Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Rob Rack and Alex Wood.
Welcome to Colorado Equals Security. This is episode 67. For the week of May 13th. Alex, what have you been up to the last week? Well, I'll tell you what, Robb, it was not my day job.
Yeah, it's been a— what did we call it? We called it, uh, Denver Security Mardi Gras. Security Mardi Gras. And, uh, and it really— it's just, just finished up here with BSides finishing up on Saturday. Uh, of course, the big kickoff though was RMISC, or RMISC as we call it in the haiku.
Yes, Rocky Mountain Information Security Conference. Let's say it a third way. Absolutely. Great. We had a great time there.
1,313 people. That'll be easy to remember. Yes. 1,313. Double unlucky.
What an amazing conference. It was really, really great. Yeah. So I started on Tuesday with that full day of trainings. Obviously, you and I spent Thursday afternoon together working in the CISO track.
Yeah. So we had the CISO leadership meeting. Great discussions happened in there. Um, I heard great feedback from people on the, uh, the cryptocurrency, um, session that we had on the, uh, auditing for cybersecurity on Tuesday. Lots of good feedback on that.
And of course, on Tuesday night, we had our, our first ever community night. Yeah. So we had the, the job fair, um, and our, the organizations from around town had, uh, their chance to come and, and talk to people. I thought that went really well. I heard from 2 different candidates who said they were connected with job opportunities that they thought was a perfect fit and that they're going to be interviewing for anytime now.
Yeah. And I heard feedback from the people that were there trying to hire people that they had a great turnout, lots of different levels of people. Overall, that was great. Yeah. I'd say the idea of doing a community night on the pre-conference night was a wild success.
I don't know, as a committee, we haven't talked about 2019 yet, but I'd say the leader in the clubhouse is to try and do something like that again. Yeah, we can only make it better, right? It was good, but it'll be even better next year. Yeah, so looking at day 2, or the first official kickoff of the conference, you know, we started on Wednesday with Lane Hensley giving that keynote, really about how we as professionals could go through the conference ready for change and go through our careers thinking about the perspectives of others and being ready to experience change. Robb, are you still crossing and uncrossing your arms?
Yeah. One of the fun things, if you weren't at the conference, he had you cross your arms over your chest and look to see which arm's on top and look to your neighbors and you'll see half the people have their left arm on top and half have the right on top. And then just try to do it the other way. And the immediate instinct is, oh my goodness, this is so weird. It's so weird to do that.
Yeah. And so part of the message was embrace being uncomfortable. Open your mind, think about different ways to do things. I thought it was a really good keynote. Yeah, so great sessions on that day.
Obviously you and I also did the Colorado CISO panel on Wednesday morning. Standing room only in the room. Yeah, you moderated. I was on the panel with Gail Corey, Sam Masiello, Rich Schliep, and Joe McComb, and we had a good time. Great session.
Also on Wednesday, we had our second annual kids event. So we had a number of different schools that brought kids in there. Um, I think we had 90 or so kids, pretty amazing, coming in to learn about different aspects of cybersecurity. Looked like the ages really as young as maybe 12 years old. Yeah.
Up to, up to end of high school, maybe 18 years old. Yeah. And I think my highlight of that part was we had a panel in that session, but with, um, women in security and, uh, the Cyber Girls team, uh, Cyber Patriots team from Highlands Ranch High School who went to the national finals. And it was really great to see how excited those girls were to come and be part of the conference and to be speakers and participate and learn and contribute. And get badges with their names on them.
Get badges and ribbons. Ribbons on the badges. It was super exciting for them. That's really cool. So another cool thing that we did for the first time this year is the lunch on Wednesday was a tabled family-style lunch rather than a buffet or even a plated lunch.
And the idea was there was a sign on every table that said, the discussion topic at this table is going to be, um, you know, maybe DevOps security or, or cloud security or GDPR or Marvel versus DC Comics or Xbox versus PlayStation. That was kind of a fun way to, to meet new people. It was. And I think, you know, there's 2 good things about that. One, you didn't have to go and wait in the buffet line.
You just went straight in, sat down at your seat. But the second was you had to interact with other people or else you weren't getting any food. So you had to make sure that you, you had good table manners so you could ask people for, you know, what was on the other side of the table. Yeah. And it sparked a lot of discussions, which was good.
That was fun too. Uh, of course we had our closing keynote that night, which was delivered by the chief marketing officer from Optiv. Initially we'd had Dan Burns, the founder and CEO, scheduled to deliver the keynote. Unfortunately he was called away last minute, uh, by his board, but I thought his CMO stepped in and was a pretty good presenter. Yeah, it turned out good.
I heard some good feedback on that session. And then, uh, of course Thursday Another great day, uh, kicked off by Daniel Meissner, uh, talking about artificial intelligence and, you know, kind of what the future holds for that. Yeah, he did a book signing afterwards with his book, is, is The Internet of Things, I think it was called, or I can't remember the name of the book off the top of my head. Internet of Everything, something like that. Anyway, he gave a book signing afterwards and we, we had, you know, a great line of folks who got to meet him and get a book, uh, personalized for them.
It was pretty cool. Yep. Great sessions on that day as well. And then of course, our closing keynote again, we did comedy this year. Phil Palisole, some good comedy, lots of fun.
Yeah. And then so I would tell— so one of his bits was, you know, hey, I'm not super handsome like some of those other guys and I can't go around wearing shoes with no socks. Right. And I was at a party tonight and there was a guy at the party who is a handsome guy wearing shoes with no socks. And I had a little chuckle.
Thanks. How was his foot gravy? Um, yeah, that's gross. So one of the other things I— that I really appreciated this year was that in addition to the great tracks and great participation, we also had a lot of kind of surrounding events, just a lot of vendors who were kind of, kind of like you'd see at RSA conference putting on events, you know, rooftop parties and, uh, you know, bars where they had private rooms, a lot of stuff going on, um, that you could do. Uh, right after the conference each night.
Yeah. Keep— it's great to see the conference going more than just what we're doing. Uh, you know, you've hit the big time when there's vendors doing happy hours and parties and other stuff like that. That was great. Uh, I think one other thing I wanted to mention, um, you know, we, one of the tracks that we had continuously throughout the conference was the Living Security Escape Room.
You know, it's a sort of escape room plus security awareness. Um, I didn't have a chance to do it, but I know you did. Yeah. Yeah. It was fun.
You know, it's like an escape room like any other one you've probably done, except it's, it's much more cerebral versus physical because they don't have a physical room like you'd have other places that, you know, mounted in place and they can reset easily. They had to do a lot more cerebral type stuff, much more technology focused, interesting stuff. I'd say for those folks who'd never done one before, they loved it. For those who've done it before, you know, it might have been a little bit easier than most of the escape rooms I've done other places, but really a fun time and a good way to get to meet. In my case, I got to meet, you know, 8 strangers, folks who I'd never got to interact with before.
