The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/Secure Networks: Endace Packet Forensics Files
Secure Networks: Endace Packet Forensics Files artwork

Episode 65: Cody Spooner, Senior Sales Engineer and IR expert, Corelight

Secure Networks: Endace Packet Forensics Files · 2026-05-28 · 18 min

0:00--:--

Key moments - from our scoring

Substance score

38 / 100

Five dimensions, 20 points each

Insight Density9 / 20
Originality7 / 20
Guest Caliber9 / 20
Specificity & Evidence7 / 20
Conversational Craft6 / 20

Cody Spooner, Principal Systems Engineer and IR expert at Corelight, discusses a critical but often overlooked distinction in threat hunting: the difference between behaviors of compromise and the enablers that make compromise possible. Using the analogy of an unlocked car with keys inside, Spooner explains how misconfigurations - such as cleartext authentication, deprecated protocols like Telnet and NTLM v1, unencrypted HTTPS connections, and forgotten legacy infrastructure - create opportunities for attackers far more prevalently than active malicious activity itself. Organizations typically focus on detecting anomalies and malicious behaviors like data exfiltration, but miss structural weaknesses that are normalized over time. Spooner advocates shifting threat hunting methodology to ask preventative questions ("How would an attacker exploit my environment?") rather than reactive ones, and emphasizes how understanding enablers reshapes incident response strategy and timeline reconstruction. The conversation also addresses emerging risks from cloud misconfigurations - particularly incomplete HTTPS implementations and unencrypted API calls - and AI-driven deployment without proper security configuration. Practitioners in incident response, threat hunting, and security operations will benefit from reframing their detection workflows around these foundational vulnerabilities.

Key takeaways

  • →Enablers like cleartext authentication, legacy protocols (Telnet, NTLM v1, SMB v1), and misconfigurations are easier to find than active compromises on large networks but equally critical to address.
  • →Security teams should reframe their questioning from 'Did someone compromise us?' to 'If someone wanted to, how would they do it?' to better identify attack pathways.
  • →Cloud migrations frequently introduce misconfigurations like incomplete HTTPS implementations and cleartext API communications, creating new classes of enablers that defenders must actively hunt for.
  • →Identifying enablers during incident response helps establish attack timelines and determine what data or lateral movement techniques were realistically available to the threat actor.
  • →AI and cloud technologies are creating more misconfigurations than they eliminate, as organizations deploy solutions without fully understanding or securing them.

In this episode

  1. 1Introduction and Background in Incident Response
  2. 2Enablers vs. Behaviors of Compromise: The Unlocked Car Analogy
  3. 3Why Misconfigurations and Legacy Protocols Get Overlooked
  4. 4Cleartext Authentication and Password Reuse as Compromise Doorways
  5. 5Deprecated Protocols and Their Role in Expanding Attack Surface
  6. 6Proactive Threat Hunting for Misconfigurations
  7. 7Shifting Security Mindset: Asking Better Questions
  8. 8Cloud and AI as Emerging Sources of New Enablers

Mentioned

CorelightEndaceCody SpoonerActive DirectoryCiscoNTLMSMBTelnet

Guests

Cody Spooner

Topics in this episode

Cloud security misconfigurationsCorelightEndaceTelnetNTLM v1SMB v1Cleartext authenticationHTTPS encryptionPass-the-hash attacksLateral movement

Questions this episode answers

What is the difference between enablers and behaviors of compromise in threat hunting?

Enablers are misconfigurations or structural weaknesses (like unlocked cars with keys inside) that aren't malicious by themselves but create opportunity for attackers, while behaviors are the actual malicious activities attackers perform. Enablers are often overlooked because they become normalized as "the way things have always been" in organizations.

Why do security teams overlook legacy protocols like Telnet and NTLM v1 even though they pose security risks?

Analysts are trained to look for anomalies against the baseline norm, but when that baseline includes deprecated protocols and misconfigurations, these enablers become invisible because they're historically present. Additionally, organizations avoid changes that might disrupt operations, allowing outdated infrastructure to persist unexamined.

How can cleartext authentication on web servers lead to full network compromise?

Threat actors can sniff cleartext credentials traversing the network and exploit password reuse across systems like Active Directory, Git repositories, or LDAP traffic. Once stolen, these credentials enable lateral movement and account takeover, turning a simple misconfiguration into a doorway for widespread compromise.

What cloud misconfigurations does Corelight see that create new enablers for attackers?

Corelight observes HTTPS on port 443 that is actually unencrypted (not fully configured), unencrypted API calls to cloud services, and applications sending data partially in cleartext. These occur because organizations deploy cloud infrastructure without completing security configuration or understanding what they've built.

