All episodes

David Wolpoff, CTO of Randori

Apple Podcasts Spotify SoundCloud

In this episode:

David Wolpoff, CTO of Randori is our feature guest this week. News from: Navigant, Arrivo, Girls Go CyberStart, LogRhythm, Red Canary, and a lot more!

Millenials + Autonomous Vehicles - Hyperloop = Traffic

Millenials appear to like Denver. Our traffic is bad, but not as bad as a lot of other places. It doesn’t look like the hyperloop is going to help us with that at all. There are going to be a LOT of automated vehicles on the road soon which might. SANS and the State of Colorado are running a program again to get girls interested in cybersecurity. LogRhythm’s CTO has a taken on the maturity of your security operations. And finally, Red Canary talks about evasion techniques in phishing emails.

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript12016 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is episode 106 for February 25th. And since I am the one introducing the podcast, that must mean that Robb is on vacation.

Robb is actually taking a little time off going to Mexico, so I have a special guest host today, Brian Byers, CEO of Red Canary. Welcome, Brian. Thank you. Thanks for having me. Yeah, thanks for doing this.

Glad to have you here. How are things going? Great. Happy to stand in for Robb anytime. He's definitely in a warmer place than we are right now.

Yeah, I was shocked by the amount of snow that we got overnight, so glad we were still able to get together and do this. There was, you know, no snowpocalypse or You know, Blizzard, nobody's stuck in here. Before we jump into the news, let's get through our announcements. We do have a Slack channel. So for those of you that want to collaborate with a number of other, almost 800 people in the Colorado area around security, come join our Slack channel.

You can find out more about that by going to the website, colorado-security.com. There is a convenient button right there on the front of the website that says Slack. Just click on that, it'll take you right to the Slack workspace and you can sign right up. And that's definitely the Slack channel you wanna be on. On the same page, you can learn more about the mailing list and get more information from Colorado Equals Security in your inbox every time something new comes out.

Yeah, and obviously if you're listening to this podcast and you're getting it somehow, we would love if you subscribed so you get it easily in your podcast player, whether that's iTunes or Google Play or whatever store it is that you get your podcasts from. And then while you're there, it would be great if you could rate us. I think having a great rating helps with other people just discovering the podcast. Absolutely. And huge thanks to all of our Patreon supporters.

You can support us also through the Colorado Equal Security website and help us continue doing everything that we're doing. So we had an interesting discussion before we started, Brian. What do you think? Is it Patreon or Patreon? Whenever I see that word, for whatever reason, I think of Harry Potter and Expecto Patronum.

And so it always makes me think Patreon. Okay, no, that makes sense. But everyone who knows me knows me well enough never to trust me when it comes to pronunciation of words. Oh well, good enough, good enough. I always say Patreon, but I have no idea what the right answer is.

So we're going with Patreon. And then finally, if you are not up for sponsoring us financially, which is perfectly fine, we would love it if you just told a friend about Colorado Equals Security. Pass on the word, have them go to the website, listen to the podcast. Use all of the resources that we have put out there. The more the merrier.

So before we jump into the news, I also want to thank one of our new patrons this week, Timothy O'Brien with Educause. Thanks. Signed up for our $10 a month, so he gets a shout out on this podcast and a free t-shirt. So again, thank you for the support. We love all of our Patreon supporters.

It helps us cover the costs that we incur for doing Colorado Equals Security. All of that money goes directly back into the podcast, the web hosting equipment, t-shirts, all that kind of stuff. So anyway, thanks Tim O'Brien, we appreciate that. And let's jump into the news. So I've got a little theme here at the beginning of the news.

The first story, you know, millennials happen to be flocking to Denver among other places. So an article came out this week saying that Houston was at the top of the list for net migration of what they are calling young adults, what some of us refer to lovingly as millennials. And followed by that was Denver and Dallas. So Denver had an average of 12,667 millennials migrating here per year. That seems like a lot of millennials.

That is a lot of millennials. But as we know, there are a lot of people coming to Denver in general. Yeah, so overall though, in terms of metro areas in the top 5, Texas was the best in terms of millennial migration. They had in total 32,398 millennials per year, followed by Washington and then by Colorado. So still in the top 3.

So we're getting, getting lots of millennials here. The big losers for millennials, they were New York, Los Angeles, and Chicago. So I don't know if I would have guessed that or not. I guess millennials are not fans of the really big cities. I don't know, it's the Chicago one surprises me most, right?

I can see some of the shifts from New York and LA because of cost of living, but Colorado, I mean, I was born a couple hours north of there. It's an awesome city to be in unless it's 3 weeks ago, in which case it earned everything you've heard about it being freezing cold in the winter. Exactly. So next, next, let's talk about traffic. So I think probably tied hand in hand there, more millennials come to Denver and Denver's traffic is not great.

Now the good news is it's worse in 18 other cities, which sounds about right to me. That sounds about right. You know, I think people in the Denver area like to complain about the traffic a lot. I think it's a little bit historical in that you know, 10, 15, 20, 30 years ago, things were pretty empty. So there was not a whole lot of traffic here at all.

And so relatively, maybe it is a lot worse, but I have been in a lot of places where traffic is a lot worse. That's my feeling as well. Coming from several years out in the DC area, I will never complain about Colorado traffic. And let's be honest, I think traffic is something you always complain about no matter where you are. That's true.

So there were 18 cities that were ranked above Denver in terms of bad traffic. The top 5 were Boston, D.C., Chicago, New York, and L.A. Those are not a surprise to me. One of the things that I thought was interesting is in Boston, which as I said was the leader, rush hour commuters lost an estimated 164 hours in traffic last year. That is a whole lot of time. I could do a lot of things in 164 hours.

Same here. And to give you an idea of scale, that compares to Denver, which was a loss of 83 hours of congestion. So we're, we're twice as good as Boston, or half as bad, whichever way you want to look at it. The great thing I will say about traffic and the things we have these days is when you do have to drive, you have great podcasts like Colorado Equals Security and others. So you have something great to pass your time.

You know, I have to say though, I've never caught up on all the podcasts I want to listen to. So maybe I should move to Boston so I have more time in traffic to listen to podcasts. It could be that. It also comes down to what speed do you listen to though at? Yeah, I'm a 1.5 guy.

I can't go past 1.5. Start aiming for 2. Man, especially any podcast where someone has an accent. Once I get past 1.5, maybe if you are, you know, with a good sort of neutral Midwestern accent, I could go up to 2, but anybody else, it drives me crazy. Solid use of good and Midwestern.

