, one of the things I really liked with the 504 00:25:09,191 --> 00:25:12,431 security cadence post is when people get in and correct me, or, you know, 505 00:25:12,461 --> 00:25:16,271 point out other things, because I'm certainly not an expert in all things. 506 00:25:16,751 --> 00:25:20,621 Uh, but in the first ransomware post, I made a person who works 507 00:25:20,621 --> 00:25:24,371 for a cyber insurance policy holder actually called me out and said, yo, 508 00:25:25,331 --> 00:25:27,281 phishing is the number one for sure. 509 00:25:27,281 --> 00:25:32,391 But right close on its heels is the proxy shell exchange vulnerability, uh, which 510 00:25:32,391 --> 00:25:37,251 is a vulnerability from last year and, you know, impacting on-prem Exchange, 511 00:25:37,671 --> 00:25:42,111 uh, deployments and, you know, still plenty of unpatched boxes out there. 512 00:25:42,501 --> 00:25:44,841 But yeah, you know, you get these massive blips, right. 513 00:25:44,841 --> 00:25:47,151 You know, a log4j S sort of thing. 514 00:25:47,151 --> 00:25:49,521 That is a crazy large vulnerability. 515 00:25:49,521 --> 00:25:51,111 That attackers jump on quickly. 516 00:25:52,251 --> 00:25:54,431 But the internal one is always fishing. 517 00:25:54,471 --> 00:25:57,871 There's always social engineering is the quickest path to get past your perimeter. 518 00:25:58,181 --> 00:25:58,391 Yeah. 519 00:25:58,511 --> 00:26:01,391 And especially with some of these large spikes, you also 520 00:26:01,391 --> 00:26:03,011 have the long tails, right. 521 00:26:03,431 --> 00:26:07,661 In terms of how long it takes to get every single system out there patched. 522 00:26:08,111 --> 00:26:11,951 And you'll always have systems out there which don't go patched for so long and 523 00:26:12,261 --> 00:26:14,051 still continues to be an attack vector. 524 00:26:14,051 --> 00:26:14,321 Right? 525 00:26:14,856 --> 00:26:15,276 Right. 526 00:26:15,336 --> 00:26:19,416 And it's that InfoSec debt that, that again, of, you know, a company that 527 00:26:19,446 --> 00:26:23,346 hired someone else that comes stand up their IT infrastructure one time 528 00:26:23,346 --> 00:26:25,656 and it's been neglected ever since. 529 00:26:26,106 --> 00:26:28,416 And there's no one patching those systems that are running 530 00:26:28,416 --> 00:26:30,576 their exchange 2003 deployments. 531 00:26:30,996 --> 00:26:32,766 I mean, they're out there. 532 00:26:33,791 --> 00:26:34,151 the way. 533 00:26:35,351 --> 00:26:36,461 Here's what I want to say. 534 00:26:36,521 --> 00:26:39,071 Who the hell is still running on prem Exchange. 535 00:26:39,191 --> 00:26:41,081 That's all I want to say about that. 536 00:26:41,381 --> 00:26:43,481 And why aren't you using 365? 537 00:26:43,511 --> 00:26:45,371 That's all I'm saying Microsoft. 538 00:26:45,371 --> 00:26:46,211 You're welcome. 539 00:26:46,781 --> 00:26:49,541 I'm just saying I don't, it's just, it's just 540 00:26:49,551 --> 00:26:52,131 Wait, wait, you forgot to add one thing to that, Curtis, 541 00:26:52,511 --> 00:26:52,901 what's that? 542 00:26:52,991 --> 00:26:53,531 What's that. 543 00:26:54,261 --> 00:26:57,171 if you are using Microsoft 365, make sure to back it up. 544 00:26:57,871 --> 00:26:58,651 Yeah, absolutely. 545 00:26:58,676 --> 00:26:59,036 Yes. 546 00:26:59,066 --> 00:26:59,576 Thank you. 547 00:27:00,086 --> 00:27:01,916 Because Microsoft isn't doing it for you. 548 00:27:01,916 --> 00:27:02,186 Yeah. 549 00:27:02,546 --> 00:27:02,756 Yeah. 550 00:27:02,756 --> 00:27:04,556 It's a standard thing. 551 00:27:04,556 --> 00:27:06,656 We have to mention here on, on the podcast, 552 00:27:07,086 --> 00:27:10,716 So a dropper is typically the initial thing that gets downloaded. 553 00:27:10,716 --> 00:27:14,706 So if you look through a normal, any sort of malware campaign, we'll keep 554 00:27:14,706 --> 00:27:18,096 it as ransomware that, you know, I sent an email, uh, as a, as an 555 00:27:18,096 --> 00:27:19,656 attacker, that's a phishing email. 556 00:27:19,656 --> 00:27:22,236 And then the whole point is to try to trick someone into clicking a 557 00:27:22,236 --> 00:27:23,736 link and downloading the program. 558 00:27:24,396 --> 00:27:27,096 Um, or maybe it's attached, uh, maybe it's a word document or 559 00:27:27,096 --> 00:27:29,976 something like that it's attached, but it's something small and. 560 00:27:30,686 --> 00:27:33,176 Typically, you're going to see it as a document macro. 561 00:27:33,746 --> 00:27:37,406 Um, and the whole point of it is that's the simple, easy thing that's going 562 00:27:37,406 --> 00:27:40,856 to slip through, you know, your, your various defenses, because it's just 563 00:27:40,856 --> 00:27:44,696 a word document, but you enable the macro in the macros, what reaches out 564 00:27:44,696 --> 00:27:47,516 and downloads the current malware. 565 00:27:47,546 --> 00:27:49,826 And there there's a few reasons for that. 566 00:27:50,316 --> 00:27:54,776 A big one is that malware could potentially being, be being generated 567 00:27:54,806 --> 00:27:59,486 on the fly, meaning that the definition that's behind that, the hash for it, or, 568 00:27:59,486 --> 00:28:02,876 you know, the, the detection mechanisms that more traditional antivirus is 569 00:28:02,876 --> 00:28:05,096 looking at won't have those definitions. 570 00:28:05,096 --> 00:28:07,586 Cause it was generated at the moment of downloads. 571 00:28:07,946 --> 00:28:11,936 Um, you know, we've just minor changes, but just to throw off that hash, um, 572 00:28:12,056 --> 00:28:16,616 but then that's the thing that actually gets downloaded and executed and, um, 573 00:28:16,646 --> 00:28:18,176 you know, causes you all your problems. 574 00:28:18,176 --> 00:28:21,506 And, you know, from there it could be any number of things. 575 00:28:21,506 --> 00:28:23,636 So as we were saying that there are people who would just tell 576 00:28:23,636 --> 00:28:24,596 you that footprint, right. 