1
00:00:02.647 --> 00:00:16.017
Marissa Notaro: Alright, so I think we're gonna get started now, because the majority of people have joined. Welcome, everyone! We're super excited to be here, and to have some great speakers to talk on a really critical topic.
2
00:00:16.017 --> 00:00:36.287
Marissa Notaro: So we're gonna start off, with covering that topic that we're gonna be going through, which is no more Missed Alerts, making the Jump from SOAR to AI SOC, how the Trinox SOC team handled routine investigation to AI agents. So, I'm gonna just go through, some housekeeping items first.
3
00:00:36.287 --> 00:01:01.187
Marissa Notaro: So just so you guys are aware, there is a Q&A section. Please ask any questions you have in there. We will get to those questions at the end of this session. This is also being recorded, so you will get the recording after. We will email that to all of the people that have attended and registered. And if you would like to have a personalized demo, feel free to use that link.
4
00:01:01.377 --> 00:01:17.357
Marissa Notaro: to request one. So, we're going to start off with introducing our speakers. So really excited to have our co-founder and president of Strike 48, Tim Leehealey. Thank you for joining, Tim.
5
00:01:18.287 --> 00:01:19.127
Marissa Notaro: Awesome.
6
00:01:19.127 --> 00:01:22.807
Tim Leehealey: Listen, super happy to be here. Thanks for, thanks for letting us do this.
7
00:01:22.937 --> 00:01:33.537
Marissa Notaro: Yep, super excited. And then we also have Adam Chapman, who is the Director of Cybersecurity from Tronox. Really excited to have you here, Adam, our special guest.
8
00:01:34.217 --> 00:01:35.907
Adam Chapman: Thank you. Good to be here.
9
00:01:36.357 --> 00:01:44.307
Marissa Notaro: Awesome. And Adam, can you share a little bit about Tronox, just so that, everyone that's on the call, can have a little bit of an overview?
10
00:01:44.727 --> 00:01:54.266
Adam Chapman: Yeah, of course. So, Trinox are a global chemical company, and mining as well, so we've got 5,700 employees around the world.
11
00:01:54.397 --> 00:01:59.326
Adam Chapman: We're operating across 6 continents, so quite a large footprint.
12
00:01:59.427 --> 00:02:06.467
Adam Chapman: And we produce high-quality titanium products. A lot of the things that are in your homes, your businesses.
13
00:02:06.837 --> 00:02:17.547
Adam Chapman: You'll probably find titanium dioxide is part of them, so paint, plastic, paper, is the materials that we produce, so chemicals that go into those products.
14
00:02:17.927 --> 00:02:27.547
Marissa Notaro: Awesome. Thank you so much, Adam. And Tim, we're gonna kick off that conversation, so I'll let you take it from here. Yeah, let's get started.
15
00:02:27.997 --> 00:02:38.816
Tim Leehealey: I'll just start out by saying, Adam, I had no idea that the pan I just bought came from you guys. It's titanium, it's all the rage.
16
00:02:39.017 --> 00:02:42.587
Adam Chapman: Yeah, it's amazing what, what our products are into.
17
00:02:42.927 --> 00:02:52.287
Tim Leehealey: Yeah. So, anyway. So, okay, listen, I wanted to start… so you and I have had a relationship now for over a year, and…
18
00:02:52.287 --> 00:03:04.896
Tim Leehealey: you know, we've gone through our highs and lows. I think it's been probably one of our most productive from a strategic standpoint, just working with you, your team, how you guys have pushed forward in embracing this technology.
19
00:03:05.007 --> 00:03:11.716
Tim Leehealey: So, I'm really excited To walk through the journey, have everybody kind of understand
20
00:03:11.757 --> 00:03:30.887
Tim Leehealey: the steps you went through, and kind of, the… the… what you've been able to produce, and how you're utilizing the product. But, I think we do a disservice if we don't start out where we were, right? Because when I met you guys, you guys were a Devo customer, and you were effectively telling me.
21
00:03:30.987 --> 00:03:36.727
Tim Leehealey: we're gonna churn, there's really not a heck of a lot of value in the SIM platform.
22
00:03:36.777 --> 00:03:51.906
Tim Leehealey: So, if you can start out telling… go back that full year to those conversations, tell me where you were as a team, kind of how you were restructuring things, and you know, again, take us back to November of last year.
23
00:03:52.577 --> 00:04:02.027
Adam Chapman: Yeah, so November last year was quite a tough time, for the team. We'd just gone through a restructuring of our SOC operations team and our security team.
24
00:04:02.257 --> 00:04:09.936
Adam Chapman: And we're at that point of assessing what tools do we have, what people do we have, how do we operate now as a new team.
25
00:04:10.307 --> 00:04:17.336
Adam Chapman: And within the Devo system that we have, the scene platform, we're ingesting gigabytes of logs.
26
00:04:17.667 --> 00:04:20.096
Adam Chapman: We're receiving loads and loads of alerts.
27
00:04:20.257 --> 00:04:22.126
Adam Chapman: And everything was manual.
28
00:04:22.247 --> 00:04:30.006
Adam Chapman: So, it's quite quickly becoming apparent that the team are becoming overloaded with that number of alerts that come in.
29
00:04:30.137 --> 00:04:33.986
Adam Chapman: And you're manually having to sift through them to find the ones that are
30
00:04:34.187 --> 00:04:50.146
Adam Chapman: important, the ones that don't need attention, and it's just a constant battle. Then, as soon as you've cleared the queue, you get another 5 popping. So, it's that constant problem that you face in a SOC environment that you've never done. There's always another job to do.
31
00:04:50.597 --> 00:04:55.697
Tim Leehealey: It just doesn't really even work, does it? I mean, at the end of the day, I mean, I have these conversations over and over.
32
00:04:55.697 --> 00:05:06.597
Adam Chapman: It doesn't scale. The more data you ingest, the more alerts you generate, the better you become, the more you find, but then the more you've got to deal with.
33
00:05:06.957 --> 00:05:12.997
Adam Chapman: So, it's kind of that cycle that you think, well, right, great, we need an alert for this, we need an alert for that.
34
00:05:13.167 --> 00:05:24.176
Adam Chapman: But now we've got to triage them, and you kind of create work without realizing it quite, quite easily. So you can quite quickly, you know, out-resource the team.
35
00:05:24.997 --> 00:05:28.636
Tim Leehealey: Yeah, you're always making that decision between coverage
36
00:05:28.977 --> 00:05:40.516
Tim Leehealey: criticality and visibility. Like, I have conversations all the time where people are like, well, listen, I'd love to ingest those logs, but it's too expensive, and if I did, I'd just have more work.
37
00:05:40.777 --> 00:05:45.966
Tim Leehealey: Do you know what I mean? But… so you're constantly in that battle of…
38
00:05:46.977 --> 00:05:53.167
Tim Leehealey: you know, not only what am I threatened by, but what can I actually achieve on a day-to-day basis?
39
00:05:53.527 --> 00:05:57.806
Adam Chapman: Yeah. The more you look, the more you find. It's as simple as that, isn't it?
40
00:05:57.967 --> 00:06:11.567
Adam Chapman: And what we've managed to do over the years… we've had the Devo platform for a number of years. If we had had an investigation or an incident that's gone on, we've then developed an alert for that in case it happens again.
41
00:06:11.837 --> 00:06:27.736
Adam Chapman: And we've kind of evolved the scene through that natural cycle, but you get to a point where some of these just become noise, and it's very hard to work out on a day-to-day basis, what should I be doing today?
42
00:06:28.267 --> 00:06:30.377
Adam Chapman: What… what cases are important?
43
00:06:30.617 --> 00:06:40.686
Adam Chapman: what things don't need to be looked at by a human, what can I just put to the side for tomorrow, maybe? That's the position that we were in.
44
00:06:41.607 --> 00:06:46.927
Adam Chapman: Yeah. So the conversation was, how do we get more value out of this system?
45
00:06:47.257 --> 00:06:49.866
Adam Chapman: And that was our conversation last year.
46
00:06:50.327 --> 00:07:05.437
Tim Leehealey: Yeah, and it was perfect timing, because at the time, we had really just launched, and let's sort of go into this, we had just launched our Strike 48 platform, which sits on top of Devo. Actually, at this point, can sit on top of any SIM, or storage, or whatever.