How should IR teams shift their threat hunting methodology to better identify enablers?

Instead of asking "Did someone break in?" teams should ask "How would someone break in if they tried?" This proactive questioning helps identify misconfigurations and structural weaknesses before attackers exploit them, and keeps those identifications relevant in daily security conversations.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

9 / 20

The enablers-vs-behaviors framing produces a handful of genuinely useful practitioner observations, but the episode is padded with analogies, affirmations, and restatements of the same car-keys metaphor. Actual novel claims per minute are low for an 18-minute runtime.

we as threat hunters responders are trained to look for the anomalous. What stands out against the norm. Well if that baseline norm is enablers of compromise, we start to ignore them simply because it's always been that way
I think AI has also created a new era of misconfigurations. We see a lot more people building stuff with AI without necessarily understanding what they're building and then just publishing it

Originality

7 / 20

The 'enablers vs. behaviors' framing is a mildly useful reframe, but nearly every concrete point - Telnet is bad, NTLMv1 is risky, cleartext credentials are dangerous, AI causes new misconfigs - is standard security-community received wisdom with no contrarian or first-principles argument.

if we play some buzzword bingo here, we can just rattle off AI and cloud really quick
I think it generally boils down to all right, I'm an analyst, maybe I'm new at the company, maybe I've been here for 20 years and I see telnet on the wire

Guest Caliber

9 / 20

Cody Spooner has genuine IR and threat-hunting practitioner roots, but the role described is sales/systems engineering at a vendor, which introduces a promotional context and limits the depth of independent, at-scale operational perspective on offer.

my background started out in the services side where I dove into incident response and threat hunting. And from there that was a natural trends, uh, transgression or transformation, uh, into the sales side of the world
The packets don't lie. It's right here.

Specificity & Evidence

7 / 20

The episode names specific protocols (NTLMv1, Telnet, LDAP, SMBv1, HTTPS 443) and gestures at conference observations, but there are zero named customers, breach case studies, quantified metrics, or dollar figures - everything stays at the level of 'we see a lot of this' generality.

when we see something like ntlm, um, version one on the network, well, the abilities that that attacker had to gain credentials and laterally move have opened up
HTTPs port 443, um, we see a lot of connections at the various conferences, both Endase and corelight support together, um, where those connections are intended to be encrypted. We can see that because they use the standard port for HTTPs, but it's all clear text

Conversational Craft

6 / 20

The host selects reasonable topics but executes almost every exchange as a soft tee-up followed by effusive affirmation ('that's a great point,' 'no, absolutely,' 'no, that's a great example'), with no follow-up challenges, no probing of vendor bias, and no productive disagreement across the full episode.

That's a great point. Uh, don't leave the door open and wonder why somebody walked in, right?
No, that's a great point. And you're right in the other comment you had.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker B65%
  • Speaker A35%

Most-used words

threat14example13compromise10cloud10response9enablers9start9network8identify8point8side7malicious7misconfigurations7telnet7perspective6door6

Episode notes

In this episode of the Endace Packet Forensic Files, Michael chats with with Cody Spooner , Principal Sales Engineer and DFIR expert at Corelight , about an interesting topic: the subtleties and differences of “ Enablers " vs " Behaviors ” of a cybersecurity compromise . Cody explains that when most people think of threat hunting or incident response investigations, they picture analysts looking for signs of malicious activity. In reality there are critical subtle differences between the “ behavior of a compromise” and the underlying “ enabler of a compromise” that often go unnoticed or overlooked. He highlights how organizations tend to focus heavily on detecting malicious behaviors - such as data exfiltration or unauthorized logins - but often miss identifying the enabling conditions - such as misconfigurations or legacy protocols - that led to those compromises in the first place. Cody shares examples of seemingly harmless issues that can become the doorway to a full compromise, such as configuration issues or outdated or deprecated protocols like NTLMv1 and SMBv1.

Full transcript

18 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: This episode's very special guest is Cody Spooner, principal systems engineer and IR expert at corelight. Cody, welcome. Thank you for joining us. Why don't you tell us a little bit about yourself and your background?

Speaker B: Sure, yeah. Thanks for having me. I appreciate your time and your invitation to be here. Um, my background started out in the services side where I dove into incident response and threat hunting. And from there that was a natural trends, uh, transgression or transformation, uh, into the sales side of the world. So a lot of that practitioner background I've kept with me now.