So it was fun. Yeah, and I did hear from them that they had an interest in coming back next year, so we may have an escape room again. Awesome. So wild success, right? It seems like every year we have this conversation and we say that, you know, it's the best RMISC ever, and I think clearly this was the best RMISC ever.
Yeah, I had lots and lots of great feedback. Usually you know, I hear, oh, this thing was great, this thing was not so great, or, you know, oh, you could improve here. Almost universally, I, I had great feedback this year, so wonderful to hear that. So, you know, of course we now have started thinking about the 2019 conference and, and what do we— who do we bring in? So if anyone out there is listening and has feedback on who you want to hear as a keynote speaker, uh, we are especially interested in finding some female keynote speakers to help us.
Uh, if you're interested in getting involved, this is the time to reach out. You can send a note to info@colorado-security.com and, and we'll We'll love to loop you in for sure. All right, enough for the the RMISC the pregame here. Let's let's get into the actual news. Yeah.
So before we get into the actual news, number one, this is the 20th anniversary of the season or the series finale for Seinfeld. Again, Robb, like most of the things we talk about here, this just makes me feel old. Yeah, absolutely. Makes me feel old as well. And I think your your quote summed it up well.
The worst the worst episode of the whole series. Yeah, you know, it was a pretty bad episode. I'd have to go back and watch all of them to see if it was the worst, but it left you with, in my opinion, a bad taste in your mouth. You know, I was a Seinfeld fan and it was not the best episode. I'm still a pretty big Seinfeld fan.
I was just recently listening to a podcast called 99% Invisible. They're talking about the laugh track. And you may have noticed that the laugh track has pretty much died off from being used on television. There's very few shows that use it. Roseanne, as the reboot, uses it, but almost nothing else does.
But Seinfeld was one of the very last successful shows to use it. That's pretty cool. Yeah, of course. Reminder, we do have a Slack channel that's up right now. We're well over 400 folks involved there.
It's a great place for you to engage with the community, get to know people, reach out, get connected. Review us on iTunes. We did get some feedback this week that it may be impossible to review us on Google Play. If you figure out a way, then go ahead and do that. If not, then don't do it.
We've been telling you for the last year, please review us on Google Play, and apparently that's not possible. Oh well. We also have a mailing list if you want to keep up to date on what we're doing, get the show notes in the mail, all that kind of stuff, then sign up for the mailing list as well. A couple shoutouts for our Patreon patrons. We had 2 new people sign up this week.
Thank you to Rock Lambros. Rock, the, uh, the former RMISC conference chair, signed up this week. Appreciate that support. Also John Von Rader with Alchemy Security, thank you for your support as well. Yeah, and we do appreciate anyone who wants to sign up.
We are using any funds we get there to improve the show and to really feed back to the community. This is always going to be a nonprofit endeavor for Alex and I, so anything you want to give, we would love it. We can increase the quality of the the audio, get some shirts out to the community. We don't know exactly, but, uh, but we'd love your support. Uh, we also run a CISO dinner series, so if you are interested in attending that, if you're a security leader and want to come hang out with us, uh, we've got a great group, um, but we're always looking for more people.
Um, and we also love to have sponsors for those dinners so that we're not paying for it ourselves. Yeah, and you can go to— go onto the website colorado-security.com. There is a security, uh, leader dinner link in there. Uh, Denver Startup Week voting is up right now, so you can go check, vote for the, the session. There's a link in our show notes.
Um, we'd love to have you vote so we can have, you know, I'd be moderating a talk with the founders of a bunch of local cybersecurity startups. So ProtectWise, Red Canary, Swimlane, OverwatchID, and, uh, CyberGRX. Yes, CyberGRX. So please go vote and get in there. You know, we're doing well on votes, but We're not assured of anything until we get further along.
And we want to make a quick, uh, clarification. It's not quite a correction, um, but last week we had a story about CenturyLink cutting, um, I think around 1,000 jobs. Yeah. Um, and we heard from, uh, Mike Benjamin of CenturyLink and said, hey, just to let you know, there are no security jobs that are going away. Yeah.
So while they have lost some jobs across the organization, they, they recognize the importance of security and how valuable those resources are. Security jobs, they look good right now. Look safe. I think that they actually have many more openings. So if you want to work for CenturyLink, I know that they have some jobs that are out there.
All right. So moving along, Colorado Springs unemployment rate declines in March to a 9-month low. Yeah. So it was back in 2017, I want to say in April, somewhere in there they had their low and now they're, I believe, back down to 3.2%. Yeah, 3.2%.
And some other interesting stats from this show that the lowest spot for unemployment in Colorado is actually Fort Collins, which is down at 2.3%. And what's actually more amazing to me than that is that the highest spot in Colorado is only 4.2%, and that's Pueblo. That's pretty incredible. Yeah. So of course, across the whole state, we're at 3%.
That is just awesome unless you're trying to hire somebody.
Next, Colorado made Chief Executive Magazine's top 10 for best states for business. Yeah, so this is— we are one of the better places to run a company. I think we were number 8 on the list. Looking at number 1 on the list was Texas, followed by Florida, North Carolina, and South Carolina are tied for third. And what do you think last place is, Alex?
You might have read the article. I have read the article, so I'm gonna go with California. California for the win. Now of course, lots of regulation in California because they are— what are they, like the 3rd or 4th biggest economy in the world. You know, if they were separated into their own, they, they have a lot of taxation, a lot of regulations make it a little bit more difficult to do business there.
Whereas, you know, Texas is number one because there's no laws there, no rules. So Colorado was 8th. Specifically, we were 27th for taxation, 10th for workplace quality, and number one for living environment. Of course, that's why everyone wants to be here. Great living environment.
All right, moving along. We do have a story here that was actually kind of national news. You may remember late last year that we had some threats that went to the spouses of servicemen, really threatening their lives, threatening to kill the spouses, not the servicemen, but the spouses at home, sending Facebook messages. And they claimed to be sent by ISIS. Yeah, exactly.
And recently it was discovered that those threats were actually sent by Russia. Um, and, and why, why does this have anything to do with us? Well, of all those people who received it, 5 of them, 5 of those wives were actually Colorado women. Yeah. I think this is, um, a fairly, uh, big cybersecurity topic.
Right. So it's, I don't know if I'll call it cyber war, but it's, you know, cyber something disruption, disruption, false flag endeavor. There's a whole bunch of stuff. And of course it falls into our world to figure out solutions to this. Stuff, right?