47
00:07:05.517 --> 00:07:16.157
Tim Leehealey: And… I gotta say, honestly, Adam, I was super excited with how your team was willing to sort of take a risk here. I saw it as a risk. I think you guys…
48
00:07:16.247 --> 00:07:29.336
Tim Leehealey: saw it as such, too, but we sort of came in and said, hey, give this a try, give us another year, let's layer this on top of Devo. We think it's going in the direction you want it to.
49
00:07:29.357 --> 00:07:37.127
Tim Leehealey: I think we were pretty upfront about the fact that we were exciting, enthusiastic, really passionate, but maybe it wasn't yet there.
50
00:07:37.387 --> 00:07:40.457
Tim Leehealey: But you guys jumped in the,
51
00:07:41.137 --> 00:07:52.487
Tim Leehealey: in the boat with us, and again, I think it's been productive, but so tell us, kind of, from your side, how you saw that, how you saw the vision, and what made you willing
52
00:07:52.807 --> 00:07:54.627
Tim Leehealey: To give us another year.
53
00:07:56.677 --> 00:08:02.997
Adam Chapman: Yeah, well, first of all, I used the AI assistant that was built into Devo.
54
00:08:03.527 --> 00:08:05.827
Adam Chapman: And… that was impressive enough.
55
00:08:06.297 --> 00:08:10.696
Adam Chapman: To think, well, if there's something better than that, then this is surely worth exploring.
56
00:08:11.287 --> 00:08:13.707
Adam Chapman: And we got on a few calls.
57
00:08:13.947 --> 00:08:17.717
Adam Chapman: It must have been an early version of the product that we saw originally.
58
00:08:17.877 --> 00:08:24.307
Adam Chapman: And some of the things it was able to do, like the investigation of things, which is far quicker
59
00:08:24.327 --> 00:08:42.847
Adam Chapman: and a lot more thorough than what a human can do. So, just that initial thought of, what can this thing do for us? If you think of our problem of just, you know, just having a new team built and everything, we had the opportunity to build a brand new SOC from the ground up.
60
00:08:43.547 --> 00:08:50.426
Adam Chapman: Which is quite a daunting thing, really. But this tool has helped us to do that.
61
00:08:50.667 --> 00:08:58.136
Adam Chapman: So, the thing about… on the screen there, about every alert analyzed, well, we took it right back to the beginning.
62
00:08:58.557 --> 00:09:07.167
Adam Chapman: And we started with our alerts and our data ingestion. So, we had AI agents from Stripe 48,
63
00:09:07.327 --> 00:09:09.596
Adam Chapman: Analyzing our current alerts.
64
00:09:09.677 --> 00:09:25.916
Adam Chapman: Have we got the right coverage? Are those alerts triggering when they shouldn't be? Are all the metadata, the entities, are they mapped correctly? All this stuff would have taken us probably weeks to go through all the alerts, one by one.
65
00:09:25.967 --> 00:09:34.906
Adam Chapman: and find that the gaps in coverage, the gaps in potentially the queries might have been a little bit wrong, or needed to be tweaked. So that was the first step, is…
66
00:09:34.987 --> 00:09:37.356
Adam Chapman: Cleaning up the alerts at scale.
67
00:09:37.917 --> 00:09:43.347
Adam Chapman: Such that when they went into the platform, They had a lot more…
68
00:09:43.507 --> 00:09:48.637
Adam Chapman: metadata around them that could then be ingested by the AI agent.
69
00:09:48.777 --> 00:09:51.686
Adam Chapman: So, a lot of this was housekeeping, a lot of clean-up.
70
00:09:51.937 --> 00:09:56.116
Adam Chapman: To begin with, But then once you've done that.
71
00:09:56.557 --> 00:09:58.567
Adam Chapman: It all starts to make sense.
72
00:09:59.607 --> 00:10:11.896
Tim Leehealey: And did you have a few… I mean, we just talked about alert triage and enrichment and stuff like that. Did you have a… at the time, were you like, okay, this is obvious, let's use this for this, or was there…
73
00:10:11.987 --> 00:10:30.536
Tim Leehealey: you know, again, you guys got into an early version of the platform. How much sort of startup time did it take? And at this point, just to be clear, you guys are very sophisticated users, right? So you've really done some incredible stuff, but take me through a little bit of the learning process in terms of
74
00:10:30.787 --> 00:10:41.867
Tim Leehealey: what you initially saw when we came and said, hey, try this Agentic platform, in terms of the potential, and kind of how you're… how you got up to speed, and how you're viewing it now.
75
00:10:42.647 --> 00:10:58.927
Adam Chapman: Well, the actual setup process was fairly straightforward. The Stripe 48 team helped us with that. It's a case of creating some API keys, linking everything together, and that's a fairly straightforward process. So, within a few hours, we had everything connected.
76
00:10:59.137 --> 00:11:03.887
Adam Chapman: And I think to start with, it's like, right, it's like having anything new, what can this thing do?
77
00:11:04.217 --> 00:11:07.377
Adam Chapman: So… what I found myself doing was.
78
00:11:08.117 --> 00:11:20.577
Adam Chapman: creating, sort of, quite simple questions. Oh, I'm investigating this alert, tell me about the activity of this user. Tell me about this IP address, this machine. Starting quite basic.
79
00:11:20.727 --> 00:11:27.776
Adam Chapman: And you start to think, wow, this thing's pretty good. You know, what more can it do? So,
80
00:11:28.137 --> 00:11:34.807
Adam Chapman: I started off writing very simple questions, very… almost like a co-pilot style…
81
00:11:34.937 --> 00:11:38.767
Adam Chapman: a question that you'd ask another colleague, for example, and…
82
00:11:38.907 --> 00:11:40.696
Adam Chapman: I just saw the power of it.
83
00:11:40.967 --> 00:11:46.467
Adam Chapman: And I think… as I've got used to the platform more, and the team are using it more.
84
00:11:46.917 --> 00:11:55.557
Adam Chapman: we've just learned to embed that in our day-to-day work, rather than it being something, oh, I remember… I need to go into this new system now to try this.
85
00:11:55.707 --> 00:12:10.147
Adam Chapman: It's now becoming the place I go to first, you know, rather than the place I'd think about going to, because I've, you know, forgot it exists. So, it's definitely becoming embedded within the team now, which is good from the beginning.
86
00:12:11.067 --> 00:12:16.016
Tim Leehealey: And how do you get the… how do you get… how did you get over, and… and how do you get your team over…
87
00:12:16.107 --> 00:12:28.647
Tim Leehealey: the skepticism factor, the… listen, we've all been lied to by ChatGPT, or politely answered incorrectly, do you know what I mean? And there's no magic to Strike 48.
88
00:12:28.647 --> 00:12:37.256
Tim Leehealey: I think it's an incredibly powerful harness, but there are pitfalls, there are ways you can confuse agents. How do you deal with the skepticism
89
00:12:37.267 --> 00:12:40.106
Tim Leehealey: that we've all sort of developed relative to AI.
90
00:12:40.147 --> 00:12:43.746
Tim Leehealey: in terms bracing it for IT-level use cases.
91
00:12:44.277 --> 00:12:47.487
Adam Chapman: Yeah, there was definitely that at the beginning, like.
92
00:12:47.977 --> 00:13:00.817
Adam Chapman: what is this thing? What can it do? Well, that's complete nonsense. Where has it got this from? And, yes, at the beginning, in the early days of December, January, when we were pretty new to the product.
93
00:13:00.957 --> 00:13:06.186
Adam Chapman: There were hallucinations, But what we've learned to do is…
94
00:13:06.317 --> 00:13:20.797
Adam Chapman: train it more to say, if I'm asking you about this, then our data is in this table, go look at that. So, we're a lot more specific now, but what we've learned to do is tune… tune the prompt, tune the tool.
95
00:13:20.897 --> 00:13:38.306
Adam Chapman: Effectively, so that if it does start to do something that either we don't want or is incorrect, we tell it not to do that again in the prompt. So we've got a series of rules that we'll introduce that says, never make up evidence. If you don't know, say you don't know, don't make it up.
