Full transcript

1

00:00:02.647 --> 00:00:16.017

Marissa Notaro: Alright, so I think we're gonna get started now, because the majority of people have joined. Welcome, everyone! We're super excited to be here, and to have some great speakers to talk on a really critical topic.


2

00:00:16.017 --> 00:00:36.287

Marissa Notaro: So we're gonna start off, with covering that topic that we're gonna be going through, which is no more Missed Alerts, making the Jump from SOAR to AI SOC, how the Trinox SOC team handled routine investigation to AI agents. So, I'm gonna just go through, some housekeeping items first.


3

00:00:36.287 --> 00:01:01.187

Marissa Notaro: So just so you guys are aware, there is a Q&A section. Please ask any questions you have in there. We will get to those questions at the end of this session. This is also being recorded, so you will get the recording after. We will email that to all of the people that have attended and registered. And if you would like to have a personalized demo, feel free to use that link.


4

00:01:01.377 --> 00:01:17.357

Marissa Notaro: to request one. So, we're going to start off with introducing our speakers. So really excited to have our co-founder and president of Strike 48, Tim Leehealey. Thank you for joining, Tim.


5

00:01:18.287 --> 00:01:19.127

Marissa Notaro: Awesome.


6

00:01:19.127 --> 00:01:22.807

Tim Leehealey: Listen, super happy to be here. Thanks for, thanks for letting us do this.


7

00:01:22.937 --> 00:01:33.537

Marissa Notaro: Yep, super excited. And then we also have Adam Chapman, who is the Director of Cybersecurity from Tronox. Really excited to have you here, Adam, our special guest.


8

00:01:34.217 --> 00:01:35.907

Adam Chapman: Thank you. Good to be here.


9

00:01:36.357 --> 00:01:44.307

Marissa Notaro: Awesome. And Adam, can you share a little bit about Tronox, just so that, everyone that's on the call, can have a little bit of an overview?


10

00:01:44.727 --> 00:01:54.266

Adam Chapman: Yeah, of course. So, Trinox are a global chemical company, and mining as well, so we've got 5,700 employees around the world.


11

00:01:54.397 --> 00:01:59.326

Adam Chapman: We're operating across 6 continents, so quite a large footprint.


12

00:01:59.427 --> 00:02:06.467

Adam Chapman: And we produce high-quality titanium products. A lot of the things that are in your homes, your businesses.


13

00:02:06.837 --> 00:02:17.547

Adam Chapman: You'll probably find titanium dioxide is part of them, so paint, plastic, paper, is the materials that we produce, so chemicals that go into those products.


14

00:02:17.927 --> 00:02:27.547

Marissa Notaro: Awesome. Thank you so much, Adam. And Tim, we're gonna kick off that conversation, so I'll let you take it from here. Yeah, let's get started.


15

00:02:27.997 --> 00:02:38.816

Tim Leehealey: I'll just start out by saying, Adam, I had no idea that the pan I just bought came from you guys. It's titanium, it's all the rage.


16

00:02:39.017 --> 00:02:42.587

Adam Chapman: Yeah, it's amazing what, what our products are into.


17

00:02:42.927 --> 00:02:52.287

Tim Leehealey: Yeah. So, anyway. So, okay, listen, I wanted to start… so you and I have had a relationship now for over a year, and…


18

00:02:52.287 --> 00:03:04.896

Tim Leehealey: you know, we've gone through our highs and lows. I think it's been probably one of our most productive from a strategic standpoint, just working with you, your team, how you guys have pushed forward in embracing this technology.


19

00:03:05.007 --> 00:03:11.716

Tim Leehealey: So, I'm really excited To walk through the journey, have everybody kind of understand


20

00:03:11.757 --> 00:03:30.887

Tim Leehealey: the steps you went through, and kind of, the… the… what you've been able to produce, and how you're utilizing the product. But, I think we do a disservice if we don't start out where we were, right? Because when I met you guys, you guys were a Devo customer, and you were effectively telling me.


21

00:03:30.987 --> 00:03:36.727

Tim Leehealey: we're gonna churn, there's really not a heck of a lot of value in the SIM platform.


22

00:03:36.777 --> 00:03:51.906

Tim Leehealey: So, if you can start out telling… go back that full year to those conversations, tell me where you were as a team, kind of how you were restructuring things, and you know, again, take us back to November of last year.


23

00:03:52.577 --> 00:04:02.027

Adam Chapman: Yeah, so November last year was quite a tough time, for the team. We'd just gone through a restructuring of our SOC operations team and our security team.


24

00:04:02.257 --> 00:04:09.936

Adam Chapman: And we're at that point of assessing what tools do we have, what people do we have, how do we operate now as a new team.


25

00:04:10.307 --> 00:04:17.336

Adam Chapman: And within the Devo system that we have, the scene platform, we're ingesting gigabytes of logs.


26

00:04:17.667 --> 00:04:20.096

Adam Chapman: We're receiving loads and loads of alerts.


27

00:04:20.257 --> 00:04:22.126

Adam Chapman: And everything was manual.


28

00:04:22.247 --> 00:04:30.006

Adam Chapman: So, it's quite quickly becoming apparent that the team are becoming overloaded with that number of alerts that come in.


29

00:04:30.137 --> 00:04:33.986

Adam Chapman: And you're manually having to sift through them to find the ones that are


30

00:04:34.187 --> 00:04:50.146

Adam Chapman: important, the ones that don't need attention, and it's just a constant battle. Then, as soon as you've cleared the queue, you get another 5 popping. So, it's that constant problem that you face in a SOC environment that you've never done. There's always another job to do.


31

00:04:50.597 --> 00:04:55.697

Tim Leehealey: It just doesn't really even work, does it? I mean, at the end of the day, I mean, I have these conversations over and over.


32

00:04:55.697 --> 00:05:06.597

Adam Chapman: It doesn't scale. The more data you ingest, the more alerts you generate, the better you become, the more you find, but then the more you've got to deal with.


33

00:05:06.957 --> 00:05:12.997

Adam Chapman: So, it's kind of that cycle that you think, well, right, great, we need an alert for this, we need an alert for that.


34

00:05:13.167 --> 00:05:24.176

Adam Chapman: But now we've got to triage them, and you kind of create work without realizing it quite, quite easily. So you can quite quickly, you know, out-resource the team.


35

00:05:24.997 --> 00:05:28.636

Tim Leehealey: Yeah, you're always making that decision between coverage


36

00:05:28.977 --> 00:05:40.516

Tim Leehealey: criticality and visibility. Like, I have conversations all the time where people are like, well, listen, I'd love to ingest those logs, but it's too expensive, and if I did, I'd just have more work.


37

00:05:40.777 --> 00:05:45.966

Tim Leehealey: Do you know what I mean? But… so you're constantly in that battle of…


38

00:05:46.977 --> 00:05:53.167

Tim Leehealey: you know, not only what am I threatened by, but what can I actually achieve on a day-to-day basis?


39

00:05:53.527 --> 00:05:57.806

Adam Chapman: Yeah. The more you look, the more you find. It's as simple as that, isn't it?


40

00:05:57.967 --> 00:06:11.567

Adam Chapman: And what we've managed to do over the years… we've had the Devo platform for a number of years. If we had had an investigation or an incident that's gone on, we've then developed an alert for that in case it happens again.


41

00:06:11.837 --> 00:06:27.736

Adam Chapman: And we've kind of evolved the scene through that natural cycle, but you get to a point where some of these just become noise, and it's very hard to work out on a day-to-day basis, what should I be doing today?


42

00:06:28.267 --> 00:06:30.377

Adam Chapman: What… what cases are important?


43

00:06:30.617 --> 00:06:40.686

Adam Chapman: what things don't need to be looked at by a human, what can I just put to the side for tomorrow, maybe? That's the position that we were in.


44

00:06:41.607 --> 00:06:46.927

Adam Chapman: Yeah. So the conversation was, how do we get more value out of this system?


45

00:06:47.257 --> 00:06:49.866

Adam Chapman: And that was our conversation last year.


46

00:06:50.327 --> 00:07:05.437

Tim Leehealey: Yeah, and it was perfect timing, because at the time, we had really just launched, and let's sort of go into this, we had just launched our Strike 48 platform, which sits on top of Devo. Actually, at this point, can sit on top of any SIM, or storage, or whatever.


