Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 91 for the week of, uh, November 5th. Alex Wood, who are you?
Who am I? Uh, I'm a— I'm just a wonderful person. Rob Rack, who are you? Well, I am, uh, I'm also a, uh, not as wonderful, but I'm an okay person. Where I heard some people recently who've been started listening to the show who don't necessarily know who we are and what we do, so I thought we could just take like 10 seconds.
Um, I am, uh, you know, my day job, I'm the CISO for Ping Identity, a security company here in town. And, uh, previous to doing this stuff, did the ISSA Denver board and get involved with some stuff in the area. What about you, Alex? For my day job, I am the CISO for a company called Pulte Financial Services. I also have been highly involved with ISSA, just finished a term on the ISSA International Board, and I'm also a co-host of Colorado's Best Security Podcast.
Absolutely. Suck it, Douglas. That's right. All right. Before we jump over to the news of the day, we have a few housekeeping type things to talk about.
We do have a Slack channel. We talked about this last week. Slack is the new way to chat and stay on top of stuff. There's over 600 people in the security community who are a part of this Slack channel. It's a good way for you to get to know peers and ask questions about what's going on in the local area.
You can get the link to join the Slack channel by going to colorado-security.com and clicking on the Slack channel button there. We also have a mailing list. So if you want to be kept up to date on the show notes and when the new podcasts are released, please join that mailing list. For those of you that are already on the mailing list, you probably got an email from me yesterday noting that we are moving that over to a MailChimp mailing list. We're growing up.
We're, we're doing things real. It's not just pasting into, into our webmail anymore, Robb. I've previously been using Google Sheets and copy-pasting the emails in every week, so this is a— we're moving on up. Next, we would— if you like the show, we'd love it if you would rate us out on iTunes or your favorite podcast player and let other folks know about the show. If you let your coworkers know, let, you know, your friends, anyone you run into know about the show, we would appreciate it.
It's a good way for us to grow and extend the reach of what we do. Yeah, and of course, along with that, subscribe, right? So you're welcome to also go to our SoundCloud page and go listen there directly, but if you subscribe through iTunes or Google Play, you'll get this every week automatically in your favorite podcast player. And then finally, if you really, really like the show and want to help us financially, we do have a Patreon campaign going. You can become a patron, help us cover the costs for the, the show.
And all that Patreon money only goes to supporting the show. Nothing goes into our own pockets. We're putting it all right back out into the community. You might pay for some stickers or whatever for the show, but, you know, everything goes right back into what we do for this. Speaking of the Patreon campaign, we have a new patron this week.
A big thanks to Jeremiah Cruitt. Jeremiah is a friend of ours, and he's now the CISO over at ThreatX, a local company, but he's personally sponsoring the show. And Jeremiah, thank you so much for doing that. Yeah, thanks, it means a lot. Uh, first on the list for news today, um, you know, we've come in behind Seattle in a list, but I think that's okay.
Seattle has dethroned Denver as the worst city to find love. Well, this is, uh, this is news from last year. We talked about where Denver was number 1. Good news is we're not number 1 anymore. We're now the 4th worst city to find love.
The criteria they used is enthusiasm about dating, opportunities for dating, frequency of dates, and dates turning into relationships. Yes, and there were some interesting quotes in the article.
One, they were talking about how Denver is sad because it's like wasted talent. There are lots of eligible people here But it's sort of like a middle school dance, you know, a bunch of women standing around talking to each other and the guys kind of off in the corner drinking their beers and stroking their beards. Pushing each other towards the women and trying to make introductions. No, go, you go talk to them. We did get to be at the top of the list for one thing.
Our men are the most passive men in America. Congratulations, guys. Step forward to collect your award. Just kidding. I know you won't do that.
Rounding out the top 5, there was obviously, we said Seattle, San Jose, California, Phoenix, And Portland, Portland, Oregon. Yes, good stuff. Next story, Amazon has opened their second ever 4-star store at Park Meadows. So this is the store that only sells items that are rated 4 stars or better on the Amazon website. And at the front when you walk in the store, they'll have things that are on the most people's wish list on the kiosks right by the front door.
Kind of a cool idea, right? The cyber world coming into reality there? It is like Amazon in real life. I would say that the primary reason I go to Amazon is because I hate going to Park Meadows Mall. So this is not really speaking to me personally, but it's a cool idea.
Yeah, I know Amazon is trying to take over the world and retail, actual in-store brick-and-mortar retail is one of those few areas that they have not yet taken over. So why not do that too? Yeah, well, good for that. And of course, for those of you who go to the Amazon store, let me know how it is. I'd love to hear about it.
Tweet to us. Next, PopSockets, the local company who has grown by— what was it, like 50,000% or whatever over the last 3 years? They just solved the biggest technical problem they had. They can now allow wireless charging with a phone that has a PopSocket on it. Oh, I was gonna say the biggest problem that they had was not making it annoying to have those things on the back of your phone.
Yeah, I have never actually had one because The cases I've used haven't worked great with it, but I do think this is a nice step in the right direction, right? You can have a PopSocket and you can wirelessly charge your phone. That's something. Yeah, it sounds like from the story you can pull part of the PopSocket off that has the design on it. It used to be that, you know, if you wanted to change the design, you had to replace the entire PopSocket.
You know, there was a sticky piece that stuck on your phone, but now you can take the design off. That also allows the phone to get close enough to the wireless charger so that you can charge the phone. So basically you don't have to destroy the adhesive in order to charge. Exactly. Good stuff.
Also, another story here, the popular studying platform Quizlet has expanded to Denver and could hire as many as 300 people. So Quizlet is a startup that is doing flashcards essentially. They're a learning platform. I read in the article that it was started by a high school student who wanted a place to to be able to study and have flashcards. And, um, they moved from— well, not move, they've added their office here in addition to their headquarters in San Francisco.