96
00:13:38.627 --> 00:13:42.127
Adam Chapman: basic stuff, and I said, earlier that
97
00:13:42.707 --> 00:13:54.766
Adam Chapman: You treat this like your office junior, like your apprentice, that it's gonna get things wrong to start with, but you correct it step by step, and eventually you build something that… that you can rely upon.
98
00:13:55.467 --> 00:13:57.977
Adam Chapman: And I think we're at that point now where
99
00:13:58.247 --> 00:14:03.967
Adam Chapman: It's a lot more accurate than it's ever been, because we've spent the time to tune it.
100
00:14:04.067 --> 00:14:10.166
Adam Chapman: And to point it in the right direction, so that when we do ask these questions, it knows where to go.
101
00:14:10.407 --> 00:14:11.266
Adam Chapman: Rather than having.
102
00:14:11.267 --> 00:14:11.587
Tim Leehealey: It's.
103
00:14:11.587 --> 00:14:15.697
Adam Chapman: say, oh, I've got all these gigabytes of data, what is it you're asking me for?
104
00:14:16.977 --> 00:14:30.137
Tim Leehealey: It's super interesting how you phrase that, because that is one thing that I really encourage people to understand about agents, is you always need to give them an off-ramp.
105
00:14:30.267 --> 00:14:32.397
Tim Leehealey: They are eager beavers.
106
00:14:32.527 --> 00:14:47.626
Tim Leehealey: And if you corner them, and they have no off-ramp, that is the number one recipe for a hallucination. But if you just tell them, if you can't find it in the data, say you don't know or can't find it in the data, they're happy to do that.
107
00:14:47.977 --> 00:14:53.157
Tim Leehealey: But if you don't tell them, they will effectively field corner and hallucinate.
108
00:14:53.837 --> 00:14:54.697
Tim Leehealey: So, yeah.
109
00:14:55.277 --> 00:14:55.937
Adam Chapman: Is…
110
00:14:55.937 --> 00:14:56.257
Tim Leehealey: Anyway…
111
00:14:56.257 --> 00:15:04.376
Adam Chapman: Another thing we saw early on was… was where you would… you'd ask a question, and it would start to go off on a little bit of a…
112
00:15:04.487 --> 00:15:14.606
Adam Chapman: a tangent and say, well, this is a confirmed breach. And you think, well, actually, no, it's not a confirmed breach, but let's just have a look at why it might think that.
113
00:15:14.677 --> 00:15:29.536
Adam Chapman: And as a human, you can read the data and go, yeah, okay, I can see why it's… why it's come to that conclusion. And it's usually because there's something in the alert, the wording of the summary that says, threat detected, or… so, you need to constantly, sort of.
114
00:15:29.537 --> 00:15:34.847
Adam Chapman: Tune it so that it's aware of your alert types, the language to use.
115
00:15:34.997 --> 00:15:42.467
Adam Chapman: And we've worked with the Stripe 48 team for the past, you know, 9 months now to tune that wording, so it's a bit softer.
116
00:15:42.697 --> 00:15:46.487
Adam Chapman: You know, something is suspicious, it's not confirmed yet.
117
00:15:46.877 --> 00:15:53.186
Adam Chapman: So yeah, it's all a learning curve on our part as well, as a team. This is brand new to us.
118
00:15:53.447 --> 00:15:57.937
Adam Chapman: And we've had to… to learn to adapt as well, but…
119
00:15:58.197 --> 00:16:01.096
Adam Chapman: I'm really happy now that we're in August.
120
00:16:01.577 --> 00:16:07.267
Adam Chapman: And, you know, it's now doing the bulk of the work for us, versus before we had nothing.
121
00:16:07.667 --> 00:16:08.627
Adam Chapman: So, yeah.
122
00:16:08.627 --> 00:16:09.167
Tim Leehealey: No.
123
00:16:09.337 --> 00:16:26.997
Tim Leehealey: So let's actually talk about that. Let's hop to your results and kind of… this is a slide you put together for us. Tell us, kind of take us through where you were, where you are, and just, you know, give us the before and after, if you will.
124
00:16:28.467 --> 00:16:31.866
Adam Chapman: Yeah, so we've been doing the alert tuning for quite a while.
125
00:16:31.976 --> 00:16:41.327
Adam Chapman: Got that done, and to a point now where we're seeing about 600 alerts a week, maybe more, maybe less, obviously that varies.
126
00:16:41.667 --> 00:16:48.287
Adam Chapman: But every single one of them needed to be looked at by one of the team. So that's quite a large workload.
127
00:16:48.877 --> 00:17:03.856
Adam Chapman: And what we found was the majority of those cases that fired, they were probably false positives. It was something that we'd set up as an alert, and actually, okay, in this context, this alert is okay. This isn't anything we need to worry about.
128
00:17:04.757 --> 00:17:22.697
Adam Chapman: So that's gonna take… if you say 15 minutes each one, that's 150 hours of human time per week spent just doing that initial triage. And we all know that 15 minutes isn't long. You can soon go down a rabbit hole, that could turn into an hour.
129
00:17:22.797 --> 00:17:29.317
Adam Chapman: quite easily, depending on the information presented. So that is probably a conservative estimate.
130
00:17:29.827 --> 00:17:34.256
Adam Chapman: And, obviously, because you've got 150 hours, you've only got a certain number of people in the team.
131
00:17:34.507 --> 00:17:49.066
Adam Chapman: They've got work to do as well as this. This isn't their only job. They're not just sat waiting for alerts to fire. They've got day jobs as well. So they've got all the workload. So that slowly leads to an overloaded team.
132
00:17:49.487 --> 00:17:53.996
Adam Chapman: We've got their Missed Alerts, but I think it's more about…
133
00:17:54.767 --> 00:18:00.716
Adam Chapman: prioritizing the work. What it means is the stuff that needs to be prioritized gets front and center.
134
00:18:00.897 --> 00:18:14.817
Adam Chapman: But it's quite easily for a low-priority alert to go a little bit longer than you'd like before it gets looked at by somebody. So, what we've translated that to now is we've got,
135
00:18:15.067 --> 00:18:20.917
Adam Chapman: an AI agent doing a lot of the first-level triage, so it will take…
136
00:18:21.167 --> 00:18:28.546
Adam Chapman: a paragraph, you know, that comes through in an alert that's got maybe an IP address, maybe a username, a hostname, whatever's in there.
137
00:18:28.767 --> 00:18:32.526
Adam Chapman: And the first level is work out what's going on.
138
00:18:33.267 --> 00:18:34.577
Adam Chapman: So, within…
139
00:18:34.927 --> 00:18:47.786
Adam Chapman: couple of minutes of an alert firing, we've got an initial AI triage that… that kind of puts that alert into context to say, what is this? Who is it? Where are they? What are they doing?
140
00:18:48.407 --> 00:18:52.157
Adam Chapman: And… It will do a mini investigation on that.
141
00:18:55.217 --> 00:19:03.737
Adam Chapman: If the AI agent thinks this is something that needs to be escalated, it will escalate it to a second-level investigation.
142
00:19:03.977 --> 00:19:08.837
Adam Chapman: If not, it will close that case on its own as a false positive.
143
00:19:09.267 --> 00:19:16.087
Adam Chapman: That was the skepticism to start with. That was where we thought, are we really wanting to trust
144
00:19:16.457 --> 00:19:23.357
Adam Chapman: Effectively, a computer, to decide whether this is a false positive or not. So that was a…
145
00:19:23.887 --> 00:19:29.957
Adam Chapman: A real conscious decision that… Are we really sure, right? So…
146
00:19:30.227 --> 00:19:35.357
Adam Chapman: We talked about this quite a lot with the team, and to start with, we did baby steps.
147
00:19:35.927 --> 00:19:46.226
Adam Chapman: So, we manually reviewed these cases first, and then we human, you know, human-reviewed them and closed them manually, based on the AI verdict.
148
00:19:46.537 --> 00:19:54.716
Adam Chapman: And then we moved a little bit further down the road and said, right, okay, now we're starting to build some trust that this is getting it right.
149
00:19:54.977 --> 00:20:03.857
Adam Chapman: let's create a status within the platform that says the status of closed by AI.
150
00:20:04.647 --> 00:20:10.797
Adam Chapman: So now, I can run a query once a day, once every few hours, however often.