577 00:28:24,596 --> 00:28:25,226 Or that foothold. 578 00:28:25,306 --> 00:28:25,666 Right. 579 00:28:26,146 --> 00:28:28,376 That dropper could download just seed, too. 580 00:28:28,396 --> 00:28:29,926 Just something that's calling back saying. 581 00:28:29,926 --> 00:28:30,046 Yep. 582 00:28:30,076 --> 00:28:32,686 I got something running on this computer and that's it. 583 00:28:32,726 --> 00:28:33,056 Hmm. 584 00:28:33,626 --> 00:28:34,646 All it could literally. 585 00:28:34,706 --> 00:28:35,516 Oh, okay. 586 00:28:35,516 --> 00:28:39,566 So he could just literally sit there and wait for the second group. 587 00:28:39,596 --> 00:28:41,126 That's going to purchase that. 588 00:28:41,336 --> 00:28:43,766 And then they download the malware that they want to download. 589 00:28:44,346 --> 00:28:44,766 Right. 590 00:28:44,826 --> 00:28:45,096 So. 591 00:28:45,296 --> 00:28:46,736 That's what you were referring to earlier. 592 00:28:47,066 --> 00:28:51,896 And so it looked like the, and again, this is common sense to you, 593 00:28:51,896 --> 00:28:57,356 but not necessarily to everybody, it looked like, you know, your 594 00:28:57,356 --> 00:28:59,966 best advice was to, to stop. 595 00:29:01,246 --> 00:29:06,676 Ransomware is to just think about how ransomware works when it gets 596 00:29:06,676 --> 00:29:08,746 in, when that dropper gets in. 597 00:29:09,286 --> 00:29:12,406 You're not going to, I mean, yes, you should do user training and 598 00:29:12,406 --> 00:29:15,526 yes, you should do, you know, you should do all those things. 599 00:29:16,306 --> 00:29:19,486 And, but you should just assume that at least one of 600 00:29:19,486 --> 00:29:20,746 them is going to get it wrong. 601 00:29:21,076 --> 00:29:26,476 I mean, I remember back when I was, uh, you know, 25 years ago when I 602 00:29:26,476 --> 00:29:35,026 was at a bank, we did regular InfoSec training with every new employee. 603 00:29:35,356 --> 00:29:39,991 And one of the things we constantly said, well, Uh, no one in it 604 00:29:39,991 --> 00:29:43,201 will ever call and ask you for your password ever, ever, ever. 605 00:29:44,071 --> 00:29:48,301 And then we would, and then immediately after the training, we would call them 606 00:29:48,301 --> 00:29:53,761 and ask them for their password and still a percentage of them would give it to us. 607 00:29:53,911 --> 00:29:54,241 Right. 608 00:29:54,931 --> 00:29:56,131 Um, So. 609 00:29:56,131 --> 00:30:00,301 you, you do the training, but then you just sort of assume that that's going to, 610 00:30:00,421 --> 00:30:06,361 um, you know, um, that th that somebody is going to click on the wrong link. 611 00:30:06,781 --> 00:30:12,121 And so then you just think about stopping that malware at that point, 612 00:30:12,121 --> 00:30:15,511 you know, stopping them from accessing a command and control server, looking 613 00:30:15,511 --> 00:30:19,381 for, you know, this, this weird, you know, domains that stood up yesterday, 614 00:30:19,381 --> 00:30:23,311 domains that were stood up a long time ago, but just suddenly when active, 615 00:30:23,341 --> 00:30:27,571 um, you know, the limiting lateral movement inside the company, all of 616 00:30:27,571 --> 00:30:30,181 these things, uh, what, what did I miss. 617 00:30:31,641 --> 00:30:35,031 A big thing that a lot of ransomware particularly will do. 618 00:30:35,031 --> 00:30:38,721 First thing is start deleting, shadow copies as a quick restoration point. 619 00:30:38,731 --> 00:30:41,871 So that is a pretty dead giveaway of, you know, you get the event ID 620 00:30:41,871 --> 00:30:43,521 that shadow copy was just deleted. 621 00:30:44,031 --> 00:30:44,331 That's 622 00:30:44,476 --> 00:30:46,396 And you're referring to VSS there, right? 623 00:30:46,396 --> 00:30:48,116 The windows shadow copy. 624 00:30:48,166 --> 00:30:48,496 Yeah. 625 00:30:48,536 --> 00:30:50,636 So I had a question for you snorkel about that one. 626 00:30:50,636 --> 00:30:56,786 Is, does that prevent backup apps from actually running that might 627 00:30:56,786 --> 00:30:59,036 leverage VSS and shadow copies? 628 00:30:59,691 --> 00:31:02,661 Maybe it is the short answer, but depending how you attack this, 629 00:31:02,661 --> 00:31:07,461 if you're, if you're attacked for this is just, I want an alert on 630 00:31:07,461 --> 00:31:08,961 anything that delete shadow copies. 631 00:31:09,501 --> 00:31:12,801 Well, you know, if you have a backup solution that makes use of shadow copies 632 00:31:12,801 --> 00:31:16,281 and deletes shadow copies, then you know, that's something that you tune out, right? 633 00:31:16,941 --> 00:31:19,821 So you need to know the source of what deleted then that should be your event 634 00:31:19,821 --> 00:31:21,171 ID and you just tune that one out. 635 00:31:22,006 --> 00:31:22,486 Gotcha. 636 00:31:22,696 --> 00:31:26,206 So then you should only look for anomalous events that happen. 637 00:31:26,666 --> 00:31:34,256 Typically backup apps are going to, um, create a, create a shadow copy just 638 00:31:34,256 --> 00:31:36,836 to have a stable frame of reference and then delete it when they're done. 639 00:31:37,541 --> 00:31:39,581 Your backup app is probably running as a service. 640 00:31:39,581 --> 00:31:43,421 So that's going to run a system or whatever your backup, um, username 641 00:31:43,421 --> 00:31:46,451 is, or a user account is, whereas your ransomware is likely going 642 00:31:46,451 --> 00:31:47,651 to be running as that end user. 643 00:31:47,686 --> 00:31:48,136 Hm. 644 00:31:49,151 --> 00:31:51,701 So when you ask yourself, does an accountant have reason to 645 00:31:51,701 --> 00:31:52,931 be deleting, shadow copies? 646 00:31:53,231 --> 00:31:54,101 Probably not. 647 00:31:55,766 --> 00:31:58,316 So you can look for all these patterns and determine what's real versus 648 00:31:58,316 --> 00:32:01,316 what's not because I guess that's the other hard part in InfoSec is like 649 00:32:01,316 --> 00:32:05,636 tuning out the noise or the normal behavior versus what's anomalous. 