Exactly. So, you know, all the stuff that's out there, um, whether it's on Facebook or, or wherever else, of Russian trolls and everything else, uh, just really interesting how the whole, um, national stage is playing out in regards to this. Yeah. Our next story here, Colorado politicians approve and then reject a bill to distinguish blockchain tokens from securities. This is a little confusing to me.
So, so what's confusing to me is how somehow it passed the Senate with a yes vote and then they revote. I don't know why. Why do you pass and then you do a second vote? But when it went through the second time, one vote flipped and it went to a no. Yeah, I don't get it exactly either.
But my guess is that it had to be— I'm not even going to speculate on that part of it. But, you know, some of the meat in here The, the, the bill was trying to, to differentiate between what we think of as currencies, which are essentially, or actually technically securities under the law, and other things. They give an example of, of CryptoKitties, which is a sort of a game based on the blockchain where you own things, these cats that are part of the CryptoKitties blockchain. So I think it was an attempt to separate things. Things related to blockchain that are not trying to make money and other things that are trying to make money.
So, so you don't want to have to regulate the CryptoKitties as a security. And that was with the purpose of the law, right, is to remove that requirement to regulate the kitties. But, but now I think they're all kind of lumped together. Is that what we're saying? Exactly.
I think one of the things that was pointed out, the attorney general was against this bill. Um, partially because it was pretty vague. And so I think that there probably would have been some ambiguity over which of these things actually should be treated as securities and which things shouldn't. Right. It— I think all this goes to show it's a really immature area of technology.
The politicians certainly haven't figured it out yet. The technologists probably haven't figured it out yet either, right? So we have a long way to go before it's really settled. Yeah. And we made sure to have this story in here this week because Robb loves blockchain so much.
We can't go a week without talking about blockchain around here at Colorado Equal Security. Next, Ballard Spahr interviewed 2 Colorado information security leaders. Yeah, it's fantastic to know that Ballard Spahr, a local— well, an international legal firm with a strong local presence, went and found what I'd call the best 2 Colorado security leaders to talk to. I would agree that it was also the best 2 Colorado security leaders. Those two were, were us.
Yeah, so, so you guys can take a look at the link in the show notes. We're not going to go through it right now. However, if you listen to the show in a week or two, you'll get to hear all the audio from this interview. So they, they kind of summarize a small subset of the conversation into a blog post. We're going to turn the entire thing into a podcast here in a couple weeks.
Yeah, should be fun. Uh, next, there was a survey done by ProtectWise and, uh, the survey company ESG about millennials and their interest in cybersecurity careers. So the headline here is that 9% of millennials are interested in cybersecurity careers. You missed a word, Alex. The headline says only 9%.
Only, sorry. So this is one thing that Alex and I were, before the recording, were kind of shaking our head about. Uh, only 9% of millennials want to do cybersecurity. Well, we don't need 9% of them to do it. We need somewhere in like the, the 2 or 3% to get into security before we'll be pretty happy.
Yeah. There are a couple other things here too, right? They're sugaring— or they're talking about millennials. Millennials are of the age, I think, 22 to 37 today, the way they define this survey. Well, that is, that is the definition of a millennial is that's the, the, the age group is 22 to 37.
So they're a generation. And that generation right now is 22 to 37. Okay. Um, and so from my perspective, um, it, it is not surprising to me that a 37-year-old would not be interested in a cybersecurity career because they probably already have a career, right? They're, they're 37.
Uh, so there, there was a couple of things I pulled out of this. We actually have 2 links in the show notes, one from a Denver Post article that covered the survey and one that goes to the actual survey at ProtectWise. Couple things I pulled out though, um, the number one most attractive career in technology Uh, it's, it's video game development. 33% of people were interested in that. Yeah, who doesn't like video games?
And what we really need is a third of our people creating video games. Yes. Yeah, that's, that's kind of absurd. One other thing I pulled out that I thought was very interesting was that, uh, very surprisingly as well, young females found security more exciting than males. 56, 57%, uh, versus 60%, uh, women to men were more interested Nice.
Yeah, I like it. That's shocking, right? That is great. Um, I think the other thing here is that, um, you know, they're, they're talking to people about whether they're going to be interested in a cybersecurity career. And, you know, again, one of the things that we're discussing is for the most part, you know, cybersecurity shouldn't be the career you're thinking about.
You should be thinking about doing something, you know, maybe relating to technology or programming or IT. And then you should think about doing that securely as opposed to security being a separate subject. Yeah. I'd rather have you go become just the best person in the world at pick your technology and then say, and now I'm going to go help secure that technology better than we do it today. That would be a much better way to look at it than saying, I'm going to be a security guy and I'm going to try and know all the technologies.
We've got to figure out where you focus. There's a couple of things that I think reiterate your point from the survey on the, on the ProtectWise side, they said that 69% had never taken a school— a class in school that focused on security. But I would hope that many of their classes focused on security as a subset, right? And they don't, they don't get into that kind of granularity. And then they also said that 65%, um, had never even offered a course on security.
That's another interesting fact. Yeah. And, and again, I might counter with that second part where I'm not sure that you need a class in security. You need a you need topics in the classes that you take that relate to security. And we talked a couple of weeks ago about the intern jobs that I had available.
We were looking for 2 interns this summer. Well, I had over 70 people apply for those 2 intern jobs. Yeah. And some of the folks that I talked to, you know, they're in school and they gave great examples of in their classes that they are taking today that they are being taught security fundamentals. So, uh, I feel like maybe this, this survey from, uh, ProtectWise is still a little too far ahead of the curve.
You know, it— I think maybe millennials is not the generation that they should have been polling. They should have been polling the whatever the next generation is after that, whatever we're calling that. All right, so, so moving along, our final story for this week. Uh, you actually found this. It's not even a link to a story, it's just a link to an SEC filing.
Red Canary filed a Form D for over $6 million of new funding. Yeah, and it sounds like they are just sort of finishing up their Series A with a little bit more funding here, getting to build out the team a little more. Yeah, so I sent a note to Brian Beyer. You know, you had him on the show last week, I think it was. So I sent him a note saying, hey, we're going on the air with this, you wanna make a comment?
And he sure did. He let us know that this would be his opportunity to do more as an organization without, you know, while maintaining the same high-quality product. That's kind of a paraphrase of his point. They're going to be able to accelerate both product and sales with this new funding. He also asked me, since we're talking about them, to make another pitch.
They're trying to hire engineers and SREs who, who want to run with a lot of data and really help work, you know, security into more focused SOC environment. And of course, SRE being Site Reliability Engineer. Thank you, sir. Um, I also, you know, got a little shiver there for a second, Robb, because, you know, you said that you reached out for— to Brian Bear for essentially for a quote. Yeah.
It almost sounded like you were a journalist there. No, I'm no journalist because I totally just paraphrased him and didn't even worry about it a little bit. Hi, Brian. All right. Moving along.
We have a Slack message of the week. Slack message of the week. Slack message of the week. All right. So this is going to go to Jericho.
Brian Martin. He brought into the Slack message a story about a false positive that impacted a self-driving Uber and actually ended up killing a pedestrian. This might have sparked the most interesting debate slash conversation of the week on the Slack channel. Yeah, I agree. There was discussion on both sides of the issue.
Very friendly. Yeah. You know, everybody thinking about these issues and what might be good, what what might be bad. Great, great discussion. Yes, I think at the root of it, you know, self-driving cars will dramatically reduce the number of auto fatalities.
That's a positive. On the other side, hey, there's a bug in a piece of software that killed someone, right? How do you, how do you balance those 2 things? I think that's an interesting question. It is, and one we're gonna be answering for a while here.
So thanks, thanks again to Andre Gaeta, who is our sponsor for the Slack Message of the Week. Brian will get the opportunity to pick something from the Colorado Equals Security store, and hopefully he'll be, uh, sporting that on the roads soon. Nice. So let's move on to events. Um, as you know, we have our event calendar on, on our website, so go to colorado-security.com and check that out.
All right, so on the 15th, we have the Colorado Secure— excuse me, the Cloud Security Alliance May chapter meeting. That's on the 15th. On the 15th and the 16th, ISSA Colorado Springs has their May meetings. Also on the 16th, OWASP Denver has their May meeting. That's at Dave Buster's on Colorado.
On the 16th, DENSEC has their monthly meetup. On the 17th, ISC2 has their May chapter meeting, and I think that's happening at the Secureset Academy down by, uh, Coors Field. On the 19th, ISSA Colorado Springs is doing their mini seminar. On the 22nd, there is a, uh, the GDPR meetup is doing their GDPR in effect Trimble, a test case. So talking about what's happening at Trimble.
Nice. Is Clay talking there? I assume Clay is going to be talking. Yeah. On the— also on the 22nd, SecureSet is doing a career conversations.
You probably left this one for me because it's a hard name to pronounce. Kelly Garrido from Skylarq Digital. On the 23rd, there's another GDPR-focused talk. Of course, it makes sense because we're just a few days before GDPR goes live on the 25th of May. But on the 23rd, there's a talk called The GDPR and Data Privacy in the US.
And then finally, on the 24th, uh, SecureSet is doing one of their capture the flag events, so go check that out. All right, let's go ahead and jump over to jobs. Just to top the list, this should be no surprise to anyone— Ping Identity is hiring a senior security analyst. We need someone who is a badass, uh, working with security operations, security controls knows how technology works, understands how Linux and networking systems work, and really wants to help us enhance our security operations. Also at Ping Identity, we're hiring a Site Reliability Engineer who is focused on security operations.
So 2 pretty similar focuses. The first, the Security Analyst, is going to be reporting into my team doing day-in, day-out security work on the SRE team. This person actually reports to SRE but does the security project work. So kind of depends on where your focus is. Nice.
Uh, next, Cognizant is looking for a senior manager in corporate security for application security architecture. Awesome. S&P Global is hiring a director of security architecture. Centura Health is looking for a security architect. 3D Systems is hiring a security engineer senior.
So that one is my favorite job of the week. Do you know what 3D Systems is? I can only assume that they make 3D printers. They do, among other things. The founder of the company was the person that invented 3D printing.
Get out of here. I will not. Next, the Department of Veteran Affairs is looking for an IT specialist in InfoSec. BT, I assume this is British Telecom, is hiring a regional security sales specialist. Yeah.
So if you wanna sell security stuff for BT, that sounds good. Raymond James Financial is looking for a cyber threat analyst. And if you are tired of having your hands on technology, LogRhythm has the job for you. They're looking for a training coordinator. And finally, GuidePoint is looking for a VSOC cyber threat hunter.
So this is actually a sort of a SOC position where you can work from home. That you might have just got bingo right there. Bingo. To close the, close the— I did not say podcast out. Cloud AI blockchain.
Chain. But we said all those things earlier. You might have just— you might have just got it for the podcast, right? Podcast ends when we finally get bingo. All right, we do have a feature interview coming up here momentarily.
We have Kris Merritt and Brian Concannon, who are co-founders for Vector8. Alex, who are these guys? Yeah, so, um, these guys have a lot of experience in, uh, in threat hunting and incident response. Um, Brian actually was in the FBI for a while. I spoke to them a little while back and had a great conversation talking about their company Vector8.
It's essentially a threat hunting platform software, and they also do training. Really great conversation. Awesome. Looking forward to hearing it, and we'll see you guys this week on Slack. And if not, we'll see you next week on the podcast.
Thanks, Robb. See ya. Hey, this is James Carder, CISO at LogRhythm. This is Colorado Equals Security. For Colorado security professionals by Colorado security professionals.
This is Alex Wood with Colorado Equal Security, and I am here today with Kris Merritt and Brian Concannon of Vector8. Welcome guys, thanks for taking a little time to talk today. Thank you. Thank you. Thanks for having us.
So before we get started here, I'm sure everyone is interested to hear what Vector8 is and what you guys do. But why don't you take a minute and introduce yourselves, how you started information security, how you got to where you are today, and any interesting stuff along the way. Yeah, who wants to start? Yeah, I'm Brian Concannon. Um, I, I don't know if there's like a standard way to get into security.
Mine's a little bit unique, um, kind of a software developer turned FBI agent turned software developer again. Um, yeah, so I mean, doing software development, you know, I obviously was very technical and then realized I wanted something more action-oriented. Um, and, uh, so I joined the FBI. FBI is a little more action-oriented than software development. Yeah, yeah, it is.
And it was a big change of pace for me, but, um, did counterterrorism for a little bit in Detroit and then got into a cyber squad and kind of got into cybersecurity that way. Nice. So, and so from there, did you come directly to Uh, so great. Or after, after 8 years in the Bureau, I kind of got sick of bureaucracy. And there was awesome things about the Bureau, um, loved working there, um, realized I wanted to kind of focus more on the tech stuff, uh, so found CrowdStrike and, uh, and left the Bureau and joined CrowdStrike.
So nice. You're almost a doctor somewhere in there, right? Yeah, yeah, yeah. Um, that was, that was one of the things I might have done in my, in my early 20s was focusing on maybe going medical school. So nice.
Yeah, good stuff. Chris? Yeah, I got my start right after college. I went into the Air Force and I was active duty for 8 years, and I was kind of an IT guy. I think they called it comm at the time.