151
00:20:11.017 --> 00:20:15.837
Adam Chapman: where a human can go and review those cases and say, okay, did AI make the right call?
152
00:20:16.397 --> 00:20:22.256
Adam Chapman: Yes, yes, yes, yes. That one, I need to pull that one out again, and I need to do that myself.
153
00:20:22.647 --> 00:20:38.766
Adam Chapman: But I'll write down, kind of, why… why that made that verdict, so we can tune it later to set. If that happens, don't close it yourself, we want to do that. And that took probably a month, where we were sat there, you know, just keeping an eye on things.
154
00:20:39.247 --> 00:20:55.906
Adam Chapman: making sure that the agent was doing what we'd asked it to do. And this is why I keep relating it to, like, a trainee, an apprentice, a junior, because if it does something wrong, you just tell it it's done it wrong, and it will then learn for the next time. But you need to put that time into tune.
155
00:20:56.407 --> 00:21:02.067
Adam Chapman: So, once we've got that place where we're starting to close things on its own.
156
00:21:02.507 --> 00:21:05.156
Adam Chapman: We then escalate the remainder.
157
00:21:05.337 --> 00:21:15.766
Adam Chapman: To another set of AI agents that are, like, deep investigators. So, they're gonna pick up a case by its type.
158
00:21:16.297 --> 00:21:25.346
Adam Chapman: and investigate that using… you could say a playbook that you'd use in a traditional SOC, but instead it's going to do that at machine speed.
159
00:21:25.947 --> 00:21:34.097
Adam Chapman: the stuff we're doing with Stripe 48, with, like, the identity alerts around MFA and failed password attempts and things like that.
160
00:21:34.227 --> 00:21:52.947
Adam Chapman: there is no way, as a human you could do that level of work as quickly or as accurately as what this is doing. Now we've tuned it. So I think that the general message is you need to be on this thing to tune it, but you put the time in, and it's just going to do it time and time again. So, we've gone from a place
161
00:21:53.467 --> 00:22:05.416
Adam Chapman: as you see on the screen there, where everything was manual, to a place now where 77.5% there on that screen in that particular week was AI closed.
162
00:22:06.527 --> 00:22:10.237
Adam Chapman: We have seen 96% AI closed.
163
00:22:12.027 --> 00:22:20.636
Adam Chapman: that could scare some people off, thinking, how are you really sure that this system is doing it correctly? So, what we then did was.
164
00:22:20.997 --> 00:22:23.757
Adam Chapman: We took those AI closed cases.
165
00:22:23.867 --> 00:22:28.816
Adam Chapman: Yes, we reviewed them as humans, but we then created another AI agent.
166
00:22:28.837 --> 00:22:39.066
Adam Chapman: to review the AI closed homework, effectively, so you've got one AI agent closing the work, closing the cases.
167
00:22:39.087 --> 00:22:51.086
Adam Chapman: And then a second agent comes along with a different prompt, different model, to say, did it get it right? Was this the right decision? Do you agree with that decision that was made? If you don't agree.
168
00:22:52.017 --> 00:23:08.457
Adam Chapman: open the ticket again, bring it back into the SOC for processing by, you know, by a human. So that… that's what we've done over the past… it's only over the past month or so. This has only been… been running maybe throughout July onwards, and already you can see the numbers there.
169
00:23:08.607 --> 00:23:15.127
Adam Chapman: you know, AI closure within 5 minutes of a case being opened, there's no way you could do that by hand.
170
00:23:17.127 --> 00:23:23.737
Adam Chapman: And what it means is the team have got more time now to spend on some of the things that do need to be analysed.
171
00:23:24.447 --> 00:23:25.637
Adam Chapman: by hand.
172
00:23:26.097 --> 00:23:28.736
Adam Chapman: And so, we can focus on the important stuff.
173
00:23:29.287 --> 00:23:43.126
Tim Leehealey: Yeah, what I love about how you've sort of positioned it and talk about it is, I have this exact same conversation with people all the time, sort of, how do you know, how do you not know, did it get it right, didn't get it right? But what I kind of tell them is, okay.
174
00:23:43.147 --> 00:23:50.176
Tim Leehealey: On the left-hand of the screen, you've got 600 alerts that you… you can't get to.
175
00:23:50.427 --> 00:23:57.327
Tim Leehealey: Right? So there are X number of alerts, you simply can't get to them. You can view this as, hey.
176
00:23:57.457 --> 00:24:03.177
Tim Leehealey: on the right side of the screen, we still have the 600 cases. They're AI closed.
177
00:24:04.007 --> 00:24:11.466
Tim Leehealey: You can still go through them if you want. It's not like they disappeared into the ether. They're now just fully enriched.
178
00:24:11.767 --> 00:24:24.117
Tim Leehealey: you now can build strategies to go through them intelligently, and as you were saying, Adam, focus on the areas we really want to focus on. But it is not like you go from this
179
00:24:24.517 --> 00:24:36.957
Tim Leehealey: situation of manual to, literally, the machine is just executing on your behalf, and you have no recourse. That's just not the case. It's just you end up with a much better
180
00:24:37.517 --> 00:24:40.426
Tim Leehealey: Starting point from which to do your work.
181
00:24:41.387 --> 00:24:41.887
Adam Chapman: Yeah.
182
00:24:42.057 --> 00:24:45.927
Adam Chapman: And especially when you give it the organizational context.
183
00:24:46.207 --> 00:24:49.007
Adam Chapman: Because we've not talked about that much.
184
00:24:49.267 --> 00:24:53.947
Adam Chapman: So, okay, you could put Stripe Fourier on top of any platform.
185
00:24:54.047 --> 00:25:07.956
Adam Chapman: But when you tell it, this is my user directory, this is where my people are expected to be, this is our site office location, these are our IP addresses, it's then contextually aware as what I am.
186
00:25:08.357 --> 00:25:16.656
Adam Chapman: If I can give it an inventory of assets, an inventory of my people, where is everything, it's got that baked in.
187
00:25:16.827 --> 00:25:19.527
Adam Chapman: So it instantly knows whether… is this…
188
00:25:19.777 --> 00:25:23.666
Adam Chapman: you know, is this friend or foe? You know, is this an IP address that we know about?
189
00:25:24.047 --> 00:25:39.466
Adam Chapman: Or is this not an IP address we know about? And in the past, it would be, moving between different platforms to get that information, and to look up in Excel some spreadsheet somewhere where I've got this information, or a CMDB to find out about this asset.
190
00:25:39.587 --> 00:25:41.286
Adam Chapman: It's just in there now.
191
00:25:41.967 --> 00:25:43.497
Adam Chapman: But I think…
192
00:25:43.957 --> 00:25:50.907
Adam Chapman: At the beginning, we didn't have that appreciation for how powerful this thing can be if you give it the right information to start with.
193
00:25:51.747 --> 00:25:56.526
Adam Chapman: So… what I've learned. The more you give it, the more accurate it's gonna be.
194
00:25:57.277 --> 00:26:03.716
Tim Leehealey: I had this presentation I had to do at Black Hat, and they sort of asked me what my hot take was.
195
00:26:03.757 --> 00:26:13.746
Tim Leehealey: And you know, you're asked to be provocative in that statement, right? Nobody wants to say, my hot take is AI is interesting. Do you know what I mean? So, and my hot take has always been.
196
00:26:13.747 --> 00:26:30.566
Tim Leehealey: that all these vendors that are building AI directly into their platform, and I'll throw Splunk under the bus, because it's the perpetual boogeyman we all fight against, but, you know, the Splunk embedded agents, or the Sentinel embedded agents, to me, my hot take is they're missing the point.
197
00:26:30.737 --> 00:26:35.876
Tim Leehealey: Right? The real strength is implementing it over the entire IT stack.
198
00:26:36.047 --> 00:26:57.897
Tim Leehealey: Not just embedding it in any one product, because it does benefit from all the things you were just talking about. It's just a better solution. Maybe the SIM is the heartbeat, but giving it access to your employee directory, giving it access to your EDR, giving it access to your ticketing system, all enrich it and result in a better outcome.
199
00:26:58.587 --> 00:27:08.997
Adam Chapman: Definitely. Yeah, and to that point, we've got the vulnerability scanner. It doesn't have any AI capability at all.