47

00:07:05.517 --> 00:07:16.157

Tim Leehealey: And… I gotta say, honestly, Adam, I was super excited with how your team was willing to sort of take a risk here. I saw it as a risk. I think you guys…


48

00:07:16.247 --> 00:07:29.336

Tim Leehealey: saw it as such, too, but we sort of came in and said, hey, give this a try, give us another year, let's layer this on top of Devo. We think it's going in the direction you want it to.


49

00:07:29.357 --> 00:07:37.127

Tim Leehealey: I think we were pretty upfront about the fact that we were exciting, enthusiastic, really passionate, but maybe it wasn't yet there.


50

00:07:37.387 --> 00:07:40.457

Tim Leehealey: But you guys jumped in the,


51

00:07:41.137 --> 00:07:52.487

Tim Leehealey: in the boat with us, and again, I think it's been productive, but so tell us, kind of, from your side, how you saw that, how you saw the vision, and what made you willing


52

00:07:52.807 --> 00:07:54.627

Tim Leehealey: To give us another year.


53

00:07:56.677 --> 00:08:02.997

Adam Chapman: Yeah, well, first of all, I used the AI assistant that was built into Devo.


54

00:08:03.527 --> 00:08:05.827

Adam Chapman: And… that was impressive enough.


55

00:08:06.297 --> 00:08:10.696

Adam Chapman: To think, well, if there's something better than that, then this is surely worth exploring.


56

00:08:11.287 --> 00:08:13.707

Adam Chapman: And we got on a few calls.


57

00:08:13.947 --> 00:08:17.717

Adam Chapman: It must have been an early version of the product that we saw originally.


58

00:08:17.877 --> 00:08:24.307

Adam Chapman: And some of the things it was able to do, like the investigation of things, which is far quicker


59

00:08:24.327 --> 00:08:42.847

Adam Chapman: and a lot more thorough than what a human can do. So, just that initial thought of, what can this thing do for us? If you think of our problem of just, you know, just having a new team built and everything, we had the opportunity to build a brand new SOC from the ground up.


60

00:08:43.547 --> 00:08:50.426

Adam Chapman: Which is quite a daunting thing, really. But this tool has helped us to do that.


61

00:08:50.667 --> 00:08:58.136

Adam Chapman: So, the thing about… on the screen there, about every alert analyzed, well, we took it right back to the beginning.


62

00:08:58.557 --> 00:09:07.167

Adam Chapman: And we started with our alerts and our data ingestion. So, we had AI agents from Stripe 48,


63

00:09:07.327 --> 00:09:09.596

Adam Chapman: Analyzing our current alerts.


64

00:09:09.677 --> 00:09:25.916

Adam Chapman: Have we got the right coverage? Are those alerts triggering when they shouldn't be? Are all the metadata, the entities, are they mapped correctly? All this stuff would have taken us probably weeks to go through all the alerts, one by one.


65

00:09:25.967 --> 00:09:34.906

Adam Chapman: and find that the gaps in coverage, the gaps in potentially the queries might have been a little bit wrong, or needed to be tweaked. So that was the first step, is…


66

00:09:34.987 --> 00:09:37.356

Adam Chapman: Cleaning up the alerts at scale.


67

00:09:37.917 --> 00:09:43.347

Adam Chapman: Such that when they went into the platform, They had a lot more…


68

00:09:43.507 --> 00:09:48.637

Adam Chapman: metadata around them that could then be ingested by the AI agent.


69

00:09:48.777 --> 00:09:51.686

Adam Chapman: So, a lot of this was housekeeping, a lot of clean-up.


70

00:09:51.937 --> 00:09:56.116

Adam Chapman: To begin with, But then once you've done that.


71

00:09:56.557 --> 00:09:58.567

Adam Chapman: It all starts to make sense.


72

00:09:59.607 --> 00:10:11.896

Tim Leehealey: And did you have a few… I mean, we just talked about alert triage and enrichment and stuff like that. Did you have a… at the time, were you like, okay, this is obvious, let's use this for this, or was there…


73

00:10:11.987 --> 00:10:30.536

Tim Leehealey: you know, again, you guys got into an early version of the platform. How much sort of startup time did it take? And at this point, just to be clear, you guys are very sophisticated users, right? So you've really done some incredible stuff, but take me through a little bit of the learning process in terms of


74

00:10:30.787 --> 00:10:41.867

Tim Leehealey: what you initially saw when we came and said, hey, try this Agentic platform, in terms of the potential, and kind of how you're… how you got up to speed, and how you're viewing it now.


75

00:10:42.647 --> 00:10:58.927

Adam Chapman: Well, the actual setup process was fairly straightforward. The Stripe 48 team helped us with that. It's a case of creating some API keys, linking everything together, and that's a fairly straightforward process. So, within a few hours, we had everything connected.


76

00:10:59.137 --> 00:11:03.887

Adam Chapman: And I think to start with, it's like, right, it's like having anything new, what can this thing do?


77

00:11:04.217 --> 00:11:07.377

Adam Chapman: So… what I found myself doing was.


78

00:11:08.117 --> 00:11:20.577

Adam Chapman: creating, sort of, quite simple questions. Oh, I'm investigating this alert, tell me about the activity of this user. Tell me about this IP address, this machine. Starting quite basic.


79

00:11:20.727 --> 00:11:27.776

Adam Chapman: And you start to think, wow, this thing's pretty good. You know, what more can it do? So,


80

00:11:28.137 --> 00:11:34.807

Adam Chapman: I started off writing very simple questions, very… almost like a co-pilot style…


81

00:11:34.937 --> 00:11:38.767

Adam Chapman: a question that you'd ask another colleague, for example, and…


82

00:11:38.907 --> 00:11:40.696

Adam Chapman: I just saw the power of it.


83

00:11:40.967 --> 00:11:46.467

Adam Chapman: And I think… as I've got used to the platform more, and the team are using it more.


84

00:11:46.917 --> 00:11:55.557

Adam Chapman: we've just learned to embed that in our day-to-day work, rather than it being something, oh, I remember… I need to go into this new system now to try this.


85

00:11:55.707 --> 00:12:10.147

Adam Chapman: It's now becoming the place I go to first, you know, rather than the place I'd think about going to, because I've, you know, forgot it exists. So, it's definitely becoming embedded within the team now, which is good from the beginning.


86

00:12:11.067 --> 00:12:16.016

Tim Leehealey: And how do you get the… how do you get… how did you get over, and… and how do you get your team over…


87

00:12:16.107 --> 00:12:28.647

Tim Leehealey: the skepticism factor, the… listen, we've all been lied to by ChatGPT, or politely answered incorrectly, do you know what I mean? And there's no magic to Strike 48.


88

00:12:28.647 --> 00:12:37.256

Tim Leehealey: I think it's an incredibly powerful harness, but there are pitfalls, there are ways you can confuse agents. How do you deal with the skepticism


89

00:12:37.267 --> 00:12:40.106

Tim Leehealey: that we've all sort of developed relative to AI.


90

00:12:40.147 --> 00:12:43.746

Tim Leehealey: in terms bracing it for IT-level use cases.


91

00:12:44.277 --> 00:12:47.487

Adam Chapman: Yeah, there was definitely that at the beginning, like.


92

00:12:47.977 --> 00:13:00.817

Adam Chapman: what is this thing? What can it do? Well, that's complete nonsense. Where has it got this from? And, yes, at the beginning, in the early days of December, January, when we were pretty new to the product.


93

00:13:00.957 --> 00:13:06.186

Adam Chapman: There were hallucinations, But what we've learned to do is…


94

00:13:06.317 --> 00:13:20.797

Adam Chapman: train it more to say, if I'm asking you about this, then our data is in this table, go look at that. So, we're a lot more specific now, but what we've learned to do is tune… tune the prompt, tune the tool.


95

00:13:20.897 --> 00:13:38.306

Adam Chapman: Effectively, so that if it does start to do something that either we don't want or is incorrect, we tell it not to do that again in the prompt. So we've got a series of rules that we'll introduce that says, never make up evidence. If you don't know, say you don't know, don't make it up.