Yep. I like it. So, So next story, something that maybe would help us with some of this traffic. Navigant released a report talking about automated vehicle deployments. We're expected to reach 34 million automated vehicles on the roads by 2035.

So that seems like a pretty big number. They're using a term that I hadn't heard before, which is highly automated vehicles. I always hear them referred to as autonomous vehicles, but maybe that's the official term. Um, so, um, there's supposed to be about 2.6 million by 2024, and then we get the really big ramp up to about 34 million by 2035. Um, also deployments are expected to be sort of limited, um, until about 2024, and then I think that's when we really start to see that, that rapid rise.

Um, but, you know, maybe that will help us get even lower on the, the traffic index. Where do you think it's going to start? Do you think it's going to start with consumer vehicles? Do you think it's going to be, you know, freight carriers? And will it be in cities or in rural areas?

Yeah, well, I think as we're already seeing, you can have both a car and I think probably some freight vehicles that can do, you know, semi-autonomous, right? So it's, hey, I need to be sitting there driving, either having my hands on the wheel or being paying attention or whatever. And, you know, I could hit a button and have it work for me for a little while. Um, I think that the hard part is going to be the— in those, those edge cases, right? So if you're in a city, if you're, um, you know, in someplace that things can change unexpectedly, it's obviously harder for those autonomous vehicles to work.

So I could definitely see sort of long-haul trucking maybe being one of those first places. You're out on the interstate highway, you know that you just have to drive straight and maybe make a couple little lefts and rights, you know, for several hundred miles, that's pretty easy to automate. So I would guess that that's probably where the first highly automated ones will be. Those are the ones that get me most excited. Growing up in a family, you know, who had a truck driving business and still does a lot of that, the idea of, you know, what Tesla is building around long-haul carriers and trucking routes like that being run by mostly autonomous vehicles, Especially if you think of things like I-70 or I-80 across the middle of the country.

What an awesome place to be able to automate that and let people— let runs run longer, higher safety, less accidents. That gets me excited. Yeah, um, I will say it does remind me a little bit of those couple scenes in Logan, the, you know, exactly the last, um, Wolverine movie where, you know, there's all these autonomous trucks driving by and they're kind of not, you know, paying attention to anybody else and, you know, maybe running people off the road a little bit. And anyway, um, is that any different than your normal ride down I-70 right now? I guess that's true.

I guess that's true. Similarly related, the Hyperloop, which would be purely consumer, they were running a test track up in Colorado and that unfortunately is no more after Arrivo is shutting down. Yeah. So we had talked about a couple stories within the last year of potential Hyperloop like test tracks. And this company, Arrivo, got a grant, looks like a little over $250,000, to do a test track.

And, you know, the idea there is, you know, Elon Musk kind of came up with this idea. It's sort of the, the vacuum tube analogy where, you know, back in the day, the banks, you'd get the little, little thing, shove your money in there, and your money goes into, into the teller. Instead, we would be putting people in there and, and know, vacuum tubing them around places. So there was going to be this test track, but apparently they couldn't get the money and decided to close down. So, oh well.

But the good news is we still retain one of them. It looks like the Virgin Hyperloop is still going to be doing some testing in Colorado. Nice. So we look forward to that one. Richard Branson set of companies here, which will mean regardless of how well it works, you'll have a great time.

That's right. Luxury Hyperlooping. Sounds like a dream to me. Yep. Next, we had a story about Colorado's 2019 Girls Go CyberStart program.

This was again something that we talked about last year. This is the second time it's being run. The state of Colorado in conjunction with SANS is running this program and girls can participate. Sounds sort of like a CTF. Sort of competition, and the best participants can win cash prizes.

So it looks like you can get cash, you can get scholarships. I didn't see any quotes in here, but I do remember some quotes last year from Debbi Blyth. So I know that this is something that the state is very proud of. Also, this is for girls 9 to 12, or sorry, in grades 9 to 12. Registration opened on February 18th, and the play begins on March 20th.

So if you have high school-aged girls, you should have them sign up. Definitely have them sign up. Looks like an awesome program, and send us feedback about how well it works and how we can help get others involved. Next, we have a great article from Logarithm, A CTO's Take on the Security Operations Maturity Model. From Chris Peterson over at LogRhythm and was a lot of fun to read through.

That article gives you a great sense of how security programs can be built and focusing on what I've always thought are 2 of your primary KPIs in a security program, which is your time to detect and time to respond. So highly recommend read that from Chris and definitely implement whatever you can. Yeah, I completely agree. We had Chris on as an interview a couple weeks back Great stuff there. And yeah, I mean, it really goes into depth on not only those metrics, but on, you know, some, some things that you can do to help implement those metrics.

I know for a long time there, there weren't great thoughts around metrics for security operations. It was, well, you know, how many events did you respond to and, you know, other things like that that really don't tell you how good a job that you're doing. So I love that these metrics are are coming out more and that they're being pushed. So, so good stuff there. One of the things I really liked as well is that he gave good guidance and created this grid that says, based on how many months, weeks, days, or hours your mean time to detection is, how would you maybe map that to a level of security operations maturity?

Yeah. You know, a lot of times we talk about these things in the abstract. You know, Chris here says if your mean time to detect and respond is in the days, timeframe, you're a level 1. You make it to a level 4 if you're talking minutes. Yeah, no, that's pretty cool.

I think, and it goes hand in hand with a recent research report that I think CrowdStrike came out with talking about how the metric that they were using, which was essentially time to lateral movement for nation-state attackers, and I think the best was in a matter of minutes. So I think that the those operations, secure operations metrics match right up well with those types of models that we're actually seeing from the attackers. Absolutely. Good stuff. And then final news story, we actually had a blog this week from Red Canary.

So Brian, I don't know if you want to comment on the blog at all. You probably have some inside information. I definitely can. I mean, I would— it's a ton of fun, especially for me, to get to read these blog posts. This is in what our team calls their Thready Threat series, where they actually take a threat that they identified during the week and write up what they saw and kind of go as a deeper dive.

And in this case, talking about a pretty typical topic, defense evasion and phishing emails, with what feels to me like an old-school spin. So instead of gaining persistence and instead of targeting and coming in with your normal phishing attachments, they came in with an ISO. And so Alex and I were talking beforehand, we were remembering back to the ISO images we had and all of the crappy shareware software we needed to mount them and run things off them. This adversary actually figured out how to put the malware on the ISO and then keep it persistent with the at.exe tool. And so all around fun read.

