1 00:00:00,247 --> 00:00:03,907 You found the backup wrap up your go-to podcast for all things 2 00:00:03,907 --> 00:00:06,157 backup recovery and cyber recovery. 3 00:00:06,607 --> 00:00:09,697 In this episode, we'll get into something, uh, that I'll be honest, 4 00:00:09,697 --> 00:00:14,767 pushed the edges of my knowledge We're talking about fless malware, the kind 5 00:00:14,767 --> 00:00:20,137 of attack that never touches your hard drive lives entirely in memory and can 6 00:00:20,137 --> 00:00:23,077 steal your credentials before antivirus. 7 00:00:24,427 --> 00:00:25,507 Even knows that it's there. 8 00:00:26,047 --> 00:00:29,647 Uh, we've of course got our, my co-author, Dr. Mike Sailor with me, 9 00:00:29,677 --> 00:00:33,187 and he breaks it down in a way that, that I think helps make it sense. 10 00:00:33,457 --> 00:00:36,517 But more importantly, the at, at the end of the episode, we get 11 00:00:36,517 --> 00:00:40,027 into some real things that you can do to protect yourself, not only 12 00:00:40,027 --> 00:00:41,977 from this threat, but many others. 13 00:00:42,157 --> 00:00:44,647 And I think of particular interest as a discussion we 14 00:00:44,647 --> 00:00:47,377 have on, uh, Mike's view of MFA. 15 00:00:47,977 --> 00:00:52,057 By the way, if you don't know who I am, I'm w Curtis Preston, AKA, Mr. Backup. 16 00:00:52,342 --> 00:00:55,942 And I've been passionate about backup and recovery for over 30 years. 17 00:00:56,152 --> 00:00:56,722 Ever since. 18 00:00:56,722 --> 00:00:59,872 I had to tell my boss there were no backups of the production 19 00:00:59,872 --> 00:01:01,312 database that we just lost. 20 00:01:01,642 --> 00:01:04,642 I don't want that to happen to you, and that's why I do this. 21 00:01:04,852 --> 00:01:09,622 On this podcast, we turn unappreciated backup admins into cyber recovery heroes. 22 00:01:09,922 --> 00:01:11,902 This is to back up, wrap up. 23 00:01:26,927 --> 00:01:28,427 Welcome to the backup wrap up. 24 00:01:28,427 --> 00:01:32,777 I'm your host, w Curtis Preston, AKA, Mr. Backup, and I have with me a guide that 25 00:01:32,777 --> 00:01:37,727 is, I think, just as excited as I am, that I got rid of a problematic tenant. 26 00:01:42,272 --> 00:01:44,282 Yes, I am excited. 27 00:01:44,612 --> 00:01:46,832 Well, I'm also kind of sad, but it's okay. 28 00:01:47,042 --> 00:01:50,672 I hope you have less stress over the next many, many months, 29 00:01:50,672 --> 00:01:52,802 Curtis, and I hope that, uh, 30 00:01:53,372 --> 00:01:53,582 Yeah. 31 00:01:53,582 --> 00:01:55,172 you enjoy having the house 32 00:01:55,427 --> 00:01:55,997 Yeah. 33 00:01:56,027 --> 00:01:58,367 Uh, it, it's been something we started doing, you know, 34 00:01:58,367 --> 00:01:59,357 for those that don't know. 35 00:01:59,357 --> 00:02:01,997 About a few years ago we've been experimenting with 36 00:02:01,997 --> 00:02:03,587 renting rooms out and, uh. 37 00:02:04,427 --> 00:02:06,707 Let's just say not all of the tenants are the same. 38 00:02:07,157 --> 00:02:12,317 And, uh, there was a very problematic tenant and I am now problematic 39 00:02:12,317 --> 00:02:14,687 tenant free as of two days ago. 40 00:02:15,377 --> 00:02:18,347 And, uh, like I said, you were, you were my problematic tenant advisor 41 00:02:18,347 --> 00:02:20,837 I think during this, uh, as usual, 42 00:02:20,927 --> 00:02:22,037 to be your advisor for many 43 00:02:22,037 --> 00:02:22,487 things. 44 00:02:22,582 --> 00:02:22,802 Yes. 45 00:02:23,417 --> 00:02:23,747 All right. 46 00:02:23,747 --> 00:02:28,757 Speaking of problematic tenets, we also have Dr. Mike Sailor on with us, my 47 00:02:28,757 --> 00:02:32,327 co-author of our book, learning Ransomware Response and Recovery, which if you're 48 00:02:32,327 --> 00:02:36,887 watching us on YouTube by the same channel name, you can see me pointing up at it, 49 00:02:37,307 --> 00:02:39,377 uh, that, that just started shipping. 50 00:02:39,377 --> 00:02:40,247 Are you excited, Mike? 51 00:02:41,267 --> 00:02:42,257 I am so excited. 52 00:02:42,302 --> 00:02:46,337 You know you're gonna, you're gonna get, uh, you're gonna get one day, but it's 53 00:02:46,337 --> 00:02:47,987 gonna show up in our hot little hands. 54 00:02:48,467 --> 00:02:49,607 I'm very excited about that. 55 00:02:50,372 --> 00:02:50,592 Hmm. 56 00:02:50,627 --> 00:02:53,477 I expect a signed copy from you, sir. 57 00:02:54,962 --> 00:02:55,052 Yeah. 58 00:02:55,052 --> 00:02:56,312 We'll have to exchange copies 59 00:02:56,312 --> 00:02:56,492 then. 60 00:02:56,792 --> 00:02:57,752 'cause I, I would love to do 61 00:02:57,947 --> 00:02:59,027 yeah, yeah. 62 00:02:59,687 --> 00:03:02,597 Uh, maybe I'll just show up at your house or something. 63 00:03:03,412 --> 00:03:03,492 Hmm. 64 00:03:03,602 --> 00:03:03,842 Come 65 00:03:03,842 --> 00:03:04,112 on, 66 00:03:05,242 --> 00:03:05,462 get 67 00:03:05,522 --> 00:03:06,212 bring your boots, 68 00:03:06,257 --> 00:03:07,007 get some barbecue. 69 00:03:07,232 --> 00:03:07,862 put you to work. 70 00:03:08,327 --> 00:03:08,687 Yeah. 71 00:03:09,377 --> 00:03:09,827 Yeah. 72 00:03:09,947 --> 00:03:10,397 All right. 73 00:03:10,397 --> 00:03:14,357 Yeah, so for, for those that don't know, Mike and I have never met in person. 74 00:03:15,227 --> 00:03:19,007 Just, uh, you know, virtually like this in the Matrix. 75 00:03:19,487 --> 00:03:22,877 So, um, so today, Mike, I'm gonna be very blunt. 76 00:03:22,907 --> 00:03:28,037 A lot of times I, you know, I, I play the dumb guy in the room and I, I just 77 00:03:28,037 --> 00:03:31,877 ask dumb questions, but I actually know what the answer is in this episode. 78 00:03:32,837 --> 00:03:34,517 Uh, I am definitely 79 00:03:34,577 --> 00:03:35,477 Don't take my job. 80 00:03:35,897 --> 00:03:36,917 Wait, what was that persona? 