96

00:13:38.627 --> 00:13:42.127

Adam Chapman: basic stuff, and I said, earlier that


97

00:13:42.707 --> 00:13:54.766

Adam Chapman: You treat this like your office junior, like your apprentice, that it's gonna get things wrong to start with, but you correct it step by step, and eventually you build something that… that you can rely upon.


98

00:13:55.467 --> 00:13:57.977

Adam Chapman: And I think we're at that point now where


99

00:13:58.247 --> 00:14:03.967

Adam Chapman: It's a lot more accurate than it's ever been, because we've spent the time to tune it.


100

00:14:04.067 --> 00:14:10.166

Adam Chapman: And to point it in the right direction, so that when we do ask these questions, it knows where to go.


101

00:14:10.407 --> 00:14:11.266

Adam Chapman: Rather than having.


102

00:14:11.267 --> 00:14:11.587

Tim Leehealey: It's.


103

00:14:11.587 --> 00:14:15.697

Adam Chapman: say, oh, I've got all these gigabytes of data, what is it you're asking me for?


104

00:14:16.977 --> 00:14:30.137

Tim Leehealey: It's super interesting how you phrase that, because that is one thing that I really encourage people to understand about agents, is you always need to give them an off-ramp.


105

00:14:30.267 --> 00:14:32.397

Tim Leehealey: They are eager beavers.


106

00:14:32.527 --> 00:14:47.626

Tim Leehealey: And if you corner them, and they have no off-ramp, that is the number one recipe for a hallucination. But if you just tell them, if you can't find it in the data, say you don't know or can't find it in the data, they're happy to do that.


107

00:14:47.977 --> 00:14:53.157

Tim Leehealey: But if you don't tell them, they will effectively field corner and hallucinate.


108

00:14:53.837 --> 00:14:54.697

Tim Leehealey: So, yeah.


109

00:14:55.277 --> 00:14:55.937

Adam Chapman: Is…


110

00:14:55.937 --> 00:14:56.257

Tim Leehealey: Anyway…


111

00:14:56.257 --> 00:15:04.376

Adam Chapman: Another thing we saw early on was… was where you would… you'd ask a question, and it would start to go off on a little bit of a…


112

00:15:04.487 --> 00:15:14.606

Adam Chapman: a tangent and say, well, this is a confirmed breach. And you think, well, actually, no, it's not a confirmed breach, but let's just have a look at why it might think that.


113

00:15:14.677 --> 00:15:29.536

Adam Chapman: And as a human, you can read the data and go, yeah, okay, I can see why it's… why it's come to that conclusion. And it's usually because there's something in the alert, the wording of the summary that says, threat detected, or… so, you need to constantly, sort of.


114

00:15:29.537 --> 00:15:34.847

Adam Chapman: Tune it so that it's aware of your alert types, the language to use.


115

00:15:34.997 --> 00:15:42.467

Adam Chapman: And we've worked with the Stripe 48 team for the past, you know, 9 months now to tune that wording, so it's a bit softer.


116

00:15:42.697 --> 00:15:46.487

Adam Chapman: You know, something is suspicious, it's not confirmed yet.


117

00:15:46.877 --> 00:15:53.186

Adam Chapman: So yeah, it's all a learning curve on our part as well, as a team. This is brand new to us.


118

00:15:53.447 --> 00:15:57.937

Adam Chapman: And we've had to… to learn to adapt as well, but…


119

00:15:58.197 --> 00:16:01.096

Adam Chapman: I'm really happy now that we're in August.


120

00:16:01.577 --> 00:16:07.267

Adam Chapman: And, you know, it's now doing the bulk of the work for us, versus before we had nothing.


121

00:16:07.667 --> 00:16:08.627

Adam Chapman: So, yeah.


122

00:16:08.627 --> 00:16:09.167

Tim Leehealey: No.


123

00:16:09.337 --> 00:16:26.997

Tim Leehealey: So let's actually talk about that. Let's hop to your results and kind of… this is a slide you put together for us. Tell us, kind of take us through where you were, where you are, and just, you know, give us the before and after, if you will.


124

00:16:28.467 --> 00:16:31.866

Adam Chapman: Yeah, so we've been doing the alert tuning for quite a while.


125

00:16:31.976 --> 00:16:41.327

Adam Chapman: Got that done, and to a point now where we're seeing about 600 alerts a week, maybe more, maybe less, obviously that varies.


126

00:16:41.667 --> 00:16:48.287

Adam Chapman: But every single one of them needed to be looked at by one of the team. So that's quite a large workload.


127

00:16:48.877 --> 00:17:03.856

Adam Chapman: And what we found was the majority of those cases that fired, they were probably false positives. It was something that we'd set up as an alert, and actually, okay, in this context, this alert is okay. This isn't anything we need to worry about.


128

00:17:04.757 --> 00:17:22.697

Adam Chapman: So that's gonna take… if you say 15 minutes each one, that's 150 hours of human time per week spent just doing that initial triage. And we all know that 15 minutes isn't long. You can soon go down a rabbit hole, that could turn into an hour.


129

00:17:22.797 --> 00:17:29.317

Adam Chapman: quite easily, depending on the information presented. So that is probably a conservative estimate.


130

00:17:29.827 --> 00:17:34.256

Adam Chapman: And, obviously, because you've got 150 hours, you've only got a certain number of people in the team.


131

00:17:34.507 --> 00:17:49.066

Adam Chapman: They've got work to do as well as this. This isn't their only job. They're not just sat waiting for alerts to fire. They've got day jobs as well. So they've got all the workload. So that slowly leads to an overloaded team.


132

00:17:49.487 --> 00:17:53.996

Adam Chapman: We've got their Missed Alerts, but I think it's more about…


133

00:17:54.767 --> 00:18:00.716

Adam Chapman: prioritizing the work. What it means is the stuff that needs to be prioritized gets front and center.


134

00:18:00.897 --> 00:18:14.817

Adam Chapman: But it's quite easily for a low-priority alert to go a little bit longer than you'd like before it gets looked at by somebody. So, what we've translated that to now is we've got,


135

00:18:15.067 --> 00:18:20.917

Adam Chapman: an AI agent doing a lot of the first-level triage, so it will take…


136

00:18:21.167 --> 00:18:28.546

Adam Chapman: a paragraph, you know, that comes through in an alert that's got maybe an IP address, maybe a username, a hostname, whatever's in there.


137

00:18:28.767 --> 00:18:32.526

Adam Chapman: And the first level is work out what's going on.


138

00:18:33.267 --> 00:18:34.577

Adam Chapman: So, within…


139

00:18:34.927 --> 00:18:47.786

Adam Chapman: couple of minutes of an alert firing, we've got an initial AI triage that… that kind of puts that alert into context to say, what is this? Who is it? Where are they? What are they doing?


140

00:18:48.407 --> 00:18:52.157

Adam Chapman: And… It will do a mini investigation on that.


141

00:18:55.217 --> 00:19:03.737

Adam Chapman: If the AI agent thinks this is something that needs to be escalated, it will escalate it to a second-level investigation.


142

00:19:03.977 --> 00:19:08.837

Adam Chapman: If not, it will close that case on its own as a false positive.


143

00:19:09.267 --> 00:19:16.087

Adam Chapman: That was the skepticism to start with. That was where we thought, are we really wanting to trust


144

00:19:16.457 --> 00:19:23.357

Adam Chapman: Effectively, a computer, to decide whether this is a false positive or not. So that was a…


145

00:19:23.887 --> 00:19:29.957

Adam Chapman: A real conscious decision that… Are we really sure, right? So…


146

00:19:30.227 --> 00:19:35.357

Adam Chapman: We talked about this quite a lot with the team, and to start with, we did baby steps.


147

00:19:35.927 --> 00:19:46.226

Adam Chapman: So, we manually reviewed these cases first, and then we human, you know, human-reviewed them and closed them manually, based on the AI verdict.


148

00:19:46.537 --> 00:19:54.716

Adam Chapman: And then we moved a little bit further down the road and said, right, okay, now we're starting to build some trust that this is getting it right.


149

00:19:54.977 --> 00:20:03.857

Adam Chapman: let's create a status within the platform that says the status of closed by AI.


150

00:20:04.647 --> 00:20:10.797

Adam Chapman: So now, I can run a query once a day, once every few hours, however often.