Speaker A: It's great having you. Corelight's a great partner of ours and we've, uh, we're just talking about some great wins we've done together. But, uh, in setting this interview up, you brought up a great topic that I'm really interested to dig into, which is really this concept of enablers versus behaviors of a compromise. And so kind of where I want to start is, uh, when most people think of threat hunting, they picture analysts looking for clear signs of malicious activity. How do you explain the difference between the, uh, behavior of a compromise and the underlying enablers of a compromise that often go unnoticed?

Speaker B: Sure. So there's a couple pieces to that. So to break it down in a non technical way, first let's imagine you drove to the store in your car and we're silly. We left our car keys in the car, it's unlocked. We go into the store to buy our groceries. Right. The fact that you left your car keys in the car, that's not bad. We were just forgetful. It doesn't mean anything bad is going to happen. It's not malicious. But a car thief is in the parking lot and that person notices the cars unlocked. Well, now their job is easier. They're in the unlocked car, the car keys there, they can start it, they can drive away. They conducted a malicious activity because they were enabled to do so by something else. And that's the same thing that translates over to the technical side, especially when we talk about networks which are important to both of us here. Yeah, um, same concept applies. You can have a misconfiguration on the network that by itself isn't bad. There's no malicious activity, but it might lead to a threat actor being able to abuse that misconfiguration for nefarious purposes.

Speaker A: Uh, that's a great example. And, uh, the word I use and I've heard from police is crime, uh, of opportunity. Right. So when you present it that easily for him with your keys in the car, uh, it's hard to. But the malicious activity is still there. Organizations tend to focus heavily on detecting malicious behaviors like data exfiltration or unauthorized logins. Why do you think enabling conditions such as misconfigurations or legacy protocols often get overlooked?

Speaker B: Yeah, so we could go into a real deep philosophical answer with that. I'm sure with the nuance of corporations, but I think it generally boils down to all right, I'm an analyst, maybe I'm new at the company, maybe I've been here for 20 years and I see telnet on the wire. Right. Something that's outdated shouldn't exist anymore, but it's there and it's there because it's always been there. Right. So we as threat hunters responders are trained to look for the anomalous. What stands out against the norm. Well if that baseline norm is enablers of compromise, we start to ignore them simply because it's always been that way. And whether that's right or wrong, I think we start to see a lot of things that are difficult to change in an organization. It's certainly not easy trying to convince it to make a change that might impact a bunch of stuff. Um, but that doesn't mean we should forget it, if that makes sense. Right. Like um, Telnet's a great example. Like we should say hey, this still exists. Why does it still exist? Um, every org does their own risk assessment and all of that stuff but um, we got to continuously challenge it and I think that's where it starts to slip through the cracks.

Speaker A: Yeah, no, that's a great example because you know most companies ssh to log into things now so clearly it's a perfect example. Um, we've seen together at some of these uh, big events that we've worked together. Corelight, uh, and Endase, um, Cleartext authentication being a problem at trade ah shows and things. It's a classic example of non malicious uh, enabler that can be exploited. Can you walk us through a scenario where harmless misconfiguration or configuration becomes um, the doorway to a full compromise?

Speaker B: Yeah, absolutely. There's a few elements here. One is just human behavior. We tend to be pretty repetitive in what we do. That means password reuse a lot of times. All right, so if you have a uh, let's say a web server that isn't have using a valid SSL certificate and you authenticate to that, there's a good chance that maybe you're reusing that password elsewhere, whether that's your active directory account, uh, login to your git repository Whatever it is, um, threat actors will abuse that if it's in the clear and it traverses the network. You know, we have great solutions that are going to identify that we're not the only ones that are going to identify that. A threat actor can sniff that as well. And if they sniff it, they can use it against you. So whether it's a web server, um, your LDAP traffic to active directory, all of those credentials are fair play for a threat actor to take and try to grow their presence in the network during a compromise.

Speaker A: No, that's a great example. Um, on that note, you mentioned Telnet earlier, um, and I think that's a perfect example as well. How do you outdated and deprecated protocols like NTLM v1 or SMB v1 that often continue to persist in some modern environments? What risks do they introduce for incident responders and threat hunters as you're trying to investigate an issue?

Speaker B: Yeah, I think risk turns into, uh, a bigger word here from a response perspective. If we see clear text stuff, whether it's telnet, web servers, whatever. I think the next question that follows up is, okay, was this used to facilitate further compromise? Right. Um, I think that's pretty dependent on what the chain of attack is going to be. Um, however, I think it also becomes very interesting when we dive into, hey, we can see the telnet. Oh, that Telnet goes to a Cisco switch that everybody forgot about and you can pull the full configuration out of it because it's old, it's antiquated and it's just forgotten. Um, threat actors love to use that as much as we love to identify it. Does that answer the question there?