Frank's an awesome author and telling these stories. So I learned a lot. Good stuff. All right. So that is the end of the news.

Let's jump over to the Slack message of the week. Thanks again to Andre Gaeta, who sponsors our Slack Message of the Week. He has been doing this out of his own pocket for an awful long time now. And of course, if you win the Slack Message of the Week, you will be given a credit to choose something from the Colorado Equals Security store. So this week, our Slack Message of the Week was from Jimmy Woodard.

So thanks, Jimmy, and you get the award for starting, well, requesting to start the CTF channel in the Slack workspace. So we had a nice conversation with some folks talking about potentially doing some CTFs, getting together with people in the community and going through those. And Jimmy said, hey, I'm gonna do this. I have one that I wanna do. Let's start a channel, get some people together and go through the CTF together.

I do have to say that there was definitely a lot of chatter on that. Within the last 24 hours, people actually working together doing some CTFs. So that was pretty cool to see. So thanks, Jimmy. We will get you hooked up with Andre to get your free Colorado Equals Security swag.

So let's go ahead and now jump over to events. First on the list, we would like to remind everyone that tickets for SnowFROCK are on sale. I know that these are limited in quantity, so I don't know if there are even tickets still available, But this is coming up quick here, 18, 19 days until the conference itself. This, of course, is the Front Range OWASP AppSec Conference. So you should go ahead and check that out.

Go to snowfrog.com to get more details. And speaking of the CTF, SnowFROC was actually the first ever CTF I participated in. Nice. Yeah, they run an awesome program there. Yeah, it's a great conference.

I will be there, looking forward to it. On February 26th, we have the Managed Security Services Forum in Denver. Also on the 26th, SecureSet is doing a Cybersecurity Career Convo with Jason Zaffuto on pentesting. The day afterward, on the 27th, the CTA, or Colorado Technology Association, is holding their Technology Day at the Capitol. Again on the 27th, The ISC² Pikes Peak chapter in Colorado Springs is doing their February chapter meeting.

The NCC is hosting the SMALLS meeting on the 28th. On the 1st of March, SecureSet is doing a capture the flag for their cybersecurity hackathon. And then back to the NCC on March 6th, we have Beyond Bitcoin: Blockchain 101 for Beginners. So if you want to be a blockchain wizard, go get your start there. And then our last event for the week, SecureSet is doing another Hacking 101, but this is on PowerShell on the 7th of March.

So if you're interested in learning about PowerShell, go check that out. Those are all of the events. So let's go ahead and jump over to jobs. Robb is not here to talk it up, but he still does have one job that is open. If you are into security operations, then Ping is hiring a manager of security operations and engineering.

So go check that out. Highly recommend. Who would not want to work for Robb? Exactly. Frankly, I would do it regardless of what the price was.

I've thought about it, but you know. Maybe we should both apply and see who wins. That's right. Let's both apply. You probably have more experience.

Hey, I run a security operations company. Maybe I'm qualified for this job. Anyway. Arrow is hiring a senior incident response security engineer. Western Union is looking for a senior info security analyst.

NREL is looking for an energy systems cyber-physical security researcher if you want to cross the kinetic barriers. Yes, we had talked— I don't know if it was the same job or one similar, but NREL has got some really cool sounding jobs lately. Cyber-physical and energy systems, that sounds really, really cool. Denver Health is looking for an IS analyst security Great West brings together security and legal and is looking for a legal counsel focused on privacy. CenturyLink is looking for an information security engineer, and this one was actually in Broomfield, so I'm guessing it is the, uh, level 3 side of CenturyLink.

US Bank is looking for an information security systems architect. Kaiser Permanente is looking for a threat intelligence Or sorry, cyber threat intelligence undergrad intern. So if you have kids that are in undergrad and want an internship for the summer, have them check that out. And finally, Valentium is looking for a medical device cybersecurity systems engineer. So a neat mix of general purpose and general focus information security, as well as some specifics on energy and medical devices.

Yeah, that again looked like a cool job. It looked like Valentium is maybe a development group that does development around medical devices. So Good to see that they're trying to hire some security people as well. So that brings us to the end of the newscast. We will now get over to our feature interview.

And this week's feature interview is with David Wolpoff, who is CTO of Randori. We kind of teased this last week. Robb sat down with him, talked about Randori and what it is that they do. Brian, you know David, and I'm sure if I say David that it sounds a little bit weird to you because I think most people call him Moose. Exactly.

I know him very well as Moose. He and I actually worked together back at Mantec back in DC, then at Kairos where we spun Red Canary out of, and Randori is actually the latest company and has a lot of the team members that I got to work with there. So there is frankly no one better at network operations and simulating adversaries than those guys. So really excited to see what they're doing with Randori. Nice.

Uh, well, everyone will get to hear from them about what they're doing. So Check out the interview, and we will talk to you next week. Sounds great. Thanks for having me. Awesome.

This is Robert Wood, VP of Security at Alps Fund Services. This is Colorado Equals Security for Colorado security professionals by Colorado security professionals.

Welcome to Colorado Equals Security. This is Robb, and today I am sitting with Moose, David Wolpoff. You are the, I believe, CTO and co-founder. For Randori. Thank you.

And co-founder of Randori. Yep. Awesome. And I bet that there is at least one person listening who doesn't know what Randori is. So we're gonna fix that for them.

Sweet. But let's not do that yet. Let's start off by, by talking a little bit about your own background and yourself. And one of the things I love to do as we start these conversations is, is kind of get into your head. And let's just say I take away your computers from you and you have to do something else What would you like to be doing?

I would throw the truck in 4 and I'd be up in the mountains fishing or camping somewhere. So yeah, get away from the people and the scene down on the flatland. So when you're, when you're up in the mountains camping, are you— can you open up your eyes and see the stars, or are you looking at a tent or the inside of a truck? What are you looking at? Well, so most of the time if I'm up, me and the missus be out there hammock camping most of the time.

So definitely looking at the stars unless it is raining actively on my head. In which case it may be throw the tarp over the top, but pretty much just wilderness and the sky. So hammock camping— I am a— I'm the biggest fan of hammocks that I'm aware of. I love to lay on a hammock. I have an office hammock.