151

00:20:11.017 --> 00:20:15.837

Adam Chapman: where a human can go and review those cases and say, okay, did AI make the right call?


152

00:20:16.397 --> 00:20:22.256

Adam Chapman: Yes, yes, yes, yes. That one, I need to pull that one out again, and I need to do that myself.


153

00:20:22.647 --> 00:20:38.766

Adam Chapman: But I'll write down, kind of, why… why that made that verdict, so we can tune it later to set. If that happens, don't close it yourself, we want to do that. And that took probably a month, where we were sat there, you know, just keeping an eye on things.


154

00:20:39.247 --> 00:20:55.906

Adam Chapman: making sure that the agent was doing what we'd asked it to do. And this is why I keep relating it to, like, a trainee, an apprentice, a junior, because if it does something wrong, you just tell it it's done it wrong, and it will then learn for the next time. But you need to put that time into tune.


155

00:20:56.407 --> 00:21:02.067

Adam Chapman: So, once we've got that place where we're starting to close things on its own.


156

00:21:02.507 --> 00:21:05.156

Adam Chapman: We then escalate the remainder.


157

00:21:05.337 --> 00:21:15.766

Adam Chapman: To another set of AI agents that are, like, deep investigators. So, they're gonna pick up a case by its type.


158

00:21:16.297 --> 00:21:25.346

Adam Chapman: and investigate that using… you could say a playbook that you'd use in a traditional SOC, but instead it's going to do that at machine speed.


159

00:21:25.947 --> 00:21:34.097

Adam Chapman: the stuff we're doing with Stripe 48, with, like, the identity alerts around MFA and failed password attempts and things like that.


160

00:21:34.227 --> 00:21:52.947

Adam Chapman: there is no way, as a human you could do that level of work as quickly or as accurately as what this is doing. Now we've tuned it. So I think that the general message is you need to be on this thing to tune it, but you put the time in, and it's just going to do it time and time again. So, we've gone from a place


161

00:21:53.467 --> 00:22:05.416

Adam Chapman: as you see on the screen there, where everything was manual, to a place now where 77.5% there on that screen in that particular week was AI closed.


162

00:22:06.527 --> 00:22:10.237

Adam Chapman: We have seen 96% AI closed.


163

00:22:12.027 --> 00:22:20.636

Adam Chapman: that could scare some people off, thinking, how are you really sure that this system is doing it correctly? So, what we then did was.


164

00:22:20.997 --> 00:22:23.757

Adam Chapman: We took those AI closed cases.


165

00:22:23.867 --> 00:22:28.816

Adam Chapman: Yes, we reviewed them as humans, but we then created another AI agent.


166

00:22:28.837 --> 00:22:39.066

Adam Chapman: to review the AI closed homework, effectively, so you've got one AI agent closing the work, closing the cases.


167

00:22:39.087 --> 00:22:51.086

Adam Chapman: And then a second agent comes along with a different prompt, different model, to say, did it get it right? Was this the right decision? Do you agree with that decision that was made? If you don't agree.


168

00:22:52.017 --> 00:23:08.457

Adam Chapman: open the ticket again, bring it back into the SOC for processing by, you know, by a human. So that… that's what we've done over the past… it's only over the past month or so. This has only been… been running maybe throughout July onwards, and already you can see the numbers there.


169

00:23:08.607 --> 00:23:15.127

Adam Chapman: you know, AI closure within 5 minutes of a case being opened, there's no way you could do that by hand.


170

00:23:17.127 --> 00:23:23.737

Adam Chapman: And what it means is the team have got more time now to spend on some of the things that do need to be analysed.


171

00:23:24.447 --> 00:23:25.637

Adam Chapman: by hand.


172

00:23:26.097 --> 00:23:28.736

Adam Chapman: And so, we can focus on the important stuff.


173

00:23:29.287 --> 00:23:43.126

Tim Leehealey: Yeah, what I love about how you've sort of positioned it and talk about it is, I have this exact same conversation with people all the time, sort of, how do you know, how do you not know, did it get it right, didn't get it right? But what I kind of tell them is, okay.


174

00:23:43.147 --> 00:23:50.176

Tim Leehealey: On the left-hand of the screen, you've got 600 alerts that you… you can't get to.


175

00:23:50.427 --> 00:23:57.327

Tim Leehealey: Right? So there are X number of alerts, you simply can't get to them. You can view this as, hey.


176

00:23:57.457 --> 00:24:03.177

Tim Leehealey: on the right side of the screen, we still have the 600 cases. They're AI closed.


177

00:24:04.007 --> 00:24:11.466

Tim Leehealey: You can still go through them if you want. It's not like they disappeared into the ether. They're now just fully enriched.


178

00:24:11.767 --> 00:24:24.117

Tim Leehealey: you now can build strategies to go through them intelligently, and as you were saying, Adam, focus on the areas we really want to focus on. But it is not like you go from this


179

00:24:24.517 --> 00:24:36.957

Tim Leehealey: situation of manual to, literally, the machine is just executing on your behalf, and you have no recourse. That's just not the case. It's just you end up with a much better


180

00:24:37.517 --> 00:24:40.426

Tim Leehealey: Starting point from which to do your work.


181

00:24:41.387 --> 00:24:41.887

Adam Chapman: Yeah.


182

00:24:42.057 --> 00:24:45.927

Adam Chapman: And especially when you give it the organizational context.


183

00:24:46.207 --> 00:24:49.007

Adam Chapman: Because we've not talked about that much.


184

00:24:49.267 --> 00:24:53.947

Adam Chapman: So, okay, you could put Stripe Fourier on top of any platform.


185

00:24:54.047 --> 00:25:07.956

Adam Chapman: But when you tell it, this is my user directory, this is where my people are expected to be, this is our site office location, these are our IP addresses, it's then contextually aware as what I am.


186

00:25:08.357 --> 00:25:16.656

Adam Chapman: If I can give it an inventory of assets, an inventory of my people, where is everything, it's got that baked in.


187

00:25:16.827 --> 00:25:19.527

Adam Chapman: So it instantly knows whether… is this…


188

00:25:19.777 --> 00:25:23.666

Adam Chapman: you know, is this friend or foe? You know, is this an IP address that we know about?


189

00:25:24.047 --> 00:25:39.466

Adam Chapman: Or is this not an IP address we know about? And in the past, it would be, moving between different platforms to get that information, and to look up in Excel some spreadsheet somewhere where I've got this information, or a CMDB to find out about this asset.


190

00:25:39.587 --> 00:25:41.286

Adam Chapman: It's just in there now.


191

00:25:41.967 --> 00:25:43.497

Adam Chapman: But I think…


192

00:25:43.957 --> 00:25:50.907

Adam Chapman: At the beginning, we didn't have that appreciation for how powerful this thing can be if you give it the right information to start with.


193

00:25:51.747 --> 00:25:56.526

Adam Chapman: So… what I've learned. The more you give it, the more accurate it's gonna be.


194

00:25:57.277 --> 00:26:03.716

Tim Leehealey: I had this presentation I had to do at Black Hat, and they sort of asked me what my hot take was.


195

00:26:03.757 --> 00:26:13.746

Tim Leehealey: And you know, you're asked to be provocative in that statement, right? Nobody wants to say, my hot take is AI is interesting. Do you know what I mean? So, and my hot take has always been.


196

00:26:13.747 --> 00:26:30.566

Tim Leehealey: that all these vendors that are building AI directly into their platform, and I'll throw Splunk under the bus, because it's the perpetual boogeyman we all fight against, but, you know, the Splunk embedded agents, or the Sentinel embedded agents, to me, my hot take is they're missing the point.


197

00:26:30.737 --> 00:26:35.876

Tim Leehealey: Right? The real strength is implementing it over the entire IT stack.


198

00:26:36.047 --> 00:26:57.897

Tim Leehealey: Not just embedding it in any one product, because it does benefit from all the things you were just talking about. It's just a better solution. Maybe the SIM is the heartbeat, but giving it access to your employee directory, giving it access to your EDR, giving it access to your ticketing system, all enrich it and result in a better outcome.


199

00:26:58.587 --> 00:27:08.997

Adam Chapman: Definitely. Yeah, and to that point, we've got the vulnerability scanner. It doesn't have any AI capability at all.


200

00:27:09.517 --> 00:27:25.727

Adam Chapman: But I can now point Stripe 48 at it, and create an agent that says, tell me about the top 10 vulnerabilities that was reported in the past 24 hours. And it'll go off and research them, tell me about them, and it's kind of mind-blowing how it does that.


201

00:27:26.187 --> 00:27:41.856

Adam Chapman: But if you think about a typical security stack, you've got on the diagram there various points. So, you've got your firewall detecting stuff, they go into the seam, you've got, the EDR platform, you might have XDR, there's all sorts of different


202

00:27:41.997 --> 00:27:44.356

Adam Chapman: Platforms, generating their own logs.


203

00:27:44.947 --> 00:27:47.417

Adam Chapman: And like you said, this sits on top of them.


204

00:27:47.547 --> 00:27:51.817

Adam Chapman: And some of the things that we've been finding is it's doing its own correlation.


205

00:27:51.947 --> 00:27:58.767

Adam Chapman: So, I was investigating a case recently, about, a user.


206

00:27:59.167 --> 00:28:06.937

Adam Chapman: There was receiving loads and loads of mail bombs, sort of, attack, 500 emails within a 10-minute period. Where is this coming from?


207

00:28:07.557 --> 00:28:09.177

Adam Chapman: And one of the agents…


208

00:28:09.357 --> 00:28:18.756

Adam Chapman: It said, oh, and did you know that at the same time as this email bomb, we've also seen a brute force attack against the same account through Active Directory?


209

00:28:18.907 --> 00:28:26.107

Adam Chapman: So it's kind of drawing logs from different places to say, I would never have found that bike, you know, myself.


210

00:28:26.107 --> 00:28:26.717

Tim Leehealey: Yeah.


211

00:28:26.937 --> 00:28:30.166

Adam Chapman: You know, it's just… it amazes me, some of the things it picks up on.


212

00:28:30.657 --> 00:28:34.566

Adam Chapman: So, all of that information that's sat there in our same platform.


213

00:28:34.727 --> 00:28:41.917

Adam Chapman: was previously just a bucket of data. It's now being used, where before it just sat stale.


214

00:28:42.357 --> 00:28:51.487

Adam Chapman: And we're going back months, if not years, with all this data. So, you said earlier about the low and slow guys, well, we can now pick them out.


215

00:28:51.707 --> 00:28:57.576

Adam Chapman: Because you can see patterns in the data starting to emerge that you probably wouldn't pick up.


216

00:28:57.717 --> 00:29:06.446

Adam Chapman: Through a detection that says, it must be a brute force attack if it's more than 10 password attempts in 5 minutes.


217

00:29:06.747 --> 00:29:10.426

Adam Chapman: You could then do that over months, if you wanted to.


218

00:29:10.707 --> 00:29:13.007

Adam Chapman: So, it's all there for the taking.


219

00:29:13.667 --> 00:29:21.486

Tim Leehealey: Yeah, it really does open up, and it opens up the ability to really re-look at the entire IT stack, frankly, and go to… I mean.


220

00:29:21.687 --> 00:29:39.527

Tim Leehealey: I'm advocating, at this point, a very cheap security data-like-like structure with an Agentic front end to solve the vast majority of your IT issues. I know I'm a little futuristic, I know I'm a little forward-leaning, but it really does look like the direction we're going, because


221

00:29:39.527 --> 00:29:48.107

Tim Leehealey: Tool sprawl is a big issue, tool overlap, storage costs, all these things are really rectified in a…


222

00:29:48.457 --> 00:30:00.307

Tim Leehealey: In an architecture where we imagine, sort of like, instead of plugging this on top of all these solutions, having just an Agentic layer sitting on top of a really low-cost data repository that everything pumps into.


223

00:30:00.687 --> 00:30:07.776

Tim Leehealey: I mean, there will be many use cases, Adam, to be clear, that won't solve, but I do think it is a radically


224

00:30:07.967 --> 00:30:14.706

Tim Leehealey: More effective and cost-beneficial outcome for a lot of organizations.


225

00:30:16.027 --> 00:30:19.767

Adam Chapman: Especially look at the time saved. I think that's the main thing, that…


226

00:30:19.767 --> 00:30:20.367

Tim Leehealey: Yeah.


227

00:30:20.367 --> 00:30:27.846

Adam Chapman: Where are we… stuck with hundreds and hundreds of alerts. If you remember, one of our early conversations


228

00:30:28.047 --> 00:30:36.746

Adam Chapman: at the start of the year was, we've got all these cases that we just haven't got to. How do we mass close all these cases from 6 months ago?


229

00:30:36.897 --> 00:30:40.737

Adam Chapman: Well, we're not having that conversation now, because we've only got a handful open.


230

00:30:41.087 --> 00:30:43.517

Adam Chapman: Because the rest have been dealt with.


231

00:30:43.857 --> 00:30:46.276

Adam Chapman: And they've been dealt with in a more manageable way.


232

00:30:47.137 --> 00:30:53.356

Adam Chapman: So we've gone from pulling our hair out to now being more manageable, so we can do all the things.


233

00:30:54.597 --> 00:30:55.187

Adam Chapman: So that…


234

00:30:55.187 --> 00:30:55.777

Tim Leehealey: No, it's fair.


235

00:30:55.777 --> 00:30:58.057

Adam Chapman: Budgets that I've seen over, you know, over the past…


236

00:30:58.827 --> 00:31:02.367

Adam Chapman: the past couple of months, really, since we've really got into it, I think there's…


237

00:31:02.517 --> 00:31:07.116

Adam Chapman: Yeah, there's, like any system, you've got to learn how it functions and how it operates and everything.


238

00:31:07.487 --> 00:31:12.036

Adam Chapman: But once the actual SOC team got in here and learned it's not just,


239

00:31:12.227 --> 00:31:19.706

Adam Chapman: a toy, you know, that a few people have been given access to. We're now using this day-to-day. There's been a lot of value taken from it.


240

00:31:21.127 --> 00:31:35.366

Tim Leehealey: Yeah, and I… we're sitting here talking about agents. That's been the anchor of the conversation. That's how everybody thinks about it. But, I wanted to show people kind of a workflow that you have, that you've been kind enough to share with us.


241

00:31:35.367 --> 00:31:47.526

Tim Leehealey: And have you just talk through a little bit about how it's really not necessarily the agent in the, sort of, the Claude Code N8N site type? Do you know what I mean? It's much more of a…


242

00:31:47.727 --> 00:32:02.857

Tim Leehealey: set of prescriptive decision nodes with Agentic sort of capability. So if you could walk through, kind of, just at a high level, what we've got here, and how it's different from what people think about, you know, just, like, their Cloud Code agent.


243

00:32:03.777 --> 00:32:15.397

Adam Chapman: Yeah, I think this is what sets it apart, and what I've quite enjoyed working with, is… is the workflows, because this isn't, like you say, just a prompt, you type in, press enter, and it's done.


244

00:32:15.837 --> 00:32:22.037

Adam Chapman: I have these set up to run on a scheduled basis, doing various different things.


245

00:32:22.287 --> 00:32:25.847

Adam Chapman: And this particular one is a workflow


246

00:32:25.947 --> 00:32:42.297

Adam Chapman: that picks up a case that's been allocated to the Level 2 agent. So, we've done our L1 analysis, we've done a basic assessment, and the AI agent at level 1 has decided that this needs escalation or deeper assessment.


247

00:32:42.417 --> 00:32:43.277

Adam Chapman: So…


248

00:32:43.457 --> 00:32:51.067

Adam Chapman: It grabs the comments that have been added to the case already, so they could be human-entered or AI entered, it's going to read all the information that's been put in.


249

00:32:51.507 --> 00:32:57.017

Adam Chapman: And then, it's gonna determine Which type of case we're looking at.


250

00:32:57.477 --> 00:33:08.076

Adam Chapman: So, this getCaseType is a very simple LLM prompt that says, read the case information, determine from a set list what we're looking at.


251

00:33:09.217 --> 00:33:16.817

Adam Chapman: So after that, we then go to an enrichment agent. So this is basically that… the SOC engineer goes,


252

00:33:17.067 --> 00:33:23.927

Adam Chapman: I think this needs to go to, hmm, Agent 1, because they're really good at doing this type of assessment.


253

00:33:24.537 --> 00:33:27.726

Adam Chapman: Or, it needs to be dealt with with this playbook.


254

00:33:28.396 --> 00:33:36.416

Adam Chapman: So, what we've got here is an identity, DLP, email, firewall, or network issue, and we can expand these.


255

00:33:36.747 --> 00:33:40.187

Adam Chapman: If it's nothing of them, then send it to a catch-all.


256

00:33:40.677 --> 00:33:42.867

Adam Chapman: So, identity agent there.


257

00:33:43.106 --> 00:33:45.336

Adam Chapman: Will… will go through


258

00:33:45.586 --> 00:34:00.306

Adam Chapman: in a very structured manner, looking at our data, history from different systems, what's this person been doing for the past so many months, weeks? What's their baseline look like? What's normal for this person?


259

00:34:00.667 --> 00:34:06.787

Adam Chapman: What's the alert we've got in front of us? Does that match their regular pattern, or not?


260

00:34:07.137 --> 00:34:15.536

Adam Chapman: And it will then go through a series of questions. There's about 15 or 20 questions it'll go through. So again, if you were to do that by hand in a Devo


261

00:34:15.617 --> 00:34:24.886

Adam Chapman: query, that's 15 different queries you've got to pull, or write by hand, to get that data. So there's no way I can do that in the time this does.


262

00:34:24.947 --> 00:34:36.486

Adam Chapman: So, we run through all these questions. Is this a new IP? Is this a new location for this user? Is this a new device for this user? And we go through all those questions.


263

00:34:36.887 --> 00:34:46.636

Adam Chapman: And at the end, we then say, is this something that needs to be escalated or not? Is this… is this a concern for us? Or is this normal behaviour?


264

00:34:46.697 --> 00:35:01.497

Adam Chapman: And we always, obviously, check with the user and do all that validation, but this has done a lot of that work for you. So, by the time the alert comes to you as an agent, you've got everything you need in front of you, probably more.


265

00:35:01.907 --> 00:35:17.316

Adam Chapman: to make a decision on, is this something I need to be concerned about or not? And you've got the results of all those questions that you've created. This isn't something that we've just downloaded off Strike 48 as a, you know, a template. We've built these ourselves.


266

00:35:17.547 --> 00:35:21.556

Adam Chapman: And it's been really successful, and this is what's doing


267

00:35:21.727 --> 00:35:27.477

Adam Chapman: a lot of the time saving, because there's no way I could do all this work as an agent.


268

00:35:27.667 --> 00:35:28.886

Adam Chapman: By hand.


269

00:35:29.357 --> 00:35:36.987

Adam Chapman: to the quality and, you know, the scale this can do it at. And these aren't just running in isolation, these things are running in parallel.


270

00:35:37.197 --> 00:35:53.686

Adam Chapman: So, I'm running this identity agent, for example, and I've given it these 5 questions to ask. It's running 5 parallel queries and bringing the data back. It's not some sequence that, you know, that goes on step by step, it's really fast.


271

00:35:53.977 --> 00:35:56.646

Adam Chapman: So that's one example of the workflow.


272

00:35:57.317 --> 00:36:10.917

Tim Leehealey: Yeah, it is… I'm always blown away by the development team, the technologies they've factored into this thing. At this point, this thing can blow out thousands of agents at once and just do incredible work, so…


273

00:36:10.917 --> 00:36:11.797

Adam Chapman: But…


274

00:36:11.797 --> 00:36:17.697

Tim Leehealey: We have… we have sort of stretched beyond the 35 target minutes here, so I'm gonna just sort of…


275

00:36:19.077 --> 00:36:25.287

Tim Leehealey: really spend a few minutes, Adam, if we could just talk about, kind of, how you guys look. You've accomplished a ton.


276

00:36:25.307 --> 00:36:35.657

Tim Leehealey: in the last year, it's just amazing. I'm super happy to have been on the ride with you. Kind of, what are you looking at to do next with the platform? Are there areas where you want to


277

00:36:35.657 --> 00:36:46.046

Tim Leehealey: sort of, hey, tiptoe into this additional exploration area, or areas you really think, hey, I'm pretty positive we can get a lot of value if we expand into these use cases.


278

00:36:46.877 --> 00:36:53.216

Adam Chapman: Yeah, I think this… this section, the next… let's say the next 12 months is going to be really interesting, because


279

00:36:53.357 --> 00:36:59.776

Adam Chapman: We've now got to a point where we've got cases that need to be looked at by humans, and


280

00:36:59.917 --> 00:37:01.487

Adam Chapman: A lot of cases.


281

00:37:01.657 --> 00:37:14.476

Adam Chapman: just need that extra bit, like an email to the end user, an email to the manager, it could be a Teams message. So I think the next natural step is to try and remove those steps, so that the


282

00:37:14.477 --> 00:37:21.677

Adam Chapman: The workflow is automatically contacting the end user, the line manager, whoever, our, you know, email teams.


283

00:37:21.797 --> 00:37:35.496

Adam Chapman: So that that is reduced, so that within a couple of minutes of an alert firing, you've got a message going to the end user saying, hey, was this you? Do you mechanise this activity? And reading that feedback back into the platform would be pretty cool.


284

00:37:35.707 --> 00:37:46.167

Adam Chapman: But I can see this in the future, starting to take remedial action. So, once you get to a point where you're confident that the system is getting it right.


285

00:37:46.437 --> 00:37:47.957

Adam Chapman: consistently.


286

00:37:48.257 --> 00:37:51.237

Adam Chapman: Would you be confident enough to say, well, actually.


287

00:37:51.377 --> 00:37:56.667

Adam Chapman: I'm okay with the AI agent going off to isolate an endpoint.


288

00:37:56.817 --> 00:37:59.727

Adam Chapman: Disable a user account, reset a password.


289

00:38:00.107 --> 00:38:02.516

Adam Chapman: I think it'd be nice to get to that point.


290

00:38:02.757 --> 00:38:05.737

Adam Chapman: Where you don't need to make a human decision.


291

00:38:06.497 --> 00:38:16.637

Adam Chapman: But at the moment, I think we're still, like I said earlier, about baby steps. We're at that edge now of, what is it when I get this case, am I always doing?


292

00:38:16.857 --> 00:38:36.747

Adam Chapman: constantly. So I get a case, first job, oh, well, we need to contact the user. Well, let's get rid of that bit. The user confirms, this wasn't me, I don't recognize this activity, I have not been to this country. Oh, why can't AI close that… close that user down, or suggest remedial action, or start to… to do that on your behalf?


293

00:38:37.347 --> 00:38:41.076

Adam Chapman: So the MCP connectivity, I think, is going to be important.


294

00:38:41.437 --> 00:38:42.867

Adam Chapman: So, enable…


295

00:38:43.147 --> 00:38:52.377

Adam Chapman: Prospector and Stripe 48 tools to reach out to all the platforms to affect them. So, EDR isolation is just one example.


296

00:38:52.897 --> 00:38:56.867

Adam Chapman: So that's where I can see it going from a SOC perspective.


297

00:38:57.497 --> 00:38:58.307

Adam Chapman: Well…


298

00:38:58.307 --> 00:39:00.466

Tim Leehealey: Yeah. There's more to that.


299

00:39:00.597 --> 00:39:16.726

Tim Leehealey: Yeah, I was gonna say, we have customers sort of all over the map. Some are… most are less sophisticated than yous in terms of building the system. Some have actually been really forward-leaning in terms of what they're willing to let these things do, which is always a little surprising to me, but but it is a huge spectrum out there.


300

00:39:17.237 --> 00:39:17.817

Adam Chapman: Yeah.


301

00:39:18.937 --> 00:39:24.487

Adam Chapman: Yeah, so that's where I think we could take it. There are other examples I just used there, like,


302

00:39:24.957 --> 00:39:29.207

Adam Chapman: We've started to experiment moving away from alerts.


303

00:39:29.627 --> 00:39:40.157

Adam Chapman: So, can you point an agent at a set of data, a set of logs, and say, find things in this bucket of information that I need to know about?


304

00:39:40.337 --> 00:39:46.716

Adam Chapman: what have I… what have I missed in my alerts? There's always that thing in security of, we expect


305

00:39:47.077 --> 00:39:50.826

Adam Chapman: That we will see these type of activities, this looks bad.


306

00:39:51.067 --> 00:40:08.756

Adam Chapman: But what if a new attack vector comes out, or a new technique comes out that you don't know about, or you've not anticipated? Can you get an agent to look at firewall logs for the past 24 hours, or whatever, and pick out important things that you might have missed?


307

00:40:09.377 --> 00:40:16.147

Adam Chapman: And I have had success with that before as well. So, can you get that to run on a scheduled basis?


308

00:40:16.747 --> 00:40:22.717

Adam Chapman: So, pick out the things that I need to know about, and move away from the traditional rulebook of


309

00:40:22.937 --> 00:40:26.177

Adam Chapman: this is bad, so it must be an alert. That's pretty…


310

00:40:26.417 --> 00:40:29.457

Adam Chapman: pretty cutting edge as well, I think, in some cases.


311

00:40:30.187 --> 00:40:43.797

Tim Leehealey: Yeah, and I actually feel like it has the potential. And you've had success here, so it's always exciting to listen to the successes you've had on this front, but it has the potential to truly deliver what UEBA was supposed to.


312

00:40:44.257 --> 00:41:03.737

Tim Leehealey: Right? There's some idea that you get this true sense of normal, and then you can just find the random anomalies and reduce the risk that way. I mean, I think that has been a journey that has been less productive than we all hoped it would have been, but this feels like it's actually delivering. I have seen it pull out


313

00:41:03.797 --> 00:41:14.026

Tim Leehealey: impossible traveler without having been asked about it. I've seen it pull out anomalistic activity in some environments that really did ultimately lead to


314

00:41:14.567 --> 00:41:18.017

Tim Leehealey: A discovery of an active attack.


315

00:41:18.457 --> 00:41:21.587

Tim Leehealey: We've had that in a proof of concept, it's crazy.


316

00:41:22.087 --> 00:41:33.017

Adam Chapman: Yeah, we've… it's part of the testing process, I didn't mention earlier, that we've, we've run the prospector agents against a known incident.


317

00:41:33.207 --> 00:41:36.586

Adam Chapman: To see how it compares to what we found out


318

00:41:37.167 --> 00:41:43.697

Adam Chapman: in the SOC. So, if you've got an incident that you know about, you know what happened, you've investigated it by hand.


319

00:41:43.897 --> 00:41:50.916

Adam Chapman: Then run the agent against it. Did it come up with the same information you did? And that's a good validation step.


320

00:41:51.227 --> 00:41:59.147

Adam Chapman: Or you do it the other way around, and you get the agent to do the investigation first, and you then follow up afterwards as a trust.


321

00:41:59.307 --> 00:42:01.697

Adam Chapman: Sort of validation step, but…


322

00:42:01.857 --> 00:42:10.667

Adam Chapman: Yeah, it is finding things that alerts don't find, and correlating more than you would typically find in an alert, because


323

00:42:11.117 --> 00:42:18.217

Adam Chapman: in a defined alert, you're expecting things to happen. And what if the expected things don't happen? Or you get…


324

00:42:18.327 --> 00:42:22.976

Adam Chapman: 9 password attempts in 10 minutes, rather than the 10 that you're alerting.


325

00:42:22.977 --> 00:42:24.177

Tim Leehealey: Yeah, right.


326

00:42:24.177 --> 00:42:27.696

Adam Chapman: But those things, this is where it really helps.


327

00:42:28.337 --> 00:42:32.656

Adam Chapman: So, yeah, there's loads of opportunity. It's now a case of working out


328

00:42:32.797 --> 00:42:37.887

Adam Chapman: where do we want to go next? That is difficult, because there's so many ways you can take this.


329

00:42:39.277 --> 00:42:50.117

Tim Leehealey: It's certainly exciting, super exciting. So anyway, listen, Adam, I really appreciate you taking the time to sort of take us through your journey. I think it's super instructive, it's super inspiring, frankly.


330

00:42:50.117 --> 00:43:08.557

Tim Leehealey: And I think it's what other people in the market need to hear, because the reality is, you really have to embrace it. You're gonna have to embrace this stuff, or you're gonna get left behind. No one wants to get left behind. So seeing people like yourself be brave enough to embrace this a year ago, and actually having it be fruitful.


331

00:43:08.647 --> 00:43:14.536

Tim Leehealey: is, I think, a really powerful message. So, thanks for taking the time, I really appreciate it.


332

00:43:15.047 --> 00:43:16.307

Adam Chapman: No, you're welcome. Marissa.


333

00:43:16.927 --> 00:43:18.827

Tim Leehealey: Do we have any questions?


334

00:43:19.067 --> 00:43:42.867

Marissa Notaro: We do, so we have a good amount of questions, but obviously, we don't have as much time, because we went through some really good nuggets here. So, I'm gonna go through just a few questions, and then anybody else that has questions, obviously you can reach out as well, and we can get that to the team. But one of the questions that came in was, after Sim


335

00:43:42.867 --> 00:43:44.477

Marissa Notaro: integration.


336

00:43:44.477 --> 00:43:54.516

Marissa Notaro: How do we define which alerts become cases, and which workflow module handles them? Is this UI-based or back-end configuration?


337

00:43:58.427 --> 00:44:00.196

Adam Chapman: I can go if you want to.


338

00:44:00.197 --> 00:44:02.656

Tim Leehealey: Yeah, you go, and then I'll go after.


339

00:44:02.947 --> 00:44:12.297

Adam Chapman: I'll say what I've done, then you can give the textbook answer. So, what we've done is, in the previous platform, we…


340

00:44:12.427 --> 00:44:15.046

Adam Chapman: We were looking at mediums or higher.


341

00:44:15.437 --> 00:44:17.807

Adam Chapman: Because that was what the team could look at.


342

00:44:18.257 --> 00:44:22.447

Adam Chapman: But now, where we've got this extended capability, let's look at everything.


343

00:44:23.397 --> 00:44:26.996

Adam Chapman: Everything may not become a case.


344

00:44:27.197 --> 00:44:31.786

Adam Chapman: But every alert's gonna get looked at to see if it qualifies to become a case.


345

00:44:32.147 --> 00:44:40.417

Adam Chapman: So that's the way… the way we've done it. So, every alert gets looked at to see if it's part of an existing case that needs to be brought in.


346

00:44:40.537 --> 00:44:50.266

Adam Chapman: Or is it something that's happened that doesn't need investigation? We don't need to make it part of the case? So, typically, we're looking at mediums or higher.


347

00:44:50.437 --> 00:44:55.487

Adam Chapman: And then the rest of the bucket kind of gets assessed for, is it worthy to bring in


348

00:44:55.817 --> 00:44:59.286

Adam Chapman: But I guess that's very specific on how you want to operate.


349

00:44:59.447 --> 00:45:02.826

Adam Chapman: your team, isn't it? That's not something that's textbook.


350

00:45:03.927 --> 00:45:15.906

Tim Leehealey: So, what we tell people is… I think it's… and it's indicative of what you guys have done, is we tell people, what you really need to do is redefine what you mean by a case, because


351

00:45:16.127 --> 00:45:31.707

Tim Leehealey: reintroduce this case type concept, right? And there is AI case closed by an AI, all this kind of stuff, and I view that as the starting point. Traditionally, alerts were the starting point. But since now you can actually look at every single alert.


352

00:45:31.817 --> 00:45:44.376

Tim Leehealey: The starting point should be the cases themselves. You can be relatively lenient with how you create them, but if you give them case types where AI created, AI assessed, AI closed.


353

00:45:44.617 --> 00:45:57.287

Tim Leehealey: you now have… that can be, if you will, the bucket you start from, versus alerts being the bucket. So, we encourage customers to get a little bit more lenient.


354

00:45:57.297 --> 00:46:05.956

Tim Leehealey: With what's considered a case, but then to have case types, so you actually reduce the manual work,


355

00:46:06.607 --> 00:46:09.077

Tim Leehealey: Needed, but you get far better coverage.


356

00:46:10.727 --> 00:46:28.516

Marissa Notaro: Thank you both. So another question that came in, so they asked, how does the Strike 48 AI agent identify zero-day threats or unknown attack vectors that lack pre-existing signatures or known IOCs?


357

00:46:28.647 --> 00:46:30.667

Marissa Notaro: So that was another one that came in.


358

00:46:31.107 --> 00:46:50.866

Tim Leehealey: So that's what Adam was talking about, sort of, at the very end. So, I would say two things, and Adam, I'd let you go. So, first of all, by no means am I claiming it can catch everything. I'm not… it's amazing what it can do. I never need to oversell this thing. It's just exciting, but that does not make it…


359

00:46:50.867 --> 00:46:54.656

Tim Leehealey: the be-all, end-all, the end of security issues. Definitely not.


360

00:46:54.737 --> 00:46:59.887

Tim Leehealey: What I would say, though, is its ability to correlate across to the vast


361

00:47:00.027 --> 00:47:03.846

Tim Leehealey: set of tools versus just looking at your SIM,


362

00:47:04.247 --> 00:47:15.057

Tim Leehealey: It has a much better ability to spot issues like that, those sort of non-alert-defined issues, or more Novell-types attacks.


363

00:47:15.167 --> 00:47:21.586

Tim Leehealey: Versus what you could ever do with a traditional toolset. Does that mean the problem's solved? No.


364

00:47:21.847 --> 00:47:30.806

Tim Leehealey: But is it… are you far better off? Yeah, you're light years better off than you are without it. But Adam, I don't know if you want to grab at the question as well.


365

00:47:30.807 --> 00:47:40.117

Adam Chapman: Yeah, I would agree with that, but I think, XDR plays a big role in that, and ingesting that information into the seam as well.


366

00:47:40.287 --> 00:47:43.386

Adam Chapman: So you, you're getting user behavior


367

00:47:43.597 --> 00:47:53.587

Adam Chapman: monitoring, so you're kind of seeing what's happening within people's machines, but I think we've got to remember that this is effectively a SOAR-type platform. It's not there to detect


368

00:47:53.767 --> 00:47:56.416

Adam Chapman: Incidents as they happen.


369

00:47:56.547 --> 00:48:03.437

Adam Chapman: like an XDR or an EDR platform would. So I think this is looking at things slightly after the fact.


370

00:48:04.067 --> 00:48:07.546

Adam Chapman: But what it is going to do is help you investigate that a lot quicker.


371

00:48:08.077 --> 00:48:18.267

Adam Chapman: and come to a decision a lot quicker is, is this something… is there something going on here I need to know about? So I don't think it's necessarily going to detect any sort of zero day on its own.


372

00:48:18.777 --> 00:48:23.666

Adam Chapman: But I don't think it's engineered to. I think Timmy might want to comment on that, but…


373

00:48:23.827 --> 00:48:31.606

Adam Chapman: I feel like this is more of an investigation platform that's looking at what's happened, rather than what's happening


374

00:48:31.817 --> 00:48:33.566

Adam Chapman: Does that make sense? Nope.


375

00:48:33.567 --> 00:48:52.066

Tim Leehealey: Yeah, it makes total sense. We do have customers that are leaning a little bit more into the zero-day detection capability of it, but I would still agree heavily with what you're saying. The sentiment of what you're saying is spot on. However.


376

00:48:52.307 --> 00:49:09.797

Tim Leehealey: you know, let's see where it goes in the next 3 to 6 months, because there's just a ton coming in terms of those type of zero-day, remediation capabilities, detection and remediation capabilities. But right now, Adam, I think you've accurately sort of categorized it.


377

00:49:10.057 --> 00:49:13.996

Tim Leehealey: So, any more questions, Marissa? I know we're sort of well at… past time.


378

00:49:13.997 --> 00:49:32.457

Marissa Notaro: Yeah, so this is the final one that we're able to take today, but the other ones we can, you know, answer offline. So to wrap it up, has Adam or anyone on his team considered any other Agentic AI companies in this space? And if so, why have you stayed with Strike48?


379

00:49:34.397 --> 00:49:38.777

Adam Chapman: I think we've built a really good partnership.


380

00:49:38.957 --> 00:49:43.027

Adam Chapman: with Stripe 48. As Tim said.


381

00:49:43.607 --> 00:49:53.517

Adam Chapman: At the beginning, I took over the team, and we were seriously considering leaving, because we just didn't see the value in what we had.


382

00:49:53.877 --> 00:50:00.806

Adam Chapman: And I think, we've not needed to look elsewhere, because the tool is doing what we need it to do.


383

00:50:01.157 --> 00:50:05.447

Adam Chapman: I haven't found anything that compares, either.


384

00:50:05.687 --> 00:50:08.576

Adam Chapman: So, even if I were to go shopping.


385

00:50:08.817 --> 00:50:11.897

Adam Chapman: would I find another platform that… that does…


386

00:50:12.127 --> 00:50:22.367

Adam Chapman: what Stripe 48 are doing. I think a lot of it that I've seen, a lot of EDR platform demos, for example, they have an agent built into the EDR platform.


387

00:50:22.587 --> 00:50:25.657

Adam Chapman: Brilliant. But that only lives in the EDI platform.


388

00:50:25.887 --> 00:50:37.556

Adam Chapman: That's all it can ever do. And I think bringing it on top of all the platforms is what makes it unique for me. I've not found another tool that does that.


389

00:50:38.047 --> 00:50:50.427

Adam Chapman: So that's one of the reasons why we've stayed, but the support that we've had from the team, you know, everyone that we've met and dealt with has been super helpful, super friendly, and…


390

00:50:50.857 --> 00:51:02.407

Adam Chapman: they're all… everybody wants to help, you know, we're in this together as a partnership, rather than, like, a supplier-customer relationship. It feels to me more like a… you know, more like a partnership that we've built.


391

00:51:02.877 --> 00:51:10.467

Adam Chapman: And I don't think that's… that's because we've been closer on this team. I think, generally,


392

00:51:11.037 --> 00:51:18.816

Adam Chapman: nimble enough to be able to, you know, to assist people where they need it, and I don't think you get that from the big players.


393

00:51:19.707 --> 00:51:22.796

Adam Chapman: So, yeah. And I've not been paid to say that, by the way.


394

00:51:22.797 --> 00:51:24.677

Marissa Notaro: I appreciate that, Adam.


395

00:51:24.997 --> 00:51:26.766

Tim Leehealey: It's very nice of you.


396

00:51:26.767 --> 00:51:28.887

Marissa Notaro: you on the spot, Adam.


397

00:51:28.887 --> 00:51:39.186

Adam Chapman: How many… how many, vendors or product suppliers have you met the CEO of on numerous occasions on Teams?


398

00:51:39.747 --> 00:51:43.057

Adam Chapman: You know, I've met Ken a few times now, and…


399

00:51:43.357 --> 00:51:49.287

Adam Chapman: That's what adds the value, I think, is from the very top, understanding what the customers are needing.


400

00:51:49.737 --> 00:51:57.357

Adam Chapman: And it feels like we can, sort of, as a customer, go top-down, bottom-up, you know, we can sort to anybody we need to, and I think that


401

00:51:58.557 --> 00:52:13.326

Adam Chapman: the ability that we've got just to reach out to Tim, who I'm sure is a very busy guy, when we need him, is valuable, and you can't do that with every, you know, with every vendor, can you? With every customer. Sorry, with every supplier. It's just not going to happen.


402

00:52:14.607 --> 00:52:15.317

Marissa Notaro: Appreciate it.


403

00:52:15.317 --> 00:52:27.076

Tim Leehealey: Appreciate those, yeah, those kind words. So, Marissa, I think we should probably end it here. We've gone way too long, but, it's been a super exciting conversation, so I didn't want to ever cut it short, so…


404

00:52:27.487 --> 00:52:47.137

Marissa Notaro: Yes, thank you so much, everyone, for joining. The recording will be sent out to everyone, so if there's anything you want to go back to, we appreciate your time, we appreciate the time of our speakers. Adam, Tim, it was such an insightful discussion, we appreciate it. And yeah, we're really excited for what's next, and thank you so much!


405

00:52:47.757 --> 00:52:49.156

Tim Leehealey: Thanks a lot, guys, really appreciate it.


406

00:52:49.157 --> 00:52:51.026

Marissa Notaro: Good day, everyone. Bye!


407

00:52:51.207 --> 00:52:51.977

Adam Chapman: Bye-bye.