By the time I left, they were calling it cyber operator. It was really the same thing, but I landed in a security role there for the first time. It was at the Air Force CERT in San Antonio. And it kind of just— I was just kind of dropped in and overwhelmed by just seeing security operations and incident response at scale, vulnerability assessment and compliance and everything under the sun, reverse engineering, and just kind of blown away by it all and overwhelmed. And I started to realize that there's just so much work that has to get done in that area, and I somehow had the background to to help out with computer engineering and other skills and stuff like that.
So I was in the Air Force for another couple years, and then I left and went to GE, General Electric, for their aviation and energy division. And I had the task of doing intrusion detection for a third of GE with 1.5 contractors. And so all the ideas I was building up at the AFSCERT on, you know, how to not do things inefficiently and how to do things more efficiently, I tried to use there. Made some progress, eventually left, went to CrowdStrike, and Brian and I actually started their Falcon Overwatch team. That's their hunting service team.
We started from scratch and grew it for over 4 years until we left, but it was easily the most rewarding experience in my career so far. And we started Vector8 a year and a half ago using a lot of the ideals we learned over, you know, the many years that we were doing security and kind of chose Vector8 to be that spot where we carry out some of our philosophies on technology and humans and how they should be interacting, that kind of stuff. Nice. So did you guys meet at CrowdStrike? Yeah.
Was that here in Colorado, or did you come out to Colorado? No, actually, I was living in Michigan at the time. Yeah, and I was in Indianapolis. So Chris actually hired me. He was my manager coming out of the Bureau.
Oh, okay. And then we kind of switched roles a little bit, and I took over or started a development team to support the analysts on the hunting team. Team. So kind of became peers a little bit there and just kind of built the 2 teams together. So nice.
Yeah. And then we both sort of separately decided to move to Colorado. Both of our families kind of always had the interest of moving west. Um, I didn't, I didn't want to stay in Indianapolis forever, and I was kind of enticed by the outdoors, outdoorsy stuff out here. And working from home with CrowdStrike made that an easy choice.
So, so you guys, uh, you came here before Yep. Uh, still with CrowdStrike, came out here, right? Both were still with it for just a few months, really. Yeah, 6 months, right? 6 months or so.
Yeah. Um, yeah, I kind of felt like things had run their course at CrowdStrike, you know. Like Chris said, it was— for both of us, it was a very rewarding time for us. We got to build a team from scratch, and that team is still going strong today. So kind of got to leave on good terms and, and come try our own thing here at Vector8.
So cool. Yeah. And so you mentioned Falcon and the hunting piece around CrowdStrike. I think that leads us into what you guys are trying to do here at Vector8, right? So maybe a quick intro into Vector8 and what you guys are trying to do.
Yeah, so philosophically, we— this doesn't answer your question whatsoever. Philosophically, when we first started the company, Brian came up with this awesome tagline that really summed up our philosophy, and that was people enabling technology enabling people. And the reason why we kind of feel so compelled by that is because we feel that in our industry and probably a lot of others, there's an overemphasis on automation in certain spots, and there's an overemphasis on human resources in other areas. And we feel like people move from one spectrum to the other, or one end of the spectrum to the other, and where we were able to have an experience at CrowdStrike where we can actually strategically use one and the other together, like purposefully. So let tech do the things that tech does best, let humans do the things they do best.
And to answer your question directly with Vector8, it's, um, for the first year we were selling a threat hunting service, and then we realized, you know what, let's help other people do what we're doing. So now the platform we built over a year ago, we're trying to— we're productizing it now to help others use our methodology philosophy is to do hunting the same way we did. Nice. Anything? Yeah, no, I mean, and like Chris mentioned, you know, like for me especially being a software developer, I just enjoy enabling people, right?
And I think, I think technology is really cool and I love, I love automation because I hate repetitive tasks. But, but in the end, like Chris said, our focus is on, on the humans. And we, when you give humans really awesome technology to use, they can do amazing things, especially when they're defending against human adversaries on the other side, you know. And so, so that's kind of just our focus, is how can we build awesome technology that kind of gets out of people's way but, but it does all the automation of the things that are repetitive and let the humans just be really good at what, what people are good at. And so, um, yeah, I sometimes call myself Chief Enabler just because that's kind of my mission, is just enabling, enabling smart people to like get the tech out of their way so that, you know— and, and don't get me wrong, like we still are all about machine learning and all the cool high-tech stuff too, but we also want to still put that focus on people.
So yeah, yeah, that's awesome. So I guess stepping back a little bit from that, I'm sure most people have an idea of what they would say threat hunting is. So maybe if you guys want to give your definition of what that is, since you're building a platform to help enable that, right? We have a class in threat hunting, so we'll have to charge you for the— yeah. We'll prorate this answer.
I'm trying to make it lengthy.
So that's a— it's a good question because it's become everything and at the same point nothing specific. So I do have a definition for it. I think what most people mean by hunting is they take an indicator of compromise and they look back in time for it. They look retrospectively across their log data or something like that, or they might scan their network looking for an IOC they learned just now against old data. I think that's what most people mean by hunting.
You can mean other things by it too. I think there are various machine learning algorithms that are trying to discover new artifacts that I would call hunting as well. And there's obviously another common form is like DFIR practices just done more proactively instead of reactively. So my definition of hunting has always been— our definition has been anything that you do towards detection that's outside of your passive monitoring apparatus. So your typical network IDS or automated solution going to a SIEM and operated by SOC analysts, I'd call that your passive monitoring data flow, that kind of thing.
I feel like anyone who wants to do some sort of mechanic— mechanical thing outside of that, they call that hunting. So our definition is really hunting is the discovery of malicious artifacts and malicious or new detection methods that you can't account for in passive monitoring. And then, Brian, with your— to your point about automation, yeah, that is the goal, to take those techniques and put them back into the passive piece. So, you know, you find this stuff, say, oh hey, here's something cool and unique, I have this passive detection capability, let me put it in there so I don't have to go hunt for it again. That's exactly— yep, there's a lot of things you'll find yourself doing when when you're hunting manually that you're like, okay, I've kind of discovered like maybe a behavior I'm looking for in an endpoint that has been giving me good results when I've hunted for it manually.
Well, I don't want to keep doing that. I just want something to automate that and then let me know, and I'm going to look for new techniques of hunting that I can use. So again, like the humans kind of doing the cutting edge, looking for new behaviors, you know, and the adversaries are always changing, right? So you kind of have to stay on top of your game, but then anything you've done that you want to repeat, that's where you want automate it. So that's, that's really the platform we're building.
Nice. So you, you mentioned also that you guys do training around this too. So is that sort of the first step in your methodology, is getting the people so that you can get them to the tool to help enable the people? Yeah, yeah, really it is. I think we have a 3-day training that we do here.