I don't have an office hammock, but I do have 2 hammocks at my house, and I'm the only one who uses either of them. So it's— that's pretty good considering the ratio there. Yeah, but I've never hammock camped. I assume what that means is you go find 2 trees that are about the right distance apart and Yep, set up. That's pretty much it.

2 trees, about the right distance. I usually carry a reasonable amount of cord so I can get some good distance, but yeah, it does limit your camping above tree line for sure. So this, this is a family podcast, but I'm gonna ask you a question. When you're hammock camping with your wife, is this a 1 hammock situation or a 2 hammock situation? Well, you can do both if you really want to.

It can get difficult, I guess, but No, usually we have our own for sleeping at least. We'll leave it, leave it at that. All right, so you mentioned, you talked about fishing, and, and yeah, at least you mentioned to me earlier fly fishing specifically. So, um, I have, I would say I have fly fished. I'm not a fly fisherman.

Yeah, I think that's all of us. Uh, I thought it was a lot of fun. It was nothing at all like what I, um, what I saw in A River Runs Through It when I did it. Yeah, I was no Brad Pitt. Um, I'd ask you, like, when you fly fish You know, are you standing on the side of a river?

Are you on a boat? Are you in the middle of a river? How do you do it? Usually in the summers in Colorado, just wading. So river shoes, standing in the middle of a river fishing.

This time of year, more from shore. Yeah, if I can get on a boat, great, but most of the waters in Colorado in the mountains, not so much. Mostly just wading around. Yeah, that's a good excuse to be out, out in the wilderness, I think. So do you have a favorite fish that you've caught?

And this is Fish Tales, so you can tell me whatever you want and I'll believe you. Uh, you know, I gotta say, I was up in the Yellowstone River outside of Livingston, Montana, and just caught a gorgeous little rainbow. It wasn't enormous, it was just the first fish that I caught on that river, and it was incredibly impossible for me because I'm also a terrible fisherman, and all the fish up there are smart and they're used to much better fishermen than me. And I finally got one and it was awesome. That's awesome.

And so the one that you catch, I guess. The one you catch is the best one. Yeah. So I, I have actually only— I haven't fished in Colorado for quite a while, but I got the opportunity to go fishing in Alaska, which I believe has spoiled me for anywhere else in the world. That's my guess.

So when you go fishing in Alaska, at least where I did, like, you know, you're catching a fish every 3 to 5 minutes. It's just ridiculous how quick you're catching fish. Yeah. Is it more in Colorado for you an exercise in doing nothing, or are you catching fish on a regular basis? Up in the mountains, you catch a lot of fish.

Do you? Not big stuff, right? But the little, little mountain river trout are hungry and stupid, and so they bite pretty much everything. If you're fishing here in town, you can actually fish here in downtown Denver at the Cherry Creek River. Yeah, at the Confluence Park is a good spot, and you can pull some pretty decent fish out of there, but they are wily.

And you need to be a little better. You're not the only one trying to get them. Yeah, for sure. For sure. Cool.

Well, that's fun. And hopefully some of those folks listening here might connect with you and talk about getting off the grid. And yeah, for sure. Pretty cool. Let's talk about your background now.

I know you're one of the very few native Coloradans I've had in the podcast. Yeah. Born and raised in Colorado. Which part of— what part of the state are you from? I grew up in Boulder, born and raised there.

And then after college, I went and lived on the East Coast for a bunch of years and now I'm back in Denver. What's your high school? Fairview. Fairview, all right. And then where'd you go to college?

CU Boulder. Finished a master's degree there. And you did your bachelor's and master's both there? Both electrical. All the way through?

Yep, electrical engineering. And one of those crazy few who snuck through it. What was your plan when you got the EE degrees? What were you looking to do? You know, it's an excellent question.

I started out doing interning up in Longmont doing electrical engineering, like, intern work late high school. And that kind of convinced me that all the electrical engineers that I met were smart. I wanted to do that because it seemed cool. I didn't really have a plan. I got into doing embedded systems and electronics design.

Yeah. And then in mass— I was doing my grad school master's degree, I was just studying cryptography, which is just like math, right? Just math. And I was looking for gigs that put together electrical engineering, embedded systems design, and crypto. And so that kind of kicked me into this whole career field.

Awesome. But no plan per se, just good luck. Well, I think most of us got here on accident, right? I think so. You know, you create some skills, have some fun, and all of a sudden you're in security.

Yeah, well, I love what you do, right? But so the— I want to just a little bit more on EE. Did you, did you do any design, like creating circuit boards, or what kind of, what kind of work did you do? Oh yeah, I mean, I still have my own soldering iron that I loath to let other people touch. And I occasionally still will design circuit boards.

Yeah, you know, in college it was very expensive. Now it's way cheaper. Yeah, I did a turn working at SparkFun up in Boulder. I guess now they're Gun Barrel. And so kind of got into the early maker scene and was connected with all that stuff.

It's been a wild ride. Yeah, that's really cool. I worked at a, at a chip plant called Variel here in town, and we had We basically made chips for cell base stations back when we were wiring the whole world. It was a good business to be in. There was a bunch of EEs there, and I was always interested in what they did.

Anyway, so I have a little bit of interest in what you did. Yeah, for sure. All right, so talk to me. Obviously, the skills, getting into cryptography, that's a pretty short line to getting into security. How did you formally go from, hey, I got an interest in this, I learned about some cryptography, to saying, I'm going to to get a career there?

Yeah, so one of my advisors was trying to get me to do a PhD, and I was done with school. I just needed to go do something else for a while, so I decided to get out. Started looking, literally monster.com, looking for jobs that had keywords that were a good fit for the skills I had. Ended up interviewing with a company out in DC doing digital forensics. And so I transitioned from doing like embedded system design to embedded systems reverse engineering and hardware forensics.

Was that for like incident response or something else? This is mostly in support of overseas conflict. So this is like heyday of Iraq and Afghanistan. And so like a lot of like digital forensics. So I figured out like how to get data out of things, and then I would teach people how to use those techniques elsewhere.

So that sounds like a Potentially troublesome skill set to have. I can see that, you know, that could be used for good or for evil. Well, I mean, it was in support of US government stuff, you know, and you see a lot of the same things show up in law enforcement. So people nowadays with, you know, things like the Cellebrite technology having made it all the way through the news, right, and people having heard about all of the kind of digital forensics becoming a thing, yeah, you know, I got into mobile device forensics and embedded systems forensics before the iPhone was a thing, right? So before we had smartphones and figuring out when phones were just media, how to treat them like a hard drive and get all the data out and you process it.