650 00:32:05,951 --> 00:32:06,401 Right. 651 00:32:06,761 --> 00:32:09,611 Um, and you know, it all starts with really, really good logs. 652 00:32:10,811 --> 00:32:13,931 you need to have that log information and then what's going on in your systems. 653 00:32:13,931 --> 00:32:18,251 But honestly, going back to deleting shadow copies, of the other call-outs 654 00:32:18,251 --> 00:32:22,361 I made from a higher level, it's just looking at what would, you 655 00:32:22,361 --> 00:32:26,411 would expect an end user to run, especially from the command prompt. 656 00:32:26,411 --> 00:32:26,741 Right. 657 00:32:27,251 --> 00:32:30,791 You know, do you expect someone in legal to ever open a command 658 00:32:30,791 --> 00:32:34,871 prompt, let alone, you know, run whoami or run nets, you know, and 659 00:32:34,871 --> 00:32:36,191 start looking around your network. 660 00:32:36,221 --> 00:32:37,241 Probably not. 661 00:32:37,241 --> 00:32:40,841 So if someone in legal opens up a command prompt, that right there, it might be 662 00:32:40,841 --> 00:32:42,281 enough for you to go well, that's weird. 663 00:32:42,761 --> 00:32:45,371 Start running, you know, typical attack commands, or, you know, 664 00:32:45,401 --> 00:32:46,691 living off the land commands. 665 00:32:47,001 --> 00:32:47,971 Now it's real weird. 666 00:32:49,101 --> 00:32:52,311 And what would you use to watch for. 667 00:32:53,096 --> 00:32:54,326 Th there was a tool. 668 00:32:54,326 --> 00:32:56,516 I forgot its name that you mentioned about that. 669 00:32:57,616 --> 00:33:01,786 Uh, so the tool I mentioned in one of my blog posts was raccine, 670 00:33:02,086 --> 00:33:07,546 which is so vaccine with an R, um, which is a tool that just monitors 671 00:33:07,546 --> 00:33:11,266 for shadow copy deletion, and just kills any process that does it. 672 00:33:11,686 --> 00:33:13,936 Um, the problem is it doesn't discriminate. 673 00:33:13,936 --> 00:33:16,606 So again, if you do have a backup tool that does make use 674 00:33:16,606 --> 00:33:19,246 of deleting shadow copies, it's going to kill that process for you. 675 00:33:19,606 --> 00:33:22,726 Um, but if you don't have that limitation, it's a really handy, 676 00:33:22,726 --> 00:33:24,586 little quick, simple solution. 677 00:33:25,346 --> 00:33:29,816 but can you tune that or do you need another tool that's tuneable. 678 00:33:30,466 --> 00:33:34,846 Uh, well, it's, it's open source, so you can certainly modify the code, but no, 679 00:33:35,086 --> 00:33:39,046 uh, the current version that exists does not have any sort of options for that. 680 00:33:39,046 --> 00:33:41,436 It is, uh, a one and done sort of thing. 681 00:33:41,986 --> 00:33:42,416 Gotcha. 682 00:33:42,451 --> 00:33:42,901 Okay. 683 00:33:43,561 --> 00:33:43,741 yeah. 684 00:33:43,741 --> 00:33:47,071 So that would be, that'd be a perfect example of, like you said, when we 685 00:33:47,071 --> 00:33:49,351 were talking earlier, let's try this. 686 00:33:49,681 --> 00:33:50,101 Right. 687 00:33:50,701 --> 00:33:54,241 Hopefully it doesn't kill the backups, but if it does kill the backups, it 688 00:33:54,241 --> 00:33:56,731 would be pretty obvious because all the backups will fail because they're 689 00:33:56,731 --> 00:34:00,211 unable to create, uh, the shadow copies. 690 00:34:00,961 --> 00:34:05,311 I think one of the ones, and I don't know which article number was from that I 691 00:34:05,311 --> 00:34:10,471 thought was very unique that you brought up was a different way to sort of trick 692 00:34:10,531 --> 00:34:16,021 the ransomware, um, into sort of not destroying your entire infrastructure. 693 00:34:16,021 --> 00:34:18,931 I think one of the examples you brought up is sort of creating 694 00:34:18,931 --> 00:34:23,221 hidden drives and book-ending normal drives available on that system. 695 00:34:23,221 --> 00:34:26,821 So ransomware kind of get stuck, or you can monitor for that. 696 00:34:27,851 --> 00:34:28,181 Yeah. 697 00:34:28,181 --> 00:34:32,231 So, I mean, it's part two, in case you're wondering, um, so the, the actions 698 00:34:32,231 --> 00:34:36,461 on objectives posts, so, you know, we have the, the initial infection, 699 00:34:36,461 --> 00:34:38,261 you know, they mapped your network. 700 00:34:38,261 --> 00:34:39,401 They're starting to spread out. 701 00:34:39,611 --> 00:34:43,731 Now they're actually going to start trying to attack, you know, at this point. 702 00:34:44,051 --> 00:34:48,311 1, you you have to call out that in 2022, one hopes that your endpoint 703 00:34:48,311 --> 00:34:50,771 security software, you know, whatever anti-virus, anti-malware, you're 704 00:34:50,771 --> 00:34:56,651 running sees process X is encrypting word document Y. I'm going to kill it. 705 00:34:56,681 --> 00:34:59,681 If it doesn't, you really need to have a come to Jesus moment with your 706 00:34:59,681 --> 00:35:01,601 endpoint protection vendor at this point. 707 00:35:02,171 --> 00:35:06,581 But you know, if you have something that's running, that's actively doing that. 708 00:35:06,881 --> 00:35:11,651 Um, at that point, I think one of the best controls you can possibly have. 709 00:35:12,531 --> 00:35:16,431 Is feeding it data that you don't care about and putting alerts on it. 710 00:35:16,431 --> 00:35:17,731 So, you know, as you were saying, Prasanna. 711 00:35:17,801 --> 00:35:23,111 One of the things I do is I create, um, deceptive file shares on my network. 712 00:35:23,111 --> 00:35:28,031 So just file servers that, you know, on their own separate windows box, doesn't 713 00:35:28,061 --> 00:35:29,531 don't have any useful data on them. 714 00:35:29,531 --> 00:35:33,671 I actually just clone my actual production file names and structures 715 00:35:33,671 --> 00:35:35,051 and just put random data in them. 716 00:35:35,711 --> 00:35:38,441 Uh, but then I make drive mappings to my end points. 