We like to do it here in Denver. Sometimes we travel for it, but it's really It's a methodology-focused threat hunting course, but at the same point it's endpoint-focused too, on purpose. And the reason why is we've realized with endpoint process data you're able to articulate with a lot of granularity what an attacker is actually doing. You can actually describe a TTP, tactic, technique, or procedure. And so we kind of teach that way of looking at attackers' activities as well as our thoughts on hunting And those combined is really what the 3-day course is about.
Gotcha. And then you guys are also— you mentioned trying to productize that and that sort of thing. So you're in the process now of building out the toolset that you guys would sort of use individually now into a platform for people to use for this sort of stuff? Is that right? Right.
Yeah, we actually— it's officially released. More or less. I mean, it's a— yeah, the engine that sort of does like— it's a real-time event processing engine, and we've been using that for a year now. So that's, you know, that's something that we've, we've used in our training, we've used in consulting things. And but now we're trying to, like you said, productize it more, put a front end on it.
And so we're doing some beta testing with some trusted partners on the actual UI for that and kind of like usability. And but like the overall concept of it, we've been using for quite a while And it is generally available for people to use. It's just a matter of, like, everyone's gonna use it in slightly different capacities because of how they integrate with their current infrastructure. But yeah, Chris, did you want to describe kind of what it is? Yeah, it really, so Sysmon, Microsoft Sysmon, that's Systeminternals, Mark Russinovich, that's their, call it your EDR sensor.
It's a free Microsoft EDR sensor. We love what it does. It's free. The toy's nice. It's nice.
And then we know how to use the data. We've been able to, like, we built expertise over the past 5 years on how to properly use that kind of data. So what we want to do is help people operationalize a tool like that. We feel very strongly you can use Sysmon in particular and find the worst attackers on your network. And we want to help people do that.
So our tool largely tries to operationalize Sysmon, but you can use it to do your own amount of hunting on any commercial EDR. Or I mean, you could send really any data type into it, but we've designed it around endpoint data. Gotcha. Yeah, your typical company that's gonna try to operationalize Sysmon is gonna probably just do Splunk or an ELK stack and just like push the data there. And there's just so much plumbing that has to be done that everybody's gonna have to kind of repeat that same thing.
Like if you're not gonna buy something like a CrowdStrike or, you know, or something that where all the plumbing is done for you and all the detection is done for you. But, um, so yeah, I think a lot of people are interested in Sysmon, but it's, it's a lot of work to operationalize it. So that's kind of where we want to help like fill that gap. Like, you know, just install Sysmon and then send the events to our cloud, and then you can write a whole bunch of plays into playbooks that will— every single event will run through every one of those plays, and you'll get automated, you know, triggers like hunting-type triggers that you can look at, and you can manipulate the events as they're going through. You can You can even then store them in Splunk or Elasticsearch at the end if you want.
That way you can kind of manually hunt as well. So it kind of augments that process, right, kind of in the middle before it gets to like a Splunk where you would just be kind of stuck with like saved searches or something that run periodically. This will do it all in real time, any of your searches. Gotcha. Yeah.
So, you know, one of the things that I've heard from a lot of people is that, you know, they would love to do um, you know, more hunting activities, but, you know, they feel like they don't necessarily have the overhead, um, the extra manpower to do stuff like that. They're, they're caught up more in that, uh, the passive operational pieces, right? And then the amount of stuff that they're getting from that, um, is more than enough for them to keep them busy. Um, do you guys see, you know, particular, uh, industries or sized companies or, you know, anything like that where where hunting is more prevalent, or where you, you know, who do you think it makes the most sense to do it with, that kind of thing? Yeah, I think the larger enterprises, like the more funded, more mature security teams, those who feel like they've kind of mastered the passive monitoring area, from what we've seen, they tend to be the ones who want to have a DIY hunting shop, right?
They want to roll their own, do whatever they need to do to kind of, instead of buying something off the shelf. What we're starting to see is that there are MSSPs who are becoming interested in upping their game. And honestly, right now that's been a bit of our target clientele, is helping MSSPs kind of up their game, provide them with, you know, kind of a basic package of, hey, here's a rich data point, here's how to look at it, and here's all this stuff you can find and they can operationalize it. So is there anything you want to add to that? No, I mean, just maturity obviously is a piece of it, right?
Like, if you're— if the rest of your security department is not mature at all, we're not going to recommend you just start hunting but you're not doing anything else, right? Like, it's something that augments what you're already doing, and you need to at least kind of have it down, the passive stuff, and being able to manage it and automate it as much as possible. So, so yeah, it is harder to get into like those smaller, less companies. But that's all we're trying to kind of push that envelope a little bit. And that's why we're trying to like make a platform where like you just install something and we'll even give you some of our playbooks that we know have very high fidelity triggers for advanced attackers, like the behavior that you're gonna see them do.
That again, it's not gonna like hunt for you, like you can't fully automate it, but we can give, we can give it to people where they could have a person that has a few hours a week that could maybe do a little bit of hunting. Hunting. And so maybe get it into some smaller companies with smaller budgets for hunting. So, um, yeah, so you guys mentioned the playbooks a couple times too. Um, maybe if you could jump into that a little bit more, what that looks like.
Is this, um, again, is that, you know, bundling some TTPs together, or is this, um, you know, sort of step ABC things that you're looking for? What kind of, uh, stuff do you look at in terms of playbooks? And yeah, in terms of doing the hunting? Yeah, I mean, a play in essence is just, um, it's just logic described in English. So if an event comes in and it's a process create event, meaning like a process just started, and the, you know, the path in the executable is this and the command line contains this, then fire an action.
So it's just logic and then actions that are fired. The action could be save the event, it could be tag the event with like an alert, you know, indication. It could be send an email, put something in Slack. So again, it's kind of like a little bit like orchestration in that sense, but on the raw data. And a lot of times we'll write plays that are looking for certain behaviors that we know that attackers are using, and then what they'll do is just tag that event with an alert, and then that event will keep going through the pipeline, end up in an Elasticsearch cluster or something, in an alert dashboard.
And so there's a lot of different ways you can use it, and that's, that's where I said, you know, we kind of have our way and we have our plays in our playbook that specifically is looking for targeted attacks for the most part. We're not trying to find everything, but Chris, I'll let you kind of fill in the gaps there. Yeah, I mean, the different kinds of playbooks we have are— there's obviously, there's the patterns, they're your detection or hunting or alert patterns. Those are the ones that have the high fidelity. We have correlators, so we can correlate some events against events that occur later on.