And then as technology advanced and cell phones became these embedded computing platforms that are incredibly powerful and got secured and hardened and resistant, I got into hacking into cell phones for forensics. At that point, mostly commercial support that we were doing. So companies I was with were doing like, we would do software development that would then show up as the product that some popular forensics company would be selling out to people, those types of things. A lot of what I was doing was just developing zero-day vulnerabilities for mobile devices so we could break into phones and that sort of thing. And that turned into a career of breaking into phones and then breaking into everything else and kind of went over to the dark side and just got into breaking into software, breaking into systems of software, breaking into corporations.

So let's walk through that a little bit at a time. So you went to the company in DC. Yeah. What's the name of the company? So I worked for Mantec for a while.

Mantec. Okay. So when you're working for Mantec, you know, you're helping them, you know, learn how to reverse engineer and get into these systems. How long did you do that? Digital forensics for about 4 years with them.

Okay. And then, you know, what did that lead to for you next? So I took a gig with a company called Kairos Technologies. Kairos is, I guess, now fairly well known in that they've spun out a couple of things including Carbon Black, Red Canary. And so I got in early with that crew, spent a lot of time helping them build out their forensics and offensive computing research stuff, and then we worked with that crew building out an offering we called Hacker on Retainer, which was like high-end red teaming.

So kind of like pen test on crack, breaking into big companies. What does a pen test on crack look like? Maybe walk me through an interesting story there. Yeah, so the types of engagements we were doing, we were trying to figure out, we were really experimenting around what should a red team engagement or a pen test really look like? What's the value proposition?

What do you want to do? And so we got into this high-end goal-oriented attack stuff that we were doing where we'd work with a customer, it's a big corporate client, and try to figure out what are you worried about a hacker or a group of hackers or criminal enterprise or nation-state doing to your business? And what would actually go wrong? What are you trying to protect? All the conversations that you would expect like a CISO would have had with the CEO and very few ever actually do.

And so we'd go through that dialogue and then we'd put a bounty on different objectives that they thought a hacker could— Flags, right? Yeah, exactly. So hey, if you can get to our source code, we'll pay you this much. If you can steal a code signing key, it's going to look like that. Get to the CEO's email and it'll look like this.

And so we try to incentive align the attack in the same way or a similar way that you'd see like an actual adversary incentive align their attacks, right? They go after stuff for a reason. So try to figure out objective and incentive alignment and then go do the hacks, right? So in a typical engagement, we'd be dropping 1 or 2 like custom zero-day that we were developing against these organizations. One client that— you kind of feel bad for some people that get kind of caught up in the fray.

But like, process engineer working for a very big company is going to a conference, is worried about the precision water control system in one of their industrial processes. Goes to a network engineer and says, hey, put this controller on the internet so that I can reach it while I'm at a conference. So we're monitoring their perimeter over the course of maybe 60 days. Able to get into the company at all. It's starting to look bad for us.

Guy plugs something into the internet. Hey, that's weird. What's that thing? Find a firmware image for the device online, download it, tear it apart, find a couple vulnerabilities in it, get into this device, pivot through that into their network. Ended up lingering inside their infrastructure for like 111 days or something all told.

So this is a pretty long engagement then. This is not a— Yeah. Minimum 6 months, ideally a year engagements for companies with very advanced security postures. Yeah. So that's pretty cool.

Yeah, it was a lot of fun. Like a lot of fun. Yeah, and you gotta feel bad for that guy, right? Well, I mean, he's just trying to do his job, right? And he probably thought he did it pretty securely.

It sounds like he didn't just like open up a port to the internet either. No, they did it. I mean, the security office didn't know about it, right? Of course. But you find all kinds of fun stuff picking on applications like that.

If you have a login page and I just put a whole bunch of A's into the password field and the thing goes away for 92 seconds while it reboots, it's a good indicator that something's gone wrong. So any other stories about that you want to talk about? I mean, we could go all over the place with these types of things. Okay, so how long were you at Kairos? Oh man, long time.

So 2011 to end of beginning of 2018. So, oh man, holy smokes. Yeah. Okay, so you got to see, you know, the spinouts. Oh yeah, it was, it was awesome.

So definitely I learned so much from that crowd, a bunch of very bright people. And then obviously, you know, getting to just have access to what became this giant behemoth of Carbon Black. And then of course, I remember Red Canary before it was a thing with the name of Red Canary, right? Yeah. So I know Brian came from Kairos, Brian Beyer.

Did any of the other team come from there as well? I think Chris and Keith McCammon both were also over there for a while. How big is Kairos? I guess I don't know much about the company. I don't think it's ever been more than maybe 40 people.

Okay, so pretty small. So it's pretty small, but every time it would get pretty big, it seemed like we would spin out another company and lose a bunch of people to the new endeavor. What is Kairos? How does a company that, other than Carbon Black and Red Canary, I'd never heard of, how does a company that, like I said, I'd never heard of, create multiple product organizations that are so interesting? Well, it's principally a services company, but I gotta say that The founders of the company had a really great vision of how to treat people well.

They kind of learned the lesson of big corporate about what treating employees badly looks like and then kind of took the mantra of don't do that. And so they just really thought about how do you incent people to be innovative, how do you create a space where people can thrive, and then mostly just get out of the way. And then when you see a cool idea, you run with it. So, you know, the thing that I really liked in running a team there was I had a tremendous amount of autonomy, but it was also backstopped by a bunch of really bright people. Yeah.

And so it's always a great opportunity to have somebody basically funding your science experiments, and then if you have a cool idea, out pops, you know, Red Canary. Yeah. So how— I have multiple questions here. Yeah. You worked for Kairos from, you said, '11 to '18, something like that?

Yeah, something like that. But you weren't in DC that whole time? No, I was not. In the middle of that, moved back to Colorado. Why is that?

Why'd you move back? So my wife and I both have family here. Okay, trying to be helpful to the parents and families. Did you move her out to DC with you? Yeah.

Yeah. Yeah. So when we first got married, it was— we got married and then I jumped in a car and drove to DC for the interview. Yeah, took a gig, and then a month later she moved out. Okay.

So yeah, so you guys were looking for a way to get back and Kairos kind of let that happen. Yeah. Yeah, they were tremendous about it. Now, of course, there's a big crew of their people still here that I just love dearly. It's a great team.

Do they have an office in town? They do. Where's that? It's down south, so not in town. Tech Center area?