200
00:27:09.517 --> 00:27:25.727
Adam Chapman: But I can now point Stripe 48 at it, and create an agent that says, tell me about the top 10 vulnerabilities that was reported in the past 24 hours. And it'll go off and research them, tell me about them, and it's kind of mind-blowing how it does that.
201
00:27:26.187 --> 00:27:41.856
Adam Chapman: But if you think about a typical security stack, you've got on the diagram there various points. So, you've got your firewall detecting stuff, they go into the seam, you've got, the EDR platform, you might have XDR, there's all sorts of different
202
00:27:41.997 --> 00:27:44.356
Adam Chapman: Platforms, generating their own logs.
203
00:27:44.947 --> 00:27:47.417
Adam Chapman: And like you said, this sits on top of them.
204
00:27:47.547 --> 00:27:51.817
Adam Chapman: And some of the things that we've been finding is it's doing its own correlation.
205
00:27:51.947 --> 00:27:58.767
Adam Chapman: So, I was investigating a case recently, about, a user.
206
00:27:59.167 --> 00:28:06.937
Adam Chapman: There was receiving loads and loads of mail bombs, sort of, attack, 500 emails within a 10-minute period. Where is this coming from?
207
00:28:07.557 --> 00:28:09.177
Adam Chapman: And one of the agents…
208
00:28:09.357 --> 00:28:18.756
Adam Chapman: It said, oh, and did you know that at the same time as this email bomb, we've also seen a brute force attack against the same account through Active Directory?
209
00:28:18.907 --> 00:28:26.107
Adam Chapman: So it's kind of drawing logs from different places to say, I would never have found that bike, you know, myself.
210
00:28:26.107 --> 00:28:26.717
Tim Leehealey: Yeah.
211
00:28:26.937 --> 00:28:30.166
Adam Chapman: You know, it's just… it amazes me, some of the things it picks up on.
212
00:28:30.657 --> 00:28:34.566
Adam Chapman: So, all of that information that's sat there in our same platform.
213
00:28:34.727 --> 00:28:41.917
Adam Chapman: was previously just a bucket of data. It's now being used, where before it just sat stale.
214
00:28:42.357 --> 00:28:51.487
Adam Chapman: And we're going back months, if not years, with all this data. So, you said earlier about the low and slow guys, well, we can now pick them out.
215
00:28:51.707 --> 00:28:57.576
Adam Chapman: Because you can see patterns in the data starting to emerge that you probably wouldn't pick up.
216
00:28:57.717 --> 00:29:06.446
Adam Chapman: Through a detection that says, it must be a brute force attack if it's more than 10 password attempts in 5 minutes.
217
00:29:06.747 --> 00:29:10.426
Adam Chapman: You could then do that over months, if you wanted to.
218
00:29:10.707 --> 00:29:13.007
Adam Chapman: So, it's all there for the taking.
219
00:29:13.667 --> 00:29:21.486
Tim Leehealey: Yeah, it really does open up, and it opens up the ability to really re-look at the entire IT stack, frankly, and go to… I mean.
220
00:29:21.687 --> 00:29:39.527
Tim Leehealey: I'm advocating, at this point, a very cheap security data-like-like structure with an Agentic front end to solve the vast majority of your IT issues. I know I'm a little futuristic, I know I'm a little forward-leaning, but it really does look like the direction we're going, because
221
00:29:39.527 --> 00:29:48.107
Tim Leehealey: Tool sprawl is a big issue, tool overlap, storage costs, all these things are really rectified in a…
222
00:29:48.457 --> 00:30:00.307
Tim Leehealey: In an architecture where we imagine, sort of like, instead of plugging this on top of all these solutions, having just an Agentic layer sitting on top of a really low-cost data repository that everything pumps into.
223
00:30:00.687 --> 00:30:07.776
Tim Leehealey: I mean, there will be many use cases, Adam, to be clear, that won't solve, but I do think it is a radically
224
00:30:07.967 --> 00:30:14.706
Tim Leehealey: More effective and cost-beneficial outcome for a lot of organizations.
225
00:30:16.027 --> 00:30:19.767
Adam Chapman: Especially look at the time saved. I think that's the main thing, that…
226
00:30:19.767 --> 00:30:20.367
Tim Leehealey: Yeah.
227
00:30:20.367 --> 00:30:27.846
Adam Chapman: Where are we… stuck with hundreds and hundreds of alerts. If you remember, one of our early conversations
228
00:30:28.047 --> 00:30:36.746
Adam Chapman: at the start of the year was, we've got all these cases that we just haven't got to. How do we mass close all these cases from 6 months ago?
229
00:30:36.897 --> 00:30:40.737
Adam Chapman: Well, we're not having that conversation now, because we've only got a handful open.
230
00:30:41.087 --> 00:30:43.517
Adam Chapman: Because the rest have been dealt with.
231
00:30:43.857 --> 00:30:46.276
Adam Chapman: And they've been dealt with in a more manageable way.
232
00:30:47.137 --> 00:30:53.356
Adam Chapman: So we've gone from pulling our hair out to now being more manageable, so we can do all the things.
233
00:30:54.597 --> 00:30:55.187
Adam Chapman: So that…
234
00:30:55.187 --> 00:30:55.777
Tim Leehealey: No, it's fair.
235
00:30:55.777 --> 00:30:58.057
Adam Chapman: Budgets that I've seen over, you know, over the past…
236
00:30:58.827 --> 00:31:02.367
Adam Chapman: the past couple of months, really, since we've really got into it, I think there's…
237
00:31:02.517 --> 00:31:07.116
Adam Chapman: Yeah, there's, like any system, you've got to learn how it functions and how it operates and everything.
238
00:31:07.487 --> 00:31:12.036
Adam Chapman: But once the actual SOC team got in here and learned it's not just,
239
00:31:12.227 --> 00:31:19.706
Adam Chapman: a toy, you know, that a few people have been given access to. We're now using this day-to-day. There's been a lot of value taken from it.
240
00:31:21.127 --> 00:31:35.366
Tim Leehealey: Yeah, and I… we're sitting here talking about agents. That's been the anchor of the conversation. That's how everybody thinks about it. But, I wanted to show people kind of a workflow that you have, that you've been kind enough to share with us.
241
00:31:35.367 --> 00:31:47.526
Tim Leehealey: And have you just talk through a little bit about how it's really not necessarily the agent in the, sort of, the Claude Code N8N site type? Do you know what I mean? It's much more of a…
242
00:31:47.727 --> 00:32:02.857
Tim Leehealey: set of prescriptive decision nodes with Agentic sort of capability. So if you could walk through, kind of, just at a high level, what we've got here, and how it's different from what people think about, you know, just, like, their Cloud Code agent.
243
00:32:03.777 --> 00:32:15.397
Adam Chapman: Yeah, I think this is what sets it apart, and what I've quite enjoyed working with, is… is the workflows, because this isn't, like you say, just a prompt, you type in, press enter, and it's done.
244
00:32:15.837 --> 00:32:22.037
Adam Chapman: I have these set up to run on a scheduled basis, doing various different things.
245
00:32:22.287 --> 00:32:25.847
Adam Chapman: And this particular one is a workflow
246
00:32:25.947 --> 00:32:42.297
Adam Chapman: that picks up a case that's been allocated to the Level 2 agent. So, we've done our L1 analysis, we've done a basic assessment, and the AI agent at level 1 has decided that this needs escalation or deeper assessment.
247
00:32:42.417 --> 00:32:43.277
Adam Chapman: So…
248
00:32:43.457 --> 00:32:51.067
Adam Chapman: It grabs the comments that have been added to the case already, so they could be human-entered or AI entered, it's going to read all the information that's been put in.
249
00:32:51.507 --> 00:32:57.017
Adam Chapman: And then, it's gonna determine Which type of case we're looking at.
250
00:32:57.477 --> 00:33:08.076
Adam Chapman: So, this getCaseType is a very simple LLM prompt that says, read the case information, determine from a set list what we're looking at.
251
00:33:09.217 --> 00:33:16.817
Adam Chapman: So after that, we then go to an enrichment agent. So this is basically that… the SOC engineer goes,
252
00:33:17.067 --> 00:33:23.927
Adam Chapman: I think this needs to go to, hmm, Agent 1, because they're really good at doing this type of assessment.
