
mnemonic security podcast · 2026-06-29 · 28 min
Key moments - from our scoring
Substance score
63 / 100
Five dimensions, 20 points each
Deception technology creates artificial resources (like AWS S3 buckets, IAM roles, or secrets) that trigger alerts if accessed, offering a fundamentally different approach to detection than SIEM-based log collection and alert tuning. Andy Smith founded TraceBit after a supply chain incident at Tessian revealed that deception could have caught compromise months earlier. Traditional honeypot solutions from companies like Illusive required expensive virtual machines deployed on-premises and left organizations to figure out placement. TraceBit's approach leverages lightweight serverless resources in cloud environments, which are low-cost, low-risk, and align with how modern attackers actually move (via credentials and lateral privilege escalation rather than network scanning). The company focuses on tripwire-style canaries deployed internally for high-confidence detection rather than threat intelligence gathering. Smith explains why adoption stalled despite earlier venture excitement, and describes emerging features like perimeter canaries - placing deceptive cookies on user workstations to catch credential theft and lateral movement attempts.
Honeypots are deployed to gather threat intelligence about attackers; canaries and honey tokens are tripwires deployed inside the perimeter to detect active compromise with high-fidelity signals when accessed, with no expectation of baseline tuning.
Earlier solutions required expensive virtual machines shipped to physical racks, had significant financial and operational overhead, and required customers to manually figure out where to deploy deception without automated placement guidance.
TraceBit uses lightweight serverless cloud resources like S3 buckets and IAM roles instead of virtual machines, which are free to deploy, require no patching, and align with how attackers actually move through cloud environments via credential-based lateral escalation.
Cloud-native resources like IAM roles have few visible properties before interaction, making them easy to make blend into the environment with proper naming and configuration similar to legitimate resources, whereas servers are fingerprintable over TCP.
Perimeter canaries place deceptive cookies on user workstations referencing legitimate-looking services like VPN; if an attacker steals cookies or runs an info stealer, the unique canary token reveals compromise and lateral movement attempts.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode packs in several genuinely useful technical distinctions - serverless canaries vs. VM-based honeypots, per-build unique key generation for CI/CD attribution, and the AI agent detection research - but is interspersed with product-pitch framing and some repetition that dilutes the signal.
they're generally not getting access to a network and running Nmap and then trying to get into a server. They're generally getting access to some credentials and then trying to move laterally or escalate privilege by jumping around
we generate unique keys for every single build that runs in an environment. So like the scale is a big, a big important part of it. And what that means is when TraceBit goes off, you can actually jump to the exact build that this occurred in
The cloud-native framing of deception (serverless resources as inherently low-cost, low-fingerprintable canaries) is a fresh and well-argued take on a stale category, and the AI agent behavioral research is counterintuitive. However, most of the structural arguments - deception as a SIEM alternative, high-fidelity vs. noisy alerts - are established positions in the security discourse.
an IAM role, let's use a different example, in a in an AWS account, only has a handful of properties to it that an attacker can see before they actually start interacting with it. So it's actually quite easy to make these blend in with the rest of the environment
Kelly Shortridge from Fastly wrote about this uh in an article called Sludge for Good. And she made the case that you know you could do 95%, 99% uh deception or canaries versus uh 1% real resources
Andy Smith is a genuine practitioner - engineering lead and de facto CISO at Tessian (acquired by Proofpoint), directly involved in a supply chain incident that motivated the company, and now building a real product with published research. He is credible and specific, though TraceBit is early-stage and his scale of experience is bounded.
I led the engineering team, and I was also at times like the de facto CISO for an email security company called Tessian. They got sort of proof point a few years ago
we realized that if we had done, we'd have caught something maybe six months before we we wouldn't have done
The episode is notably specific for a security podcast: named study (Tularosa), named researcher (Kelly Shortridge, Fastly), named AI model (Opus), quantified outcomes (20%→3% success rate, 8-minute detection window, 14-minute time to root), and named platforms (GitHub, CircleCI, Guard Duty, Terraform). Some statistics are asserted casually without sourcing, which prevents a higher score.
the data we've we've produced and we've we published this show that we can make these detections of these offensive AI agents, like eight minutes into their their path to to domain admin
you speak to a CISO, and there's probably, I would say there's a 90% chance they're familiar with Deception and see some value in it. I'd say there's a 5% chance they've actually deployed it today
The host is clearly knowledgeable, prepared (referencing a pre-interview elevator conversation about the Tularosa study), and covers multiple angles including IR use cases and the five-year cat-and-mouse scenario. However, he consistently validates rather than challenges, never pushes on the sourcing of key statistics or the competitive moat claims, and occasionally completes the guest's thought before letting him answer.
If you had to take something out to put this in, make the make the case for you know spending 500k on trace bit then and 500k on something else
Is there ever like a case where you have so many canaries inside of an environment that like even that the attacker has to just and they just move on and they give up?
Computed from the transcript - who did the talking, and the words that came up most.
Why did the security industry stop talking about deception technology? And why should we start paying attention again? In this episode, Robby is joined by Andy Smith, CEO and Co-Founder of Tracebit, to discuss the evolution of deception technology and its role in modern security. Andy explains how organisations can deploy canaries, honey tokens and other deceptive resources in their environments to generate high-fidelity alerts when attackers move laterally, escalate privileges or attempt to access credentials and sensitive data. These alerts are designed to be both simple and highly reliable: if someone touches a fake resource, something suspicious is happening. The conversation explores modern deception techniques, what these look like when customers deploy them in their SOCs, how realistic decoys can be customised for different environments and the next generation of deception technology. Send us Fan Mail
Transcribed and scored by The B2B Podcast Index.
1 - > Speaker: From our headquarters in Oslo, Norway, and on behalf 2 - > of our host, Robby Peralta, welcome to the mnemonic security 3 - > podcast. 4 - >
Speaker 3: We all love a good SIEM project. 5 - > Collect some logs, normalize the data, tune the alerts, 6 - > reduce the noise, and do it all again with the next environment. 7 - > Now compare that to a canary. 8 - > You place a fake credential, bucket, secret, or session token 9 - > where no one should touch it. 10 - > And the moment someone does, you know something is wrong. 11 - > No tuning, no baseline, just a high fidelity signal. 12 - > And in some environments, that might be the only signal that 13 - > you can realistically get. 14 - > CI-CD pipelines, cloud accounts, appliances that barely 15 - > log. 16 - > Environments where sending everything to the SIEM is just 17 - > too expensive or simply not possible. 18 - > So if deception gives you cheap, fast, high confidence 19 - > visibility, why did the industry stop talking about it? 20 - > And why should you maybe start looking at it again? 21 - > Andy Smith: I'd say the spark that started to trace bit was my 22 - > previous role. 23 - > I led the engineering team, and I was also at times like the de 24 - > facto CISO for an email security company called Tessian. 25 - > They got sort of proof point a few years ago. 26 - > Um, and it was there basically in that role as thinking about 27 - > security of the organization. 28 - > I wanted to do deception. 29 - > So I was thinking about how we could detect thractors that got 30 - > into our environment, how we would do that. 31 - > And because of like the large, sprawling, ever-changing nature 32 - > of our environment, uh, the idea of deploying some like 33 - > tripwires effectively around that environment to detect 34 - > intrusions seemed like a good idea. 35 - > Long story short, we looked at the market, nothing really made 36 - > sense for this kind of large, ever-evolving cloud environment. 37 - > Um, we looked to build something ourselves in-house, 38 - > realized to do that would take actually way too many resources 39 - > that we couldn't justify. 40 - > Um, so we shelved the project. 41 - > And I can't really share the details, but we were 42 - > unfortunately hit by an incident. 43 - > It's actually a supply chain attack that led us to deeply 44 - > regret not investing in deception. 45 - > Um, we realized that if we had done, we'd have caught something 46 - > maybe six months before we we wouldn't have done. 47 - > Fortunately, there was not a significant impact to the 48 - > business, but that was kind of the spark really that started 49 - > TraceBit. 50 - > Myself and my co-founder were both deeply involved in that 51 - > incident, and we kind of saw the opportunity that that deploying 52 - > some deception in the environment would have would 53 - > have saved us, basically. 54 - > Robby Peralta: Do you think that what incident would have been 55 - > any different if you actually had deception in place? 56 - > 100%. 57 - > Andy Smith: Yeah, so so um again, I don't want to go on 58 - > don't want to go into too much detail, but when we when we dug 59 - > into it, the the the deception we wanted to deploy would have 60 - > been hit on day one of this this incident, and we didn't 61 - > actually pick up signals till months later. 62 - > Robby Peralta: Would you mind explaining you said tripwires, 63 - > uh canneries, I've heard, I've heard honey pots as well, and I 64 - > know there's a difference there. 65 - > What is deception? 66 - > Andy Smith: Yeah, for sure. 67 - > Um so deception technology has has many different definitions, 68 - > and it can be quite confusing. 69 - > I mean, fundamentally, the idea is to create artificial 70 - > resources somewhere inside your environment, could be inside the 71 - > perimeter, outside the perimeter, to deceive attackers 72 - > in one way or another. 73 - > People do this to seek when they seek different outcomes. 74 - > Some are seeking to produce threat intelligence to 75 - > understand more about the threat actors are how are how they're 76 - > attacking them. 77 - > That's when you'll often hear like the word honeypot used. 78 - > So this is where you might put a honeypot on the internet and 79 - > you might associate it with your organization and you know, see 80 - > who's going after you and what they're trying to do. 81 - > And that would produce threat intelligence. 82 - > What we focus on at TraceBit is more on the tripwire side of 83 - > things. 84 - > And that's where you hear terms like canaries or honey tokens 85 - > or these sorts of things. 86 - > And they would often be deployed inside the perimeter. 87 - > And that the goal is high fidelity detections. 88 - > But ultimately, they're they're fake resources that should 89 - > never be interacted with by a threat actor. 90 - > So it could be in a cloud environment, you might have an 91 - > S3 bucket that should never be read. 92 - > And if someone goes and reads it, you would jump on that 93 - > signal because it likely indicates there's some 94 - > compromise or some insider risk. 95 - > Robby Peralta: Would you mind going into some of those 96 - > artificial resources and what they actually are? 97 - > You mentioned AW or an A or S3 bucket you said. 98 - > Andy Smith: Yeah, yeah, for sure. 99 - > Um, yeah. 100 - > So I mean the kind of classic way of doing this was uh virtual 101 - > servers or network-based canaries. 102 - > So you might have an SSH server or you might have a web server 103 - > or a telnet server even, and you might be seeing who logs into 104 - > those. 105 - > Um the kind of approach we've taken that is a little bit 106 - > different from these more traditional ways of doing things 107 - > is leveraging like serverless resources in cloud environments. 108 - > The reason we've done that is one, that is how threat actors 109 - > are traversing through these environments. 110 - > You know, they're generally not getting access to a network and 111 - > running Nmap and then trying to get into a server. 112 - > They're generally getting access to some credentials and 113 - > then trying to move laterally or escalate privilege by jumping 114 - > around. 115 - > It could be roles or secrets or buckets or things like that in 116 - > those environments. 117 - > So, what we would canary, as we call it, would create deceptive 118 - > resources for would be things like an S3 bucket or a secret 119 - > manager secret in AWS, an IAM role. 120 - > We do a ton of different things in a ton of different cloud 121 - > environments, but it's it's the serverless resources. 122 - > And the other benefit of that, as well as in being like how the 123 - > attack paths actually look in environments, is they're 124 - > actually very low cost and low maintenance. 125 - > So it's basically financially intenable for any of our 126 - > customers to deploy uh network honeypot into every virtual 127 - > network they have in their system. 128 - > They could have thousands of virtual networks, servers cost 129 - > money to deploy. 130 - > It's not really feasible to do that. 131 - > But if you compare that to like an S3 bucket, which is 132 - > basically free to deploy, you could deploy thousands and 133 - > thousands of these without incurring a financial cost. 134 - > And then also the cloud providers are maintaining these 135 - > for you. 136 - > You know, you're not patching your S3 bucket. 137 - > So the actual risk and operational overhead of 138 - > deploying these is also very low. 139 - > Robby Peralta: Interesting. 140 - > I was gonna ask you, how did you go about choosing those 141 - > artifacts? 142 - > Was it because of incidents that are going on? 143 - > That's probably a little bit of that, and also because they are 144 - > you also had to balance that with like the keep the 145 - > operational overhead low. 146 - > Andy Smith: Exactly. 147 - > So so yeah, of course, we're we're always gonna focus on you 148 - > know, where are the like the juicy parts of an attack path 149 - > that the attackers are after going after? 150 - > So, like reading public threat reports, speaking to customers, 151 - > that's like part of it, and popular resources as well, 152 - > right? 153 - > It's it's no good, it's no good as building a product around a 154 - > resource that is very, very rare in environments. 155 - > We we're shooting for that realism. 156 - > And actually, it's surprising. 157 - > We actually have you know six resources we do in AWS, and 158 - > we're constantly hearing from customers like, actually, those 159 - > are the ones I'm I'm worried about, like by and large. 160 - > So that's part of it. 161 - > Like, are these actually used in attack paths? 162 - > And then, yeah, the other part is like the operational 163 - > overhead, but also the risk, right? 164 - > So the other benefit of an S3 bucket is it's many, as an 165 - > example, is it's in many ways benign. 166 - > You know, if a threat actor gets full access to that and uh 167 - > you know they're able to do whatever they want with it, they 168 - > don't have remote code execution. 169 - > They can't like leverage that as a foothold and then pivot 170 - > around the network from there. 171 - > Uh, compare that to a server, there's actually quite a lot of 172 - > risk with deploying a server in an environment, right? 173 - > If I exploit your Honeypot server, it's like it's like a 174 - > own goal that a lot of security teams don't really want to take 175 - > that risk on. 176 - > So the operational overhead and the the low risk is very much a 177 - > big part of it as well. 178 - > Robby Peralta: Do customers want different things? 179 - > Do they ever ask you to make you know canaries for them that 180 - > you didn't make before? 181 - > Andy Smith: So part of what we do with the platform is like 182 - > customizing these canaries. 183 - > So we will scan our customer environments and we're gonna 184 - > like we're gonna take the naming configuration for the resources 185 - > we we deploy. 186 - > So it's gonna look similar. 187 - > Um worth saying as well, actually, that the nice thing 188 - > about that is it's quite hard to fingerprint these these things. 189 - > You know, like uh an IAM role, let's use a different example, 190 - > in a in an AWS account, only has a handful of properties to it 191 - > that an attacker can see before they actually start interacting 192 - > with it. 193 - > So it's actually quite easy to make these blend in with the 194 - > rest of the environment. 195 - > Again, compared to a server, which is going to be 196 - > fingerprintable over TCP. 197 - > So that gets us very far with customers, just like making the 198 - > resources named in a similar way and configured in a similar 199 - > way. 200 - > Where we want to get to is like imagine a world where you plug 201 - > some threat intelligence into Claude or Codecs, and you say, 202 - > Hey, I want some deception in my environment if for this threat 203 - > actor. 204 - > Uh and you know, you plug into TraceBit and we can deploy like 205 - > nested canaries and deception around your organization, both 206 - > on the out external perimeter and internal perimeter to detect 207 - > and deceive that specific threat actor. 208 - > That's not where we are today. 209 - > We deploy lots of canaries at scale for for good coverage, uh, 210 - > but that's where we want to go with the platform. 211 - > Robby Peralta: I understand the internal case. 212 - > What's the external case? 213 - > Andy Smith: So historically, the external case has been, to my 214 - > point earlier, around threat intelligence. 215 - > So putting pieces of honeypot, yeah, the research. 216 - > Yeah, exactly. 217 - > Um we have this feature we're launching soon called perimeter 218 - > canaries, where you could point some public facing 219 - > infrastructure at trace bits. 220 - > So imagine vpn.customer.com points to us. 221 - > Now, obviously, it's not it's not super useful for us to tell 222 - > you someone scanned vpn.customer.com because that's 223 - > going to be happening all day, every day. 224 - > It's not actionable. 225 - > You know, what are you gonna do with that? 226 - > Your security team's already really busy, you know, they 227 - > don't they don't need more information. 228 - > It's not that's not super useful. 229 - > But what if you placed a cookie on every single one of your 230 - > users' workstations that referenced VPN.customer.com with 231 - > a with a unique cookie. 232 - > Well, now if a threat actor gets into that one of those 233 - > workstations and they dump the cookies in an attempt to like 234 - > move laterally, you know, or run an info stealer as is often the 235 - > way, that's gonna be like really high up on their list of 236 - > targets. 237 - > Because they think they're they're gonna think they've got 238 - > the VPN access. 239 - > It's gonna make it look really believable and really 240 - > legitimate. 241 - > And then you know, you can imagine the future like 242 - > customizing that to specific instance you've had or specific 243 - > like things that are being targeted in your industry. 244 - > Robby Peralta: Yeah, cool. 245 - > So I had an episode four years ago about deception. 246 - > I called it deception. 247 - > Yeah. 248 - > Uh as with Illusive. 249 - > Okay. 250 - > And then a couple, it mightn't have been that long before that. 251 - > I had one on uh honeypots. 252 - > But I haven't seen the adoption take off in in our neck of the 253 - > woods, right? 254 - > Uh in Europe. 255 - > Why is that and what's changed? 256 - > Andy Smith: Yeah, uh, it's it's absolutely not taken off. 257 - > And I think, you know, if you look at the history of this, you 258 - > can see there was a lot of venture capital excitement in in 259 - > Deception, maybe eight to ten years ago, and that's where 260 - > companies like Elusive came out of. 261 - > Uh, there were there were a bunch of them, and there was a 262 - > lot of excitement. 263 - > And I think I hear stories that if you went to RSA 10 years 264 - > ago, like the expo floor was full of like deception 265 - > technology as far as the eye could see. 266 - > Uh, and you're right, like, you know, you speak to a CISO, and 267 - > there's probably, I would say there's a 90% chance they're 268 - > familiar with Deception and see some value in it. 269 - > I'd say there's a 5% chance they've actually deployed it 270 - > today, like from our experience. 271 - > Um, I think that past wave of technologies from the folks we 272 - > speak to that that bought and deployed them, they suffered a 273 - > lot from some of the challenges I've already touched on around 274 - > the heavyweight nature of deploying like virtual machines. 275 - > And some of these technologies you actually shipped to a 276 - > physical rack you had to go deploy into your data center. 277 - > And then these things are expensive to deploy, right? 278 - > You want to deploy like hundreds of servers. 279 - > There's actually like a significant financial cost to 280 - > deploy them. 281 - > And then again, there's uh an operational overhead. 282 - > The other challenge that I understand from folks who 283 - > deployed these is that that like maintenance and management of 284 - > them. 285 - > So they often gave you some really nice building blocks to 286 - > go and deploy deception in your environment, but they they left 287 - > you to it. 288 - > Like you had to go and go and figure out where to where to put 289 - > all of this all of this stuff. 290 - > Um, and because it was in the data center and it was an 291 - > on-prem network, it was quite a lot of work to go and do that. 292 - > We think it's different this time because like the cloud, you 293 - > know, teams have aligned behind certain technologies, like 294 - > Terraform is one of those, Kubernetes is another one, which 295 - > allow for like the rapid scale of infrastructure around your 296 - > environments. 297 - > That infrastructure is lightweight, it's easy, easy to 298 - > deploy. 299 - > The other unlock for us uh has been LLMs. 300 - > So we are using LLMs to create suggestions to customer 301 - > environments. 302 - > So when we started the company three years ago, they weren't 303 - > that great. 304 - > We did things like look to prefixes and suffixes for our 305 - > naming schemes and things like that, but they've obviously come 306 - > on leaps and bounds. 307 - > So we will actually take metadata from customers' 308 - > environments and we'll use that to say, hey, you know, create me 309 - > sets of resources that are attractive to would-be 310 - > attackers, that are benign to would-be attackers, create all 311 - > these different resources and make them look realistic and 312 - > tell a realistic story for this environment. 313 - > And the security teams we show this stuff to are like, wow, 314 - > like, you know, I wouldn't have even thought about that. 315 - > Or I forgot we even did that project, but it'll be great to 316 - > have a canary over there. 317 - > So that that time save is a big part of it because security 318 - > teams are usually the most busy people in the company. 319 - > And the idea of spending three weeks to go and come up with 320 - > some great deception is just not really feasible. 321 - > Then, not least, if you think about maintaining that in the 322 - > long run, right? 323 - > Because your environment's going to change in six months 324 - > from now. 325 - > So six months, six months down the line, are you really gonna 326 - > put in like another couple of weeks to go and move the 327 - > deception around and reconfigure it? 328 - > But if you automate that from day one and you use LLMs to 329 - > create believable looking deception, that's where we think 330 - > there's a lot of value. 331 - > Robby Peralta: SOC, Security Operations Center. 332 - > I'm assuming all your customers today are probably large and 333 - > mature. 334 - > And we can get back to whether we need to be. 335 - > We can get back to that. 336 - > Yeah, whether you need to be not. 337 - > Yeah, we talked about this before. 338 - > Yeah. 339 - > But the ones that do have it today, what does it look like 340 - > when they have deployed this technology in their current SOC? 341 - > Like how does that coexist? 342 - > Andy Smith: Yeah, so it's it's fairly straightforward. 343 - > We'll we'll usually be working with the SOC often. 344 - > The SOC will buy trace bit. 345 - > Obviously, it depends from customer to customer. 346 - > But fundamentally, we are feeding these alerts into their 347 - > sim. 348 - > Uh and then the SOC team is taking those, it's they're 349 - > augmenting them with other data in their environment, and then 350 - > they're responding to those alerts. 351 - > So it's it's relatively relatively simple. 352 - > Robby Peralta: If you know everybody has a limited budget, 353 - > if you had to take something out to put this in, make the make 354 - > the case for you know spending 500k on trace bit then and 500k 355 - > on something else. 356 - > Yeah. 357 - > Andy Smith: Yeah. 358 - > Um, I think there's we we have worked with customers on use 359 - > cases around sim usage. 360 - > And you know, we've we've heard from them, hey, I'm I'm not 361 - > even doing anything with this sim data, it's way too noisy. 362 - > I'm getting I'm getting too many alerts off it already. 363 - > Uh certainly other tools like guard duty and things like that, 364 - > like there's just no value in it. 365 - > But I don't want to turn it off because that would leave me 366 - > with zero visibility in that environment. 367 - > So in some cases, there's a billion the ability to do that. 368 - > I think the other interesting use case is when teams are 369 - > wasting time on false positives. 370 - > And again, they're in that state where they either put time 371 - > into tuning them out, they turn them off. 372 - > That's that's too much risk. 373 - > There's there's a time-saving piece there where you know you 374 - > can you can take a set of false positives and say, let's let's 375 - > just turn these off because they're they're creating too 376 - > much noise for us and we have comfort that we've augmented 377 - > this, you know, we've we've replaced this with the 378 - > visibility trace bits given us into that environment. 379 - > Robby Peralta: So cheap visibility and no matter what, 380 - > better than nothing. 381 - > Yep. 382 - > Yeah. 383 - > Andy Smith: Yeah, yeah, 100%. 384 - > We go into environments where there just isn't that much 385 - > telemetry. 386 - > CI CD environments are a really good example of this, where 387 - > what what logs do you have from those environments, especially 388 - > if you're running that in in GitHub or Circle CI or places 389 - > like that? 390 - > Like, do you do you really have that much visibility of what's 391 - > going on in those environments? 392 - > Like, this is a quick win to get something in there very, 393 - > very early that's going to give you that high fidelity signal if 394 - > something is compromised, that environment. 395 - > Robby Peralta: As we're speaking right now, there's probably a 396 - > supply chain attack going on. 397 - > I have no doubt. 398 - > Yeah, we'll open our phones after this and read about it. 399 - > Andy Smith: I'm sure. 400 - > Robby Peralta: Knock on the table. 401 - > Yeah. 402 - > Uh how would you, your technology, any deceptive 403 - > technology sort of fit in that use case? 404 - > Andy Smith: Yeah, so so we we we did some research recently that 405 - > we that we published with this, where um the the team PCP 406 - > attacks that are very friendly for a lot of folks at the 407 - > moment, one of the things they did was steal AWS keys and SSH 408 - > keys from environments. 409 - > And that's one of the ways that they that they spread. 410 - > So very concretely, we ran some of that, those info stealers 411 - > within some GitHub actions, and we were able to show that these 412 - > would these would take these these keys from these 413 - > environments. 414 - > So TraceBit would detect when those keys were being used. 415 - > One of the nice things that we do is we generate unique keys 416 - > for every single build that runs in an environment. 417 - > So like the scale is a big, a big important part of it. 418 - > And what that means is when TraceBit goes off, you can 419 - > actually jump to the exact build that this occurred in. 420 - > So we met folks who've like built this themselves. 421 - > They put a single AWS key in a Git repo that hundreds of 422 - > developers have access to, and it pings one day from a funny IP 423 - > address. 424 - > And you fundamentally don't actually end up doing anything 425 - > with that alert. 426 - > You know, you know something bad has happened, but you don't 427 - > even have the data or the telemetry to go and figure out 428 - > where that bad thing has has occurred. 429 - > Um, whereas when Tracebook goes off in an environment where 430 - > like, hey, it was this build, you know, the the credential 431 - > existed, you know, in the context for like 10 minutes. 432 - > Like you need to go and investigate this right now. 433 - > And obviously, if a lot more light up, then you know you'll 434 - > have a you'll have a big impact. 435 - > Robby Peralta: What about the other top initial access? 436 - > Uh I mean, thinking of like, yeah, Mandiant would say that uh 437 - > appliances getting popped are the uh the largest or info 438 - > stealers, uh phishing. 439 - > Do you uh do you have use cases for all those sort of yeah? 440 - > Andy Smith: So we do we do a lot on on workstations. 441 - > So deploying deploying credentials onto workstations is 442 - > a big one. 443 - > I've mentioned this the session cookie piece that we're we're 444 - > working on at the moment that I think is going to be gonna be 445 - > really, really powerful. 446 - > Um yeah, appliances I think is another really good example. 447 - > Um we don't have like a ton of uh active deployments there, but 448 - > I think credentials on appliances is super powerful. 449 - > You don't have, you know, these they are often so underpowered 450 - > you can't create logs or ingest those logs into your sim. 451 - > But it's pretty trivial to go have like a cron, go deploy a uh 452 - > a unique credential every every 24 hours. 453 - > And if someone got onto that system, that's gonna look like a 454 - > really attractive opportunity to move laterally. 455 - > So that's the sort of detection we would make. 456 - > Robby Peralta: Forgot his name, Caleb Simer. 457 - > Caleb? 458 - > Yes. 459 - > He's fantastic. 460 - > I don't know him, unfortunately. 461 - > But uh he was on the cloud security podcast, I believe it 462 - > was. 463 - > Um, also a fantastic podcast. 464 - > He said that it was surprising to him that companies don't 465 - > invest that they go for like a big expensive sock as a reactive 466 - > capability instead of going for something like your technology. 467 - > Yep. 468 - > I would assume that you would agree and like him saying that. 469 - > Yeah, I thought it was really interesting. 470 - > Uh because I I I share his viewpoint. 471 - > Andy Smith: We really do see this as a as a quick win that 472 - > you can do early on. 473 - > Um, by deploying deception previously, this was going to be 474 - > something that was actually gonna create a bit of a workload 475 - > for the team just to keep the thing like valuable. 476 - > Whereas now it's automated, now this is something you can just 477 - > plug and play. 478 - > I I, incredibly biased, do think, you know, why not just do 479 - > this like on day one of your security program? 480 - > Like the idea that the times of value on deploying a sim, 481 - > right? 482 - > I'm talking like super early on. 483 - > Like the times of value on deploying a sim. 484 - > We speak to teams, you know, you come back six months later 485 - > and they're still integrating this data source and that data 486 - > source, they're still tuning. 487 - > Like they could have had some super high fidelity detections 488 - > across like a broad set of their environments within weeks if 489 - > they deployed some deception in that environment. 490 - > So I I think that like it is it is a massive quick win, but I'm 491 - > obviously very biased. 492 - > Robby Peralta: Yeah, SIEM is a never-ending project, as uh we 493 - > both know. 494 - > Uh LLMs. 495 - > Yes. 496 - > What are your thoughts around LLMs and deception? 497 - > Andy Smith: Yeah, I think there's I think there's like two 498 - > key parts to this. 499 - > Like one is offensive AI agents. 500 - > Um we've actually done our own research on on this. 501 - > Uh so we we created like a cloud lab and we we tested this 502 - > out and we had an environment where they could get to 503 - > basically root in in 14 minutes. 504 - > Um, so I think I think LLMs for any security team right now, 505 - > specifically offensive AI agents, you know, mean that 506 - > attackers are gonna run much quicker through their 507 - > environments. 508 - > I also think they're just gonna have a broader set of 509 - > techniques that they're gonna have available to them to get 510 - > into those those environments. 511 - > So, so for us, that means you want those high fidelity signals 512 - > as soon as humanly possible. 513 - > Um, and our tests show that that trace bit canaries like 514 - > play a really good role in that. 515 - > So the the the data we've we've produced and we've we published 516 - > this show that we can make these detections of these 517 - > offensive AI agents, like eight minutes into their their path to 518 - > to domain admin. 519 - > I I want to get that that number down. 520 - > Uh, and I think there's there's all sorts of work we can we can 521 - > do there. 522 - > But I really think that, yeah, it's it's it's obvious that this 523 - > is going to get um more and more serious over time. 524 - > When the open weight models you know get this, get that good, 525 - > which is probably six months away, we're gonna be in a really 526 - > interesting situation. 527 - > Um the other the other piece worth touching on uh that we do 528 - > see in customer environments is like the internal AI agents. 529 - > So you know, customers are are deploying these. 530 - > Uh sometimes they're allowed to, sometimes it's it's shadow 531 - > AI, you know, to do their to do their job. 532 - > Um and what we're finding with deception is actually proving is 533 - > quite a valuable detection for when those internal authorized 534 - > AI agents like overstep the mark. 535 - > So we've had examples in customer environments where the 536 - > security team were surprised to find an AI agent you know make 537 - > it all the way to a production canary. 538 - > Uh and turns out, you know, an engineer was saying yes, yes, 539 - > yes, yes, yes. 540 - > And that's been a really useful uh detection for the security 541 - > team to have that they otherwise wouldn't really have had any 542 - > visibility of. 543 - > Robby Peralta: So there's an insider use case here, not 544 - > necessarily a human being or malicious insider, or but but it 545 - > does cover both. 546 - > Andy Smith: We we cover both, and yeah, I've we've not really 547 - > touched on that, but like folks will like buy Trace bit, usually 548 - > for the outside in, the the external threat actor, and we'll 549 - > provide value there, of course. 550 - > But those um those detections, you know, are fortunately in 551 - > most customer environments relatively rare, right? 552 - > No, you're not getting popped every week. 553 - > But the insider, you know, the someone who's it's it's not even 554 - > insider risk, it's sometimes risky insider. 555 - > You know, it's uh it's non malicious intent. 556 - > Someone's trying to do their job, but maybe they've strayed 557 - > into an environment they should have, maybe they're they've gone 558 - > off a pro off a process they they shouldn't be following, and 559 - > you know, they they End up saying off a canary. 560 - > And those are often signals that the sim isn't tuned to 561 - > detect and you know the security tool isn't set up to detect, 562 - > but can often be the smoking gun for a security team that allows 563 - > them to get a process fixed, you know, get some training 564 - > improved, you know, get some um get some like guardrails 565 - > tightened up and reduce risk for the business. 566 - > Robby Peralta: Maybe uh sort of far out there, but has anybody 567 - > ever used your technology for incident response use case? 568 - > Andy Smith: Uh it's something we have uh have explored with a 569 - > few folks. 570 - > But yeah, I think it's I think it's a super interesting use 571 - > case, you know, when you you know someone is in the system 572 - > and like proactively deploying that out. 573 - > Just slow them down, right? 574 - > Slow them down, confuse them, uh, detect them in places you 575 - > you're you might not have telemetry for. 576 - > Uh yeah, it's it's something we're exploring. 577 - > It's not something we actively do with a product today. 578 - > Robby Peralta: What was that study that we talked about in 579 - > the elevator on the way up here? 580 - > Andy Smith: Uh the Tularosa study. 581 - > Yeah, tell us that. 582 - > Yeah, so the Tularosa study was um they took a couple hundred 583 - > pen testers and it was kind of a test with a quadrant. 584 - > So uh somewhere they were told there was deception and 585 - > somewhere they were not told there was deception, and 586 - > somewhere there um there was deception, and somewhere there 587 - > wasn't deception. 588 - > So that that was a quadrant, and that and they were trying to 589 - > test out, you know, if you tell people there's deception in an 590 - > environment and there isn't, like, does it change their 591 - > behavior? 592 - > Uh and if you put deception in environment and the and you 593 - > don't tell people about it, does it does it change the behavior? 594 - > Can you make detections? 595 - > And yeah, the the the long and the short of it is they found 596 - > that even the understanding or perception that deception was in 597 - > an environment did change behavior and made folks less 598 - > likely to reach their goal. 599 - > And to the point earlier around the research we've been doing, 600 - > we found that the same is true for for AI agents in 601 - > environments. 602 - > So I think it was Opus specifically. 603 - > We found when you we ran this through our cloud lab, if you 604 - > told Opus there was deception in the environment, its likelihood 605 - > of reaching admin went from 20% to 3%, just because it believed 606 - > canaries were there and it was trying to avoid them or taking 607 - > steps to not get detected. 608 - > Robby Peralta: I feel like it was one of your podcasts you had 609 - > with uh the guy from Riot where you said uh where one you guys 610 - > talk together and and you arrived at the conclusion that 611 - > if everybody moves to deception, it'll be a cat and mask game as 612 - > security always is, and the attackers will change. 613 - > So in five years, if TraceBit is super successful and 614 - > everybody's using Deception, what does the world look like 615 - > then? 616 - > What are the attackers gonna do differently? 617 - > Andy Smith: Yeah, it's a great question. 618 - > I mean, and I think that's that is the case where we would make 619 - > the case that like partnering with a vendor makes a lot of 620 - > sense because you know you want someone, someone actively 621 - > developing this. 622 - > Because even if you went and did your own automation and set 623 - > that up and did a really good job of it, so it does evolve 624 - > automatically, you know, you're not gonna be inventing new 625 - > resource types, you're not gonna be plugging different pieces 626 - > together, you're not gonna be like building support for more 627 - > systems over time, you're gonna build one piece. 628 - > Uh, so for us, that's why it's really important uh to be 629 - > constantly evolving the platform and adding new features. 630 - > Um, and that's also why we're really excited about this like 631 - > AI range that we've we've set up, because we can constantly 632 - > iterate AI agents against these against these environments, and 633 - > as they get better, um, we can detect that and we can evolve 634 - > the product and platform to get better at detecting them. 635 - > Robby Peralta: Is there ever like a case where you have so 636 - > many canaries inside of an environment that like even that 637 - > the attacker has to just and they just move on and they give 638 - > up? 639 - > Andy Smith: Yeah, yeah. 640 - > It's um so I think Kelly Shortridge from Fastly wrote 641 - > about this uh in an article called Sludge for Good. 642 - > And she made the case that you know you could do 95%, 99% uh 643 - > deception or canaries versus uh 1% real resources. 644 - > That is not something we've explored so far, to be honest 645 - > with you. 646 - > Uh I think uh you know our focus really is you know ease of 647 - > deployment for us is also about not getting away in the way of 648 - > your software engineers who you know are busy people and and you 649 - > know don't want uh a ton of resources in their way. 650 - > I I do see scope for that in the future for sure as something 651 - > customers could opt into. 652 - > Robby Peralta: Because if there were that many resources, how 653 - > would it be in their way? 654 - > Andy Smith: Yeah. 655 - > Uh from a software engineer's point of view, yeah. 656 - > Well, imagine you're logging into a cloud environment and you 657 - > know you're debugging a production issue at three 658 - > o'clock in the morning and you're trying to find the real 659 - > resource that is that is broken, and there's 10,000 canaries in 660 - > there that you know you have to scroll through or page through. 661 - > Yeah, so it's you know very valuable if you're a threat 662 - > actor. 663 - > It's gonna be basically impossible for you to find the 664 - > real resource without sending it off. 665 - > But that could create some friction if you are uh you know 666 - > a DevOps engineer responding to an incident. 667 - > Robby Peralta: Yeah, and that's what's been kind of holding 668 - > deception back, if I understood you correctly, is the 669 - > operationalization of it. 670 - > Andy Smith: The operational holding deception back is the 671 - > opera opera line opera what's been holding the overhead for 672 - > sure. 673 - > Um but I would say that like that sludge idea is is maybe 674 - > just taking things to the to the extreme, which I don't think is 675 - > a bad idea. 676 - > I just think it's it's something you would not want to 677 - > put in every single environment. 678 - > Yeah, for sure. 679 - > Because like humans are operating in some of those 680 - > environments. 681 - > Robby Peralta: Yeah. 682 - > Do you have any final thoughts or anything that we did not 683 - > cover that you think is worth mentioning to enlighten 684 - > security? 685 - > Andy Smith: No, I think um honestly, I think if you've if 686 - > you've been intrigued by what you've heard, I would I'd really 687 - > go sign up to our community edition. 688 - > Uh something you can go and protect your your home PC with 689 - > with deception right now, uh, and and your email and your 690 - > password manager and other pieces like that. 691 - > So I think that's a great place to start. 692 - > Uh if you'd like to know more, you can you can book a demo on 693 - > our website. 694 - > Cool. 695 - > Andy Smith, thank you so much for your time. 696 - > Thank you much. 697 - > We appreciate it. 698 - > Thanks a lot. 699 - > Robby Peralta: Well, that's all for today, folks. 700 - > Thank you for tuning in to the Mnemonic Security Podcast. 701 - > If you have any concepts or ideas that you'd like us to 702 - > discuss on future episodes, please feel free to hit me up on 703 - > LinkedIn or to send us a mail to podcast at mnemonic.no. 704 - > Thank you for listening, and we'll see you next time.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.