Yeah, not in Denver proper. Okay, cool. I didn't know that. And you said you led a team. What was your team?

Was it the advanced pen testing team? Yeah, so reverse engineering, like all the stuff that I might call offensive computing, but really figuring out how to break stuff as opposed to just defend stuff. And then did you guys do that as like a— to create tools for your pen testing to work with, or as like customers would ask you, can you reverse engineer this for us, or how did that happen? Yeah, it was all kinds of stuff. So anything from, hey, tear me apart, tear this apart and do a security assessment of it, to, hey, here's, break into this company, come after us and do this, to my personal favorite was always, hey, a nation state just came and messed us up, here's the after-action report of everything that happened.

Can you guys do all of this again? Yes, yes we can. Very cool. All right, so obviously something happened along the way that gave you an idea, right? Yeah, I assume while you were working at Kairos.

Maybe you can talk about where this idea came from and like kind of what that led to. Yeah, so through the series of inner business connections that occur, I got to know Brian Hazard, who is a one of the early employees at a company called Bit9 that then acquired, merged, whatever, with Carbon Black and became the big thing that it is now. It bought Carbon Black and took their name. Yeah, exactly. Oh, it was a better name.

Hadn't been breached too. Yeah.

Well, yeah, yeah. So Brian and I got together by way of Mike Viscuso, who is still a principal over at Carbon Black. He was one of the founders of Carbon Black and a founder of Kairos. He and I had worked together years prior as well, so just known this kind of crew for a long period of time. And literally sitting at dinner chatting with Brian about the state of security, kind of brainstorming around how to bring the experience that we were giving people through this kind of red team engagement, but at scale.

What were the real value propositions that you can bring from providing a hacker experience, right? Because a lot of times you'd go break into companies and people would feel like you just showed up and punched them in the face and then walked away, and that's kind of a tough sales pitch to run with, right? But everybody that we did this to really loved it. And so there was a lot of hemming and hawing about what is it about the experience of getting beaten up on that people are finding valuable. And there's a couple things that stick out to me, most notably in all the companies that I've breached, it's been really rare for anybody to ask me how to fix something.

You know, most of the problems that we run into are more structural, institutional, political, right? Technology is generally pretty good.

And so we're really just brainstorming around, hey, how could you give people this, like, the red team experience, right, and that different perspective in a way that And we basically said, what we came to was, if you just build this attack platform, right, this theoretical infrastructure that we all assume that nation-states and high-end criminal organizations have, and then instead of using it just to break into companies, actually turn it around and let companies see how the wolves look at the sheep, people could get this experience but without having to pay for the people behind an expensive red team. And, you know, a bunch of hemming and hawing about names later, out pops Randori. So who is part of this founding team? You mentioned a few names. I want to be really clear on that.

Yeah, yeah. So Brian Hazard and myself are the 2 co-founders of the company, and then we pulled, pulled in early a number of advisors as well as some early teammates. And so it's just been a wild ride ever since. And I don't want to skip over the names Randori, it doesn't immediately bring anything to mind for me. Does it have a comp— does it mean something?

Oh yeah, it absolutely does. So it's a term from jiu-jitsu, which I do not do, but one of my longtime teammates, Evan Anderson, is a guy who rolls and likes to choke people unconscious. And as we were drinking whiskey and talking about what names of companies should be, we kept coming back to this concept of practice how you fight. And Randori really means that. It's this freeform, unscripted practice.

So if you've ever seen like a martial arts flick where some dude's in the middle of a circle just getting attacked by a bunch of people, like, we're not going to kill you, but we're definitely going to make it seem real. Yeah, that's, that's the randori. Okay, that's really cool. I didn't know that. So is that Japanese?

Chinese?

Japanese. You guys should know this. All right, um, so very cool. Japanese for practice like you fight. Yeah, I think— I don't know if I like— I don't know the whole cultural construction of it.

I know that it's used very much in the Brazilian jiu-jitsu community. Yeah, which of course has roots in the Japanese martial arts. So you've kind of given a high-level, you know, exposing how the hackers see you, but that doesn't mean anything to me. Yeah, it doesn't mean anything to anybody. What is that?

What do you actually do? Yeah, so we have 2 offerings today. So full disclosure, we're brand new. We've been around for a year. And the technology that we brought into the company is all about reconnaissance and discovery, right?

So we start with no information about a company, you know, plug in an email address, and from that automatically build out this huge map of what the company looks like. So discovery of all the technical and social assets that make up the institution. And then we stack rank all that based on this idea that we have called target to representation, which is like, how does a hacker view this piece of software or asset or component? And then after that, it's all about how do you attack a piece? What can you do with that?

And then having attacked a piece, what happens after that? So we're providing a capability to bring the entire kill chain of a breach, right, from zero-knowledge blind reconnaissance all the way through, you know, exfiltration, internal pivoting, you know, objectives on target, right? And we're doing that in a way that's, uh, automated. So it feels to me like I just heard several things that you kind of put together. Oh, there's a lot of stuff there.

I heard, um, I heard some of, some of what sounds a little bit like what you might get from like Digital Shadows or someone where they're basically like looking to see what you're, what you look like from the outside, and maybe even a little bit of like a BitSider security scorecard where you're looking, going to Aaron and figuring out what your IP addresses are, looking to see, do I see that kind of behavior? And then maybe taking it a little bit further to say, okay, now that I've identified those things, I'm going to do some, just guessing now, like a vuln scanning type activities against those assets. Yeah, so what we're trying to do is provide the same experience that a customer would have gotten from me breaking into their company with a team of red teamers, but without having to have the team of red teamers, right? So when you look at the things that were difficult about doing like high-end red teaming was really how do you apply, how do you make the economics work, right? Because zero-day is expensive, exploits are expensive, attacking is expensive.

But everybody's got the same infrastructure, everybody's company looks like everybody else's company. So if you start looking at grand-scale companies as a whole, right, all of a sudden you can apply economies of scale to doing ATT&CK. So we start with no information about a company, company signs up, and you're welcome to, you know, go to our website and register for the beta if you want to try it out. And from nothing but an email address, we'll build up a picture of all of the discoverable assets of a company from an external perspective. And we include in that things like you said, all of the IPs and servers and infrastructure and whatever is poking around on the internet that we can find.

And we've got a lot of technology that we use to do that in an automated and pretty quick way. And once we know about stuff, we keep an eye on it. Just, hey, is that thing still there? Has it changed? Is the version updated?