717 00:35:38,561 --> 00:35:40,901 Um, hidden drive mapping said, you know, from the windows GUI, 718 00:35:40,901 --> 00:35:43,841 you can't see them, but, you know, from command prompt, you can. 719 00:35:44,471 --> 00:35:46,631 Um, and I just book in my valid drives. 720 00:35:46,691 --> 00:35:51,161 So, you know, you have a home drive at H. So put something before 721 00:35:51,161 --> 00:35:52,571 that and put something after that. 722 00:35:52,601 --> 00:35:55,691 And, you know, hopefully the ransomware will go after those first. 723 00:35:56,291 --> 00:36:00,731 Um, and then I put just, you know, files on those servers that I monitor. 724 00:36:00,731 --> 00:36:03,821 If anything gets changed for them, no reason for anyone 725 00:36:03,821 --> 00:36:05,011 to ever touch these servers. 726 00:36:05,011 --> 00:36:06,461 No reason for anyone to touch these files. 727 00:36:07,181 --> 00:36:10,481 So, if anything gets modified, then it sets off alerts and I 728 00:36:10,481 --> 00:36:12,251 know something weird is going on. 729 00:36:12,701 --> 00:36:16,391 Um, and hopefully it buys you enough time to, you know, to remote in at three in 730 00:36:16,391 --> 00:36:18,611 the morning and down whatever's going on. 731 00:36:19,301 --> 00:36:22,961 Um, and yeah, the other thing I, I offered up in that it was what 732 00:36:22,961 --> 00:36:26,591 I coined as a ransomware tar pit of an actual service that's just 733 00:36:26,591 --> 00:36:28,871 running or monitoring that server. 734 00:36:29,321 --> 00:36:31,391 And it just starts seeing files getting modified. 735 00:36:31,451 --> 00:36:32,621 It starts generating more. 736 00:36:33,101 --> 00:36:36,731 Um, so, you know, Hey, the ransomware, it hit my fake file share. 737 00:36:36,731 --> 00:36:38,001 It file one. 738 00:36:38,231 --> 00:36:41,741 Well, here's four more files for you and it'll just keep going and just keep going. 739 00:36:41,771 --> 00:36:45,911 And you know, it may not be foolproof, but it might just depending on 740 00:36:45,911 --> 00:36:47,951 how the ransomware is written, it might just put it in the loop 741 00:36:47,951 --> 00:36:49,301 that it will never escape from. 742 00:36:50,371 --> 00:36:50,611 Yeah. 743 00:36:50,611 --> 00:36:54,331 I mean, uh, the concept of honeypots is not new, but I like to sort 744 00:36:54,331 --> 00:37:00,467 of modifying it to, you know, the world of, of, uh, ransomware. 745 00:37:01,307 --> 00:37:04,867 I agree with everything you said about stopping it in the first place. 746 00:37:05,647 --> 00:37:10,717 What about, um, detecting data exfiltration? 747 00:37:10,747 --> 00:37:15,997 What, what do you think, um, companies can do there? 748 00:37:16,632 --> 00:37:19,992 Yeah, so it's a definitely a trickier process. 749 00:37:20,442 --> 00:37:23,982 Um, mainly from a tooling standpoint, at this point, you're probably 750 00:37:23,982 --> 00:37:25,722 going to have to open up the wallet. 751 00:37:26,352 --> 00:37:30,252 Um, but you know, there there's one, there's just a basic security controls 752 00:37:30,342 --> 00:37:35,652 of content filtering and making sure that your end users don't have a path out to 753 00:37:35,652 --> 00:37:39,897 the internet for mass file transfers. 754 00:37:40,197 --> 00:37:44,067 So for most enterprises, you probably don't need more than HTTP 755 00:37:44,067 --> 00:37:46,257 and HTTPS from your workstations. 756 00:37:46,737 --> 00:37:50,727 Um, so you know, a lot of those transfers are trying to transfer out via FTP 757 00:37:50,727 --> 00:37:53,217 or, you know, a more traditional file transfer method that shouldn't be allowed. 758 00:37:53,727 --> 00:37:57,717 Um, but going further, you need to look at, you know, what sites are out there 759 00:37:57,717 --> 00:38:02,387 for allowing mass transfers, you know, to, to keep it simple, to do all your users 760 00:38:02,387 --> 00:38:07,387 need to be able to reach Dropbox, um, or box or Google drive or any of that stuff. 761 00:38:07,387 --> 00:38:10,527 If the answer's no, prevent it because that's an exfiltration method. 762 00:38:11,157 --> 00:38:11,757 Um, 763 00:38:12,587 --> 00:38:13,547 Let me ask you about that. 764 00:38:13,877 --> 00:38:21,737 I guess I had this, this apparently misconception that they would be sending 765 00:38:21,737 --> 00:38:28,127 these exfiltrated files to something that they owned and controlled. 766 00:38:28,662 --> 00:38:29,082 Right. 767 00:38:29,232 --> 00:38:33,072 So, and that's, so I'm trying to build this out from, what's easier to, harder 768 00:38:33,072 --> 00:38:36,102 to implement, um, going to that point. 769 00:38:36,102 --> 00:38:36,552 Yes. 770 00:38:36,582 --> 00:38:39,042 So when you get to the point of we're going to just 771 00:38:39,042 --> 00:38:39,852 transfer to something we own. 772 00:38:39,852 --> 00:38:42,492 And honestly, at that point you're probably hitting up AWS 773 00:38:42,492 --> 00:38:43,572 or Azure or something like that. 774 00:38:43,572 --> 00:38:45,132 And that's where it gets really messy. 775 00:38:45,642 --> 00:38:49,692 Unfortunately, in the cloud world, we live in, you can't exactly block Azure. 776 00:38:49,752 --> 00:38:50,202 Right. 777 00:38:50,292 --> 00:38:53,922 Um, but that's where I started looking at DNS security. 778 00:38:54,192 --> 00:38:58,212 Um, and one of my absolute favorite controls is just blocking newly 779 00:38:58,212 --> 00:39:02,832 registered domains or domains that have been parked for years that 780 00:39:02,832 --> 00:39:03,702 have all of a sudden gone live. 781 00:39:04,592 --> 00:39:07,502 Um, cause a lot of the attack infrastructure, and this is honestly a 782 00:39:07,502 --> 00:39:10,712 great way of also stopping the initial drop or download because there's a 783 00:39:10,712 --> 00:39:15,092 good chance that that's going to go somewhere that was just newly stood up. 784 00:39:15,722 --> 00:39:20,252 Um, but yeah, so that, that is another control where you might be able to 785 00:39:20,252 --> 00:39:23,912 just stop them from being able to get to whatever destination there 786 00:39:24,152 --> 00:39:26,042 they stood up to accept these files. 