So it's kind of interesting because the headline talks about 300 people, but as of today it looks like maybe they have 2 people in Denver. They've recently hired a director of engineering and a full-stack developer. They plan to get up to about 25 people sometime next year in that office. So while we're, we're talking about 200 to 300 people in the longer term. In the next year or so, we should see a pretty small growth here.
Yeah, it also sounds like they don't actually have an office yet, that they are working out of a coworking space until they get out of that, uh, that boat of 2 people and need a full office for people. So does this press release or news article, whatever, does this tell us that we've officially reached the top of the talent bubble when this is an announcement? Right. Hey, uh, we've sent some people to your city. They're gonna be working in a coworking space.
There's 2 of them, and we think we're gonna get 300 of them. We don't know when, we don't know how. Yeah, yeah, beautiful. All right, well, invest all your money in the stock market, everybody. Uh, next, the election integrity has been in the news a lot, uh, especially electronic voting machines and other things like that.
There was a Colorado Sun article this week, uh, talking about election integrity, electronic voting machines, and the Denver tie here is that one of the 3, um, basically 3 only companies to make those voting machines is based here in Denver. And they have all of their security figured out. Is that where we are? I think so. Good.
We're done. Good, I'm glad we can move on from that. Well, we do know that our Secretary of State is the best for election security. Alex, we were just talking right before we hit record that I found out and shared with you that there's a website you can go to to see whether they've received your ballot yet. It's something like Go Vote Colorado, and you can go see, you know, you mailed it in or you dropped it off, that my county has now received it, I'm gonna be counted It's pretty cool.
That is pretty cool. Don't have to worry about it getting lost in the mail or stolen. Also, as this episode will be released right before voting day, if you have not done your mail-in ballot and are going to vote in person, please go vote on voting day. Also, you need to make sure that if you are going to be voting by mail, that you have your vote received by the end of voting day, I believe, or you have to turn it into a physical voting box. I think you need to— at this point, you should not drop it in the mail.
You need to go drop it into one of those boxes somewhere. Next, speaking of government security, there's an article here about the Colorado IT, the Office of IT and the CDOT attack that happened recently with an interview with our CTO. Yeah, so I think we've talked about this before on the show that CDOT had a big ransomware attack and then actually I think a subsequent ransomware attack a little while back. Uh, but this is just them talking about, uh, some of the steps that they have taken to try and make sure that we are remaining secure. Um, so this is David McCurdy, the CTO of the state of Colorado, and he was given an interview, um, at a conference he was attending.
Pretty good stuff. He also makes a shout out for our own Debbi Blyth, the CISO for the state of Colorado. So good to see those guys working together and investing to help keep all of our data safe. For sure. LogRhythm had a press release this week announcing the new version of their software.
A couple big things that they announced: one, they have some integrated playbooks into their SIEM, so you can now take standardized steps as you're investigating incidents that are discovered through LogRhythm. Also some additional automations and actions, you know, moving more towards the built-in SOAR platform as well in LogRhythm. Um, and then, uh, SOC metrics as well. Oh yes, metrics. Yeah, that was the thing.
So it looks like you can basically get your mean time to remediation, mean time to, uh, response. Good stuff for, for that. Yeah, pretty cool, all built into the platform itself. Awesome. Uh, so next we have a story here from Secure64.
They are the DNS provider up in, uh, Fort Collins, I think, right? Um, and they basically have upgraded their own hardware to be, you know, more secure in providing a an enterprise-quality DNS provider that has security built in. You know any details on that? Yeah, it sounded like they were just making the attack surface on their platform a little smaller as well, removing some stuff that didn't need to be— didn't need to be there. Also making it easier for updates, so managing their platform in an easier way.
Quite a few press releases this week from local security companies. We also got one from Coalfire. They have promoted Dixon Wright to be their VP over all of their ISO and SOC services. He previously worked internally, but this is a step up for him and a larger scope of responsibility. Congratulations to Dixon Wright.
Also, Webroot released their Cyberattack Malware— Worst Cyberattack Malware of 2018 report. A few things listed in there. They have some top lists on the different categories of malware and which ones were the worst. So worst botnets and banking Trojans. The nastiest, Emotet.
Of course, we all, we all hate Emotet. Yeah. TrickBot and Zeus Panda made the top list for those. For crypto mining and crypto jacking, Ghostminer, WannaMines, and CoinHive made the top 3. And the 3 nastiest ransomware: Crysis/Dharma, GandCrab, and SamSam.
I don't know how SamSam didn't make number 1 on that list because that's the one that I seem to hear about the most. That's the one that gets the most buzz because, you know, they got all those government organizations. Final piece of news this week, we have a blog post from Jeremiah Crew. We talked about Jeremiah earlier. He is the new CISO at ThreatX.
He has a blog post talking about what the new age of web applications means for security. And what does that mean? Basically, you know, all of the applications are moving us to the cloud— excuse me, moving us to the web, and security has to happen more at the web layer. We have to have more visibility and intelligence built in from a security perspective there rather than trying to do it at a network level or even at a system level. Perfect.
Thanks, Jeremiah. Good plug. Good stuff. And, uh, moving over, that is the news for the week. Next, we have a Slack message of the week.
So as a reminder, each week, uh, Andre Gaeta, who is the kind of one of our patrons for the show, uh, helps us recognize one of the folks who has a good comment in the Slack channel. Basically, if you said something interesting out there, we want to call it out, kind of drive some more traffic and more conversation there. Yeah, and one of the big pieces of conversation this past week was about IBM acquiring Red Hat and $34 billion. Billion with a B, everybody. Big, big, big number.
Yeah. Uh, and so this week's winner was James Carder who said, this just in, IBM rebrands Red Hat to OS/3. That was— that made me laugh. Maybe not the most insightful, but definitely the funniest comment of the week. So for those of you youngsters out there, IBM had an operating system called OS/2.