253
00:33:24.537 --> 00:33:27.726
Adam Chapman: Or, it needs to be dealt with with this playbook.
254
00:33:28.396 --> 00:33:36.416
Adam Chapman: So, what we've got here is an identity, DLP, email, firewall, or network issue, and we can expand these.
255
00:33:36.747 --> 00:33:40.187
Adam Chapman: If it's nothing of them, then send it to a catch-all.
256
00:33:40.677 --> 00:33:42.867
Adam Chapman: So, identity agent there.
257
00:33:43.106 --> 00:33:45.336
Adam Chapman: Will… will go through
258
00:33:45.586 --> 00:34:00.306
Adam Chapman: in a very structured manner, looking at our data, history from different systems, what's this person been doing for the past so many months, weeks? What's their baseline look like? What's normal for this person?
259
00:34:00.667 --> 00:34:06.787
Adam Chapman: What's the alert we've got in front of us? Does that match their regular pattern, or not?
260
00:34:07.137 --> 00:34:15.536
Adam Chapman: And it will then go through a series of questions. There's about 15 or 20 questions it'll go through. So again, if you were to do that by hand in a Devo
261
00:34:15.617 --> 00:34:24.886
Adam Chapman: query, that's 15 different queries you've got to pull, or write by hand, to get that data. So there's no way I can do that in the time this does.
262
00:34:24.947 --> 00:34:36.486
Adam Chapman: So, we run through all these questions. Is this a new IP? Is this a new location for this user? Is this a new device for this user? And we go through all those questions.
263
00:34:36.887 --> 00:34:46.636
Adam Chapman: And at the end, we then say, is this something that needs to be escalated or not? Is this… is this a concern for us? Or is this normal behaviour?
264
00:34:46.697 --> 00:35:01.497
Adam Chapman: And we always, obviously, check with the user and do all that validation, but this has done a lot of that work for you. So, by the time the alert comes to you as an agent, you've got everything you need in front of you, probably more.
265
00:35:01.907 --> 00:35:17.316
Adam Chapman: to make a decision on, is this something I need to be concerned about or not? And you've got the results of all those questions that you've created. This isn't something that we've just downloaded off Strike 48 as a, you know, a template. We've built these ourselves.
266
00:35:17.547 --> 00:35:21.556
Adam Chapman: And it's been really successful, and this is what's doing
267
00:35:21.727 --> 00:35:27.477
Adam Chapman: a lot of the time saving, because there's no way I could do all this work as an agent.
268
00:35:27.667 --> 00:35:28.886
Adam Chapman: By hand.
269
00:35:29.357 --> 00:35:36.987
Adam Chapman: to the quality and, you know, the scale this can do it at. And these aren't just running in isolation, these things are running in parallel.
270
00:35:37.197 --> 00:35:53.686
Adam Chapman: So, I'm running this identity agent, for example, and I've given it these 5 questions to ask. It's running 5 parallel queries and bringing the data back. It's not some sequence that, you know, that goes on step by step, it's really fast.
271
00:35:53.977 --> 00:35:56.646
Adam Chapman: So that's one example of the workflow.
272
00:35:57.317 --> 00:36:10.917
Tim Leehealey: Yeah, it is… I'm always blown away by the development team, the technologies they've factored into this thing. At this point, this thing can blow out thousands of agents at once and just do incredible work, so…
273
00:36:10.917 --> 00:36:11.797
Adam Chapman: But…
274
00:36:11.797 --> 00:36:17.697
Tim Leehealey: We have… we have sort of stretched beyond the 35 target minutes here, so I'm gonna just sort of…
275
00:36:19.077 --> 00:36:25.287
Tim Leehealey: really spend a few minutes, Adam, if we could just talk about, kind of, how you guys look. You've accomplished a ton.
276
00:36:25.307 --> 00:36:35.657
Tim Leehealey: in the last year, it's just amazing. I'm super happy to have been on the ride with you. Kind of, what are you looking at to do next with the platform? Are there areas where you want to
277
00:36:35.657 --> 00:36:46.046
Tim Leehealey: sort of, hey, tiptoe into this additional exploration area, or areas you really think, hey, I'm pretty positive we can get a lot of value if we expand into these use cases.
278
00:36:46.877 --> 00:36:53.216
Adam Chapman: Yeah, I think this… this section, the next… let's say the next 12 months is going to be really interesting, because
279
00:36:53.357 --> 00:36:59.776
Adam Chapman: We've now got to a point where we've got cases that need to be looked at by humans, and
280
00:36:59.917 --> 00:37:01.487
Adam Chapman: A lot of cases.
281
00:37:01.657 --> 00:37:14.476
Adam Chapman: just need that extra bit, like an email to the end user, an email to the manager, it could be a Teams message. So I think the next natural step is to try and remove those steps, so that the
282
00:37:14.477 --> 00:37:21.677
Adam Chapman: The workflow is automatically contacting the end user, the line manager, whoever, our, you know, email teams.
283
00:37:21.797 --> 00:37:35.496
Adam Chapman: So that that is reduced, so that within a couple of minutes of an alert firing, you've got a message going to the end user saying, hey, was this you? Do you mechanise this activity? And reading that feedback back into the platform would be pretty cool.
284
00:37:35.707 --> 00:37:46.167
Adam Chapman: But I can see this in the future, starting to take remedial action. So, once you get to a point where you're confident that the system is getting it right.
285
00:37:46.437 --> 00:37:47.957
Adam Chapman: consistently.
286
00:37:48.257 --> 00:37:51.237
Adam Chapman: Would you be confident enough to say, well, actually.
287
00:37:51.377 --> 00:37:56.667
Adam Chapman: I'm okay with the AI agent going off to isolate an endpoint.
288
00:37:56.817 --> 00:37:59.727
Adam Chapman: Disable a user account, reset a password.
289
00:38:00.107 --> 00:38:02.516
Adam Chapman: I think it'd be nice to get to that point.
290
00:38:02.757 --> 00:38:05.737
Adam Chapman: Where you don't need to make a human decision.
291
00:38:06.497 --> 00:38:16.637
Adam Chapman: But at the moment, I think we're still, like I said earlier, about baby steps. We're at that edge now of, what is it when I get this case, am I always doing?
292
00:38:16.857 --> 00:38:36.747
Adam Chapman: constantly. So I get a case, first job, oh, well, we need to contact the user. Well, let's get rid of that bit. The user confirms, this wasn't me, I don't recognize this activity, I have not been to this country. Oh, why can't AI close that… close that user down, or suggest remedial action, or start to… to do that on your behalf?
293
00:38:37.347 --> 00:38:41.076
Adam Chapman: So the MCP connectivity, I think, is going to be important.
294
00:38:41.437 --> 00:38:42.867
Adam Chapman: So, enable…
295
00:38:43.147 --> 00:38:52.377
Adam Chapman: Prospector and Stripe 48 tools to reach out to all the platforms to affect them. So, EDR isolation is just one example.
296
00:38:52.897 --> 00:38:56.867
Adam Chapman: So that's where I can see it going from a SOC perspective.
297
00:38:57.497 --> 00:38:58.307
Adam Chapman: Well…
298
00:38:58.307 --> 00:39:00.466
Tim Leehealey: Yeah. There's more to that.
299
00:39:00.597 --> 00:39:16.726
Tim Leehealey: Yeah, I was gonna say, we have customers sort of all over the map. Some are… most are less sophisticated than yous in terms of building the system. Some have actually been really forward-leaning in terms of what they're willing to let these things do, which is always a little surprising to me, but but it is a huge spectrum out there.
300
00:39:17.237 --> 00:39:17.817
Adam Chapman: Yeah.
301
00:39:18.937 --> 00:39:24.487
Adam Chapman: Yeah, so that's where I think we could take it. There are other examples I just used there, like,
302
00:39:24.957 --> 00:39:29.207
Adam Chapman: We've started to experiment moving away from alerts.
303
00:39:29.627 --> 00:39:40.157
Adam Chapman: So, can you point an agent at a set of data, a set of logs, and say, find things in this bucket of information that I need to know about?
304
00:39:40.337 --> 00:39:46.716
Adam Chapman: what have I… what have I missed in my alerts? There's always that thing in security of, we expect
305
00:39:47.077 --> 00:39:50.826
Adam Chapman: That we will see these type of activities, this looks bad.