81 00:03:37,577 --> 00:03:38,627 Don't take my job. 82 00:03:39,662 --> 00:03:39,872 yeah. 83 00:03:39,872 --> 00:03:42,122 Usually you're playing the guy, the dumb guy in the room on 84 00:03:42,122 --> 00:03:43,532 our, our typical recordings. 85 00:03:43,772 --> 00:03:47,612 But in this episode, uh, I think both of us are playing the dumb guy in the room. 86 00:03:47,612 --> 00:03:51,392 But the, but in this case, this is this thing that we're gonna talk about 87 00:03:51,392 --> 00:03:53,222 today, I think is very interesting. 88 00:03:53,732 --> 00:03:56,132 But it definitely, I'm, I'm gonna say a couple things about it. 89 00:03:56,132 --> 00:04:00,602 One is it's definitely way out there on the edge of my, my understanding. 90 00:04:00,602 --> 00:04:04,292 And two, I think this is one of those things where. 91 00:04:05,822 --> 00:04:09,272 You should listen to some of the other episodes first, right? 92 00:04:09,272 --> 00:04:11,762 Some of the things, you know, solve those things first. 93 00:04:11,762 --> 00:04:16,172 But this is something I do think you should be aware of, but when we, when we 94 00:04:16,172 --> 00:04:19,502 get to the, to the, um, do you call it? 95 00:04:19,502 --> 00:04:19,952 Um. 96 00:04:20,702 --> 00:04:25,382 Um, the, the action items, the action items, I, I would say, are a little 97 00:04:25,382 --> 00:04:28,862 bit more advanced than the typical action items that we talk about. 98 00:04:29,102 --> 00:04:35,012 And so it's a bit like, you know, don't start talking about investing in a 401k. 99 00:04:35,012 --> 00:04:36,992 You don't have like a, a, um. 100 00:04:37,532 --> 00:04:38,642 An emergency fund. 101 00:04:38,732 --> 00:04:39,092 Right. 102 00:04:39,122 --> 00:04:40,502 That, that's, it's sort of like that. 103 00:04:40,682 --> 00:04:42,812 So this is sort of the 401k part. 104 00:04:43,082 --> 00:04:48,332 But anyway, we are talking today about something called violist malware. 105 00:04:48,872 --> 00:04:51,992 Do you wanna explain that to, to the mere mortals in the room? 106 00:04:53,342 --> 00:04:53,732 Sure. 107 00:04:54,602 --> 00:04:56,762 So malware, traditionally, and, 108 00:04:56,762 --> 00:05:00,332 and, and, you know, malware short for malicious software, software being 109 00:05:00,332 --> 00:05:03,527 indicative of something that you would download and install on your computer. 110 00:05:04,472 --> 00:05:08,792 And tools, security tools that are out there today to, to try and detect 111 00:05:08,792 --> 00:05:14,402 and prevent that, uh, fundamentally look for things that are written to 112 00:05:14,702 --> 00:05:16,412 the, the hard drive on a computer. 113 00:05:16,832 --> 00:05:23,072 So if I download it, it, it traverses memory, but then as I, depending on, 114 00:05:23,072 --> 00:05:27,752 on what it is, as I interact with that, it's, it's installed or written to or 115 00:05:27,752 --> 00:05:31,157 saved to hard drive in your computer. 116 00:05:32,462 --> 00:05:39,662 And so, uh, one of the efforts of bad guys to try and, uh, maintain some success 117 00:05:39,662 --> 00:05:45,842 at infecting computers, and it, it, it is limited to certain types of attacks. 118 00:05:46,607 --> 00:05:50,537 Uh, so instead of downloading something to be written to the, to 119 00:05:50,537 --> 00:05:54,017 the hard drive in your computer, it's downloaded and is simply resident 120 00:05:54,017 --> 00:05:55,757 in the memory of the computer. 121 00:05:56,357 --> 00:05:58,757 Uh, and it, there are some tactics too. 122 00:05:58,817 --> 00:06:01,937 Uh, 'cause if, if you think about it, uh, similar to my memory, when 123 00:06:01,937 --> 00:06:05,057 I go to sleep at night, it, you get, you know, completely erased. 124 00:06:05,507 --> 00:06:06,947 Uh, I wake up fresh the next day. 125 00:06:06,947 --> 00:06:11,267 Well, computers are very similar when you turn it off and it's truly powered off. 126 00:06:11,627 --> 00:06:14,447 Um, that memory also called volatile memory. 127 00:06:14,867 --> 00:06:18,407 Uh, which requires power to maintain its content goes away. 128 00:06:18,947 --> 00:06:23,087 Uh, so I've got malware and memory and I turn my computer off and restart it. 129 00:06:23,087 --> 00:06:24,467 It shouldn't be there anymore. 130 00:06:24,887 --> 00:06:27,257 Uh, but bad guys have have figured that out. 131 00:06:27,647 --> 00:06:30,917 Uh, and so what they'll do is instead of writing hardware to, uh, 132 00:06:30,917 --> 00:06:36,317 writing software to your hardware, uh, they will make modifications to 133 00:06:36,317 --> 00:06:38,087 the way your operating system works. 134 00:06:38,627 --> 00:06:42,977 So that if you think I'll just turn it off and erase all that bad stuff and turn 135 00:06:42,977 --> 00:06:47,567 it back on when, when it comes back on, uh, what they've written to the operating 136 00:06:47,567 --> 00:06:52,037 system, reinfect your memory, uh, and they're able to continue that attack. 137 00:06:53,637 --> 00:06:54,177 Mike. 138 00:06:54,872 --> 00:06:58,592 This is fascinating 'cause I don't think most people think about this. 139 00:06:59,072 --> 00:07:02,432 The second use case you talked about though, modifying the operating system. 140 00:07:02,702 --> 00:07:07,442 I know I've heard in the past where, uh, malware actors, uh, 141 00:07:07,652 --> 00:07:12,992 infect the UEFI boot on for like a window system that's sort of like. 142 00:07:13,412 --> 00:07:16,352 Things that happen before the operating system comes up, it's 143 00:07:16,352 --> 00:07:18,452 not technically written to disc. 144 00:07:18,662 --> 00:07:21,932 Are those the sort of things you're talking about in terms of modifying 145 00:07:21,932 --> 00:07:26,762 the operating system in order to sort of provide that persistence without 146 00:07:26,762 --> 00:07:29,882 necessarily writing to a hard disc or SSD. 147 00:07:31,052 --> 00:07:35,377 Sort of, uh, but, uh, some of what you described, the UFE, 148 00:07:35,477 --> 00:07:39,632 the UA, the UEFI also called the baseboard management controller. 149 00:07:39,992 --> 00:07:40,082 Um. 150 00:07:40,652 --> 00:07:44,702 Those are, you have to be in, you have to be on the same network, like physical 151 00:07:44,702 --> 00:07:48,392 network and, and or even physically connected for those types of attacks. 152 00:07:48,392 --> 00:07:49,682 But definitely possible. 153 00:07:50,252 --> 00:07:51,122 Uh, what, 154 00:07:53,522 --> 00:07:57,392 what most bad guys are doing with the fless memory stuff is it's, uh, 155 00:07:57,392 --> 00:07:59,612 you know, embedded in an email or, 156 00:08:00,032 --> 00:08:02,942 uh, embedded in a, a website. 157 00:08:03,482 --> 00:08:04,117 Um, and so. 158 00:08:05,102 --> 00:08:08,822 A lot of that content, like if you, if you open a, an email that's got 159 00:08:08,822 --> 00:08:13,442 a lot of rich content like HTML, those graphics are stored in memory 160 00:08:13,442 --> 00:08:15,182 while you're viewing that file. 161 00:08:15,572 --> 00:08:19,142 When you go to that website and there's animation or a lot of content, 162 00:08:19,142 --> 00:08:21,062 a lot of that is stored in memory. 163 00:08:21,482 --> 00:08:23,972 Uh, to make the best, you know, your best. 164 00:08:23,972 --> 00:08:24,452 Uh. 165 00:08:25,202 --> 00:08:29,612 Uh, interaction with whatever, you know, that that artwork or, or website is. 166 00:08:30,242 --> 00:08:32,852 Um, and so that's what they're taking advantage of. 167 00:08:32,852 --> 00:08:37,082 What is it that's being written to memory during these different types 168 00:08:37,082 --> 00:08:42,392 of activities that I can hide malware in that isn't gonna be detected by 169 00:08:43,382 --> 00:08:47,312 traditional antivirus anti M malware software that's looking for stuff 170 00:08:47,312 --> 00:08:49,442 getting written to the disc now today. 171 00:08:51,182 --> 00:08:55,532 some of the newer computers have these, you know, TPM modules and 172 00:08:55,892 --> 00:09:00,662 different hardware that looks for rogue addressing in memory. 173 00:09:00,902 --> 00:09:02,702 Rogue Read writes in memory. 174 00:09:03,062 --> 00:09:08,432 Um, and so it's getting better and I think we're evolving into, you know, some 175 00:09:08,432 --> 00:09:10,892 capabilities to, to mitigate that threat. 176 00:09:10,892 --> 00:09:13,802 But for the most part, you know, people are, are still 177 00:09:13,802 --> 00:09:15,482 being victimized by this fless 178 00:09:16,367 --> 00:09:20,687 Do you wanna talk about the arc, GIS, um, attack and how 179 00:09:20,687 --> 00:09:22,907 this falls under that, um, idea? 180 00:09:24,662 --> 00:09:25,022 Sure. 181 00:09:25,022 --> 00:09:30,782 And, and you know, in, in another episode, we, we, we covered living off the land, 182 00:09:30,962 --> 00:09:40,262 uh, type of attacks and similarly, uh, memory resident or file this, uh, malware. 183 00:09:41,802 --> 00:09:45,257 It isn't talked about as much as part of an overall attack 184 00:09:45,257 --> 00:09:46,847 because it was just a piece of it. 185 00:09:47,507 --> 00:09:52,697 And very often you'll get the file is malware component that then evolves 186 00:09:52,697 --> 00:09:58,337 into living off the land or vice versa, or even combined at the same time. 187 00:09:58,877 --> 00:10:01,757 And so, uh, you know, living off the land, we, we had talked about 188 00:10:01,757 --> 00:10:06,227 PowerShell as being one of those, uh, very frequently used tools. 189 00:10:06,617 --> 00:10:09,937 Same happens in, in, uh, fileless. 190 00:10:11,027 --> 00:10:13,367 attacks, you know, we compromise memory. 191 00:10:13,547 --> 00:10:16,517 Uh, a lot of times memory is where credentials are stored. 192 00:10:16,997 --> 00:10:22,487 Uh, if I'm logged in as admin, especially if it's across a session, uh, RDP or 193 00:10:22,492 --> 00:10:26,267 or, or in a web session, a lot of that's stored in memory and I can utilize 194 00:10:26,267 --> 00:10:33,137 that then to run services with those credentials, um, or simply run, um. 195 00:10:33,542 --> 00:10:36,482 Run malware and memory to harvest those credentials. 196 00:10:36,872 --> 00:10:42,302 And so very often, the file memory, the fileless, uh, uh, malware is very 197 00:10:42,302 --> 00:10:47,552 focused on credentials and how can I use session, uh, and credential type, 198 00:10:47,762 --> 00:10:51,152 um, uh, information to conduct more. 199 00:10:51,722 --> 00:10:55,142 I guess in some cases, living off the land would be an evolution or 200 00:10:55,142 --> 00:10:57,182 simply, uh, you know, remote access. 201 00:10:57,182 --> 00:10:59,792 You know, those, those, uh, initial access brokers, that's all they're 202 00:10:59,792 --> 00:11:01,952 after is credentials and so they'll. 203 00:11:02,627 --> 00:11:02,867 they'll. 204 00:11:02,867 --> 00:11:07,127 infect a website, uh, and, and do like a waterhole attack and, and get a bunch 205 00:11:07,127 --> 00:11:10,847 of people to go to this website and then just harvest all those credentials. 206 00:11:11,327 --> 00:11:13,667 Um, but in particular attacks. 207 00:11:14,027 --> 00:11:18,437 Um, and, and there's, there's tons of examples of, of this, uh, 208 00:11:18,467 --> 00:11:25,487 where it's, it's a, uh, it's a spectrum of of, of attack types. 209 00:11:25,637 --> 00:11:32,897 You know, is it just credentials and persistence or is it That evolves into 210 00:11:32,897 --> 00:11:37,877 something a lot more complex and, and broad sweeping across a whole enterprise. 211 00:11:38,507 --> 00:11:40,547 Um, and one of the 212 00:11:40,547 --> 00:11:43,697 things that I mentioned a second ago is, you know, I can, I can infect 213 00:11:43,697 --> 00:11:47,597 a machine and in order to maintain persistence, I'm the, one of the first 214 00:11:47,597 --> 00:11:49,667 things I'll do is modify the registry. 215 00:11:50,027 --> 00:11:52,457 Uh, and there's, there's a couple of different keys in the registry 216 00:11:52,457 --> 00:11:55,217 for startup and, uh, initialization. 217 00:11:55,217 --> 00:11:59,822 And I will just inject myself into that in a. Kind of a nondescript way so 218 00:11:59,822 --> 00:12:03,002 that you, you know, it doesn't say, you know, reinfect this computer on startup. 219 00:12:03,002 --> 00:12:06,242 It says something, you know, you wouldn't necessarily recognize. 220 00:12:06,632 --> 00:12:10,052 Um, or it looks, it looks like something that might need to be there, so that 221 00:12:10,052 --> 00:12:15,362 when you reboot that computer, uh, it, it reinfect, you know, it, um, uh, I maintain 222 00:12:15,362 --> 00:12:17,192 that persistence even after reboot. 223 00:12:17,442 --> 00:12:17,927 I know that 224 00:12:18,062 --> 00:12:18,602 yes, sir. 225 00:12:18,887 --> 00:12:21,347 in the, in the case of the Arc GIS attack, it looks like 226 00:12:21,347 --> 00:12:23,027 they, they modified the actual. 227 00:12:23,867 --> 00:12:25,217 Base software, right. 228 00:12:25,217 --> 00:12:26,537 That, that the tool did. 229 00:12:26,537 --> 00:12:29,867 So that anytime they would reload, they, anytime they reboot the server, they would 230 00:12:29,867 --> 00:12:34,547 restart that software and that would then, um, implement their, their hack, whatever, 231 00:12:34,547 --> 00:12:35,597 whatever it was that they were doing. 232 00:12:35,597 --> 00:12:37,187 And they were in there for two years. 233 00:12:38,237 --> 00:12:41,087 Yeah, there's a lot of trip wires and, and contingencies 234 00:12:41,087 --> 00:12:43,127 that bad guys will, will employ. 235 00:12:43,127 --> 00:12:48,047 And sometimes you don't know what those are, uh, until you, you trip over one. 236 00:12:48,587 --> 00:12:50,837 And so we see this a lot in, in forensics. 237 00:12:51,227 --> 00:12:55,157 Uh, where bad guys have stuff on their computer and it, and it's completely 238 00:12:55,157 --> 00:12:58,577 fine in its current state, but once you, once you reboot the computer 239 00:12:58,577 --> 00:13:03,257 or you start it up in safe mode or whatever it is, uh, their malware is 240 00:13:03,257 --> 00:13:05,327 looking for those types of activities. 241 00:13:05,327 --> 00:13:09,377 And then it triggers some, know, uh, you know, backdoor, 242 00:13:09,377 --> 00:13:10,427 booby, trap, what have you. 243 00:13:10,427 --> 00:13:13,967 And so in, in the case that you had mentioned, what bad guys 244 00:13:13,967 --> 00:13:18,707 did was they, um, they created some persistence by rewriting. 245 00:13:19,397 --> 00:13:22,817 Uh, the operating system on the disc during a reboot. 246 00:13:23,387 --> 00:13:29,357 Uh, so they're in memory, they modify the startup file and, you know, there's 247 00:13:29,747 --> 00:13:35,867 any number of, um, references to startup files, whether it's registry or uh, or 248 00:13:35,867 --> 00:13:37,937 some initialization file, whatever it is. 249 00:13:38,327 --> 00:13:40,757 Um, and so on, on reboot. 250 00:13:40,757 --> 00:13:43,667 It then writes like a ton of things do. 251 00:13:43,667 --> 00:13:47,057 As soon as you tell a machine to shut down, it does nothing but write stuff. 252 00:13:47,822 --> 00:13:48,782 And so it's hiding. 253 00:13:48,782 --> 00:13:52,592 Its its activities in the, in the trash, right? 254 00:13:52,592 --> 00:13:56,972 You kind of like when, when, uh, the Millennium Falcon let go of the destroyer 255 00:13:56,972 --> 00:13:59,792 before they went to Lightspeed, they, they let all their trash go and they 256 00:13:59,792 --> 00:14:01,322 just un docked with all the trash. 257 00:14:01,772 --> 00:14:04,592 Well, very similarly, uh, file this memory. 258 00:14:04,862 --> 00:14:06,677 Bad guys realize what's going on. 259 00:14:06,817 --> 00:14:11,872 And so even, fileless malware resident in memory can force. 260 00:14:12,262 --> 00:14:16,512 An over utilization of resources to make you think, oh, my com my, I bet my 261 00:14:16,512 --> 00:14:18,702 computer will work better after I reboot. 262 00:14:19,092 --> 00:14:23,142 And so the, the malware now goes, all right, I see the, the, the 263 00:14:23,142 --> 00:14:25,032 initialization command for reboot. 264 00:14:25,242 --> 00:14:28,002 I'm gonna start writing stuff to the drive while everything 265 00:14:28,002 --> 00:14:29,922 else is, and when it reboots. 266 00:14:29,922 --> 00:14:33,132 I've actually got stuff now on the drive that can run. 267 00:14:33,477 --> 00:14:35,697 And be more effective than just me in memory. 268 00:14:35,907 --> 00:14:38,907 But at the same time, when it reboots, I'll be back in memory. 269 00:14:38,907 --> 00:14:43,557 Also, one in your case, uh, Curtis, uh, they rewrote the operating 270 00:14:43,557 --> 00:14:47,127 system so that they were like hardcoded embedded in that malware. 271 00:14:47,127 --> 00:14:50,457 You would've had to have completely reformatted and rebuilt that 272 00:14:50,457 --> 00:14:51,927 machine from scratch to get rid of 273 00:14:52,122 --> 00:14:53,682 Yeah, which is what they ended up doing. 274 00:14:53,682 --> 00:14:55,662 They had to like re-image all the systems. 275 00:14:55,662 --> 00:14:56,232 By the way. 276 00:14:56,562 --> 00:15:02,027 Great Star, star Wars reference, uh, bringing Star Wars into, uh, ransomware. 277 00:15:02,772 --> 00:15:06,522 So you're talking about fileless malware. 278 00:15:07,347 --> 00:15:12,957 Does that imply though that it is limited in reach to just a single machine, 279 00:15:13,227 --> 00:15:15,657 that its world is that single machine? 280 00:15:15,927 --> 00:15:20,637 I know you talked about maybe a bad actor might have multiple people go visit the 281 00:15:20,637 --> 00:15:24,687 same website, like the watering hole example, but really kind of like what it's 282 00:15:24,687 --> 00:15:26,757 doing is limited in scope to that machine. 283 00:15:26,757 --> 00:15:29,817 It's not necessarily spreading across to other machines and that sort 284 00:15:29,817 --> 00:15:32,032 of thing, or is that not the case? 285 00:15:33,492 --> 00:15:38,622 Well, truly, uh, memory only resident malware would only affect the machine 286 00:15:38,622 --> 00:15:41,022 that it, that, um, that's hosting it. 287 00:15:41,502 --> 00:15:41,802 Um. 288 00:15:43,977 --> 00:15:46,467 But very rarely does it stay in memory. 289 00:15:46,887 --> 00:15:48,417 Uh, that's just, it's, it's 290 00:15:48,477 --> 00:15:49,797 springboard, it's jumping off 291 00:15:49,797 --> 00:15:50,907 point and that's it. 292 00:15:50,907 --> 00:15:55,557 That's the silent, you know, stealthy phase one recon, um, 293 00:15:55,587 --> 00:15:58,767 foothold, um, part of the attack. 294 00:15:59,127 --> 00:16:02,907 Uh, it can escalate very quickly and, and once it's figured out what it 295 00:16:02,907 --> 00:16:07,167 needs to do next, uh, whether that's infect the rest of this computer or 296 00:16:07,257 --> 00:16:10,922 realizing it has access to a bunch of stuff, which is memory resident. 297 00:16:11,577 --> 00:16:14,097 So when you, when you log into a network and you've got a bunch of 298 00:16:14,097 --> 00:16:17,607 network shares, all that, all those authentication tokens come through memory. 299 00:16:18,162 --> 00:16:18,362 Mm-hmm. 300 00:16:18,477 --> 00:16:21,417 malware can go, oh, I know you've got a C drive, an S drive. 301 00:16:21,417 --> 00:16:23,127 A U drive, right? 302 00:16:23,127 --> 00:16:27,627 And so it realizes all that stuff, and when it's ready, it'll deploy and, 303 00:16:27,627 --> 00:16:31,737 and become more active, uh, across a physical, more of the physical, 304 00:16:32,037 --> 00:16:33,057 uh, parts of the environment. 305 00:16:33,577 --> 00:16:36,582 You, you know, you got, you, you, you put the phrase silent, but 306 00:16:36,582 --> 00:16:38,292 deadly in my, uh, in my brain. 307 00:16:41,052 --> 00:16:43,032 Uh, because inside I'm still five. 308 00:16:43,542 --> 00:16:47,772 Um, all right, let's talk, let's talk a little bit about what we can do and, and 309 00:16:47,862 --> 00:16:54,342 when we were looking at this particular episode, this is why I started, um, saying 310 00:16:54,342 --> 00:16:58,842 that I, I, I think the first one here on our list is one that we talk a lot 311 00:16:59,052 --> 00:17:07,002 about, and that is MFA and specifically, uh, doing, um, phishing resistant, MFA. 312 00:17:07,002 --> 00:17:07,972 Do you wanna talk what that is? 313 00:17:11,137 --> 00:17:11,357 Uh, 314 00:17:14,562 --> 00:17:19,752 well, I have a, I have a, I have an inherent, uh, uh, bias with, 315 00:17:19,752 --> 00:17:22,032 with MFA, not because the, uh. 316 00:17:22,542 --> 00:17:28,092 I think technically MFA is good, um, but realistically it's, it's 317 00:17:28,092 --> 00:17:29,952 rarely implemented effectively. 318 00:17:30,492 --> 00:17:34,692 In other words, you know, a company can turn MFA on, but then they 319 00:17:34,692 --> 00:17:37,452 let people store their passwords and their credentials in the 320 00:17:37,452 --> 00:17:41,022 browser, or let this computer be trusted so I don't have to do MFA. 321 00:17:41,022 --> 00:17:43,782 Again, MFA only works if you do it every 322 00:17:44,112 --> 00:17:44,532 Mm-hmm. 323 00:17:45,162 --> 00:17:47,112 It's only effective if you do it every time. 324 00:17:47,502 --> 00:17:50,697 And bad guys know that we we're lazy, so we'll save stuff. 325 00:17:51,582 --> 00:17:54,852 Well now when malware comes into our environment, one of the first 326 00:17:54,852 --> 00:17:57,972 places it looks is our web cache. 327 00:17:58,632 --> 00:17:59,712 Like what have you stored? 328 00:17:59,892 --> 00:18:03,972 And if I can, and I'm glad you, I'm glad you've developed the, the discipline of 329 00:18:03,972 --> 00:18:06,552 using dedicated browsers for your banking. 330 00:18:07,002 --> 00:18:11,322 Because what bad guys will do is they'll, they'll have an infected website and 331 00:18:11,322 --> 00:18:16,662 just by going there, it harvests all the current session tokens from all 332 00:18:16,662 --> 00:18:18,267 of your other tabs that you have open. 333 00:18:19,467 --> 00:18:23,757 Uh, and so now if, if I can do that and, and and be quick about it, I could 334 00:18:23,757 --> 00:18:27,117 potentially hijack a session you've got open with, you know, Google or your 335 00:18:27,117 --> 00:18:31,737 bank or, um, whatever else, office 365. 336 00:18:32,187 --> 00:18:36,897 Um, if I've got a, an MFA token outta your browser, I can quickly 337 00:18:36,897 --> 00:18:41,277 hijack that session and potentially, you know, uh, authenticate without 338 00:18:41,277 --> 00:18:43,137 any bells and whistles going off. 339 00:18:45,687 --> 00:18:49,917 So are you saying then, Mike, that the best form of security is 340 00:18:49,917 --> 00:18:53,667 to write post-it notes with your passwords and keep 'em on your desk? 341 00:18:56,757 --> 00:19:03,237 No, no, I, I'm saying that you need, you need to find what works for you 342 00:19:03,237 --> 00:19:07,347 from a security perspective that allows you to do whatever that is every time. 343 00:19:08,307 --> 00:19:13,107 You know, we, I was the CIO for a financial institution and we implemented 344 00:19:13,197 --> 00:19:18,297 biometrics and as you use the biometrics, it incorporated both the bios, the 345 00:19:18,297 --> 00:19:20,847 BitLocker encryption, and your office 365. 346 00:19:21,687 --> 00:19:23,847 Well, the workforce would not support that. 347 00:19:24,147 --> 00:19:28,767 They hated biometrics and they, they intentionally made a, 348 00:19:28,767 --> 00:19:30,117 a political issue out of it. 349 00:19:30,117 --> 00:19:33,777 And we had, we ended up having to give the, the executive over 350 00:19:33,777 --> 00:19:36,627 that team the 28 character. 351 00:19:37,257 --> 00:19:43,167 BitLocker key for all those laptops because it didn't fit the culture. 352 00:19:44,247 --> 00:19:49,287 And from a, from an audit compliance governance perspective, you wanna 353 00:19:49,287 --> 00:19:52,347 make sure that the controls that you implement are designed well. 354 00:19:52,407 --> 00:19:54,627 'cause if they're not, people are gonna circumvent them and 355 00:19:54,627 --> 00:19:56,157 they, they're just not effective. 356 00:19:56,607 --> 00:20:00,537 Uh, the, the analogy I use a lot is, uh, Texas a and m University, 357 00:20:00,537 --> 00:20:01,887 whenever they build a new building. 358 00:20:02,202 --> 00:20:04,752 They don't pave the sidewalks, they let people walk through the 359 00:20:04,752 --> 00:20:07,902 grass for a period of time, and that's where they put the sidewalk. 360 00:20:07,902 --> 00:20:09,252 So that's a good control design. 361 00:20:09,822 --> 00:20:14,022 So from a security perspective, whether that's MFA or passwords or whatever 362 00:20:14,022 --> 00:20:18,222 it is, figure out what's gonna work best for you and that, you know, 363 00:20:18,222 --> 00:20:21,642 complies with minimum requirements from an organization or whatever. 364 00:20:23,622 --> 00:20:25,992 Using the same password everywhere is bad. 365 00:20:26,292 --> 00:20:31,152 Um, writing it down's bad, saving, it's bad trusting a computer's bad. 366 00:20:31,152 --> 00:20:35,532 So what is it that I can do that isn't bad that I'm okay doing every time? 367 00:20:37,332 --> 00:20:38,002 You just gotta figure that out. 368 00:20:38,712 --> 00:20:42,792 And so, uh, your, your response, your initial response was interesting. 369 00:20:43,242 --> 00:20:48,252 And so obviously you're not saying MFA bad, you're just saying per perhaps 370 00:20:48,732 --> 00:20:53,922 maybe a lot of implementations of MFA are bad, but also, and I I think you 371 00:20:53,922 --> 00:21:00,342 would agree that, that paske would be better, but MFA it it, but I, I don't 372 00:21:00,342 --> 00:21:03,072 think you're saying don't do MFA. 373 00:21:03,612 --> 00:21:06,462 Uh, like, you know, this is a good, better, best thing, right? 374 00:21:06,462 --> 00:21:08,592 So don't do passwords without MFA. 375 00:21:08,622 --> 00:21:09,732 Please don't do that. 376 00:21:09,912 --> 00:21:10,332 Right? 377 00:21:10,692 --> 00:21:13,152 So if you have to use passwords, you're gonna use MFA. 378 00:21:13,212 --> 00:21:15,762 But what, I don't wanna put words in your mouth, but let me, let me see 379 00:21:15,762 --> 00:21:18,552 if I can tell me if I, if I'm right. 380 00:21:18,582 --> 00:21:21,492 And that is, you know, obviously don't do passwords that matter without 381 00:21:21,522 --> 00:21:26,622 MFA and don't do MFA in a way that, like, I, I liked your, your way of 382 00:21:26,622 --> 00:21:32,082 the, this idea of not allowing people to save those things in a way that. 383 00:21:32,442 --> 00:21:37,872 Would allow that, that session to be hacked, uh, and try to get to a 384 00:21:37,872 --> 00:21:40,002 place where MFA is no longer relevant. 385 00:21:40,002 --> 00:21:43,992 Try to get to a place where we're doing a, a Fido compliant passkey. 386 00:21:44,712 --> 00:21:45,762 How did I do? 387 00:21:47,127 --> 00:21:48,267 I think you did really well. 388 00:21:48,267 --> 00:21:52,797 And one of the things I want to add to that is the, the value of MFA. 389 00:21:52,827 --> 00:21:57,207 I think a lot of people think MFA is just designed to keep bad people out. 390 00:21:58,257 --> 00:22:02,847 MFA is also designed to let you know when bad people are trying to get in, 391 00:22:04,197 --> 00:22:04,677 Mm-hmm. 392 00:22:04,767 --> 00:22:07,197 So you get an email that goes, here's your code. 393 00:22:07,407 --> 00:22:08,847 Like, I didn't ask for a code. 394 00:22:08,937 --> 00:22:10,827 Well, maybe now I need to go change my password. 395 00:22:11,502 --> 00:22:14,472 Because if they were able to get to the code part, they already know my password. 396 00:22:14,952 --> 00:22:15,252 Right. 397 00:22:15,942 --> 00:22:19,932 So it's also an indication that someone other than you might be 398 00:22:19,932 --> 00:22:21,702 trying to access your accounts 399 00:22:22,502 --> 00:22:23,382 I got a request I, 400 00:22:23,502 --> 00:22:24,552 just click accept. 401 00:22:24,627 --> 00:22:26,187 a Venmo code today, by the way. 402 00:22:27,102 --> 00:22:27,702 Oh, right on. 403 00:22:28,512 --> 00:22:32,952 Well, so if you, if you save your MFA, if you trust that machine, 404 00:22:33,042 --> 00:22:37,332 then you won't know when somebody is trying to access your account. 405 00:22:38,262 --> 00:22:39,132 So MFA. 406 00:22:39,792 --> 00:22:40,992 So passwords. 407 00:22:41,952 --> 00:22:44,322 Passwords are just a, a delay. 408 00:22:46,362 --> 00:22:51,792 Bad guys can get your account if it only has a password on it over over time. 409 00:22:52,212 --> 00:22:54,762 You know, it's not today, it's probably not tomorrow, it could be 410 00:22:54,762 --> 00:22:58,722 next year, especially if you use the same password across multiple accounts. 411 00:22:59,742 --> 00:23:02,712 But if you use MFA on top of a password, you're at least 412 00:23:02,712 --> 00:23:04,602 making it more difficult, right? 413 00:23:05,142 --> 00:23:06,822 So in the real world, uh. 414 00:23:07,197 --> 00:23:10,467 Do you just have a lock on your handle or do you also have a deadbolt? 415 00:23:11,787 --> 00:23:17,697 Right, so the multifactor part of that is having more than one thing that 416 00:23:17,937 --> 00:23:22,227 people need to authenticate to an account and the multifactor authentication 417 00:23:22,227 --> 00:23:24,267 part of that would be every time. 418 00:23:24,687 --> 00:23:28,257 So when you leave your house, do you just lock the the handle or do you also 419 00:23:28,257 --> 00:23:29,847 lock the deadbolt every time? 420 00:23:30,507 --> 00:23:31,617 Curtis Locks, neither 421 00:23:33,972 --> 00:23:34,812 Actually, you know what? 422 00:23:34,947 --> 00:23:36,057 doors locked themselves. 423 00:23:36,642 --> 00:23:40,572 you know what I like your, some would say kinetic example. 424 00:23:40,902 --> 00:23:46,692 Um, my new word, by the way, my, I have smart locks. 425 00:23:47,107 --> 00:23:49,177 My smart locks are for me. 426 00:23:49,447 --> 00:23:51,727 And what they do is they lock five minutes. 427 00:23:51,727 --> 00:23:55,147 They lock every five minutes whether I'm inside the house or outside the house. 428 00:23:55,357 --> 00:23:57,817 So if I forget to lock them, they just lock. 429 00:23:58,327 --> 00:24:04,957 Um, anyway, uh, so in interest of time, I wanna move on to this. 430 00:24:05,017 --> 00:24:06,877 Again, this is a maturity level. 431 00:24:07,497 --> 00:24:11,217 One of the, one of the first things, once we get all these base things 432 00:24:11,217 --> 00:24:15,387 outta the way, it's time to tar start talking about EDR or XDR. 433 00:24:15,867 --> 00:24:19,017 Do you want to talk about what that is and why? 434 00:24:19,017 --> 00:24:21,867 Why I might wanna put it in and the kinds of things I might want 435 00:24:21,867 --> 00:24:23,007 to think about if I'm doing that, 436 00:24:25,002 --> 00:24:30,042 So EDR today is an evolution of just, you know, our old antivirus, anti-malware. 437 00:24:30,612 --> 00:24:32,292 Um, and it's designed to. 438 00:24:32,322 --> 00:24:33,837 by the way, uh, endpoint 439 00:24:33,887 --> 00:24:34,877 endpoint detection 440 00:24:34,877 --> 00:24:35,567 response. 441 00:24:38,057 --> 00:24:42,887 So anti-malware historically is really good at saying that that looks bad 442 00:24:42,887 --> 00:24:44,117 and I'm not gonna let it do anything. 443 00:24:44,117 --> 00:24:48,317 So we just quarantine it and then you would have to go into the console and 444 00:24:48,317 --> 00:24:51,947 look at all the stuff that's quarantined and decide, uh, I, I need that, or 445 00:24:51,947 --> 00:24:55,577 I don't, uh, you know, delete it or make sure this doesn't happen again. 446 00:24:56,747 --> 00:25:01,832 And that was typically on a. On one machine to one machine basis. 447 00:25:01,832 --> 00:25:05,912 And then over time, they figured out a way to network all that together so 448 00:25:05,912 --> 00:25:10,352 that the people in it or the people that care can log into just one screen 449 00:25:10,352 --> 00:25:15,242 and see everybody's, uh, you know, the status of everybody's, uh, antivirus, 450 00:25:15,242 --> 00:25:21,392 anti malware, uh, but very rarely was it capable of, of taking action on its own. 451 00:25:21,572 --> 00:25:21,872 Right? 452 00:25:21,872 --> 00:25:26,132 So, aside from quarantining, it didn't rewrite rules or policy, 453 00:25:26,522 --> 00:25:27,467 uh, it didn't think ahead. 454 00:25:28,322 --> 00:25:32,402 Uh, it didn't correlate events across different devices to say, well, I think 455 00:25:32,402 --> 00:25:35,912 it started on Bob's computer and then it ended up on Sally's computer and, 456 00:25:36,392 --> 00:25:39,362 you know, it changed something, but I think it's the same attack and it 457 00:25:39,362 --> 00:25:43,082 came from the same place and just not very good analytics and correlation. 458 00:25:43,082 --> 00:25:44,942 So EDR is an evolution of that. 459 00:25:45,632 --> 00:25:51,062 Uh, so with EDR and especially some of the newer ones that have some AI 460 00:25:51,062 --> 00:25:54,272 embedded in it, uh, it can take, um. 461 00:25:55,352 --> 00:25:57,992 You know, informed or intelligent action. 462 00:25:58,442 --> 00:26:02,312 Uh, so in addition to saying, you know, user on this computer did something 463 00:26:02,312 --> 00:26:07,262 stupid or something weird got installed and it's doing something stupid, so 464 00:26:07,262 --> 00:26:11,132 now I can con, I can quarantine or isolate the device, the whole device 465 00:26:11,132 --> 00:26:16,682 from the network or just the file or just its activity or just the user. 466 00:26:17,222 --> 00:26:18,537 And if I've got it configured right. 467 00:26:19,187 --> 00:26:21,077 And I think the user's compromised. 468 00:26:21,137 --> 00:26:25,187 My EDR can now reach out to active directory on my network and suspend 469 00:26:25,187 --> 00:26:29,087 that user account from doing anything anywhere else in my environment. 470 00:26:29,357 --> 00:26:34,907 So whether that's Office 365 or uh, remote access, or whatever the case may be. 471 00:26:35,567 --> 00:26:37,637 And then the other important part about 472 00:26:39,677 --> 00:26:43,787 uh, EDR tools today is their ability to integrate into much broader 473 00:26:43,787 --> 00:26:46,187 cybersecurity tools like XDR. 474 00:26:46,607 --> 00:26:48,767 So extended detection response. 475 00:26:49,172 --> 00:26:55,022 Is XDR and so on the ED on the EDR level, I can only see what's going 476 00:26:55,022 --> 00:26:56,822 on on my computers and my servers. 477 00:26:56,822 --> 00:26:59,462 So I don't see network traffic, I don't see firewall, I don't 478 00:26:59,462 --> 00:27:00,662 see anything in the cloud. 479 00:27:01,742 --> 00:27:07,772 So you need an XDR tool that collects what we would consult the anything on the 480 00:27:07,772 --> 00:27:13,262 inside of a network we call, uh, east West traffic and anything coming in and out of 481 00:27:13,262 --> 00:27:15,242 the network we call North South traffic. 