So another playbook might be preprocessors. Like, okay, I've got Sysmon event coming into my platform. I also have Carbon Black events. Let me normalize it so I only have to write one pattern later on that applies to either one of those. And we have other things like classifiers.
Classifier might say every time you see command.exe, PowerShell, PowerShell.exe, classify it as shell. So later on I can write a pattern that says, you know, this sort of browser launched a shell, and then you're able to have a little more abstract patterns in that way. Right, bring it down a level so you don't have to constantly make sure you're capturing everything. Exactly, and you're not having a regex show up 107 times in your plays. A lot of people do that kind of stuff at index time with Splunk.
You know, they'll use Splunk and then they'll have, what are they, like extracted fields and other things that happen where, you know, you may want to do a regex on the command line to pull out something and Um, whereas the way we do it is we do it in real time. So like, events are kind of messy when they come out of Windows, right? Like, you have, you have some fields in there that have a lot of extra data that you don't need, and you're paying a lot of money to store that. Yep, somewhere. And so we just have a play that says remove these fields because we don't need them and we don't want to store them, you know.
So again, so it's like we get the, like, normalization, we get the events how we want them, we do all the different, um, like hunting things we would do manually, we do them automatically with these plays. And then what comes out the other end is like, you know, a nice-looking event that it's already tagged with whatever you need. And, and you can still store it and hunt on it later, but you also can trigger something to happen to alert you. Yeah, happen in real time. So yeah, you're getting Windows event logs and it's, you know, the beginning of each one it says it's XML format, right, and the version number.
Okay, well, now that I know that, I can just get rid of it. Well, and then there's a field called message that has the entire event repeated as a string. So, okay, we don't need everything twice. Let's not pay double to these storage companies. Yeah, so you also, you guys mentioned earlier that you're targeting MSSPs.
I think that that's sort of an interesting prospect, and I've heard from other companies too, not necessarily in this space, but it's because people don't necessarily have the resources, they're looking more to the MSSP model, but then those MSSPs are still on sort of that traditional model where it's, we're just gonna throw a bunch of people at it, right? They may or may not be skilled, and so you're gonna get the same services, you're just not gonna do it yourself. So I think that's a really interesting thing to think about, to try and make the MSSPs better, right? So that we can get better services from those service providers. That's partly why we have a class too, because like hunting is still relatively new, especially on endpoint data.
And so, you know, that's why we want to offer a place to train people like MSSPs as well, um, you know, to learn how to use our tool. It's not even for our tool, it's really to learn how to hunt. So, right. Yeah. But have you guys— how many people have you put through that class?
Has it been pretty popular? Yeah, probably. Probably kind of done it maybe once a quarter on average. Maybe like 50, 50 people or something. Yeah, something like that.
Yeah. So it's— classes are pretty small. We don't like to get— we don't like to let it go. Try to cap it at 10. Yeah.
2012. Yeah. And we kind of almost do them ad hoc at this point. You know, as people keep asking for it, we'll put one on the calendar. But we've talked about trying to get a regular cadence with the class.
So nice. Yeah, definitely a lot of interest though, for sure. So a little bit more on the company itself. So you guys are— well, I guess, you know, give me a little bit more about the company. You know, how big are you, where are you sort of along your life cycle, um, that sort of stuff.
Yeah, yeah, we started a year and a half ago. Um, we're what, 2 and a half, 3 and a half? How are we, how are we saying it, 3 and a half, 2 and a half? 3 people. We're just, we're a handful of people.
Yeah, some of it, you know, part-time, some kind of more partner relationships. Um, but very, very early still, right? And, and as Chris mentioned, you know, we kind of started off you know, doing some consulting and, and, and offering a service, more of a hunting service, right? And then kind of almost just made our own decision that, all right, we've done that and we enjoyed doing it, but now we want to just help people do that. And so that— so we still are going to continue to train and consult on helping people set up a hunting program, but we also— our main focus is going to be on, on just enablement, like building out a platform to help people do that.
So we're kind of, kind of, I would say, over the past few months shifting our focus to be more of a product company. So relatively new in that department. And so, have you taken on funding, or is this using the consulting piece to kind of fund the development efforts? Trying to bootstrap as long as we can. I think, I don't know, bootstrapping sounds fun, but it definitely is a lot of work.
Funding is something we talk about often, but we're not quite ready for that yet. We want to get a little bit more adoption of our platform, get some feedback from from people using it and, and kind of see where it takes us. So yeah, the consulting and training definitely help pay the bills, um, you know, for the development time that Brian's been doing. But it's also strategic for us too. Like, we don't ever want to stop being a part operationally, whether it's services or training, however that ends up looking, because we don't want to become a pure platform company to the point where we actually don't know how to use the platform anymore, right?
It's also like The more we can be involved operationally, even if it's just helping other companies, the more that's going to drive a better product that we can make and that we can empathize with our users better. So we kind of don't want to lose that piece. Yeah, kind of make sure you still have that services arm that can come in and, hey, well, you're going to use our product, but we'll come in, we'll train you, we'll make sure that you can use this the way that you need to use it, that kind of stuff. Yeah, exactly right. Nice.
So do you— it sounds like the product side is pretty new. Do you guys have a roadmap areas where you think you're going? I'm not asking you to give away all the secrets or anything like that, but we don't even have a page on our website yet about the product, so that'll probably come next week. Maybe when this thing airs. When this airs, there will be.
So that's step 1 in product roadmap, announce product. We've definitely got a long roadmap, and but right, you know, because we know what to build, right? Because we've done this and we know the pain points. And so we've kind of, we've gone a pretty long way down that road of knowing what to build, but we want to kind of take some steps where we pause and get feedback from people. And, you know, we do have a handful of people using it, and I think we kind of want to make sure the feedback we're getting from them matches what we know, you know, because we're kind of experts at using it, but not everybody's going to be.
And so there's going to be different requests that we're going to try to, you know, try to build into it. So yeah, we have visions of doing some more advanced analytics directly, you know, maybe some batch analytics, maybe machine learning algorithms, more stuff inline, that kind of, that kind of stuff. And, and just kind of being— we would love to be a hub of just process endpoint process analytics, just knowing, you know, what's normal for a process. Is it normal? Does it normally do that or get launched by that?
That kind of thing. We just haven't found— there's not a central spot you can go to anywhere to get an answer to that besides, you know, when you put a process name into Google and you get about 75 automated pages repeating your Google search. Yeah, yeah, we definitely have a good corpus of data to draw from, and that's one of the things that we're also gonna at some point in the future launch a kind of a search engine for process, like, process behavior data in Windows or other environments as well. Nice. Because there really is no go-to place for that right now, and that's something we've spent the last 5 years, you know, kind of becoming experts on what's normal for like Windows behavior, you know, underneath the hood.