306
00:39:51.067 --> 00:40:08.756
Adam Chapman: But what if a new attack vector comes out, or a new technique comes out that you don't know about, or you've not anticipated? Can you get an agent to look at firewall logs for the past 24 hours, or whatever, and pick out important things that you might have missed?
307
00:40:09.377 --> 00:40:16.147
Adam Chapman: And I have had success with that before as well. So, can you get that to run on a scheduled basis?
308
00:40:16.747 --> 00:40:22.717
Adam Chapman: So, pick out the things that I need to know about, and move away from the traditional rulebook of
309
00:40:22.937 --> 00:40:26.177
Adam Chapman: this is bad, so it must be an alert. That's pretty…
310
00:40:26.417 --> 00:40:29.457
Adam Chapman: pretty cutting edge as well, I think, in some cases.
311
00:40:30.187 --> 00:40:43.797
Tim Leehealey: Yeah, and I actually feel like it has the potential. And you've had success here, so it's always exciting to listen to the successes you've had on this front, but it has the potential to truly deliver what UEBA was supposed to.
312
00:40:44.257 --> 00:41:03.737
Tim Leehealey: Right? There's some idea that you get this true sense of normal, and then you can just find the random anomalies and reduce the risk that way. I mean, I think that has been a journey that has been less productive than we all hoped it would have been, but this feels like it's actually delivering. I have seen it pull out
313
00:41:03.797 --> 00:41:14.026
Tim Leehealey: impossible traveler without having been asked about it. I've seen it pull out anomalistic activity in some environments that really did ultimately lead to
314
00:41:14.567 --> 00:41:18.017
Tim Leehealey: A discovery of an active attack.
315
00:41:18.457 --> 00:41:21.587
Tim Leehealey: We've had that in a proof of concept, it's crazy.
316
00:41:22.087 --> 00:41:33.017
Adam Chapman: Yeah, we've… it's part of the testing process, I didn't mention earlier, that we've, we've run the prospector agents against a known incident.
317
00:41:33.207 --> 00:41:36.586
Adam Chapman: To see how it compares to what we found out
318
00:41:37.167 --> 00:41:43.697
Adam Chapman: in the SOC. So, if you've got an incident that you know about, you know what happened, you've investigated it by hand.
319
00:41:43.897 --> 00:41:50.916
Adam Chapman: Then run the agent against it. Did it come up with the same information you did? And that's a good validation step.
320
00:41:51.227 --> 00:41:59.147
Adam Chapman: Or you do it the other way around, and you get the agent to do the investigation first, and you then follow up afterwards as a trust.
321
00:41:59.307 --> 00:42:01.697
Adam Chapman: Sort of validation step, but…
322
00:42:01.857 --> 00:42:10.667
Adam Chapman: Yeah, it is finding things that alerts don't find, and correlating more than you would typically find in an alert, because
323
00:42:11.117 --> 00:42:18.217
Adam Chapman: in a defined alert, you're expecting things to happen. And what if the expected things don't happen? Or you get…
324
00:42:18.327 --> 00:42:22.976
Adam Chapman: 9 password attempts in 10 minutes, rather than the 10 that you're alerting.
325
00:42:22.977 --> 00:42:24.177
Tim Leehealey: Yeah, right.
326
00:42:24.177 --> 00:42:27.696
Adam Chapman: But those things, this is where it really helps.
327
00:42:28.337 --> 00:42:32.656
Adam Chapman: So, yeah, there's loads of opportunity. It's now a case of working out
328
00:42:32.797 --> 00:42:37.887
Adam Chapman: where do we want to go next? That is difficult, because there's so many ways you can take this.
329
00:42:39.277 --> 00:42:50.117
Tim Leehealey: It's certainly exciting, super exciting. So anyway, listen, Adam, I really appreciate you taking the time to sort of take us through your journey. I think it's super instructive, it's super inspiring, frankly.
330
00:42:50.117 --> 00:43:08.557
Tim Leehealey: And I think it's what other people in the market need to hear, because the reality is, you really have to embrace it. You're gonna have to embrace this stuff, or you're gonna get left behind. No one wants to get left behind. So seeing people like yourself be brave enough to embrace this a year ago, and actually having it be fruitful.
331
00:43:08.647 --> 00:43:14.536
Tim Leehealey: is, I think, a really powerful message. So, thanks for taking the time, I really appreciate it.
332
00:43:15.047 --> 00:43:16.307
Adam Chapman: No, you're welcome. Marissa.
333
00:43:16.927 --> 00:43:18.827
Tim Leehealey: Do we have any questions?
334
00:43:19.067 --> 00:43:42.867
Marissa Notaro: We do, so we have a good amount of questions, but obviously, we don't have as much time, because we went through some really good nuggets here. So, I'm gonna go through just a few questions, and then anybody else that has questions, obviously you can reach out as well, and we can get that to the team. But one of the questions that came in was, after Sim
335
00:43:42.867 --> 00:43:44.477
Marissa Notaro: integration.
336
00:43:44.477 --> 00:43:54.516
Marissa Notaro: How do we define which alerts become cases, and which workflow module handles them? Is this UI-based or back-end configuration?
337
00:43:58.427 --> 00:44:00.196
Adam Chapman: I can go if you want to.
338
00:44:00.197 --> 00:44:02.656
Tim Leehealey: Yeah, you go, and then I'll go after.
339
00:44:02.947 --> 00:44:12.297
Adam Chapman: I'll say what I've done, then you can give the textbook answer. So, what we've done is, in the previous platform, we…
340
00:44:12.427 --> 00:44:15.046
Adam Chapman: We were looking at mediums or higher.
341
00:44:15.437 --> 00:44:17.807
Adam Chapman: Because that was what the team could look at.
342
00:44:18.257 --> 00:44:22.447
Adam Chapman: But now, where we've got this extended capability, let's look at everything.
343
00:44:23.397 --> 00:44:26.996
Adam Chapman: Everything may not become a case.
344
00:44:27.197 --> 00:44:31.786
Adam Chapman: But every alert's gonna get looked at to see if it qualifies to become a case.
345
00:44:32.147 --> 00:44:40.417
Adam Chapman: So that's the way… the way we've done it. So, every alert gets looked at to see if it's part of an existing case that needs to be brought in.
346
00:44:40.537 --> 00:44:50.266
Adam Chapman: Or is it something that's happened that doesn't need investigation? We don't need to make it part of the case? So, typically, we're looking at mediums or higher.
347
00:44:50.437 --> 00:44:55.487
Adam Chapman: And then the rest of the bucket kind of gets assessed for, is it worthy to bring in
348
00:44:55.817 --> 00:44:59.286
Adam Chapman: But I guess that's very specific on how you want to operate.
349
00:44:59.447 --> 00:45:02.826
Adam Chapman: your team, isn't it? That's not something that's textbook.
350
00:45:03.927 --> 00:45:15.906
Tim Leehealey: So, what we tell people is… I think it's… and it's indicative of what you guys have done, is we tell people, what you really need to do is redefine what you mean by a case, because
351
00:45:16.127 --> 00:45:31.707
Tim Leehealey: reintroduce this case type concept, right? And there is AI case closed by an AI, all this kind of stuff, and I view that as the starting point. Traditionally, alerts were the starting point. But since now you can actually look at every single alert.
352
00:45:31.817 --> 00:45:44.376
Tim Leehealey: The starting point should be the cases themselves. You can be relatively lenient with how you create them, but if you give them case types where AI created, AI assessed, AI closed.
353
00:45:44.617 --> 00:45:57.287
Tim Leehealey: you now have… that can be, if you will, the bucket you start from, versus alerts being the bucket. So, we encourage customers to get a little bit more lenient.
354
00:45:57.297 --> 00:46:05.956
Tim Leehealey: With what's considered a case, but then to have case types, so you actually reduce the manual work,
355
00:46:06.607 --> 00:46:09.077
Tim Leehealey: Needed, but you get far better coverage.
356
00:46:10.727 --> 00:46:28.516
Marissa Notaro: Thank you both. So another question that came in, so they asked, how does the Strike 48 AI agent identify zero-day threats or unknown attack vectors that lack pre-existing signatures or known IOCs?