787 00:39:26,942 --> 00:39:32,522 Another point is always just a basic security, um, control of proper ACL's. 788 00:39:32,912 --> 00:39:36,062 Um, you know, when it gets to data exfiltration again, you know, keep 789 00:39:36,062 --> 00:39:39,342 picking on poor Susie in accounting, but Susie and in accounting shouldn't 790 00:39:39,342 --> 00:39:40,982 be able to get to your HR documents. 791 00:39:41,192 --> 00:39:43,322 She shouldn't be able to get to your operations documents. 792 00:39:43,322 --> 00:39:43,532 Yeah. 793 00:39:43,802 --> 00:39:48,542 They might be able to export out your payroll, which that's terrible, but 794 00:39:48,842 --> 00:39:52,052 you know, your payroll showing up on pay spend tomorrow is a bad day. 795 00:39:52,742 --> 00:39:54,872 It's not an end of the company sort of day though. 796 00:39:54,872 --> 00:39:55,082 Right? 797 00:39:55,082 --> 00:39:56,672 Like that's not trade secrets going out. 798 00:39:57,242 --> 00:40:00,392 Um, you know, so, so that's another control. 799 00:40:00,392 --> 00:40:03,662 Another thing that I would absolutely call out though is still honey documents. 800 00:40:03,797 --> 00:40:07,637 You know, having documents for them to interact and transfer out that as soon 801 00:40:07,637 --> 00:40:11,867 as you see somebody interact with that, you're, you're figuring out what process 802 00:40:11,867 --> 00:40:15,527 it was and figuring out where system that came from, just stopping that information. 803 00:40:16,217 --> 00:40:20,057 Um, and then going into the, probably the more logical solution, but 804 00:40:20,057 --> 00:40:24,917 definitely at a cost it's just the behavioral controls because in that 805 00:40:24,917 --> 00:40:28,337 exfiltration attempt, there's going to be an end point that's all of a sudden 806 00:40:28,337 --> 00:40:32,507 transferring a lot of data out to a new source that has never been seen before. 807 00:40:33,047 --> 00:40:36,287 And if you really know what normal looks like in your network, that should 808 00:40:36,287 --> 00:40:38,717 stick out like a big, big red flag. 809 00:40:39,227 --> 00:40:43,547 Um, and it's a very hard thing to do with free solutions, but there 810 00:40:43,547 --> 00:40:47,387 are plenty of security products out there that are all about mapping, 811 00:40:47,387 --> 00:40:50,777 how your end points interact with each other on the network and what 812 00:40:50,777 --> 00:40:52,427 looks like normal, what isn't normal. 813 00:40:53,237 --> 00:40:56,177 Um, I think it's money well spent for those types of controls. 814 00:40:56,977 --> 00:41:00,937 Can I ask a question about an earlier topic you brought up around EDR. 815 00:41:01,837 --> 00:41:07,927 So if most, or if EDRs are useful for detecting when encryption is happening and 816 00:41:07,927 --> 00:41:14,437 killing processes, et cetera, if that's the case, would a lot of these ransomware 817 00:41:14,437 --> 00:41:16,897 attacks be prevented to start with. 818 00:41:18,162 --> 00:41:22,812 Or, and is it that companies who've been hit with ransomware have not deployed 819 00:41:22,842 --> 00:41:25,002 EDR solutions in their environments? 820 00:41:26,042 --> 00:41:31,952 If EDRs can detect when encryption is happening on endpoint devices, if a 821 00:41:31,982 --> 00:41:36,032 company has deployed EDRs, does that mean they'd be able to stop ransomware? 822 00:41:36,032 --> 00:41:38,972 And so a lot of companies who got hit with ransomware. 823 00:41:39,717 --> 00:41:41,277 Didn't have EDRs deployed. 824 00:41:42,557 --> 00:41:45,257 Endpoint detection response is what we're talking about here. 825 00:41:45,527 --> 00:41:48,947 So first information security is all about layered defenses, and 826 00:41:48,947 --> 00:41:51,077 you never rely on a single defense. 827 00:41:51,407 --> 00:41:56,237 Um, in my mind when your antivirus, your EDR, WM, whatever your endpoint security 828 00:41:56,237 --> 00:42:00,677 tool is, if that's the thing that stops the malware, thank God it was there, 829 00:42:00,707 --> 00:42:02,387 but that's still a, oh my goodness. 830 00:42:02,387 --> 00:42:04,817 How many different things failed before it got to the point 831 00:42:04,817 --> 00:42:06,107 where that had to step up? 832 00:42:06,137 --> 00:42:08,117 Like, I never want to see anything out of that system. 833 00:42:08,717 --> 00:42:10,907 Um, that's not false positives. 834 00:42:10,907 --> 00:42:14,087 Cause that's the fun with EDR is they are a pile of false positive. 835 00:42:14,872 --> 00:42:20,062 Um, you know, to your question, did they not have it maybe, um, you know, EDRs 836 00:42:20,062 --> 00:42:22,592 are expensive, they are expensive tools. 837 00:42:22,592 --> 00:42:24,292 They are great tools, but they're expensive. 838 00:42:24,712 --> 00:42:28,462 And like so many other expensive security tools that are rarely 839 00:42:28,462 --> 00:42:29,512 set it and forget it tools. 840 00:42:29,512 --> 00:42:31,792 They are tools that require a lot of tuning and a lot of 841 00:42:31,792 --> 00:42:33,142 the finding of what's right. 842 00:42:33,502 --> 00:42:34,912 Excuse me, within your enterprise. 843 00:42:35,602 --> 00:42:39,292 Um, but you certainly have a lot of companies out there that are still, 844 00:42:39,862 --> 00:42:45,532 you know, with prop with old definition based antivirus, that's just scanning 845 00:42:45,532 --> 00:42:49,282 files and doing your nightly full scans. 846 00:42:49,432 --> 00:42:53,542 You know, like we did back in the nineties, um, and companies that have 847 00:42:53,722 --> 00:42:57,562 been very happy to embrace Microsoft defender as their only antivirus. 848 00:42:57,562 --> 00:42:59,302 And, you know, there there's some logic to it. 849 00:42:59,302 --> 00:43:02,512 It's a great solution and it's free depending on what your 850 00:43:02,512 --> 00:43:04,402 office 365 licensing looks like. 851 00:43:04,942 --> 00:43:09,322 Um, but I think the number of customers out there that have these large EDR 852 00:43:09,322 --> 00:43:11,242 solutions are few and far between. 853 00:43:12,227 --> 00:43:15,847 Uh, definitely the companies I'm targeting with my security cadence 854 00:43:15,847 --> 00:43:19,417 posts are the companies that probably don't have that kind of assessment. 855 00:43:19,587 --> 00:43:19,827 Yeah. 856 00:43:20,637 --> 00:43:24,147 Or even if they did sort of managing it on a daily basis, becomes 857 00:43:24,807 --> 00:43:27,297 difficult, especially with everything else they have to do, because it's 858 00:43:27,297 --> 00:43:29,527 not a one and done sort of a deal. 859 00:43:30,207 --> 00:43:30,447 Right. 860 00:43:30,447 --> 00:43:33,937 And you know, honestly, if you think about it as a, the evolution of antivirus, 861 00:43:33,997 --> 00:43:37,897 antivirus was a one and done for the most part, you know, you deployed Symantec 862 00:43:37,897 --> 00:43:40,217 back in the day, next next finish. 863 00:43:40,217 --> 00:43:41,197 And you never touched it again. 864 00:43:41,197 --> 00:43:41,527 Right. 865 00:43:42,397 --> 00:43:43,477 EDRs aren't that. 866 00:43:43,807 --> 00:43:47,047 EDR is, are constant tuning and definitions and breaking 867 00:43:47,047 --> 00:43:49,267 things in your environment and having to tune them back out. 868 00:43:49,267 --> 00:43:52,417 And I think that's also in the recall that I know of a number of 869 00:43:52,417 --> 00:43:56,347 companies have thrown their EDRs out because, oh, it just broke everything. 870 00:43:56,347 --> 00:43:57,487 That product was terrible. 871 00:43:58,117 --> 00:44:01,957 It wasn't, you just needed the resources to handle it properly. 872 00:44:02,117 --> 00:44:02,279 Yeah. 873 00:44:02,279 --> 00:44:04,409 I want to sort of round out things here. 874 00:44:04,745 --> 00:44:07,555 There's some things that we haven't talked about that were obvious ones that were. 875 00:44:08,345 --> 00:44:11,765 You mentioned in your first post that, you know, you talked about, you know, you 876 00:44:11,765 --> 00:44:14,165 password security, you talked about MFA. 877 00:44:14,615 --> 00:44:17,855 Um, these are things that just everybody should be doing. 878 00:44:18,365 --> 00:44:22,115 Uh, my, my personal opinion at this point, you know, th th you know, 879 00:44:22,115 --> 00:44:26,615 if you're not doing MFA on anything that matters, uh, you know, you're 880 00:44:26,615 --> 00:44:30,935 not doing your job and, uh, and you know, that's my opinion for what it's 881 00:44:30,935 --> 00:44:34,685 worth, but MFA stops so many things. 882 00:44:37,165 --> 00:44:40,685 Yeah, I If you were waiting for me to disagree. 883 00:44:40,705 --> 00:44:41,515 I wasn't going to. 884 00:44:42,285 --> 00:44:44,355 I have a question for you though. 885 00:44:45,075 --> 00:44:49,215 So I dunno if we're going to talk about it now or later, but I've read 886 00:44:49,245 --> 00:44:53,745 recently with a lot of the Lapsis attacks as well as other gangs, right. 887 00:44:54,135 --> 00:44:58,305 There is a notion of SIM swapping attacks, right. 888 00:44:58,845 --> 00:45:03,795 Which sort of hurt some of the MFA approaches taken. 889 00:45:04,870 --> 00:45:07,810 So Prasanna, don't let perfect get in the way being good, 890 00:45:08,215 --> 00:45:11,605 I I was gonna I was going to say that that goes right to that, right? 891 00:45:11,875 --> 00:45:12,295 Yeah. 892 00:45:12,325 --> 00:45:15,955 Just because it won't fix everything doesn't mean you shouldn't do it, right. 893 00:45:16,000 --> 00:45:16,390 but no. 894 00:45:16,795 --> 00:45:18,655 not, there is no silver bullet. 895 00:45:19,165 --> 00:45:19,585 Right. 896 00:45:20,095 --> 00:45:25,585 Um, and you know, a good backup person would never say don't do InfoSec and 897 00:45:25,585 --> 00:45:28,675 a good InfoSec person would never say, do backup or not do backup. 898 00:45:29,065 --> 00:45:36,295 Um, but I think that MFA is just so, and by the way, I, I finally 899 00:45:36,295 --> 00:45:41,845 ate my own dog food maybe about two years ago where I just realized that 900 00:45:42,265 --> 00:45:46,645 there were a lot of vendors that I personally interacted with, banks and 901 00:45:46,645 --> 00:45:49,995 things, that offered MFA as an option. 902 00:45:50,445 --> 00:45:56,475 And I finally said, look, I know it's going to make it harder for me to access 903 00:45:56,475 --> 00:46:02,055 my bank account and my, you know, my PayPal and, you know, I, there, there's 904 00:46:02,055 --> 00:46:08,205 only like, I dunno, there's only like 20 accounts that I felt had that level 905 00:46:08,205 --> 00:46:10,725 of information that I needed MFA on. 906 00:46:11,205 --> 00:46:15,975 Um, and then, and then, and then I became like this like MFA Nazi, where I was like, 907 00:46:16,275 --> 00:46:18,495 I'm mad at them if they don't offer MFA. 908 00:46:18,915 --> 00:46:22,425 I remember what happened when you traded in your phone and 909 00:46:22,425 --> 00:46:24,375 you lost access to your MFA. 910 00:46:24,580 --> 00:46:24,910 Yeah. 911 00:46:25,120 --> 00:46:30,010 So I was using a Google authenticator, not realizing that when I traded in my 912 00:46:30,010 --> 00:46:32,500 phone that I lost all of my MFA tokens. 913 00:46:32,890 --> 00:46:37,660 And so I switched actually to authy, so that I can, I don't have that problem. 914 00:46:38,140 --> 00:46:43,270 But, um, and now, and now I'm actually looking at a password manager. 915 00:46:43,330 --> 00:46:49,210 I think it's one password that manages both your passwords and your MFA stuff. 916 00:46:49,240 --> 00:46:50,290 That sounds nice. 917 00:46:50,290 --> 00:46:54,490 So I'm already a big password manager, uh, fan, I just, um, 918 00:46:54,910 --> 00:46:59,350 didn't, you know, I currently have to use two solutions, but Yeah. 919 00:46:59,580 --> 00:46:59,760 Yeah. 920 00:46:59,790 --> 00:47:03,300 And to your point, Prasanna, about, you know, SIM jacking you know, and not being 921 00:47:03,300 --> 00:47:07,410 the silver bullet, the one thing I'd say is not all MFA's are created equal. 