Speaker A: No, it does. And your example fits perfectly because you get to that old switch and then you have routing configurations and other IPs of key devices, you know, DNS servers, things like that within your infrastructure and you begin to open Pandora's box of what you can get access to. Right, so that's a good example.

Speaker B: Um, sorry. Yeah, I mean, it also becomes interesting not just from the response side, but if we take a proactive approach from a threat hunting side to try to identify things before they're a problem. Um, it's really interesting to go to companies and challenge what their business stance is. If we go to a company and say, hey, when was the last time you did a tech refresh on your core networking stack? A lot of them will say, oh yeah, we've done that in the last five years. But then we'll go look at the network traffic, um, and we can see oh, well, why is this newer switch using Telnet for access to, um, Then it turns out, oh, that stack was forgotten about. From a proactive side as well, we're able to start identifying those things and start challenging. Hey, your expectation was this didn't exist. The packets don't lie. It's right here.

Speaker A: Yeah, no, absolutely. From your experience, and I know you've got a lot of perspective on this, uh, what's harder? Detecting behaviors of active compromise or identifying those quiet misconfigurations and structural weaknesses that really enable them and why.

Speaker B: Yeah, so this will turn into my personal opinion. Um, but I think it's easier to identify misconfigurations because they're more prevalent. Right. The likelihood that there's an active compromise is significantly lower than the likelihood that there's something misconfigured on a massive network of a Fortune 500 company.

Speaker A: Right.

Speaker B: There's just. The scale is massive. Um, so I think from that perspective, you will identify more misconfigurations on the network than nefarious threat actors. But with that said, I think more tends to happen with a threat actor involved than with the mundane. This traffic exists because it's always been that way. Right. It's easier to actually do something with that information and more, I think we see it more commonly something done with that information when there is a threat actor involved.

Speaker A: No, that's a great point. And you're right in the other comment you had. There is the size of some of these environments. Right. It's just so easy for things to get out of date and, um, kind of left unattended in some of these infrastructures. And that's even from my perspective and our perspective, that's even, um, compounding with some of the migrations to cloud workloads because they don't have full grasp of everything in the infrastructure in the cloud. And then they've got legacy systems they're not paying attention to because they're focused on the new stuff. Uh, I think that's an excellent point. If you had to advise, uh, security teams on shifting their mindset, what practical steps should they take to better identify and prioritize enablers and not just behaviors in their threat hunting workflows.

Speaker B: Yeah. So when we get into both response and hunting, at the end of the day it's all about asking and answering questions. So I think the shift needs to be in what questions we're asking, not so much, hey, did somebody break into my car? But if somebody were to break into my car, how would they do it? Well, the door was unlocked and the key was in there. That's important information to know because that might help us answer. Did they break in?

Speaker A: That's a great point. Uh, don't leave the door open and wonder why somebody walked in, right?

Speaker B: Yeah, absolutely. I think if we shift the questions we ask, um, it'll help us identify more of those enablers and ideally if we're asking those questions routinely, hopefully we keep those identifications or artifacts relevant. Ah, in our day to day conversations.

Speaker A: Mhm, that's a great point. So how do uh, enablers influence the way IR teams should interpret and contextualize those indicators to your example of if the car was unlocked? Um, but in other words, how does the why behind a det and CK change the response strategy?

Speaker B: Sure. So every response strategy is going to be a little bit different. Every customer, every company has a different break glass scenario. Um, I think the artifacts start to steer that quite a bit. For example, when we see something like ntlm, um, version one on the network, well, the abilities that that attacker had to gain credentials and laterally move have opened up.

Speaker A: Right.

Speaker B: That door has opened up a little bit. So there's more avenues we need to explore there. Things like pass the hash for example, where if you're using, I don't want to say more secure, but maybe more modern protocols, updated versions of those protocols that are encrypting things and you know, where the skeletons are in terms of misconfigurations, you can see how wide that door is open. Um, if everything's encrypted and you know, hey, they probably couldn't do this technique in our environment, then we're going to change the question to look elsewhere. Right. Maybe it wasn't past the hash, maybe it was some other exploit or technique they use to gain credentials, whether it be phishing, um, some exploit, etc.

Speaker A: Right. Now that's a good point. Is there any sort of interpretation, kind of following on to uh, that is there any sort of interpretation of what the end goal might be based on if they got in with an enabler versus you know, brute forced it way in, I guess is, I mean this

Speaker B: kind of goes back to crime of opportunity, right? If you are spreading ransomware in an environment, your goal is to inflict damage. Now we see a lot with things like ransomware with extortion and stealing data. Well, if you left the door open and they have an easy way to get that data, okay, maybe this is an extortion plus ransomware case. So I think it comes down to what that misconfiguration is what that open door is to try to figure out, okay, maybe they didn't steal this, but could they have stolen it? And if they could steal it, why wouldn't they? Right. Does that kind of make sense?