357
00:46:28.647 --> 00:46:30.667
Marissa Notaro: So that was another one that came in.
358
00:46:31.107 --> 00:46:50.866
Tim Leehealey: So that's what Adam was talking about, sort of, at the very end. So, I would say two things, and Adam, I'd let you go. So, first of all, by no means am I claiming it can catch everything. I'm not… it's amazing what it can do. I never need to oversell this thing. It's just exciting, but that does not make it…
359
00:46:50.867 --> 00:46:54.656
Tim Leehealey: the be-all, end-all, the end of security issues. Definitely not.
360
00:46:54.737 --> 00:46:59.887
Tim Leehealey: What I would say, though, is its ability to correlate across to the vast
361
00:47:00.027 --> 00:47:03.846
Tim Leehealey: set of tools versus just looking at your SIM,
362
00:47:04.247 --> 00:47:15.057
Tim Leehealey: It has a much better ability to spot issues like that, those sort of non-alert-defined issues, or more Novell-types attacks.
363
00:47:15.167 --> 00:47:21.586
Tim Leehealey: Versus what you could ever do with a traditional toolset. Does that mean the problem's solved? No.
364
00:47:21.847 --> 00:47:30.806
Tim Leehealey: But is it… are you far better off? Yeah, you're light years better off than you are without it. But Adam, I don't know if you want to grab at the question as well.
365
00:47:30.807 --> 00:47:40.117
Adam Chapman: Yeah, I would agree with that, but I think, XDR plays a big role in that, and ingesting that information into the seam as well.
366
00:47:40.287 --> 00:47:43.386
Adam Chapman: So you, you're getting user behavior
367
00:47:43.597 --> 00:47:53.587
Adam Chapman: monitoring, so you're kind of seeing what's happening within people's machines, but I think we've got to remember that this is effectively a SOAR-type platform. It's not there to detect
368
00:47:53.767 --> 00:47:56.416
Adam Chapman: Incidents as they happen.
369
00:47:56.547 --> 00:48:03.437
Adam Chapman: like an XDR or an EDR platform would. So I think this is looking at things slightly after the fact.
370
00:48:04.067 --> 00:48:07.546
Adam Chapman: But what it is going to do is help you investigate that a lot quicker.
371
00:48:08.077 --> 00:48:18.267
Adam Chapman: and come to a decision a lot quicker is, is this something… is there something going on here I need to know about? So I don't think it's necessarily going to detect any sort of zero day on its own.
372
00:48:18.777 --> 00:48:23.666
Adam Chapman: But I don't think it's engineered to. I think Timmy might want to comment on that, but…
373
00:48:23.827 --> 00:48:31.606
Adam Chapman: I feel like this is more of an investigation platform that's looking at what's happened, rather than what's happening
374
00:48:31.817 --> 00:48:33.566
Adam Chapman: Does that make sense? Nope.
375
00:48:33.567 --> 00:48:52.066
Tim Leehealey: Yeah, it makes total sense. We do have customers that are leaning a little bit more into the zero-day detection capability of it, but I would still agree heavily with what you're saying. The sentiment of what you're saying is spot on. However.
376
00:48:52.307 --> 00:49:09.797
Tim Leehealey: you know, let's see where it goes in the next 3 to 6 months, because there's just a ton coming in terms of those type of zero-day, remediation capabilities, detection and remediation capabilities. But right now, Adam, I think you've accurately sort of categorized it.
377
00:49:10.057 --> 00:49:13.996
Tim Leehealey: So, any more questions, Marissa? I know we're sort of well at… past time.
378
00:49:13.997 --> 00:49:32.457
Marissa Notaro: Yeah, so this is the final one that we're able to take today, but the other ones we can, you know, answer offline. So to wrap it up, has Adam or anyone on his team considered any other Agentic AI companies in this space? And if so, why have you stayed with Strike48?
379
00:49:34.397 --> 00:49:38.777
Adam Chapman: I think we've built a really good partnership.
380
00:49:38.957 --> 00:49:43.027
Adam Chapman: with Stripe 48. As Tim said.
381
00:49:43.607 --> 00:49:53.517
Adam Chapman: At the beginning, I took over the team, and we were seriously considering leaving, because we just didn't see the value in what we had.
382
00:49:53.877 --> 00:50:00.806
Adam Chapman: And I think, we've not needed to look elsewhere, because the tool is doing what we need it to do.
383
00:50:01.157 --> 00:50:05.447
Adam Chapman: I haven't found anything that compares, either.
384
00:50:05.687 --> 00:50:08.576
Adam Chapman: So, even if I were to go shopping.
385
00:50:08.817 --> 00:50:11.897
Adam Chapman: would I find another platform that… that does…
386
00:50:12.127 --> 00:50:22.367
Adam Chapman: what Stripe 48 are doing. I think a lot of it that I've seen, a lot of EDR platform demos, for example, they have an agent built into the EDR platform.
387
00:50:22.587 --> 00:50:25.657
Adam Chapman: Brilliant. But that only lives in the EDI platform.
388
00:50:25.887 --> 00:50:37.556
Adam Chapman: That's all it can ever do. And I think bringing it on top of all the platforms is what makes it unique for me. I've not found another tool that does that.
389
00:50:38.047 --> 00:50:50.427
Adam Chapman: So that's one of the reasons why we've stayed, but the support that we've had from the team, you know, everyone that we've met and dealt with has been super helpful, super friendly, and…
390
00:50:50.857 --> 00:51:02.407
Adam Chapman: they're all… everybody wants to help, you know, we're in this together as a partnership, rather than, like, a supplier-customer relationship. It feels to me more like a… you know, more like a partnership that we've built.
391
00:51:02.877 --> 00:51:10.467
Adam Chapman: And I don't think that's… that's because we've been closer on this team. I think, generally,
392
00:51:11.037 --> 00:51:18.816
Adam Chapman: nimble enough to be able to, you know, to assist people where they need it, and I don't think you get that from the big players.
393
00:51:19.707 --> 00:51:22.796
Adam Chapman: So, yeah. And I've not been paid to say that, by the way.
394
00:51:22.797 --> 00:51:24.677
Marissa Notaro: I appreciate that, Adam.
395
00:51:24.997 --> 00:51:26.766
Tim Leehealey: It's very nice of you.
396
00:51:26.767 --> 00:51:28.887
Marissa Notaro: you on the spot, Adam.
397
00:51:28.887 --> 00:51:39.186
Adam Chapman: How many… how many, vendors or product suppliers have you met the CEO of on numerous occasions on Teams?
398
00:51:39.747 --> 00:51:43.057
Adam Chapman: You know, I've met Ken a few times now, and…
399
00:51:43.357 --> 00:51:49.287
Adam Chapman: That's what adds the value, I think, is from the very top, understanding what the customers are needing.
400
00:51:49.737 --> 00:51:57.357
Adam Chapman: And it feels like we can, sort of, as a customer, go top-down, bottom-up, you know, we can sort to anybody we need to, and I think that
401
00:51:58.557 --> 00:52:13.326
Adam Chapman: the ability that we've got just to reach out to Tim, who I'm sure is a very busy guy, when we need him, is valuable, and you can't do that with every, you know, with every vendor, can you? With every customer. Sorry, with every supplier. It's just not going to happen.
402
00:52:14.607 --> 00:52:15.317
Marissa Notaro: Appreciate it.
403
00:52:15.317 --> 00:52:27.076
Tim Leehealey: Appreciate those, yeah, those kind words. So, Marissa, I think we should probably end it here. We've gone way too long, but, it's been a super exciting conversation, so I didn't want to ever cut it short, so…
404
00:52:27.487 --> 00:52:47.137
Marissa Notaro: Yes, thank you so much, everyone, for joining. The recording will be sent out to everyone, so if there's anything you want to go back to, we appreciate your time, we appreciate the time of our speakers. Adam, Tim, it was such an insightful discussion, we appreciate it. And yeah, we're really excited for what's next, and thank you so much!
405
00:52:47.757 --> 00:52:49.156
Tim Leehealey: Thanks a lot, guys, really appreciate it.
406
00:52:49.157 --> 00:52:51.026
Marissa Notaro: Good day, everyone. Bye!
407
00:52:51.207 --> 00:52:51.977
Adam Chapman: Bye-bye.