922 00:47:07,980 --> 00:47:12,740 Any MFA is better than no MFA, um, but you know, it doesn't have to be a 923 00:47:12,740 --> 00:47:16,910 roadblock in your organization, you know, Fido keys, Titan keys, things like that, 924 00:47:16,940 --> 00:47:20,690 that are literally you get the prompt and you tap a, the thing hanging out of 925 00:47:20,690 --> 00:47:26,540 your USB port or taps onto your phone is a really, really nice MFA solution. 926 00:47:26,540 --> 00:47:28,250 That's really easy for your users. 927 00:47:28,380 --> 00:47:31,520 And they require something that you have that's truly physical. 928 00:47:32,120 --> 00:47:36,080 Um, and rather than, you know, replying to a text message, you know, there's, 929 00:47:36,080 --> 00:47:40,790 uh, one of the big debates going on in the InfoSec world right now is the, the 930 00:47:40,790 --> 00:47:42,680 push notifications of yes, that was me. 931 00:47:43,040 --> 00:47:47,090 Um, and it's right out of, uh, the playbook of lapsis of just that they 932 00:47:47,090 --> 00:47:51,200 actually had a picture on Twitter, um, yesterday of one of their chat things. 933 00:47:51,650 --> 00:47:51,770 Yeah. 934 00:47:51,790 --> 00:47:52,820 Just spam them a hundred times. 935 00:47:52,820 --> 00:47:54,320 Eventually they'll get mad and hit yes. 936 00:47:54,755 --> 00:47:55,925 Yeah, absolutely. 937 00:47:56,075 --> 00:48:00,035 And it's funny, cause I actually had, um, our MFA at work today went a little 938 00:48:00,035 --> 00:48:03,215 bit sideways and they started pinging me repeatedly for something I had just 939 00:48:03,215 --> 00:48:08,615 tried to sign into it had in the back of my mind, like, Hmm, check the logs to 940 00:48:08,615 --> 00:48:10,535 make sure like, this is kind of weird. 941 00:48:10,865 --> 00:48:14,855 Um, but still it's, it's better than nothing and yeah. 942 00:48:14,855 --> 00:48:16,715 Your end user may fail you and hit. 943 00:48:16,715 --> 00:48:17,495 Yes, that was me. 944 00:48:17,495 --> 00:48:19,595 Cause I got tired of getting this prompt a hundred times. 945 00:48:19,595 --> 00:48:25,325 at three in the morning, but still, um, but as InfoSec practitioners, 946 00:48:25,865 --> 00:48:28,805 that's where we need to step in and go don't we think it was abnormal that 947 00:48:28,805 --> 00:48:31,715 they got a hundred prompts, like did that not set off an alarm right there? 948 00:48:31,745 --> 00:48:34,865 Why is it if we're getting pinged over and over and over and over again? 949 00:48:35,435 --> 00:48:37,565 Um, cause I guarantee you that created a log somewhere. 950 00:48:37,655 --> 00:48:37,805 Yeah. 951 00:48:38,920 --> 00:48:39,310 All right. 952 00:48:40,540 --> 00:48:40,780 All right. 953 00:48:40,780 --> 00:48:45,250 Well, the summary statement of your, of your blog series or your post series, 954 00:48:45,250 --> 00:48:48,490 whatever you going to call this, and by the way, your posts are long. 955 00:48:48,700 --> 00:48:53,680 I, uh, after you made the comment I went and while you were talking, 956 00:48:53,680 --> 00:48:57,310 I copied and pasted the three posts into a, uh, Google docs. 957 00:48:57,910 --> 00:49:00,610 Uh, one of them is 4,500 words long my friend. 958 00:49:01,120 --> 00:49:03,600 I mean, that's long, even for me, I'm just saying 959 00:49:03,600 --> 00:49:06,300 I got to tell you someone the other day commented about how 960 00:49:06,300 --> 00:49:07,440 much they liked my writing style. 961 00:49:07,440 --> 00:49:11,610 And it was the first time ever in my 42 years of life that 962 00:49:11,610 --> 00:49:12,990 anyone has ever said such a thing 963 00:49:13,465 --> 00:49:14,935 I actually liked your writing style. 964 00:49:14,935 --> 00:49:15,485 I thought it was good 965 00:49:15,535 --> 00:49:17,795 This is a reason, this is a reason you're here is you. 966 00:49:18,825 --> 00:49:20,685 Well, it's a complicated issue. 967 00:49:20,685 --> 00:49:25,755 So, you know, I, I jab, but you know, 4,500 words is not that much 968 00:49:25,755 --> 00:49:28,275 for, for an issue of this magnitude. 969 00:49:28,305 --> 00:49:28,665 Right. 970 00:49:29,055 --> 00:49:31,275 But, uh, the first was 2,500. 971 00:49:31,275 --> 00:49:34,065 The second one was 2000, but the last one was 4,500. 972 00:49:35,175 --> 00:49:36,915 I was like, yeah, the boy could talk. 973 00:49:37,245 --> 00:49:41,835 Um, I would just reiterate what I said of so many companies 974 00:49:41,835 --> 00:49:44,145 focus on the recovery side. 975 00:49:44,625 --> 00:49:49,815 Um, and that focus comes from focusing on what the actual objective was of 976 00:49:49,815 --> 00:49:51,105 the ransomware group to begin with. 977 00:49:51,105 --> 00:49:51,495 What was it? 978 00:49:51,495 --> 00:49:53,685 They were trying to do, whether they were going to encrypt your stuff. 979 00:49:53,895 --> 00:49:56,455 So you start there and it's the wrong place to start. 980 00:49:57,450 --> 00:49:59,580 Start at the beginning, start with how they're going to 981 00:49:59,580 --> 00:50:02,160 compromise your first endpoint. 982 00:50:02,790 --> 00:50:07,950 And if you start looking at InfoSec from that perspective, what you'll end up 983 00:50:07,980 --> 00:50:14,490 finding, and it's a really gratifying feeling is you would turn on the news one 984 00:50:14,490 --> 00:50:18,780 day and there will be the latest, massive vulnerability or exploit being discussed. 985 00:50:19,500 --> 00:50:23,070 And you'll look at it and go, oh, my controls account for that. 986 00:50:23,430 --> 00:50:27,180 Not because I built controls around that particular exploit or vulnerability, 987 00:50:27,210 --> 00:50:32,490 but because I just built my controls around, how do I walk an attacker through 988 00:50:32,910 --> 00:50:37,310 initial foothold, moving laterally throughout my environment, and then acting 989 00:50:37,310 --> 00:50:40,650 on their objectives and then how do I stop them at each one of those steps? 