Speaker A: It does, it does. And I think, uh, that's the hard part. For incident response and threatening teams. Figuring out when enough is enough or when you, when you think you've rooted out the whole issue, I guess, is a better way to put it. Sorry, go ahead. Oh.

Speaker B: From a response perspective, it's very, very rare that we, we find the start and the end of a compromise like, so cleanly. Typically, we find something in the middle that causes some form of alarm. We have to work backwards and forwards to figure out what that timeline is. Those identifying those enablers can help certainly help figure out what that timeline might have been, especially in the early stages.

Speaker A: No, that's a great point. The last individual I interviewed was, uh, really big on the timelining of an incident response, so that was a key point there too. So it's the second time I've heard that here just recently. Um, Cody asking you to kind of look ahead. Um, I always like my guests to give me a prognostication, shall we say, what emerging technologies or architectural trends do you think will create new classes of enablers that defenders need to really start paying attention to now?

Speaker B: Sure. I mean, if we play some buzzword bingo here, we can just rattle off AI and cloud really quick. Um, those are definitely both very prevalent. I think AI being the newest of our buzzword bingo game. Um, cloud certainly existing. It's, you know, everyone's had a shift to cloud for the last five years, and I don't think we've seen that slow down. Um, there's a couple of pieces there with the cloud side. We're still seeing quite a bit of misconfigurations in terms of, hey, I threw this thing in Cloud X and it must be secure, right, Because I can connect to it. Everything's fine, but we're seeing a lot of things. For example, uh, HTTPs port 443, um, we see a lot of connections at the various conferences, both Endase and corelight support together, um, where those connections are intended to be encrypted. We can see that because they use the standard port for HTTPs, but it's all clear text, as in they didn't finish configuring it. So we see a lot of that in cloud. Um, especially with API calls, that's pretty prevalent. We see a lot of applications on phones reaching back to cloud, uh, that are at least partially in the clear. So that's been pretty interesting. I think AI is a phenomenal tool. Um, I'd be lying if I said our technology isn't exploring AI, um, just like every other technology out there is right now. Uh, with that said, I think AI has also created a new era of misconfigurations. We see a lot more people building stuff with AI without necessarily understanding what they're building and then just publishing it, which then feeds the cloud problem of we're deploying things, uh, not fully configured. So that was a really roundabout way of saying. I think the enablers are probably growing more than reducing.

Speaker A: No, I completely agree with you. And the AI front's a multilevel complexity because not only is it, um, opening up some of those doors you talked about, but it's sharing data. Right? Part of the value of AI is in questions and data you share with an engine that now becomes public domain or potentially depending on which AI platform you're using. Uh, I think a lot of people haven't fully grasped that yet and the ramifications of that. So that's an excellent point. Cody. Thank you for taking time. I know you're super busy. Certainly appreciate your expertise, um, and sharing your insights and how to better secure networks. We'd ask our listeners to tune in next time for another edition of the N Days Packet Forensic Files. For more information about ndase's network packet capture platform and our integrations with our fusion technology partners like Corelight, please go to ndays.com Again, Cody, thanks for taking the time. Really appreciate it.

Speaker B: Thank you,

Speaker A: Sam.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Why “Cyber Is Broken”, And Building Trust in an AI World - Karl Van den Bergh CMO IllumioCyber Go-To-Market Talk · on Lateral movement87 / 100
  • Masters of MEDDICC - How To Build A Diverse Winning Team With Josh ReinerMasters of MEDDICC · on Cloud security misconfigurations74 / 100
  • Packetlabs CEO Richard Rogerson on Avoiding RansomwareeWeek eSpeaks · on Lateral movement58 / 100
  • SN 1082: The Malicious Use of AI - Anthropic's Red Team ReportSecurity Now · on Lateral movement44 / 100

More from Secure Networks: Endace Packet Forensics Files

All episodes →
  • Episode 65: Andrew Cook, CTO Recon InfoSec
  • Episode 64: Steve Fink, CTO and CISO at Secure Yeti
  • Episode 63: Jack Chan, VP of Product and Field CTO at Fortinet
  • Episode 62: Jessica (Bair) Oppenheimer, Cisco's Director of Security Operations
  • Episode 61: Jean-Pierre Bergeaux - Federal CTO, GuidePoint Security
Explore the best B2B Engineering & DevTools podcasts →
All Secure Networks: Endace Packet Forensics Files episodes →