Yeah, so James will get to pick some swag from the Colorado Equal Security store, and if you want to be the winner next week, go say something funny in one of the public Slack channels, or maybe insightful or useful or otherwise. All right, moving over to our events. As a reminder, we do have an event page— a calendar rather— on our website at colorado-security.com. You can see all the stuff coming up for the next few months. Um, there's a, there's a brand new series of events that start on the 5th, on Monday here.
Uh, SecureSet is doing their Denver WarGames series, and this is basically a kind of a half teaching, half hands-on lab that they're doing for the next, I think it's like next 3 weeks, 8 different sessions where you can get out there and really get hands-on technology and learn how to get into security. So if you know someone who's, you know, maybe technical but not into security, or really wants to figure out if security is for them, I think recommending that they go to these war games is a good start. Hello, Robb, do you want to play a game? Good one. Your voice is almost exactly like a— like the robot.
Yeah. Uh, so the first one is on Monday the 5th, and that's the kickoff, basically talking about the series. And then from then, they're gonna have a bunch more over the next few weeks. On the 7th, CTA is hosting their annual Apex Awards. Again, the CISO of the Year Award will be given out at that banquet.
Robb Reck, James Carder, and Debbi Blyth are the finalists. Should be fun. Also on the 7th, ISSA Denver is doing their Women in Security meeting. On the 8th, CSA is doing their Colorado Fall Summit. On the 12th, SecureSet has their War Games Intro to Strategy and GRC.
On the 13th, CTA is doing an event called Craft Your Career Path featuring General Assembly. On, uh, the 13th and 14th, we have ISSA Denver's November meetings. As a reminder, on the 13th, that means there'll be lunch in Boulder. Tuesday the 13th, there'll be dinner in downtown Denver. And then Wednesday the 14th, it'll be lunch in the DTC.
In case you don't want to do ISSA in Denver, ISSA Colorado Springs is also doing their November chapter meetings on the 13th and 14th. They have a similar setup. There are lunch and dinner type meetings. Yep. On the 14th, SecureSet has their War Games with Applied Cryptography.
If you want to learn how to do cryptography and apply it, this is the meeting for you. On the 15th, ISACA Denver is doing their November chapter meeting. Also on the 15th, ISC² is doing their November meeting. And finally, Colorado Springs ISSA is doing one of their mini seminars on the 17th of November. That's— that is the last for the next 2 weeks, but I want to call out a new meeting that was just posted this morning.
Um, ISSA and ISACA posted their joint December meeting. This is always one of the really fun social events and, and programs in the area each year. This, this year looks maybe even more fun. It's going to be on December 10th from 2 PM to 6 PM at the Soil Dove Underground. Wow, kind of a fun venue, right?
Yeah, they've done comedy works a couple years and they're, they're moving on. I assume that there'll be someone singing some really good music. It's not you, Robb. I thought they signed you up to sing. I'm not making any announcements at this point.
Their number one keynote speaker is Tim Prendergast, who is the Chief Cloud Officer for Palo Alto Networks. Wow. You do get 2 CPEs for showing up. There's giveaways, there's drinks, there's food. Good time to come.
And you get to hear Robb sing. And it's possible that you could hear somebody sing at the Soiled Dove. Yeah. Sweet. I think that's, that's it for events here, right?
Yeah, so let's move over to jobs. First job on the list I will give it back to you, Robb. Yeah, why don't you let me go ahead and take this one. Uh, Ping Identity, we're hiring a GRC analyst focused on business continuity and incident response. So this is someone who's going to be really kind of getting their arms around and helping us manage both our business continuity and IR programs, doing testing, doing follow-up on those incidents.
Looking for someone who has some programmatic experience and wants to help Ping excel. A second position I'm hiring at Ping is a security program business analyst. This is someone who's going to help us really run the security program, work directly for me, work with me day-to-day on all of the things we're managing, do our metrics, do our financial reporting, all the stuff we do programmatically, you know, really have their hands into the day-to-day stuff. So if you can tolerate working directly for Robb, apply for that job. And there is free beer, so it helps with tolerance.
That does help. Next, Accudyne Industries is looking for a global IT security and compliance manager. Is that the company where you're going to help design the Terminator? Is that— I don't think you're allowed to talk about that. Oh, sorry.
Yeah. The State of Colorado Department of Revenue is hiring a Director of Security and Investigations focused on the lottery. Yeah, this one sounded really cool. So you get to help investigate and secure the lottery systems. I assume that this person gets to take some of the lottery winnings and just leave with it.
Is that how this works? Well, clearly you're an insider, so you can do whatever you'd like. I don't know how they'd be able to stop you. Indianapolis Power and Light is looking for a manager of vulnerability management. Whoa, whoa, whoa, this is Colorado equals security here.
What's happening? Colorado equals security. If you look at the job, Robb, you could be in Indianapolis, you can be in Boulder, or you can be in one of several other places too. I'm sorry, I shouldn't have cut you off. They seem to be fairly broad in where you can work for the Indianapolis Power and Light Group.
Sorry, what are they hiring again? Manager of vulnerability management. All right. Sorry about cutting you off there. I just couldn't believe you were going to talk about an Indianapolis job on the Colorado Legal Security Show.
Spectrum is hiring a supervisor of network security operations. Datavail is hiring a director of strategic alliances. So not necessarily security in and of itself, but works really closely with different security aspects there. It looks like a really fun job too. Western Union is hiring a senior information security analyst.
Aetna is hiring an information security third-party risk assessor. All right, and then finally Prologis is hiring a security engineer. We actually talked about this job a little while ago, but it's still open. It is an AppSec-focused engineering position working for, you know, one of the bigger companies here in town. Awesome.
And that takes us to the end of jobs. All right, so our feature interview this week, you sat down with Greg Foss, who is the senior manager of threat research at LogRhythm, I think. Something close to that. And we were gonna run the show next week, but then we realized Greg just announced He's moving on from LogRhythm, but we got to get this in now before it's out of date. That's right.