990 00:50:41,130 --> 00:50:46,260 Um, so I guess the, the, the too long, didn't read it to use Reddit terminology. 991 00:50:46,800 --> 00:50:50,430 Don't focus on ransomware, just focus on how attacks function and you'll get 992 00:50:50,430 --> 00:50:52,630 ransomware taken care of by default. 993 00:50:54,175 --> 00:50:58,015 Right in the, the only major one that we didn't discuss, which we really 994 00:50:58,015 --> 00:50:59,815 should have is the whole patching thing. 995 00:51:00,235 --> 00:51:00,505 Right. 996 00:51:00,545 --> 00:51:06,415 I go back to, I'm pretty sure if my, if my memory serves correctly, Wannacry. 997 00:51:07,185 --> 00:51:08,655 Was, you know, it was one of the. 998 00:51:08,655 --> 00:51:13,185 first big ones that really went, you know, it went haywire and everywhere. 999 00:51:13,965 --> 00:51:18,825 If I recall correctly, it was an exploit that had been patched 1000 00:51:18,825 --> 00:51:21,915 a year prior in a windows. 1001 00:51:22,455 --> 00:51:26,775 And if you had just been anywhere near up to date, then you'd have been fine. 1002 00:51:27,034 --> 00:51:27,364 Yeah. 1003 00:51:27,364 --> 00:51:33,724 And Microsoft is, they are both great in how they maintain with a 1004 00:51:33,724 --> 00:51:37,504 lion's grip to a, or with an iron grip to backwards compatibility. 1005 00:51:37,564 --> 00:51:39,274 And they are also just ridiculous. 1006 00:51:40,044 --> 00:51:44,244 in they're lions grip, iron grip on backwards compatibility, 1007 00:51:44,634 --> 00:51:45,844 but I mean, Wannacry. 1008 00:51:45,894 --> 00:51:51,264 The other side of Wannacry is exposure to the internet, um, which, and this kind 1009 00:51:51,264 --> 00:51:52,464 of goes back to the proxy shell thing. 1010 00:51:52,464 --> 00:51:55,464 You know, Wannacry has went gangbusters because of all the companies that 1011 00:51:55,464 --> 00:51:59,934 have Samba, SMB exposed to the internet, which again is you take 1012 00:51:59,934 --> 00:52:01,674 a step back and go good god, why? 1013 00:52:02,094 --> 00:52:04,164 But then you go jump on something like showdown and you look 1014 00:52:04,164 --> 00:52:05,334 like, oh yeah, there's tons. 1015 00:52:05,814 --> 00:52:09,084 There's tons of vCenters exposed to the internet and you go good god, why? 1016 00:52:09,474 --> 00:52:14,274 Um, and again, it just kind of comes down to, well, I had this one sysadmin who 1017 00:52:14,274 --> 00:52:18,204 was overworked and doing what they could, and we had this use case and he stood 1018 00:52:18,204 --> 00:52:20,154 it up, but he wasn't InfoSec focused. 1019 00:52:20,604 --> 00:52:21,594 He didn't know what he was doing. 1020 00:52:21,594 --> 00:52:23,544 And from that regards and didn't see the problem with it. 1021 00:52:24,114 --> 00:52:26,844 Um, so yeah, I mean, to your point of patching. 1022 00:52:26,844 --> 00:52:27,564 Absolutely. 1023 00:52:28,074 --> 00:52:34,994 Uh, but I guess my takeaway is focusing on the big things. 1024 00:52:35,114 --> 00:52:38,054 And don't worry about the latest zero day, quite as much. 1025 00:52:38,294 --> 00:52:41,594 Um, cause I tell you attackers rarely are focused on that. 1026 00:52:41,594 --> 00:52:44,204 Cause there's so much low-hanging fruit of the stuff that has 1027 00:52:44,204 --> 00:52:45,584 been patched since 2018. 1028 00:52:45,584 --> 00:52:46,184 Anyways. 1029 00:52:47,334 --> 00:52:47,514 Yeah. 1030 00:52:47,514 --> 00:52:49,314 you, you mentioned SMB. 1031 00:52:49,524 --> 00:52:55,914 My other big one is RDP RDP to the internet is just, I just want to slap you. 1032 00:52:56,554 --> 00:52:58,654 Well, listen, we could talk all day. 1033 00:52:59,014 --> 00:53:04,144 Uh, I just, I want to say thank you again, and, you know, for 1034 00:53:04,144 --> 00:53:07,594 coming on the podcast and talking to these really important things, 1035 00:53:08,214 --> 00:53:09,294 No, it was a pleasure to be here. 1036 00:53:09,294 --> 00:53:11,934 I really, I have to say when I got, when I got your message, 1037 00:53:11,934 --> 00:53:13,644 like, wait, is that Mr. Backup? 1038 00:53:13,794 --> 00:53:15,114 That is Mr. Backup! 1039 00:53:15,684 --> 00:53:16,644 I was really excited. 1040 00:53:17,644 --> 00:53:18,274 this is me. 1041 00:53:18,274 --> 00:53:21,514 I, well, and I'm honored that you, that you knew who I was, so, Hey, 1042 00:53:21,514 --> 00:53:25,934 you know, we're, we're members of the mutual admiration society, Prasanna? 1043 00:53:26,764 --> 00:53:30,159 Yeah, no, it's been great snorkel having you on and yeah, great 1044 00:53:30,159 --> 00:53:32,199 articles I'm will continue to read. 1045 00:53:32,199 --> 00:53:36,429 I hope you keep doing your weekly posts on security cadence, because I'm sure a lot 1046 00:53:36,429 --> 00:53:37,809 of people learn a lot of things from that. 1047 00:53:37,809 --> 00:53:38,049 So 1048 00:53:39,159 --> 00:53:40,629 I'll try to make a cliff notes version. 1049 00:53:40,789 --> 00:53:41,959 yeah, I keep it long. 1050 00:53:41,959 --> 00:53:42,049 I 1051 00:53:42,139 --> 00:53:42,399 Yeah. 1052 00:53:42,639 --> 00:53:45,199 Good, good luck with that. 1053 00:53:45,529 --> 00:53:50,029 Uh, yeah, he's easy to find on Reddit is snorkel 42, make sure to check them. 1054 00:53:50,029 --> 00:53:52,105 out and make sure to subscribe. 1055 00:53:55,029 --> 00:53:59,729 The Backup Wrap Up is written, recorded, and produced by me, W. Curtis Preston. 1056 00:54:00,319 --> 00:54:05,079 If you need backup or DR consulting, content generation, or expert witness 1057 00:54:05,079 --> 00:54:07,879 work, check out backupcentral.com. 1058 00:54:08,389 --> 00:54:11,449 You can also find links for my O'Reilly books on the same website. 1059 00:54:12,179 --> 00:54:16,149 Remember, this is an independent podcast, and any opinions that 1060 00:54:16,149 --> 00:54:20,119 you hear are those of the speaker and not necessarily an employer. 1061 00:54:20,989 --> 00:54:21,649 Thanks for listening