482 00:27:15,962 --> 00:27:20,912 So EDR is good at East, west XDR on its own is good. 483 00:27:20,912 --> 00:27:24,332 At north South, you really need both to get the whole north, south, 484 00:27:24,332 --> 00:27:26,162 north, south, east, west traffic. 485 00:27:26,432 --> 00:27:29,582 So you've got a better picture of what came in your environment, what's going 486 00:27:29,582 --> 00:27:33,632 out of your environment, what's happening inside your environment, and with those 487 00:27:33,632 --> 00:27:37,952 tools collectively now, if an endpoint gets compromised inside your network. 488 00:27:38,477 --> 00:27:40,247 I can look in, I can look at the firewall. 489 00:27:40,247 --> 00:27:40,787 Where'd it go? 490 00:27:40,787 --> 00:27:42,407 Where's it, who's it talking to? 491 00:27:42,677 --> 00:27:44,177 Can I block that IP address? 492 00:27:44,177 --> 00:27:45,647 Can I write rules on the firewall? 493 00:27:45,647 --> 00:27:46,967 Can I isolate the machine? 494 00:27:46,967 --> 00:27:48,287 Can I suspend the user? 495 00:27:48,617 --> 00:27:52,697 Can I look across the entire environment and all my email and all the attachments 496 00:27:52,697 --> 00:27:56,447 and figure out what's going on here and how can I prevent this from spreading? 497 00:27:56,867 --> 00:28:01,397 It's, it's a pretty huge, uh, capability, um, uh, with the 498 00:28:01,397 --> 00:28:02,657 tools that are out there today. 499 00:28:03,932 --> 00:28:05,942 And that would also cover fileless malware. 500 00:28:06,932 --> 00:28:09,722 It would, so it's, uh, more recent EDR tools. 501 00:28:09,722 --> 00:28:11,402 Look at memory resident. 502 00:28:11,402 --> 00:28:13,352 And so there's agents on each computer. 503 00:28:13,802 --> 00:28:15,722 Uh, we use Huntress as an example. 504 00:28:16,172 --> 00:28:18,572 Uh, and Huntress is amazing at doing. 505 00:28:19,442 --> 00:28:23,342 Uh, volatile memory analysis, uh, behavior analysis. 506 00:28:23,732 --> 00:28:25,592 Um, it sandboxes things. 507 00:28:25,592 --> 00:28:29,462 So the, for the couple of microseconds after you install something, it goes, 508 00:28:29,462 --> 00:28:30,752 lemme see how you're gonna behave. 509 00:28:31,622 --> 00:28:35,702 even though some malware today will behave nicely at first, um, it 510 00:28:35,702 --> 00:28:37,352 continues to do a pretty good job. 511 00:28:37,352 --> 00:28:40,412 And then it's integration with all these other tools as far 512 00:28:40,412 --> 00:28:43,772 as the ability to respond and remediates, uh, pretty impressive. 513 00:28:44,387 --> 00:28:48,407 Yeah, I, you know, when I was, um, hang on, I went the wrong way. 514 00:28:49,637 --> 00:28:51,107 I was getting ready for the book. 515 00:28:51,887 --> 00:28:55,217 I got this little thing right. 516 00:28:56,117 --> 00:28:56,297 I'm, 517 00:28:56,867 --> 00:28:59,042 What is it, say Curtis, or people who are 518 00:28:59,087 --> 00:29:00,317 a afternoon read. 519 00:29:00,437 --> 00:29:01,277 As you can see, 520 00:29:01,412 --> 00:29:03,062 The heart of memory forensics. 521 00:29:03,152 --> 00:29:03,302 Yep. 522 00:29:03,617 --> 00:29:07,757 it's a. It's, it's 800 pages, I'm just saying. 523 00:29:08,267 --> 00:29:12,707 Anyway, uh, yeah, memory forensics, you know, definitely an advanced topic. 524 00:29:12,707 --> 00:29:14,957 I like this idea of, of having a tool that can. 525 00:29:15,497 --> 00:29:17,567 They can do, uh, some of that work for you. 526 00:29:18,077 --> 00:29:22,787 Um, all right, so the, I I like the idea, you know, we talked once again reiterated 527 00:29:22,787 --> 00:29:29,357 the idea of putting more barriers in the way of, um, if someone steals your 528 00:29:29,357 --> 00:29:33,617 credentials, more barriers in the way of, of them being able to use those. 529 00:29:34,037 --> 00:29:35,207 I like this idea. 530 00:29:35,237 --> 00:29:39,647 Uh, again, you, you, you, you said more than once, you said this idea of 531 00:29:40,427 --> 00:29:43,367 not saving the things that you know. 532 00:29:43,672 --> 00:29:48,082 You know, and, and you shouldn't do it as a person, but it sounds like in a, in 533 00:29:48,082 --> 00:29:51,112 a corporate environment, you should be setting up so that they're not able to 534 00:29:51,112 --> 00:29:53,002 save that for the credentials that matter. 535 00:29:53,662 --> 00:29:54,232 Uh 536 00:29:54,272 --> 00:29:56,537 Yeah, don't, don't put the key under the rock by the front door. 537 00:29:58,072 --> 00:29:58,552 oh. 538 00:29:58,552 --> 00:29:58,942 Okay. 539 00:29:59,002 --> 00:29:59,902 Do people still do that? 540 00:29:59,962 --> 00:30:00,802 Hang on, I'll be right back. 541 00:30:01,487 --> 00:30:02,162 All right. 542 00:30:02,162 --> 00:30:03,092 Well, thank you. 543 00:30:03,122 --> 00:30:03,962 Thank you, Mike. 544 00:30:04,052 --> 00:30:07,772 Uh, like I said, I, I definitely felt like the dumb guy in the room in this one, 545 00:30:07,772 --> 00:30:10,562 but, um, uh, I think the, I think the. 546 00:30:11,067 --> 00:30:15,057 The recommendations at the end will work for pretty much a, a lot of 547 00:30:15,117 --> 00:30:16,437 these things that we talk about. 548 00:30:16,497 --> 00:30:20,217 Um, you know, uh, put those barriers in, in the way. 549 00:30:20,517 --> 00:30:26,157 And, um, and then also when you get to that, when you get, when you're 550 00:30:26,157 --> 00:30:29,697 ready to take things to the next step, it's time for an E-D-R-X-D-R tool. 551 00:30:30,807 --> 00:30:31,257 All right. 552 00:30:31,407 --> 00:30:32,397 Thank you very much, Mike. 553 00:30:33,657 --> 00:30:34,227 Anytime. 554 00:30:34,317 --> 00:30:34,647 right. 555 00:30:34,647 --> 00:30:35,477 And thanks, Prasanna. 556 00:30:35,547 --> 00:30:36,087 How you doing? 557 00:30:38,712 --> 00:30:39,252 Hello. 558 00:30:39,432 --> 00:30:41,562 All right, everyone. 559 00:30:41,562 --> 00:30:42,402 Thanks for listening. 560 00:30:42,552 --> 00:30:43,662 That is a wrap.