Has it been patched? What's going on? On top of that, yeah, we've got a fair amount of vulnerability discovery, but we're not super interested today in trying to just replace the vuln scanning component, right? I assume that if you're a reasonable security company, you know how to run a vuln scanner against your infrastructure, you're paying somebody to do that.

But if you don't know about the infrastructure, you're probably not scanning it. We're pretty good at finding stuff that you might not know about, or if something flickers or comes online for some period of time.

Where most recon companies, right, are gonna stop there, you know, and our objective is not to be a recon company. Our objective is to be an attack company. So we go from that to, hey, what of these assets can we attack? How can we attack them? Press button and receive an attack against these assets.

And then having attacked an asset, what happens? You know, great, you've got some unpatched thing, right? Everybody's got an unpatched thing. Somewhere, but did the compensating controls you have sitting behind it actually detect it? Did your security operations group actually respond in some reasonable way?

Or as happened with one of our early partners, did you exploit a thing and then nothing happened because nobody knew because your security services provider had turned off alerts from that box because it's too noisy? So the harsh realities of the security world, right? Yeah, it's a common enough thing, right? Exactly, yeah. So we're really trying to help shake people out of a defender's mindset, get away from building bigger and better castles, and help people start to think like an attacker so that you can contextualize risk a little better, think about what's actually going to impact your business.

So I love that. I like the way you're talking about it. One of the things that you mentioned when you were talking about what you called like the high-end pen testing or red teaming was the ability for your clients to establish what I called flags, right? Or you called bounties on some things that you find. And I think that that's interesting, right?

'Cause for an organization, if you're a mortgage company, you've got a repository of loan applications that are high value that, other company down the road doesn't have. If you're a retail company, the credit card information may be what you need to protect. Everyone's got their own unique stuff. Do you somehow factor that in with what you're doing as like, yeah, you don't need to worry as much about that, but this you really do need to worry about? Yeah, the types of— so what we're working towards in the ATT&CK is the what now or what then.

So when you go do some sort of data searching or like poking around somebody's network, right? Kind of who cares if you can enumerate a bunch of computers, right? Like, talk to me about things that matter. So today we're just doing the early stage attack and pivoting into an environment, right? And then the follow-on pieces are all more what we would think of as campaigns, right?

So go find things that have password in the name, right? Go find me user credentials. Go find me things that look like sensitive information and exfiltrate or simulate exfiltration of those types of things, right? See what actually happens. Are you guys at a point where your system— I totally get it that your system is probably built to gain persistence, and that seems like a really good way to start, but the actual intelligence to say, I'm going to go find the interesting stuff, is the system smart enough to do that?

We're getting there. We're getting there. I'm not going to say that we're there today, but the types of things that are easy for like a CISO to contextualize for us or to provide are like the nuggets of information about like, hey, what do you care about? And that's one of the things that was usually when we did these like high-end engagements in the past, right? You would talk to somebody and say like, I'm really worried about this one thing in this one place, right?

And sometimes it's the thing that the Russians went after when they came after you before, or that whoever hacked into you previously stole this. But usually those things are fairly reasonably constrained. I think a lot of times the Randori part, right, the practicing the breach, people don't do that a whole lot in any sort of real way. And so if you can tell me, go after anything in my environment that looks like X, I would love to do that. We've got a lot of tooling that provides those types of search mechanisms because that's the easy part, right?

Yeah, I think, I think if anyone who hasn't spent the time figuring out like, here's the 4 or 5 things that would really hurt if someone got access to them, you know, that's the first thing they should be doing. And then, yeah, honestly, it takes a little bit of trust to even tell you what those things are, right? Like, yeah, some of it's obvious at the low mortgage company, the loan documents, but there's some other stuff that we just don't want to say. But I think that that's required for this to be super effective. Yeah, I think that the honest discussion about what matters is one of the core things that I've seen missing in the industry as a whole.

I'm hoping to help facilitate by hook or by crook, I guess. But as much as I wish that I could say that my experience indicated that people generally knew what they needed to defend, my experience has mostly been that people still think they have to defend everything from everybody everywhere all the time. Yeah, I worked, I worked at a large bank, and I won't say any names, and we had an executive who said, we're just gonna defend it all the same because it's too hard to segment up. And, you know, at the time it was earlier in my career, I'm like, okay, I get it. And now looking back, like, so expensive.

And number one, it's very expensive. Number two, it just doesn't work. Like, you could spend all of the money on it, but It doesn't matter because you can't defend everything. Yeah, well, I think one of my mantras over the last several years has been really about definitions of success. And if you define success as keeping hackers out of my network, and I'm air quoting for people who can't see me because we're not on video, if keeping hackers out of the network is your only definition of success, you're gonna lose every time just by definition.

You're not gonna keep them out of your network. I think winning is all about detecting early, responding reasonably, and keeping the business running. Most companies are not in the business of cybersecurity. They're in the business of building widgets or selling product or doing whatever they do for a living. Just that exercise of asking, what does winning mean?

If the answer you come up with is keeping them out of the network, I agree with you, by the way, that's not reasonable, but at least it's a definition and you can at least use it to start building around. I think it's a starting point for dialogue, right? But if you don't even ask the question, which I bet you most folks haven't actually asked the question, you can't even work from that. Yeah, I think technologists tend to get caught up in the technology. I will point fingers squarely at the security market for this too.

Your average CEO does not understand how the computer— and so they're depending on people to communicate to them effectively. One of the things that I see is the operations group and the infrastructure group and the risk group talk past each other because they use different languages, right? It's taken a really long time for the security space to catch up on just how to dialogue with the rest of senior management. Now that we're kind of getting there, you start to see some change, but the companies that did the best at defending against us breaking into them were the companies that had put cybersecurity under risk as opposed to the ones that had put it under IT. And I think only because they had a better framing for what they were trying to accomplish.

And a lot of the technologists came at it from, I'm just gonna protect everything and if I can fix every vulnerability, I'll be good. But I'm here to tell you, you're not gonna fix every vulnerability 'cause you don't even know about them all. And if that's your only defense, you're in trouble. But if you can know what normal looks like and you have some basic capacity to, you know, kind of unbreak stuff that you run into, you end up doing pretty well. So talk about the company.

Really cool technology side. Um, I see on your website, you know, request beta right now. So are you actually, you know, selling things to customers? Where are you guys at as a company right now? Yeah, so we've been around for— we're just coming up on our 1 year.