So, and then also like just having data that we can draw from, you know, and anonymize, like we can actually capture some of that. So I search for a process, like this is like 95% of the time this is its parent, these are its children, these are the DLLs it loads, these are the network connections it makes. And it's really helpful for people when they're hunting to see if what they're seeing in their environment matches what's normal for Windows. Yeah, and I can see where that would be cool to build into the product too, right? So, hey, we just saw this behavior, it's 73% expected.
Yep, right, exactly, exactly. So maybe don't pay attention to this one quite as much because it's most likely legit, but you still have a chance that it might not be. So, you know, if you got the time, look at it or something like that, right? Exactly. Yeah, and we've got about 100 of those things in our head that we want to add into the product as we go, so So we're kind of excited about where it can take us.
And we've made a strategic decision to keep it in the cloud. We know not everybody wants to send their data to the cloud, but trying to manage a purely cloud-native platform as well as one that's going to be on-prem is just a big challenge. And so we've made that decision to be cloud-native. And we're also, for any more technical people out there, trying to stay as serverless as possible. What that does for our customers is it keeps our costs way down, which means we can offer a platform like this for way cheaper than you normally would be able to because we don't have to have massive clusters of servers.
We can pay for serverless architecture where you pay as you go. So we pay as our customers send events through the platform, we pay a little bit and then we charge them a little bit. And the beautiful thing is we can, one of the visions of the roadmap is you can maybe be a single licensed user. You just go to the website, pay whatever, a few bucks a month for your single license, and we can scale and be profitable with that one license. And we can also scale to a very large enterprise too.
So that's our goal. I mean, we're pretty much there now. We just haven't built in like the mechanisms for billing and all that stuff so it's self-service. Yeah, it really takes a lot of forethought to offer a product that can work for one person or for an enterprise, right? And so that's kind of what we— the goal we've been moving towards with the serverless.
One person can use it and it actually is worth our time to let them use it, right? And then also an enterprise can use it and it'll scale just fine. Nice. Yeah. And then you mentioned you guys have some partner companies that are testing this out, working through it with you guys.
Is that— do you feel like you have a good partner ecosystem built out? Are you guys looking for more people to participate? Absolutely looking for more. Yeah, we feel like the more the better. Um, for sure.
Um, it just gives us feedback. It gets, you know, kind of gets the word out and gets, um, real people using in the real world, and that's, that's ideal. You know, we could, like I said, we could keep building this for ourselves. We know what we want, but we want to make sure others are able to get as much out of it as we do. So, um, I'm going to go out on a limb here and say that there's not a formal way for people to get back to you other than emailing you if they wanted to get involved in that, since the product isn't even on the website yet.
But maybe by the time people are hearing this Yeah, there will be also. Yeah, there'll be a little spot down there, but info@vector8.io. Honestly, now is really timely because of where we're at. We kind of just hit a milestone with the base set of features that we wanted in there, and it's a great time for people to try it out for free. And, you know, give us— it kind of helps us, kind of helps them, you know, evaluate it and see maybe what they're missing with what they currently are using.
And so yeah, definitely reach out. Nice. So You know, earlier you, uh, Brian, I think you mentioned that, you know, both of you guys sort of independently, uh, your families wanted to move to Colorado. Yeah. Um, how's that been so far?
Has it, you know, have you enjoyed Colorado? Enjoyed not only Colorado itself but the, the security community here? Any thoughts on that? Absolutely love it. Yeah, like everything about it.
Yeah, I don't think we've ever made a better decision. I mean, my whole family loves living here. Um, we love the outdoors and Coming— no offense to Indiana, but we were in Indiana for 4 years and it's like everything about it, if you compare it, it's not Colorado. Like the weather, like the views, unless you like cornfields, you know? Right.
So yeah, we love it. And then the fact that there's so many security people out here is awesome. That was a nice surprise. You can find security people anywhere, but like not really like an ecosystem of people that are kind of passionate about it. So yeah, when we moved here, we Very first weekend we were here, my boys discovered there's a, there's a Lego store in the mall close to us.
So right away they were hooked. And the very next day the Broncos won the Super Bowl. So they're just like, Colorado is amazing. Yeah. And I think the next weekend we went tubing in Fraser.
So I think we— they've been pretty much excited since we got here. We've loved every minute of it. I don't think— Brian and I talked a lot. We didn't expect there to be this much of a security community here. And I think we've been very surprised.
Even actually an entrepreneur community. Yeah, we knew there was a startup culture here, but until you move here and kind of like start to see it, you know, startup and security, it's been kind of a pleasant surprise. Like, we knew it would be better than Detroit and Indianapolis where we both came from, but yeah, it's been great. Yeah, and so I met you guys both at the Red Canary offices. Have you been working with, with other security startups in the area.
Um, obviously you know those guys. Yeah. Um, you know, they, you know, sort of on the back end do some similar stuff. Similar stuff, but internally, right? Right.
Yep. Um, yeah, they've been great. We, we kind of— funny story about how we met them. I don't know if we'll tell it or not. We kind of, we kind of stalked them.
Oh yeah, that's right. We just kind of wanted to be like, who are these Red Canary guys? We showed up at the office and, and it was one of those offices I think were like high security. There was some other like secret stuff going on, and so we got reported as like being suspicious. Got it.
Eventually met the guys and, and had a good friendship since. Yeah. But yeah, definitely been talking with other security companies. Swimlane, we're doing a webinar with them next week. And, um, so it's just been neat.
Like, even if there's a lot of overlap, it's just neat talking with people that are doing similar work. Yeah. Yeah, well, cool. We're getting close to the end of time for the interview. Any other stuff that you guys wanted to talk about?
Anything that people need to know about? Um, no, I don't think so. I'll be speaking at the Rocky Mountain Information Security Conference. I'll be talking— I'll be sharing some war stories is the goal. So I mean, I tend to get very philosophical and strategic when I, when I get on a soapbox, which is often.
But I like to back it up with like real-life facts. Like, here's the stuff we saw, this is how we saw the adversary move. And this— so I plan on sharing a lot of war stories during that conference in, I think, May. Yep, sometime in May. Yeah, and our next hunting course is May 1st through 3rd.
It's actually going to be here, so like very casual, laid-back atmosphere. We're going to cap it at 10 people or so, so people are interested in that, that's on our website. Nice. So vector8.io if people are interested. Yeah, anything else?
No, I'm good. Awesome. Well, thanks guys. Thank you. Appreciate your time.
Good talking to you. And everybody go check out Vector8. Thanks. Awesome. Thanks.
Cool. This is Alex Wood, and we'll talk to you next time. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, account calendar of upcoming security events and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado Equals Security.