So it was a good interview with Greg. I sat down at their annual user conference, Rhythm World, here in Denver. We talked about stuff that he'd been doing at LogRhythm and other stuff that Greg is up to. Well, we look forward to hearing, number one, this interview, and then we'll hear what he does at his new gig when he gets there. Exactly.
Awesome. Well, thanks, Alex. We'll talk to you again next week. Thanks, Robb. Hey, this is James Carder, CISO at LogRhythm.
This is Colorado Equals Security. Security for Colorado security professionals by Colorado security professionals.
Welcome to Colorado Equal Security. This is Alex Wood, and we have a special guest today recording live from Rhythm World 2018. I have Greg Foss of LogRhythm here. Hey, Greg. Hey, thanks for having me, Alex.
You're welcome. You are a I'll call you a known commodity in the local Colorado security scene here, Greg. And, you know, you— I think, well, even nationally, you know, you've been on, you know, Paul's Security Weekly and other things like that. So I'm sure that there's lots of people that know you. But for those that don't, maybe we can start out by giving a little bit of history of where you've been and things that you've done, how you got to being where you are today at LogRhythm.
Oh, sure. Well, Well, thanks, you're too kind. Maybe infamous might be a good word, I don't know. But yeah, so I've been in InfoSec for quite some time now professionally, a little over 10 years. Just started out as a web developer, building sites based off of content management frameworks and stuff like that back into— through college.
And out a little bit after college. And going from there into kind of the real world, starting to realize how bad my code was and some of these other kind of scary things that we're putting out there. And from there, I got into web application security, fortunately working for the Department of Energy, working in one of the national labs where we actually had a very massive web development program there. They hosted everything on renewable energy servers, which was kind of cool. So that's why DOE wanted to kind of host everything with us.
And so one of the aspects of that was building up an application security program to adequately protect all of these assets, you know, do full source code security up through the development lifecycle, and then monitoring and maintaining them afterwards. And that was kind of where I really got into security initially, was kind of that web application hacking and defense kind of thing. And then now I'm fortunate enough to work at LogRhythm. Where I get to run the threat research team. And so it was kind of funny, I started out on the threat research side and went over to build up our internal security program here, which has been fun.
It's been a different challenge trying to build a security program for a security company, much different than some of the previous places I've been. And so with that, now I think we have kind of a mature program and we've expanded it out quite a bit. So now moving back into the threat research side, It's been a fun ride for sure. And so that's a pretty new thing for you, moving back into the threat research side. Yeah.
Was that because that was an interest to you? You wanted to do something different? You know, just sort of situational? How'd that come about? Yeah, so that was something where I— the reason I came to LogRhythm was to do threat research.
And, you know, the security aspect, building that out, kind of came out of as a commodity for, hey, you know, we kind of are doing this sort of, but we need to build a full program. We need to actually expand this out and do this in a way that we can be the example for our customers. And so part of that, it all kind of feeds back into the threat research side a little bit. But for me, the operations is fun and all, but I definitely wanted to get back into threat and really have more open kind of freedom to explore a lot of the possibilities for new attacks and defense and just kind of dive into that whole side of things. Yeah, so you mentioned a bit ago that it was interesting, maybe even a bit of a challenge for you developing a security program at a security company.
What were some of the interesting things that you saw during that or learnings or challenges? Oh yeah, yeah, definitely. I mean, and one of the real cool things is we have so much support in our whole company for the security program, for doing kind of the right thing. So that was really helpful because they really wanted us to build this up and be kind of that example. And so part of that, some of the challenges we ran into are just getting coverage on everything, separating development assets from corporate assets.
That was a big one right there because we're testing a lot of things like exploits and attack and defense kind of stuff, so we have to have that logically and physically separated from our actual corporate assets where, you know, we have customer data, you know, in our cloud environments and things like that. So having that separation and ability to monitor both effectively but differentiate, you know, what's an actual concern and what's not, that was kind of one of the biggest challenges was getting that kind of architecture developed at first. And then now our big challenge is moving fully to cloud, trying to push towards a zero-trust model where we're actually trying to base everything fully based on your identity. So who you are, what permissions you have, where you are within the company, what you're supposed to touch, all those kind of things. And that being the full governing aspect of what you can actually do within the company, whether inside the company through the VPN or on any of the diverse kind of cloud assets that we have.
Yeah, that's pretty cool. You know, you hear a lot about Zero Trust in the industry today, but you hear more either vendors talking about how it's cool or, you know, product companies pushing their products for zero trust, but less in terms of the people that have actually gone through it and implemented it. So what, in terms of implementing zero trust, how far down the road are you guys in that? And then what was the hardest thing in that model, and/or what would you recommend people do? Yeah, yeah.
And so for us, you know, I'd say we're about halfway through our whole process to get to a full Zero Trust model. The hardest parts are going to be just changing behavior and getting people out of habits that, you know, where they're used to logging into things in a certain way or used to using certain tools where depending on what technologies you implement for Zero Trust, that could change that. Like for us, we did a big push with Okta, and so we have so many cloud assets that we decided to use Okta to help secure those. Which I'm actually a big fan of Okta. I thought it went really well.
We have some cool SIEM integrations there, and we have the ability now to control a lot of access to different systems using the SIEM, which is something that's kind of new that we haven't seen really other people doing. So based on the log data we see from Okta, we can determine if maybe someone's session was hijacked or there's an attack going on or someone's credentials have been exposed. And we can dynamically clear all the user sessions across all these remote assets in seconds. And then we can lock users out, we can do all sorts of things like that just from within the SIEM. And so that move to Okta was probably one of our biggest changes, and that was one that had the most user impact because it changed how people were logging in.
But at the end of the day, once people started using it, they found it was actually much easier. And on top of that, having that additional layer of security. And so do you feel like you have, um, since you're halfway, uh, do you feel like time-wise you're halfway? Or did you guys— were you able to get a lot of the easy stuff first and now you're gonna have like, you know, the weird— I mean, even though you guys are a startup, you know, weird sort of legacy stuff that it's gonna be harder to make in that. And it's, you know, you got half of it left to go, but maybe, you know, more time than just half of Yeah, and that's a good question because it's hard to quantify in time because, you know, we won't really know until we start going down the path to really implement some of this stuff.
But I think in terms of the controls we put in place, you know, we have our UEBA solution where we're looking deep at the user accounts and then, you know, having that automation aspect on top of it, which that opens up a lot of possibility for us in general. And then adding Okta to it, that really helped out as well with just controlling and governing that access, all kind of centered around using that within the SIEM so our SOC analysts can go out and perform these actions real dynamically. And so, you know, other things that we do still need to implement are like full NAC, you know, a CASB solution. We have kind of a CASB lite right now where we're looking at, you know, what's uploaded and downloaded, what's being shared from our public storage like Box and Office 365 and those kind of items. But we still want to have more access into tagging these documents, marking things as classified, unclassified, things like that.
And then doing kind of web bugging sort of things where you can see where things go. We've done that in kind of hacky ways up to this point for real sensitive stuff. But in general, we want to get a full CASB and go that route. And then kind of really have our full stack kind of laid out where we can actually implement everything and audit it all with the SIEM.
So it should be fun. Yeah. So are you still gonna get to play with that stuff even though you're now moving over to a threat research role? Yeah, and that's kind of the nice part about it. I get to play in both sides of it.
Like the threat research team, we still fully support the SOC, so anything that comes in that's really weird or interesting or something where we could develop content in the SIEM. You know, that's something where we always take a look at that. You know, we also augment the staff over there, so when, you know, there are people out and stuff like that, threat research guys fill in for the SOC. And so we use a lot of our own internal datasets to generate a lot of the content that you end up seeing in the SIEM. And also, you know, once we make this move to the LogRhythm Cloud, that's something where we'll actually be able to open up that door to here's what we're seeing across all of these different diverse deployments with different customer bases and different industry verticals, which then we'll be able to custom tailor a lot more content specifically from there.
We've got a lot of cool stuff coming, and right now being able to still play on both sides, it opens it up for us so we can actually get enough data to really figure out what makes sense and what's working, what's not. We're kind of the guinea pigs for anything that we're planning to put into the product. And so if it's going out to customer deployments, we want to try it in-house first and make sure it works. Yeah, so I guess for people that don't know, you guys have traditionally been— you guys being LogRhythm— have been a traditional either appliance or install on your own hardware kind of solution, but you guys are coming out with the cloud version of your software where it's more a hosted SaaS version of LogRhythm. So are you guys internally, are you going to be an early adopter of the cloud version and move your whole internal platform there?
Exactly, and that's exactly what we're planning to do. Right now what we'll probably do is like a hybrid where we'll have logs just split between 2, so we'll have our on-prem, we'll have our off-prem, until we slowly migrate probably to full cloud, just because we want to be running the same environment as our customers are and be experiencing these kind of same things. We always like to do the patches first and things like that, just so our customers don't have to deal with any bugs or anything. So yeah, we definitely plan to do that. That's awesome.
Bit to the threat research versus the operational teams. Is that a sort of a defined career path that you guys have within the company? I think a lot of times it's— you have a security organization where you might not have a threat research group within your organization, so that's not really even a thought in terms of career progression. But it sounds like for you guys, you have, you know, more security operations, engineering, and moving towards that threat research piece? Is that something that you guys thought about specifically?
Yeah, usually we want to bring people into the threat research side who've had experience in security operations centers, who've done penetration testing, who essentially have that experience working in these more professional settings where, like in a security operations center where you're handling alerts and things like that. We definitely want to have people coming in with those kind of skill sets into the threat research side. That said though, we do bring people over just based on how passionate they are about the topic and what their abilities are and what their goals are and what they're able to really reach for. I tell you, some of the best people we've brought in to both security and threat research have actually been from support and help desk roles. Those guys are really willing to grind and They come in knowing a lot, actually.
It's good. And I think— so I started my career on the help desk. Yeah, that was my first job. I think you, you learn a whole lot there, right? Yeah, deal with everything.
You deal with everything. The customer service piece, which it's really hard to learn unless you've actually done a job like that. Yeah, yeah. I mean, I know that you can take, you know, customer service training or things like that. No substitute until you've had people yelling at you on the phone and, you know, having to solve problems for people when you can't see exactly what it is that they're doing, stuff like that.
You can't really get a good grasp on that customer service piece until you've really done it. So I think that that's— it's a great base skill to have. Oh yeah. You know, plus you have to learn fast, right? Yeah.
Thrown into the deep end. Hey, go— people are gonna call you, you got to solve their problems. So you gonna have to learn, you're gonna have to be resourceful. Yeah, the people that do the best at that kind of stuff, you know, can do that and they want to move up. So, right, you know, I have somebody on my team that started as a, you know, sort of customer service and, you know, sort of more entry-level person, and, you know, he does a great job now because he's willing to put in that work.
And anyway, yeah, agreed, it's all good stuff. Yeah, definitely. Well, it's like one of the cool things, see people grow into these new roles. You know, you kind of give them the sort of first steps to get into it, and then from there it's kind of open. They can really dive into certain topics and figure out where they want to go in the whole security industry.
So it's neat to watch and help people kind of get there. Yeah, it does worry me a little bit how we have more and more formal education today around security. Yeah, which, I mean, yes, I'm glad that people are learning about topics in security, but I mean, it's a different spin on it. Security is, I mean, it's a, it's a sub-discipline. It's a, it's an add-on.
It's a, you know, an umbrella to, to other parts of IT, right? It really isn't a discipline in and of itself, you know. There's, yeah, the security of the things that we're already doing. When you have people that are coming in and getting their degree in security and maybe you don't understand the other disciplines really as well. You just understand the security tools or whatever it is you learned in class.
I feel like those people aren't going to be as knowledgeable and as prepared as other people that have spent time going through the IT industry first. Agreed, agreed. That's a big aspect of it is understanding how the business operates because that comes first. Like, you can have, you know, massive vulnerabilities and things like that that you see as a big issue, but really when the company sees it, how is that going to impact profitability? Is this going to affect their bottom line?
Is this going to tank their brand? You know, all these things are things that they weigh on, and if this little minute vulnerability, you know, that you maybe found inside the company isn't really going to impact them, that's something where, you know, understanding that business side and then just general IT systems management and patch management and things like that. Those are very important skills to have and understanding in general. Yeah. We've been going through some hardening, developing some standards internally.
We've run across a few things. Basically, we're starting with CIS benchmarks and customizing for ourselves. Running across a couple things where it's like, Okay, well, this is the recommended setting, but we know our business does XYZ, and so if we put the recommendation in, it's going to break all kinds of business processes. And you have somebody that comes in that doesn't understand how the business actually works, they say, well, hey, here's your security standard, you have to apply all this stuff. You're going to end up in a bad place.
Right, and a lot of it too is it's very costly to do a lot of these security fixes. It's time-consuming. And there's all these other aspects where people don't understand, like you have to give people windows to do these things. You can't just say, hey, this is bad, you need to fix it now, kind of thing. You know, really understanding the business and how these other groups operate is so key to being a successful security analyst at the end of the day.
So let's jump in a little bit more to LogRhythm itself. Yeah, I think most of our listeners will probably probably know what LogRhythm is, but for those people that don't, you want to just give a quick high level? Sure, yeah. So we are a security intelligence company, basically primarily focused around security information event management. So we have a main flagship SIEM product that's kind of the lifeblood for the company, our appliance.
And then now, you know, we also have some network forensics tools as well. We have NetMon Freemium, and then we have the paid version of NetMon to do that kind of analysis of data, not looking at traditional IDS signatures, but more behavioral-based, which I think is kind of cool because then you have the IDS NetMon kind of dual layers, which we run internally, because then we have that signature hits, but then we also can look at these more advanced kind of behavioral activities over time using the other tools. And then we also have our AI Cloud, which is essentially analyzing end-user data and authentication activity essentially with machine learning and statistical analysis to kind of make some assumptions about what are people doing, how are they deviating from these baselines, are they doing so in such a way that it causes concern, and what are the exact kind of things that are happening when they're deviating from these baselines. So we're just kind of looking at all these different ways to track that user activity. So that's kind of our main service offerings.
Yeah, so I love it that the platform itself has lots of different pieces to it, right? Oh yeah. You've got some of the network coverage, you've got your sort of traditional SIEM coverage and rules, you've got the new behavioral monitoring, the AI cloud stuff where you're looking at stuff that's maybe not rules-based, but the machines can see patterns much better than we can. Oh yeah, pulling some of that stuff out. So I think that's really cool.
Yeah. What is— what's one thing about the platform that you think is really cool that people probably don't know about or wouldn't think about from, you know, a quote SIEM provider? Yeah, so probably one of my favorite aspects is the Smart Response capability. So Smart Response is our version of security automation, and so that basically allows people to write scripts or load up binaries and things like that that will trigger whenever certain alarms fire. So this is something where we actually built our whole kind of phishing analysis platform off of SmartResponse, where when we detect an odd email over the wire or something like that using our regex engines or threat lists or various kind of analysis of just the email logs in question, we can go out and pull that email down, analyze the contents, and determine a risk score.
And then from there, we can actually update a LogRhythm case with all the associated information from the attack that came in. We can actually go do quarantine actions automatically if you set that to do that after a certain quarantine threshold has been passed. And so all of that is kind of made available through the LogRhythm Smart Response functionality. So that's probably one of my favorite aspects. Yeah, the smart response stuff is obviously very powerful, and I sort of was teeing up that question.
I was hoping that your answer was going to be related to PAI and the phishing stuff. Oh yeah, because you guys spent a whole lot of time putting that together. Yeah, and it's, you know, it's near and dear to my heart too because in the business that I'm in, we deal with a whole lot of phishing emails. Not that other people don't deal with them too, but we have a— it's a pain. We are acutely sensitized to that problem, and so anything that you can have to help automate the analysis and remediation of that stuff is awesome.
Oh, thanks. Yeah, and Pi has been a fun project to work on because that's one, like, just like every other company out there, we get hammered with phishing attacks all the time. And it's funny, our Our old CFO, he's actually on our threat list now because his emails spoof so often that we're just like, okay. We're just going to block all emails from you now. Yeah, exactly.
And that's the thing though, they go out and they map out your company architecture or your organizational architecture through LinkedIn and determine who knows who, and they put all these pieces together to build pretty elaborate attacks sometimes. Now most of them are these commodity, you know, oh, click this thing, or hey, send me money through wire transfer, or whatever. We have had some really tricky ones that are definite spear phishing towards targets that have been hand-selected, and a lot of them, you know, do trick the people. And so that's one of the aspects that we look for is, you know, we make the assumption that people will get in at some way and, you know, somehow and some way eventually, but it's how we detect them after that. Can we immediately detect that they've popped a shell on this host and can we kill that session?
Can we make sure they're not going to actually get any data out? Can we see a user responding to a phishing attack? Can we see someone visiting a phishing link? All these things are kind of made available through the PI Engine where essentially once we aggregate this data from a suspect email, we plug everything back into ThreatList. So if we see anything go bad, we're gonna flag it, we're gonna have an alert that we know, okay, someone fell for this phish.
And so we kind of look for all these different things to follow through and make sure that, you know, the end-to-end handling of this email attack is actually being taken care of. Yeah, and of course that's really powerful for people that are LogRhythm users, but I think also you can use, even if you're not a LogRhythm user, you can use some of the pie Exactly. Frankly. Also, correct? And you guys, it's open source or it's free?
It is. Yeah, fully open source. And that's one of my favorite things about it is LogRhythm lets us do these open source projects. And PI in particular, we've had some great feedback from the general community around this. We've had people develop, you know, some of the people who are out here at Rhythm World have actually written plugins for PI.
So we have a Shodan integration now, a Wildfire integration. A lot of neat stuff. Is there a Have I Been Pwned integration? There is. There is.
And that's the cool thing. We wanted to make it so it's just a very open framework where whatever other people find useful, they can go ahead and add it back into the framework and then we can just start aggregating the data. So if somebody wants to find Pi, where do they find it? It's on our GitHub page. So it's just github.com/logarithm-labs.
And then we actually have a bunch of other open source Smart Response plugins up there as well. And then we have the officially vetted ones on our community. So it's community.logarithm.com. So we like to have both because we have that open kind of aspect of sharing with everyone regardless of if they use Logarithm or not. And the nice thing with PI, you can actually do searches in it now.
So you actually don't need the SIEM capability. You can go target searches through your inboxes and stuff. And so we wanted to make that so, you know, if you're using even one of our competitors like Splunk or QRadar or something like that, we want you to be able to plug this in, in line with whatever solution you're using. Because that's just one of the things where, you know, regardless of our customers, we want people to be able to perform these kind of actions like delete mail and block senders and as automated and quickly public way as possible. Awesome, that is, it's really great.
I think it is really a boon to the community to have stuff like that, so thanks, thanks for doing that. Thank you. So, so now in your new role, in your, your threat intelligence role, what's some cool stuff that you're, you're working on or stuff that you found? Yeah, so, so right now we're doing a lot of work with the MITRE ATT&CK framework, really looking at mapping, you know, everything that we can accurately test from the MITRE ATT&CK framework back to controls within the SIEM. And we want to do it in such a way that people don't need to use something like an EDR tool such as Carbon Black or CrowdStrike or something like that to get a lot of this rich data.
So we've been looking into Sysmon and ways to use Sysmon and build configurations that allow people to capture all this data in really verbose ways from all of their diverse systems, in such a way that they can actually detect all of these different types of attacks. And so that's a big one we're working on right now. Yeah, I've seen more and more work from people around MITRE ATT&CK framework, and I think it's really promising. I love the framework and the idea behind it, so I'm glad to see more and more stuff going into that. Presumably then that's something that will, you know, work its way into the product in the future?
Yeah, yeah, definitely. And right now we can detect most of these attacks, but we want to do it in such a way where you have a module that actually maps to these controls. And one of the cool things, like Red Canary here in Colorado, they put together the Atomic Red Team testing kits, and like the tools that they're putting out and the data that they're sharing with the community has been extremely helpful. 'Cause we can actually just take that, run through their simulated tests, and see what log data is generated, see how we can tune our rules and really detect these things. And by trying to use just the base OS and then log collection, like Windows Event Forwarding, Sysmon collection, stuff like that.
So we're trying to do it in such a way where maybe, you know, if people don't have budget for EDR, they can still get this data. Yeah, that's cool. I mean, I'd love to see it too, you know, down the road where you have, you know, things are more buckets, right? So if you, you know, you think about the ATT&CK framework, you've got the different areas, or you could think about, you know, kill chain-wise. If you want to look at kill chain too, it's like, all right, I see, you know, this type of activity, then this type of activity, then this type of activity.
Exactly. You know, it makes it even more logical and easy to think about when you're doing security monitoring, right? Instead of an alarm that fires that says, hey, detected this thing. It's like, hey, here's this fired, but it's also this part of the kill chain, and then you can relate it to the other things that are going on. Exactly.
As part of the ATT&CK framework. Anyway, I think it's really cool stuff. Yeah, well, and you bring up a good point with the kill chain, like looking at that progression, right? So maybe we don't alert on something where they're just doing some enumeration or things like that, But we track that data so that if they start progressing, say they go from enumerating to actually dumping local creds or something like that, then we're going to start firing on that and then reference back to these other kind of things. So you can actually trace back, possibly back to that entry point with as minimal effort as possible.
Good stuff. Fun times. It is fun times.
Greg, that you do things other than specifically LogRhythm. I know in the past you've been involved in the CCDC. I also know you recently were involved in a cryptocurrency conference that we had here in town. Do you want to talk about that? Yeah, sure.
So the cryptocurrency stuff is pretty fun. So one of my friends, he ended up essentially wanting to create a local cryptocurrency conference. And so cool thing, he kind of reached out to ask about doing a talk on some blockchain attacks and stuff like that. And also we started working on a CTF for that as well. We called it Capture the Coin, where you could go and essentially, you know, gain access to a wallet, and if you can steal the contents, it's yours kind of thing.
The conference was really cool. It was such a mix of people from so many diverse kind of backgrounds. Like, there were economists there and lawyers and marketing and graphics design people and sales and like kind of all walks of life were at this conference. And so this was really neat to see everyone kind of their different takes on, you know, blockchain in general. And blockchain is such a weird kind of thing, right?
Like, a lot of people hate it. A lot of people love it. I'm kind of like, I think it's cool. I think the technical aspects are way cool, especially the security implications. And that's actually tomorrow I'm doing a breakout session on blockchain attacks, and it's just a bunch of things we found while I was researching the topic to determine what are ways that people can game the system that are in place, what are smart contract attacks, and how these kind of work together.
One of the most interesting ones I found was this guy, he ended up setting up a honeypot online. And the way he did this was he got some ERC-20 token, which— so ERC-20 is basically a spinoff of Ethereum, where it's like a smart contract based off of Ethereum that is another token in and of itself. And so it was some like little unknown kind of token. I think it was like Mirai or something like that. I forget the name of the token.
But he set up this wallet and it was a MyEtherWallet where you can store all these kind of ERC-20 tokens in. And he set this up in such a way that there was no gas in the wallet. There was about $5,000 worth of this token, but no Ethereum gas. And so the way Ethereum works in order to transact any money, you actually have to pay a little bit, so it's like the transaction cost, which is Ethereum gas. And so there's no gas in this wallet, and he goes out and tweets his private key to this wallet.
And so as soon as all these people found his private key, you know, they start attacking the wallet. And the funny thing is he set up a script so that whenever they hit the wallet and tried to steal his money and move it to theirs, it would just take the gas that they put in and it would rotate it off and put it in another wallet. And so, and the guy, he ended up making a lot of money just by letting people attack this wallet. So there's a lot of real creative kind of attacks for these new smart contract technologies. I think that's the scariest part, right?
It's we don't really know all the implications yet. But I think that there are some people that are putting some pretty heavy reliance, yeah, on this technology. Um, I feel like there's going to be some bad consequences in the short term, yep, for people that, that really hadn't thought through all those, those things. Um, and it's also a sort of a great market for all of the people that are super creative, the hacker types, where it's like, oh yeah, let me think of the, you know, 27 different ways that it's possible to break this thing, right? Right, right.
And so I'm sure people will have a heyday, and that, you know, that's part of the fun of being a hacker is figuring out— yeah, yeah, I'm not gonna say a hacker in a bad way, someone, you know, someone that's figuring stuff out. It's, you know, hey, you know, you said that it should do this. Well, let me think about the ways that it shouldn't do this and see if I can do those. That's, that's the cool part about it. And, you know, like traditional, like AppSec, say you find like a cross-site site scripting vuln and you pop a JavaScript little alert or something like that.
When you go over into Solidity, which is the Ethereum smart contract programming language, and you do an attack against, say, a smart contract directly, you're not just getting like an alert box, you're getting possibly like $10,000. Like, it's like real-world, instant, direct consequences where all of a sudden you're connected to this environment where you can instantly launder that money and You know, pass it around to different tokens and move it through privacy coins and stuff. Not that you would do any of that stuff. No, no, but that's something criminals are doing very much so now. Like, it's a crazy environment.
Everything, you know, I would say 90% of the whole, you know, cryptocurrency scene is Ponzi schemes. There's no SEC regulations on trading. You know, if you have enough money, you can manipulate an entire market yourself. In this environment, which is fascinating and scary, you know. Let's not even get into ICOs or stuff like that where, hey, I'm offering you this thing that's not worth anything, may never be worth anything.
But my white paper sounds great. But yes, but here, let me describe it for you. It's gonna be awesome. Yeah, and people, you know, throw money at these things. ICOs in particular are one where you don't have to have a working product.
You don't have to prove anything. You just have to have a flashy site and a way to collect Ethereum or Bitcoin or whatever you want to get paid in. And a lot of those are exit scams too. These people just collect the money and, oh, I got hacked, quote unquote. And that's a common occurrence we're seeing too.
Like these exchanges, I think every week or so a different exchange is getting hit and, you know, they're losing millions of dollars. And, you know, part of having crypto handled in the way it is, where some of these exchanges you don't have to have identification, you don't have backups or anything like that, you know, like full legal recourse. There's, you know, once your money is gone, it's actually gone. Right. And yet that is the drawback to no regulation, right?
Yeah. Which means there's probably no safety net, there's probably no insurance, there's none of that kind of stuff. If it's gone, it's gone. Yeah, exactly. That's the scary thing.
When people are putting hundreds of thousands of dollars into these systems, you're really crossing your fingers and hoping nothing happens. Because there's things like the Large Bitcoin Collider, which is out there just constantly trying to— it's pretty crazy. It's like this group where they're just constantly trying to get private key collisions in order to take over wallets. And whenever they do, they just split the money. Like, how is that ethical?
But at the same time, how do you stop it? Right. It's, it's this crazy gray area. Yeah. I mean, it's not ethical in the sense that, you know, it's not nice.
You shouldn't be doing that stuff. Yeah. But probably technically within the rules of Bitcoin, there's nothing that says you can't get that as long as you've got the private key. That's the thing. Yeah.
Like once you own the private key, you're essentially saying that's my wallet. Now. And it's, yeah, it's sketchy. One thing that's pretty cool, I've been reading this book on Bitcoin Investigations, which is talking about ways to trace Bitcoin transactions back to actual payouts, which is kind of cool, like through Bitcoin tumblers and stuff like that, all the ways people try and mask their transactions. The funny part about all this, like people using it for crimes and stuff, is the fact that Bitcoin's public.
It's a public ledger. It's extremely public. It's going to be there forever. So, you know, maybe they don't have a means to find out what you did right now, but in 10 years, if they start backtracing this stuff, once they develop that technology, like, you better be worried. Well, and right, people think, oh, it's anonymous in the sense that, you know, they don't know whose username is what.
Yeah. But, you know, what if tomorrow all of a sudden you become unmasked and someone knows what your username is? Oh, let me go back and see all the stuff that you did. Exactly. And you have to convert to cash at some point, right?
And, and to do that, you have to go through some of these, uh, some of these different means. You know, there's so many different ways to, to essentially get caught, essentially. Exactly. Well, Greg, uh, we're running short on time here, right? Um, it's, it's been great.
I appreciate your time. Anything else you want to talk about before we get going here? Oh no, thanks so much for having me, and, uh, it's been fun, Alex. Awesome. Well, Robb is gonna hate this interview because we talked about Okta.
This is true. And we talked about Bitcoin and cryptocurrencies. Hey, Robb. So we did a great thing here, Greg. Anyway, it's perfect.
Appreciate your time. Thanks for the interview, and we'll talk to you soon. All right, thank you. This has been Colorado Equals Security. We'll talk to you next time.
Learn more about the Colorado security scene at colorado-security.com. Where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.