Uh, February will be the anniversary. We have a beta availability for our reconnaissance offering. We've got attack in alpha. We just launched our first attack against one of our early partners back in November. I would say that went swimmingly for us.

Does that mean you broke in? Well, we— not so well for them. Broke in, yeah. So that was good. I think that we've helped uncover some institutional conversations that need to take place there.

Good for them too. Doing really well, I think, and they're going to get better. So I'm excited, um, and it's helping us learn. So right now we're at a phase where we're very much not interested in money. We're more interested in feedback and making sure we're building the right product.

Yeah, uh, we're expecting that we'll be, uh, in GA, so kind of general availability, about mid-year. Okay, so we're moving quick. Yeah, um, it's been a pretty wild ride. And now you live in Colorado? I do.

Um, Brian lives in— Brian lives in Boston. So, uh, company's Headquartered in Boston, and we've got all of our engineering is here in Denver. Do you guys have an office in town? So we office at Thrive Workplace. Yeah, here in downtown Denver, and it's awesome.

Are you hiring anybody? You want— do you need to hire people? I am always looking for bright people. Definitely looking for a number of positions right now, most notably if you happen to be a director of engineering and looking for that kind of thing. Yeah.

Want to move at a rocket ship pace, please, please, please reach out. Awesome. You looking for someone who's going to have hands-on code or someone who's going to run a team? Uh, yes, yeah, yes, yes. It's— well, it's early stage startup, right?

We're 18 people and yeah, just moving as fast as we can. So wherever people can pitch in. Yeah. Um, so I, I'm going to take us way back. Let's go back.

This idea, you know, to, to build this platform, you start talking to Brian about it. Uh, or he brought, you know, someone brought it up that you start talking about it. How does that go? You know, you're, you're employed by Kairos. Um, how does it go from saying, hey, I got this other job, to like, I'm gonna do a whole new thing?

There's— that's a big step at some point, and I'd love to hear your thought process and, and that, that— well, I was like, I mean, so I was excited about an opportunity, right? And I gotta say, I wasn't like looking for a job. Um, you know, people know me here in Denver will appreciate that I have been known to be long-winded and hem and haw and talk and philosophize about things. So I wasn't looking for a gig. Like I said, I love my team at Kairos.

Those guys are awesome. And if there were any way I could hire any of them, I would totally do that. But I don't— like, I love the company, right? And so we were kind of chatting with Brian, and really what we saw was there were some shifts that were beginning to take take place in the market. And the timing felt really right for this type of offering.

And, you know, we had a good opportunity with some early conversations with some VCs who were interested in funding a thing that looked like what we wanted to do. And it definitely became one of those things where without looking for a new opportunity, it kind of just fell in your lap. And you're like, well, I sat down and I kind of decided that I'd feel like an ass if didn't take the opportunity. And so we, we just did it. Yeah.

So yeah, and like I said, I'm super grateful to like both my team that I came from, the team that I have now, you know, kind of everybody involved in the whole transaction because it just worked out really well. Yeah. So I want to— I'm totally excited to hear where this goes and probably want to talk to you about getting a look at your platform a little bit more, but yeah, for sure, we'll take that offline. Moving kind of Randori aside for now, you and I have met through industry stuff in Colorado in the past, BSides, and I'd love to hear your experience of the security community. I know before we hit record on this, we were talking about all the different stuff going on here.

Talk to me about how you got plugged in and how do you interact with the security community? Yeah, so I am terrible at the media and the communication and search. Certainly in the last year, it's just been all startup all the time. But yeah, I remember in Denver playing pool and drinking drinks at Cafe Netherworld, like way back in the day when all the InfoSec kids in the area just hung out there and hemmed and hawed about all of the security stuff. For those who don't know what you're talking about, what year are you talking about?

2001. Yeah. Like, this is just a bunch of random guys getting together. Well, I wouldn't call it, call it random, but I think it's open secret that there's a pretty good community of folks doing InfoSec in the Denver area. And out have popped a number of, you know, companies and, you know, reasonably famous professionals, I guess.

And so I'm not gonna claim that I was in any way instrumental or, you know, involved in that, but it's just like a crew that I knew. Yeah. When I came back to Colorado, I started, you know, going back to like the local 303 meetups and the DC 303 meetups, and there was a kind of growing crowd of people putting together a number of get-togethers. You know, I'm not one of the people who's super involved in all the different like certified communities. Yeah, but a lot of the, uh, the more B-sides and, you know, SkyTalks-driven stuff, I would say.

Yeah, it's, you know, more my scene. So hoodies and black t-shirts more than the suits. The infamous basement hacker with the hoodie. Come on. Yeah, yeah.

Why not, right? Why not? Yeah, so I still try to get to the DC303 meetup every month if I can down at DenHack. Any opportunity to grab a beer and talk about security, whatever. I would say that there's a lot of people who've got a lot of really good ideas here, which I appreciate.

I know you, at least previously, were meeting up with the CitySec folks when Jacob was running it, and I know Colin's been running it for a while. I don't know if you've been still doing that. I haven't really been since Jacob took that brilliant position and moved back out to where I used to live. But I try to get out and visit out there once in a while. If you guys don't know Jacob, he's at DARPA saving the world or something.

Something good like that. Yeah, or something. I don't know. He gets paid to think, I think, which is good. It works for him.

Program manager over there. Cool stuff. Well, so, you know, I got to ask you some interesting questions. Is there anything that you wish I asked you? Something you want to talk about for listeners that I haven't asked you about?

Yeah, you know, I don't have anything in particular. I got to say though, I'm super excited about what I see as very positive change in the cybersecurity space. I'm like, you know, really excited to see people actually talking about, you risk and trying to think about how does security evolve. I kind of hope that I get to be part of that conversation and put a little force in the right direction for that. Yeah, awesome.

Well, so your website, is it just randori.com? Randori.com, yeah. R-A-N-D-O-R-I.com?

Yep, that's it. I see a pretty picture of your smiling face on the website. Well, I can't control the marketing, unfortunately. I try to ignore it so that I don't have to get teased too much. But yeah, it's a great team, and I'm really, really excited about all we're doing.

Awesome. Well, thanks for your time. This has been a lot of fun, and I guess I would love to touch base maybe a year from now and just see what have you guys done, what's out, because you should be a long way from— Yep. Yeah, a year from now it's gonna be a totally, totally different thing, so I'm excited. All right, well, have a good one.

We'll talk to you again soon. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes