The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/SOC Unlocked: Tales from the Cybersecurity Frontline
SOC Unlocked: Tales from the Cybersecurity Frontline artwork

Rethinking Threat Intelligence in an Agentic AI World with Piotr Wojtyla

SOC Unlocked: Tales from the Cybersecurity Frontline · 2025-12-30 · 55 min

0:00--:--

Key moments - from our scoring

Substance score

60 / 100

Five dimensions, 20 points each

Insight Density13 / 20
Originality11 / 20
Guest Caliber14 / 20
Specificity & Evidence10 / 20
Conversational Craft12 / 20

Piotr Wojtyla brings a hybrid approach to threat intelligence at Abnormal AI, merging traditional known-bad indicator-based intelligence with behavioral anomaly detection powered by machine learning and LLMs. Rather than solely chasing indicators of compromise like malware hashes and bad IP addresses, Abnormal's platform establishes baselines of normal user behavior - understanding who typically communicates with whom, typical email patterns, and routine workflows - then flags deviations as potentially malicious. Wojtyla contrasts this with legacy approaches: where a SOC analyst historically enriched alerts against threat intelligence feeds to determine if an indicator was known-bad, Abnormal's non-good modeling surfaces behavioral anomalies first, then intelligence enrichment validates whether that anomaly correlates to known threat actors, tools, or techniques. This shift from linear (data → model → decision) to circular (data → model → LLM reasoning → model refinement → decision) processes has matured alongside cloud adoption, verbose logging, and cheaper compute. Wojtyla draws parallels to the evolution of network detection rules (Snort, Zeek) that could work on structured firewall logs but failed in unstructured application logs - until ML made sense of them at scale. The discussion includes war stories from his time at CrowdStrike's threat hunting team and incident response work, including cases involving Chinese nation-state actors and complex breach investigations spanning multiple acquired companies.

Key takeaways

  • →Combining known-bad threat intelligence signals with known-good behavioral baselines and ML models allows more nuanced detection than signature-based approaches alone, detecting threats even when tools and techniques are novel.
  • →Behavioral anomaly detection powered by machine learning can now work on previously intractable unstructured application logs, enabling SOCs to detect abnormal activity at scale where hand-written rules would fail.
  • →LLMs acting as reasoning layers on top of ML models in a feedback loop enable iterative refinement and deeper analysis than single-stage detection pipelines, improving decision quality over time.
  • →Threat intelligence teams embedded across both internal security and product R&D, rather than siloed in one function, can ensure threat intelligence principles are baked into AI products from design.
  • →Simple attacks can cause massive business impact - file-renaming malware without actual encryption caused more operational damage than sophisticated attacks, and false assumptions about what constitutes ransomware can trigger costly and unnecessary isolation decisions.

In this episode

  1. 1Threat Intelligence Role at Abnormal AI and Hybrid Approach
  2. 2Merging Known Bad and Known Good Modeling with AI
  3. 3Behavioral Attribution and Non-Good Anomaly Detection
  4. 4Evolution from Network Rules to Machine Learning and LLMs
  5. 5Hospital Ransomware Investigation: The Old Virus False Alarm
  6. 6Nation State Attribution Cases and CrowdStrike Threat Intel Work
  7. 7Ransomware Evolution and Tabletop Exercise Predictions
  8. 8Chinese Nation State Incident Response Investigations

Mentioned

Abnormal AICrowdStrikePiotr WojtylaMick Leach

Guests

Piotr Wojtyla

Topics in this episode

CrowdStrikeLarge Language Models (LLMs)Incident responseAbnormal AIemail securityThreat IntelligenceBehavioral anomaly detectionKnown-good modelingMachine learning and anomaly detectionNation-state attribution

Questions this episode answers

How does known-good behavioral modeling differ from traditional threat intelligence approaches to detection?

Traditional threat intelligence focuses on known-bad indicators (malware hashes, bad IPs, C2 domains) that SOCs enrich in alerts to determine if something is malicious; known-good modeling instead establishes baselines of normal user behavior (who talks to whom, typical email patterns) and flags anything outside that norm, then enriches with intelligence to confirm if the anomaly correlates to known threat actors or techniques.

Why does Abnormal use both known-bad and known-good modeling together rather than just one approach?

Combining the two approaches enables more nuanced detection: known-good behavior surfaces anomalies that might indicate novel threats, while known-bad intelligence confirms whether those anomalies correlate to specific threat actors, tools, or techniques, making the models more accurate and context-aware - for example, IT staff sending ScreenConnect is normal, but finance staff pretending it's a Teams invitation is not.

What role do LLMs play in Abnormal's threat detection platform?

LLMs act as a reasoning layer on top of ML models in a circular feedback loop, allowing the models to understand and derive deeper insights from data, inform necessary model changes based on new context, and perform more detailed analysis through multiple iterations rather than a single linear detection decision.

What happened in the hospital ransomware incident that turned out not to be ransomware?

A hospital's systems started showing file extension changes and took themselves offline for nearly three days, but investigation revealed it was a legacy 1980s virus from a network share that simply renamed files without encrypting them - the old antivirus had been blocking it, but when the AV was removed during an EDR upgrade, the virus spread, creating the appearance of ransomware without actual encryption or harm.

How did Piotr attribute a breach across three independent companies to Chinese nation-state actors?

When investigating a breach of an organization that had been acquired and sold off years earlier, he found malware and indicators attributed to Chinese nation-state APTs on the original company's domain controller; by cross-referencing infrastructure connections in the other independent entities that the original company had previously owned, he pieced together a holistic intrusion story across three separate networks and confirmed the same state-sponsored group had compromised all of them.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

13 / 20

The episode contains some substantive technical insights, particularly around the known-good vs. known-bad threat intelligence paradigm and behavioral anomaly detection models. However, much of the discussion devolves into anecdotal storytelling and generalized commentary about AI buzzwords. The signal-to-noise ratio deteriorates significantly in the second half, with extended narrative digressions that lack actionable takeaways for practitioners.

marrying the two of those worlds between the known bad modeling that threat intelligence brings and the non good modeling really allows us to kind of bring that together
AI is not going to replace jobs. Smart people with AI are going to replace some jobs, but AI itself is not going to replace jobs

Originality

11 / 20

While the known-good behavioral modeling framework is reasonably fresh, much of the discussion recycles familiar themes: AI skepticism toward vendor claims, the value of open-source tools over expensive commercial products, and nation-state sophistication. The North Korean remote worker angle is more novel but treated primarily as anecdote rather than analytical framework. The conversation lacks contrarian takes or first-principles deconstruction of established security paradigms.

don't be afraid to ask difficult questions and challenge any sort of AI capability inside of the product because there's a number of examples of products and companies that claim to do AI
smart people with AI are going to replace some jobs, but AI itself is not going to replace jobs

Guest Caliber

14 / 20

Piotr Wojtyla holds a credible threat intelligence leadership position at Abnormal AI and has relevant prior experience at CrowdStrike in incident response and threat hunting. His portfolio of hands-on investigations (nation-state attributions, memory forensics, IR operations) demonstrates legitimate practitioner depth. However, he functions somewhat as a company spokesperson discussing Abnormal's product philosophy, which slightly dilutes pure operator credibility.

I'm working for Abnormal AI. I'm the head of Fred into and platform
I used to work at Crosstrike and this is one of their threat hunting team, hands down is probably the best in the world

Specificity & Evidence

10 / 20

The episode severely lacks concrete data points, metrics, or named organizations (aside from CrowdStrike, Abnormal, and vague references to a hospital). Stories are told with dramatic flair but minimal specifics - no timelines provided for investigations, no quantified impact numbers, no specific malware hashes or IOCs, no customer statistics. The North Korean remote worker discussion references 'three or four' jobs per individual but provides no broader dataset. Claims about AI adoption rates are asserted without supporting evidence.

they used to work with some phenomenal people. There's a bunch of stories that are not only my stories, they're just stories from being in the trenches
there were other connections to that, to the infrastructure associated with the Chinese nation state

Conversational Craft

12 / 20

The host asks reasonable opening questions and demonstrates genuine enthusiasm, but rarely probes deeply into claims or requests concrete examples. When Piotr offers anecdotes, Mick responds with personal parallels rather than follow-up queries. The 'main takeaway' segment at the end accepts a platitude about AI enablement without challenging its specificity. The conversation reads more as two practitioners bonding over war stories than as rigorous interrogation of substantive claims. Softball moments like the threat actor naming tangent consume airtime without advancing learning.

Can you tell us some stories or you know, an example of something you've come across in your threat intel hunts where maybe you got to the attribution
I was like, okay, like, walk me through that

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker B68%
  • Speaker A32%

Most-used words

threat29point23security19back17team17tools17specific15cool15network15jobs15intelligence14data14different13extremely13started13nation13

Episode notes

Threat intelligence leader Piotr Wojtyla joins host Mick Leach on the latest episode of SOC Unlocked to unpack how AI, behavioral modeling, and threat intelligence are converging to reshape modern security operations. Drawing from years in incident response and nation-state investigations, Piotr explains why combining known-good behavior with known-bad intelligence is critical to detecting today’s most evasive threats. Together, Mick and Piotr explore how machine learning and LLMs are transforming the SOC from a linear alert factory into a feedback-driven decision engine - while also exposing new risks, from remote insider scams to agentic AI and SaaS token abuse. The conversation blends war stories, practical lessons, and forward-looking insight, underscoring a central theme: AI can elevate defenders dramatically, but strong security still depends on human judgment, curiosity, and fundamentals done right.

Full transcript

55 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Foreign. Hello and welcome to SOC Unlocked Tales from the cybersecurity front line. I'm Mick Leach, your host and guide on this exciting journey into the SOC universe. Of course. In each episode I chat with various cybersecurity professionals about the latest in industry news, emerging threats, practical strategies to keep your organization safe, and much more. And this week I am really excited to have a dear friend and colleague here at Abnormal piot. Piyo, welcome to the show.

Speaker B: Thank you. It's so great to be here.

Speaker A: Yeah, absolutely. So, piyot, can you tell us a little bit about your current role and how it shapes your organization's security strategy?

Speaker B: Absolutely. So, um, I'm currently a, uh, my role is, uh, I'm working for Abnormal AI. I'm the head of Fred into and platform. So it's a very interesting mix because usually threat intelligence teams are somehow embedded inside of the, um, internal security teams, um, or they're somehow embedded into the R and D side of the house, where it's kind of behind the product. Uh, for me it's a bit of a mix, so it's a hybrid of both. So I support both the internal security program under our CAO here as well as work very closely and partner very closely with the product R and D teams and pretty much make sure that everything that abnormal does, by definition also has the threat intelligence embedded in that. And as we do a lot of stuff with AI, that is a very interesting intersection, uh, because by definition kind of threat intelligence has been very human led, I think, and very, very, uh, known bad trip. So the principle behind it is like, you know, that there's something bad about a technique, tool, threat actor, and you kind of take that and you do research and you understand more about the campaign, cluster product, et cetera, et cetera. And Abnormal, on the other hand, is very focused on the principle of non good. So non good modeling and then looking for anything that is outside of the norm is more what our models and products and AI capabilities are focusing on. So marrying the two of those worlds between the known bad modeling that threat intelligence brings and the non good modeling really allows us to kind of bring that together and elevate, uh, the ability to deck what fractures do on a daily basis in everything that we do.

Speaker A: That is awesome. I love that approach. Um, I'm intrigued, candidly in terms of known good, um, to your point, I've done threat intelligence for a long time being, uh, SOC leader and those kinds of things we work very closely with in using threat intel. But again, to your point, that's Always been sort of defining what evil look like and then trying to find that definition in, in our logs, whether that's hash value or reputation, uh, these kinds of things, right? A bad IP address, those kinds of things. So I'm, I'm, I'm intrigued how that's done in terms of defining known good in the threat actor space. So what does that look like?

Speaker B: Yeah, so to your point, and it's actually a really good point, right? Like, I think like from a, ah, from a security operations center standpoint, you know, stock analyst, um, standpoint very often intelligence is more focused around specific indicators and as you triage the alerts, as you see the activity, you try to seek enrichment and intelligence, um, to make decision whether something that you see is good or bad. Um, and you know, that could be in the form of a, of a simple enrichment that could be in the form of a report that could be in, in the form of like seeing that this indicator is correlated, is correlated to another indicator. I think where we kind of marry those two worlds together is that on the product and abnormal specific side, the modeling of nongood really comes down to the behavior, uh, and understanding the behavior. So if for instance we have um, I like to say that from the attribution standpoint, what abnormal does from a product and non good standpoint is really understanding that like hey, a user, Bob in finance, this is the typical behavior and typical baseline for that user in terms of email communication, who they speak to, who they talk to, et cetera, et cetera. And then the ultimate attribution in that space comes down to like, hey, email from Sarah to Bob is not, is not normal. It's um, abnormal. Therefore we should kind of look at it and do something about that. From intelligence standpoint, attribution is a lot more about like, okay, I have a hash, that hash is associated with a malware file. That malware file has a specific fingerprint that I can then attribute to a, to a specific thread group. And I know that every time I see this tool, this is associated with this thread group. So if we marry those two worlds, if I, if we're able to pretty much surface up that, hey, for the, for the behavior specific individual, there's something abnormal about this behavior. Uh, that pretty much gives us a bit of a, huh, there's something here for us to look at. And then that ultimately allows us to then pretty much bring the insights from, from the, from the intelligence world to be like, okay, cool. Is there something about this that is associated with any of the known bad, um, Signals that we know about. And then we can kind of like pretty much combine the two to then allow our models to make a better determination about is dad associated with specific thread, a specific tool, specific technique, et cetera. And ultimately it's really about helping the models to become a lot more nuanced and how they make determination. Because for instance, me sending you an email with a screen connect attached to it, if I'm your IT support person, that's going to be okay. Me being, you know, a finance person trying to send you a screen connect, pretending to be an invitation to a teams call, probably not, right? So it's kind of an example of what we can marry those two and really understand the behavior and the intent behind the behavior in a lot better, a lot deeper in a. Sorry, I'm, um, missing words here. We can understand it on a much deeper level.

Speaker A: Gotcha. Gotcha. I love this because it reminds me of kind of the old days of ndr, network detection and response. Do you remember these days, like back in the old snort days, when we would write these rules that would define activity in our network firewall, uh, logs or network logs, and say, I want you to spot anomalous activity in terms of volume, in terms of port usage, these kinds of things. And then later with like bro, which became Zeke, um, you know, we were doing much the same thing, but we couldn't. You couldn't really do that outside of the network space because none of the other logging that we had available to us in our applications was as rigidly defined as network logs. Right. Or firewall logs. Those were so well, uh, defined, defined. And we knew exactly what data was contained in what fields that we could write, those kinds of rules. You could never do that in the application space until just recently. Right. Because the logging was application logging. Goodness gracious. Every vendor could write it however they wanted and then they would routinely move things around within their logs. Right. You would spend all this time writing, you know, a SIM rule or whatever, looking for X period of, you know, X amount of data in this field, only to find that they shifted it and now that value is in a different field and it broke the. Broke, you know, broke the, uh, the SIM rule. Man, it used to drive me crazy. But now to your point with, uh, now that machine learning has kind of grown up and matured, compute, uh, got a little bit cheaper, storage is cheap now we can suddenly throw these kinds of application logs, completely unstructured application logs, into a machine learning model and go, hey, baseline this and tell me when you see Something unusual. And again, that's so cool.

Speaker B: Yeah, it really is. And then you, in addition, even to uh, what you, what you described, then we have the entire world of LLMs that can kind of act as the layer on top of, to really help with the decision process and understanding and deriving even more understanding. And then that instrument the models to, you know, perform even more, um, detailed, you know, analysis of what is happening. So it's not really about like a single flow of like, okay, from data to model to decision, end of the process. It becomes a lot more of a, like a, of a, of a, of a circle. Right, in which we can be like, hey, data model, maybe some sort of LLN that can actually inform the models about the changes that needs to happen. And then that ultimately kind of like, you know, free through multiple iterations leads to a much better decision at uh, the end of the day. So that shift from kind of linear to more circular, um, process definitely made a big change at what is available. And obviously with the adoption of cloud and SaaS and the verbosity of the log, there's so much data that obviously for human to be able to vet that data, there's gotta be a better way.

Speaker A: Yeah, it's like living in the future. Man, this is so cool. Um, but it occurs to me with your role, uh, in threat intel, and this isn't your first role in threat intel. That's not how you get to be ahead of threat intel first timer. Uh, so you've done this kind of work for a good period of time. So what I know about that is you have to have some stories, right? You have to have come across some things. Can, can you. And I don't want to get anybody in trouble. No one wants to go to jail or get sued, um, most of all me. So, so protecting the names of the innocent, uh, and worse yet, the, the guilty. Can you tell us some stories or you know, an example of something you, you've come across in, in your threat intel hunts where maybe you got to the attribution, maybe you've pinned it down to a threat actor and what happened?

Speaker B: Yeah, well, um, I think there's uh, I don't want to say like, oh, there's so many, but, uh, I think I was really, um, I used to work with some phenomenal people. Um, you know, I used to work with some. I work both on the instant response teams, I work on the threat hunting teams, and I work with threat intelligence teams pretty much in either of those. And then I ultimately became also part of a Threat intelligence team and threat research team at a later stage of my career. So, uh, between that I was extremely lucky work with phenomenal and extremely smart folks. Um, and there's a bunch of stories that are not only my stories, they're just stories from being in the trenches with those folks. Um, um, so yeah, there's a number of different examples comes to mind. But it's kind of from silly stories to really, really cool stories. So I can give you an example of a super silly story, uh, from one of our engagements is you know how in the world of ransomware people have this tendency like, oh, pull the plug, pull the plug. You need to pull the plug so you can like kind of limit the, isolate the network. And we were, we were one time, um, engaged by a big hospital, um, uh, in the US and we were on the run somewhere where like our security folks pulled the plug. You know, we're completely shut down. It was I think 24 hours in and we came in, we started investigating and you know, I just don't see the obvious ransomware stuff like, you know, just going for this, going to the patient zero where they did. The person apparently saw that the files on the desktop started changing their name. So the files got, you know, the reason why they pulled the plug is that the files on the, on the desktop started changing the extensions and like the files started being changed to different names. So I was like, okay. So we started looking into that and then that system, there was no, no ransomware indication, but the origin of that activity actually happened from a network share. So we went into the network share, we investigated that and it turns out that the TLD adversaries, it wasn't ransomware. It was an old timer, an old virus that was just doing the simple change of the file names. But the funny thing about that is that they used to have an old legacy AV tool in place. And that legacy AV could not remove the virus from the network share, but it was able to block it from spreading. But then they were undergoing the project of replacing the AV and bringing the EDR in. And once they ripped the AV out, that's when the file, you know what, where there was no block in place. So it started just like mutating the files and it wasn't encrypting that, it wasn't causing any harm. But the indication of that was the exact same to what people would consider ransomware to be live. So the hospital went down for like two, I think almost three days, uh, because of like simple virus from probably like 1980s that was just living on a network share that no one could remediate. So that was like a, that's like a silly, silly story. But um, uh, the cool. I think one of the. I was really, I think blessed in many ways that I got to work on a lot of nation state cases, uh, whether it was Russian nation states or Chinese nation states. And I think like, it's one of the cool stories that I can share is that like, um, um, we were involved in an investigation from an old breach, let's say it was four or five years after. And the organization that was initially targeted actually sold a number of companies. So they were independent companies. But because four years ago they were connected, all of those companies were actually breached. So we went in and we started investigating the first case and it was like, oh, you know, we see this thing originating from this system and we were like, oh, this is not our. This used to be our domain controller that connected to this, this thing. I was like, oh, that's interesting. And then we started like pretty much seeing indication of specific malware incline that was attributed to Chinese, uh, Chinese nation state and specific indicators. And through research we actually identified that there were other connections to that, to the, to, to, to the infrastructure associated with the, with the Chinese nation state that were coming from those other organizations. So pretty much we had to go and be like, hey, remember the company that used to own you? Like you know, own you, uh, four years ago they actually owned you, so now we have to come and help you. Uh, so it was kind of like a mix of like going like each new entity and kind of working with them through and pretty much piecing together the intrusion like four or five years after from three separate networks with three independent entities to kind of one holistic story. So it's just, it's just like a bit of a twist on a typical ir. But um, yeah, I think like, because we had a very extensive threat intelligence team, um, I used to work at Crosstrike and this is one of their threat hunting team, hands down is probably the best in the world. Their threat intelligence team is top notch. Um, I think that there was so much richness of information that allowed us to make determination about whether that was associated with redactor X or Y or Nation State ADC, whatever. The famous DNC case, 2016. Not to get into politics. I think it's publicly known that Kravitz was involved in response to that. So there was a lot behind the scenes that, you know, that, that allowed people to make determination why that was attributed back to Russian nation states. So a lot of those cases were extremely cool. And even being partially involved, those, it was, it was like the, you know, one of the little highlights of my career.

Speaker A: That is so cool. That's so cool. So, uh, first my question is, did you ever get to weigh in because you were part of the threat intel team at CrowdStrike, did you ever get to weigh in on the naming?

Speaker B: No.

Speaker A: Do you lay claim to any of those scattered spider like fancy Panda, like.

Speaker B: No. No, unfortunately not. So, uh, uh, I do believe if I remember correctly, uh, uh, and maybe my, some of my crossword friends can, can. Can correct me, but I do do, do remember that the person who actually, you know, discovers the, the, the, the, the. The actor gets to name the, the actor. Uh, uh, so, uh, so yeah, I, I didn't get a, I didn't get a chance to. I don't have the privilege of doing that.

Speaker A: Uh, ah, that's that. Because I would just want to know which one did you pick? Right. Fancy Bear. There's, there's lots of really good ones.

Speaker B: I don't think I would be allowed to pick one because it'll be stupid probably, you know, Pierogi Panda to be like a Polish Polish team. That would be like, no, go away. I love it.

Speaker A: I love it. Piot got banned from naming things at CrowdStrike. Um, no. It's funny, the silly one that you mentioned at the beginning, uh, actually hit really close to home for me. I, At a previous company we had a similar case where uh, we had, we had a laptop that got struck by ransomware. This was a similar ransomware in that the irony was that it actually didn't actually encrypt anything. It did change the name to like a, like a dot ENC or something along those lines. Um, that made you believe that it was encrypted. But the, the files themselves weren't actually encrypted, they just were renamed. So it was like a simple rename script. But the problem was it hit that box and that box had mounted a file share as an actual like lettered drive. And it followed that, that, you know, that that file share, that, that uh, mount point to the file share and then proceeded to not encrypt but, but rename hundreds of thousands of critical business files and broke a ton of things. And we all were like, well, I mean there's good news. It's not actually encrypting anything. What we learned the bad news was just a simple rename script, right? Just in Python that would simply rename the files to what they used to be named, was easier to write than restoring the files from backup. And yet that took so long. It was like 32 hours to run to actually complete its job. So we, even though nothing was actually encrypted, it still caused 32 hours worth of impact. Uh, and we, we were there for something like 54 hours nonstop, like, straight working through the incident. So, um, also kind of silly and yet devastatingly impactful. For as silly as it was, it's silly.

Speaker B: And it's not silly because when you get to that point of, like, actually having a conversation with the decision makers about what happened, you know, know, they made a decision to, like, you know, hold the network down, to isolate systems. They were not operational. Obviously, it's a hospital. Like, there's patients, people, lies at, you know, at, at risk potentially. There's a lot of complication to that. And then you get to have that conversation with the decision maker and you explain the silly part. And no one is laughing, right? No one is not at that moment. They're not sad that we spent X amount of money on this and all this stuff. It's, It's a, It's. It's a very awkward conversation to have. Right. Um, and there's no playbook to it. Like, you can't blame the employee either. Right. Like, to the extent of their knowledge, they did the best that they fought with the data that was presented to them. Uh, and with this, you know, ransomware everywhere, it's easy to just, you know, to be paranoid. Um, so, yeah, I absolutely hear you. Like, it's a funny story to share, uh, in this kind of situation, but when you're actually involved in that and you have to deal with it, it's not as silly as it sounds.

Speaker A: Uh, yeah, because that was kind of the funny part. We had a great EDR in place. And because it wasn't actually trying to encrypt anything, all it was doing is renaming files. That, that wasn't in and of itself like a malicious activity. So the EDR didn't care. And yet it still caused havoc from, uh, a business operations perspective. So it was just a mess. And to your point, right, we, we kind of chuckled like, good news, it's not actually ransomware. Like, okay, it kind of. They were trying to hold us for ransom, but nothing was encrypted. So we're all right. We still have all the data. Uh, we just got to rename it all back. It just. Nobody realized just how painful that was, that process was going to be crazy, crazy stuff.

Speaker B: You know what? It's like, another thing that you just kind of reminded me is that, um, back by, back when, you know, when I was so part of the user response team and we used to do tabletop exercises, uh, one of, one of the scenarios that, like, Framework was created, um, by the team was like, hey, you're being ransomed and someone exfiltrated your data and now is like, trying to extort you. And back in the day, that wasn't at all what was going on. You had like, a simple dropper coming from some sort of exploit kit on a single system, encrypting that system. It was annoying. But that was ransomware back in the day. Yes. That evolve more into, like, for access, being like, hey, I can actually compromise. You move around, go to the domain controller and then deploy around somewhere. And that's probably going to, you know, cost you a lot more, and you're going to be a lot more inclined to actually pay me the ransom. And then someone had this amazing idea of like, you know, what, what if we take their data first and then we're going to actually tell them, like, hey, we're going to release the data until you pay us, whether we run some you or not. That's kind of like a secondary thing, but we'll see. But the funny thing is that, like, we used to run those tabletops, like, you know, years before that became a thing, and then that became a thing, and it was kind of like, oh, maybe we'll just stop making those scenarios up because, like, you know, they became a thing. So just kind of like it. I'm not claiming I was one of, uh, I'm not trying to claim that. I, I, I invented that. It was like another team that was. But I remember kind of hearing those jolts. I was like, you know what? Maybe you should stop. Maybe you should.

Speaker A: Yeah, yeah, let's stop coming up with new and interesting ways to, that you could be hacked. Because bad guys must be listening because they immediately do the thing we just came up with. Maybe we should stop coming up with ideas. Maybe that'll actually stop them. Oh, my goodness. So that's, that is wild. Um, any more crazy stories worth sharing? I, I don't want to, you know, move on before. This is my favorite part, to be honest.

Speaker B: I feel like I, I don't have a good way to say, but I feel like I had a, in some, in some way I attracted, you know, Chinese nation states. Uh, and I, I got, I, I somehow was involved and Then it turns out to be nation state. Like my entire career pretty much started with a Chinese nation state compromising network and me randomly investigating that. Um, just because it, you know, a, uh, it's actually a funny story. Like we were building completely new capability. Um, we had no tools, nothing. We were just kind of, hey, we're going to build a computer security incident response team. Let's just do it. And we had no budget, no tools. We were just kind of figuring things out. And it was Friday and it was afternoon and I got a phone call from a random IT admin in Turkey. And he's like, I see a service on my Windows server that I don't recognize and 9 out of 10 people probably on Friday afternoon be like, I have more important things to do. Just kind of like, buy cool, you know, go investigate, whatever. Um, but I asked him for, I asked him for, like, hey, can you, you know, I was actually studying for, for volatility. Uh, you know, the volatility authors, they love volatility. Look, I was like, you know what? Like, I would actually love to have some practical like snapshots I can play with. So I was like, hey, can you dump me the image of that systems. I have memory because it was a virtual machine. So just, just dump me the, the, the, the state of the machine. I'll be able to investigate it. And he sent it to me and I was just. Literally had my book on my desk and I was looking at, I'm going to run this command, I'm going to run this command. And then I think it's the chapter about the backdoors, like the kernel level backdoors. And there's a command there that pretty much just enumerates different drivers and whether they're hooked or not. Run this command. And I looked into the book and the book says if you see this output, it means that there's this specific backdoor installed on it. And I looked at my screen, I was like, this output looks like this thing in the book. No, there's no way, right? It was so, so kind of like, there's no way. But I started looking more and more into this. Like, okay, that was an actual thing. And uh, it turns out that it was an entry point pretty much like all six servers with an entry point into a massive network of the service provider and then to a conglomerate, to a global conglomerate that they were actually after, right? So they used like the IT provider to get out, go after the organization they wanted. But the funny thing about that was that we had no Tools, no budget. We had volatility and like six images that we asked for and we still had more findings than the entire security team of the company that was actually targeted and affected. And there was like a 30 people's team with all the tools, end cases, X ways, whatever. And I remember that just being like one of those moments was like, you know what, there's power to open source, there's power to sharing, there's power to knowledge sharing and people sharing those stories, uh, because that ultimately can help someone down the line. So I really don't mind sharing fun stories and ways and tools and things like that because I was on the receiving end of that. And that pretty much started my career into Freddie intel, instant response threat hunting. Because from that investigation I was just like, I just want to do this all the time.

Speaker A: Yeah.

Speaker B: So yeah, a little bit of an origin story for you.

Speaker A: Yeah, no, that's fantastic. I love it. Also, uh, massive fan of volatility. Used uh, it in some saints courses and, and uh, then beyond of course. Um, but it reminds me, uh, we, some friends and I used to go round and round, you know, at a bar over beers or whatever about this very topic because we would see these um, these big companies that we were, we were friends with guys over there and they would have these super cool tools, right? They cost millions of dollars and we were super jealous and we, and I remember we would go back and forth about yeah, but if you, if all you know how to do is make that tool do its thing, but you don't actually understand what's happening under the covers, like do you really know how to do security? Like do you know forensics? If all you can do is make a case, uh, do its thing, right. Maybe not.

Speaker B: Ah.

Speaker A: And that's because the reality is, and this is where we would, we would go back and forth and say the tools will let you down at some point, right? You're not going to have uh, the agent running on the right system at the right time or whatever. It's on a test system that somehow gets brought into scope of the attack and it doesn't have the tooling we're used to having now you're left with open source tools or things that are easily um, available off the shelf and you've got it, you've got to just figure it out. You, you know, now it's just you and a terminal prompt figure it out. And that's where you really see kind of who, the difference between capabilities or skills and uh, pardon me. And that's what was for me so fun about doing those kinds of things, um, is because there, there was and still are, I think even more today available open source capabilities that, that can really help you, um, you know, understand what's going on in, in an environment, whether that's a system or within a network environment.

Speaker B: Yeah, 100%. And I think you're touching on something extremely important that uh, um, I had, I had my own number of conversations over beers with my friends about it. But uh, to your point, like I, I never, I, I didn't grow up with, you know, X ways and case. I did kind of forensics the hard way by looking at hex editor or pretty much using a simple script line, tools to go and pull maybe something from Registry and then trying to understand what I'm actually looking at. And ultimately I found that this was like, this was really extremely helpful because I pretty much developed this um, set of skills that were not bound to specific tools. I would have 5, 10, 15 different tools that I could achieve the same objective with and then depending on the use case, I could apply, you know, whatever I needed for the situation that I was handling in that given moment. So that gave me a lot of flexibility. Uh, and to your point, like some tools will misparse the data. They will not tell you when they error out. They will, you know, they might, they will produce an output and they will not really give you the information they need. And it's, if your trust is in that output or what that tool is giving you, you're going to miss some stuff. Um, so yeah, being able to like have alternatives, being able to first, first and foremost to your point, I think like the most important point is like really understanding how the tool and what the tool is doing so you can actually do that yourself and then leveraging the tool more for the automation of it and really being able to like, so you don't have to repeat the boring manual task. That's how you want to think about the problem and not just approach it in place. Like I need a tool and then whatever tool is telling me that's what I'm going to apply. The backdoor is then pretty much the simplest backdoors in SSH. Like the back in the day from the 80s when you have a backdoor inside of the SSH statement that would just hide an inbound connection is a perfect example of that. Right? If you trust the binary that is going to tell you something, there's a way attackers can hide activity from you. And if that's your only way to think about this, then you probably will have some problems down the line.

Speaker A: Yeah, I couldn't agree more. Uh, that's also partially why I really like Sans. This is going to sound like some sort of commercial for them. It's not. But um, but, but what I loved about them is the training that they did is most of the tools that we were leveraging in those courses were open source tools. Right. They were written by either instructors or other students who were encouraged, uh, by like Chad, uh, Chad Tilbury, uh, amazing um, instructor for them. But one of the things he did was say guys, here are things that aren't well solved today. And he would like challenge every class. Well, every four or five classes there's going to be a developer, like a closet developer in there who's actually quite good, who goes, I'll tackle that. And then they build it and then you know, a couple of weeks later you got something worth testing and uh, and you're playing with those things. But even like the beaconing behaviors that you were seeing, right, Like John Strand and then the team over at Black Hills Information Security, you know, I remember when he wrote RITA and was able to capture like beaconing behaviors for the first time that at least that I was able to find, um, using the tools that he was building. Just super, super cool stuff. I love the innovation, I love the community, um, particularly in the digital forensic side of things because it's so much more tight knit because the, the mission focus is very, very linear, uh, and well defined. So the cool things that are being built in open source today just ah, awesome. Super cool. Especially with the advent of AI and bringing AI and LLMs into, you know, into the mix.

Speaker B: It's so much m. It's so funny you mentioned that like if Chad is ever listening to this, like sending all the love because Chad was actually the, it was my first uh, Crosstrek recruiter. So he, Chad was the first. No way spoke to when, when I was interviewing. Yeah. And he was also one of the big reasons I was like I, I think I'm actually gonna be serious about this. I was like, you know, if he's there, I want to be there. Uh, yeah, they have a, they have a phenomenal group of, of. Of teachers, people who brought in their life to, to research and then really educating, you know, the next generation really of, of security analysts. When you think about it, pretty much everyone in the soc IR teams, they probably either used their training or went to their training. So, so they, they pretty much educated a generation of, of. Of the Next responders in soc. So yeah, kudos to that entire team.

Speaker A: Yeah. Because I'm one of them. Uh, you know, and it sounds like you are as well. So I mean that's, that's super cool. Uh, okay, well it's, we got to move on to more, more, you know, other things. I don't know, there's more interesting things but uh, but, but other areas. Otherwise uh, I'd stay here forever. Um, so, so what's maybe some of the most common misconceptions that you hear about AI in cybersecurity?

Speaker B: Um, that's a good question. I think there's, there's probably two things. Uh, the, the, the two biggest things. One is that AI is going to replace jobs.

Speaker A: Mhm.

Speaker B: Um, especially like for, for SOC analysts or you know, for, for security operation centers, autonomous centers, whatever you want to call it, you know, self driving cars in soc. Uh, but uh, I don't, I don't believe that's going to be the case. AI. I think smart people with AI are going to replace some jobs, but AI itself is not going to replace jobs. So to any SOC analyst there, even the L1s were like being fearful of the new world that we're stepping into. Ah, I don't think that's going to be the case and I can expand on that even more. But I'm just going to kind of put a pin on this for now. The second thing that um, when it comes to know AI based um, uh, kind of misleading statements in, in cyber, it became a buzzword. Right. So a lot of organizations claim to be a native. That is my personal favorite now. Like everyone used to be doing machine learning. Like that was a thing and now everyone is AI native. And that's, that's, you know, like with every other buzzword, marketing, whatever, like that's what people are going to do. Uh, I do believe there's a very, there's not a lot of. Let me, let me, let me rephrase that. The percentage of companies that are a native is very small. Mhm. Uh, the percentage of companies that does ML well is still relatively small. Uh although everyone is going to tell you that they do it. So I think as a, as someone, what is a, what are your security operations center analyst or whether you, some sort of director or decision maker or someone who's even evaluating tools as part of, you know, bigger incentive. Don't uh, be afraid to ask difficult questions and challenge any sort of AI capability inside of the product because there's and I know a number of examples of products and companies that claim to do AI, and they have not even the basic model behind the scenes. So, um, that's where we built a certain level of, hey, we do AI, but not really. And then kind of people get burned by it. Uh, so those are probably the two biggest misconceptions I would call out here. Uh, maybe controversial. Controversial as well. But that's kind of where I feel like we are kind of from an industry standpoint.

Speaker A: Yeah, I mean, so I don't think it's controversial at all. Um, uh, maybe it's just because I agree, uh, I don't think AI is necessarily taking jobs. I think they're going to take, um, some of the work that we've never enjoyed doing to begin with in terms of like collecting log data, uh, bringing everything together, you know, just collecting lots and lots. I, I liked, I heard this, this phrase, machines sift and analysts analyze. Right. Or humans will analyze. That's kind of where we're getting to now. It can it kind of do some triage? Yeah, yeah, I think we're getting close to that. But to your point, I don't think it's really taking jobs. Um, now what I will say in terms of AI being the buzzword. Uh, no, it's not anymore. It's agentic AI. Everything's about agent AI. Agents are everywhere. That's what I keep hearing every. The conferences I go to. But I had to laugh as you were, you were explaining that. Because I was at, um, I was at Black Hat Europe last year and I was walking the floor and I came across an md. Ah, ah. An MDR vendor who shall rename, uh, remain nameless. And they were like, hey, we do AI. You know, we're an AI company. I was like, great, uh, tell me more. And they're like, yeah, it's, uh, you know, it's, it's in everything. I was like, okay, like, walk me through that. And they said, oh, yeah. So, you know, after, after an alert fires and an analyst has completed their investigation, they make a determination and, and uh, you know, everything's basically done. Then we use AI to help write the report. And I was like, yeah, that's not really AI. Like, it's not AI native. That's bolting it onto the side.

Speaker B: Yeah. If there was a word that describes someone doing the Google search, that when they triaged the alert, they Google search the IP and then they got the results. Whatever. The buzzword comes in here. But yeah, uh, I 100% agree.

Speaker A: Oh my gosh. I just had to Let me Google that for you. Like, flashback. As you were. You were talking through that. I mean, yeah, that, that's not analysis. Okay. That's not actual, like, work. Oh, my goodness. It cracks me up. But that, that's the kind of stuff we're seeing today. So. So let me shift gears then and look a little more forward, uh, and ask, like, what new or unexpected threat techniques have surfaced in 2025 that concern you? Like, like you're at the forefront of this in threat intel.

Speaker B: I think there's couple of things that concern me. Um, where do I begin? I'm going to start with my favorite one. And we actually, because we're friends and we talk quite a lot, uh, we talked about it just the other day. Uh, I think what North Koreans brought to the table with the remote it scam is something that concerns me, but not specifically, specifically to what they did as much as, like, the technique that they showcase and the gaps that they, that they showcased in terms of how easy it is to do what they do. And for anyone who might not know the context, because what I'm saying is North Korean actors pretty much exploit the concept of remote workforce. They started pretty much, um, interviewing with companies and getting hired as employees, and then they sit and collect paychecks, and then that pretty much is one way how they can go and fund that money back to, to their, to their government. Uh, so they pretty much became a malicious insider. Uh, the gaps that they expose are very much specific to the hiring process. Right. The lack of any sort of professional or maybe, you know, proper screening, the lack of vetting the documents, and a lot of the basic issues that someone with a fake driving license can pretty much land a job in, you know, big enterprises, uh, in the U.S. so that's, that's a big of a. That's, that's a gap, and that's a problem that's not a, you know, easy problem to solve because it's more of a process problem, not a technological problem. I mean, there's a, there's a bunch of technologies you can use, but at the same time, it sounds like there's a lot more of a process that needs to be improved and people would actually focus on that problem to solve that. But the part that concerns me about that more is that one of the two things that they do is they, they do use deepfakes as part of their interviews. Uh, and those deepfakes are not perfect, but they will get better. And once they get better, it's going to be extremely difficult to spot that you're actually speaking to a deep fake, um, a North Korean actor that will have a perfect English accent, similar to how we used to spot a business email compromise. Because it just didn't line up, uh, with deepfakes. We can still hear accent, we can still hear words. The words don't line up with what you hear and what you see. But that will get better. And when that gets better, that kind of attack surface is going to get extremely interesting. But the other aspect is that North Koreans didn't really use that for majority of it to do anything malicious. Uh, it was more to collect, you know, the funds. But if you think about like nation states leveraging the same approach to get access to networks, systems and organizations of around the world and then be able to from any sort of activity, think about ransomware actors. Why wouldn't ransomware actors now do the same thing? Why wouldn't they get hired and then pretty much ransom you from the inside as a malicious insider? I hope I'm not creating a new scenario here discussing, but that door is quite open. We've heard about Shiny Hunters and others pretty much offering briberies of scattered spider to employees so they would give them access. I do believe that Crow Shack even was affected by that. Know in, in the last month or so when they published it. Like one of the employees actually gave access to their SSO because they were offered some money or whatever. I don't even remember the specific details there, but it was some, some, some, something along the lines of, of um, of that use case of like pretty much bribing your employee. But what if you just start hiring those folks? Right? That's, that's another aspect of that. Like what if that kind of like shift goes this way? So that concerns me because I don't think we solved the problem since North Koreans started doing that. I don't think there's a lot of solutions to that problem just yet on a table. Uh, and that pretty much is an open door to other threat actors to leverage that for completely different purposes. So that's one big thing that concerns me. The other thing that concerns me is, um, I mentioned, I think this couple of months ago that agentic AI is another buzzword. But that kind of brings two different concerns that I have. One, obviously agents will ultimately start performing intrusions and I think Anthropic dropped this phenomenal report. Phenomenal. They had not shared all the details. That's why the industry kind of pushed back on their claims. But they did mention how China's nation state leveraged their models and abuse their models to pretty much operationalize full intrusion life cycle. Uh, it's not really new for us to hear that nation states are leveraging AI. If there was anyone, why wouldn't they? Uh, they're probably the ones who actually innovate. What can we do with that? But being able to use that for an automation in almost like a fully autonomous way or close to autonomous is concerning because once we get to that point, the pace of the intrusion is going to be beyond what we're currently able to detect, prevent and respond to with our traditional approaches. Uh, and then the flip side to that, that the more companies put those agents in and the more we give those agents the ability to perform autonomous decisions without proper controls in place and availability to really maintain the security of those agents, we're kind of opening ourselves up to a very interesting world. Uh, so when it comes to the agentic AI, those are my two concepts there. Uh, and beyond that, I can speak uh, to email side of things and all the things we're seeing there mostly because of what I see at abnormal. But one other thing that I'm going to mention is that I think what attackers do after they get access to the environment and how they get access to the environment, one of the shifts that I think is concerning to me is the supply chain, the third party, um, ultimately the compromises of partners, security vendors and vendors themselves to then attack individuals inside of the organizations. Um, because those are extremely difficult to detect as well. Those trends of we're not really seeing attackers walking away from email, they're still leveraging email as that initial point of access, um, but also that additional focus on integrations, SaaS, applications stealing tokens, walking away more for credential towards token and then leveraging tokens, um, and malicious apps and you know, and any sort of integration between sales applications, that becomes an extremely, extremely interesting problem to solve as well. So there's a number of areas where I don't think we have a good outlier for that just yet. And obviously AI is making it extremely difficult for us to predict where that's going to go and how quickly we're going to get there.

Speaker A: Yeah, I do want to go back for a moment to the North Korean actors that are, um, that are interviewing, applying for and interviewing for roles because, because you and I were just, you alluded to it, but we were just talking about this yesterday on, on a side thing and I was kind of surprised because like many folks, as a security guy, I'm like, oh man. So as soon as they get in, their goals are to, you know, start exfiltrating data or attacking our customers or what, you know, whatever the, the goals are when they get into these. But you, you corrected and said that's actually not it right now. At least tell me more about what the goals are because it's less complicated, it's less malicious necessarily than that, at least for now. What are they trying to do?

Speaker B: Yeah, uh, mostly right now based on what we're seeing, based also on some of the intelligence that is kind of, you know, floating around between different teams and different individuals who are involved in this investigation across many different companies, uh, most of this is really focused on monetizing on that access. So ultimately they're getting those jobs. And when you think about those are AI jobs, engineering jobs, DevOps jobs, those are pretty well paid five figure jobs. So ultimately they get a number of those jobs and then they operate inside of that company by pretty much becoming a normal employee and collecting paychecks. And then that's one of the ways how they can fund uh, and provide actual stream of revenue to uh, to, to the government that is behind this, this, this, this, this entire campaign. And you know, North Koreans had in many different ways how they would fund their operations through cyber intrusions. They've historically been involved in, you know, cryptocurrency, um, hacks. They've been involved in swift hacks and, and really touching the money and being able to fund that money somehow back because that, that the cyber operations has been one of the ways they've been funding pretty, the stability of the government. So that became another way for them to generate a stream of revenue, uh, thanks to the, thanks to the amazing American economy and the businesses that work here to be able to leverage that to bring that money back.

Speaker A: Okay. And so I want to unpack this just a hair more because I was shocked at the other aspect of this. So what I hear you saying is they're getting these jobs to collect the paycheck. So they aren't actually doing the job, they're just collecting the paycheck. Right, but you said no, they're actually doing the job and doing it well. Right.

Speaker B: There's, there's, there's some in, in, in some cases like those, those employees were hired for months. M. Uh, in some cases they were hired for, even, for even longer. So you know, there's, there's some in the one, there's an indication in that, in of itself that like either you hire someone and you never check on them and somehow, you know, they, they managed to float for a year and you just paid them or. Which is probably unlikely to some extent, maybe somewhere, but still unlikely. Um, um, but there's also been some signals that pretty much indicate that like, you know, when, when those situations are being handled, uh, those, those are employees, they actually perform their jobs and they, they do, they do that job, you know, in a, in a decent way to a point that like, you know, they're, they're, they're um, they're being good employees. So it's not as simple as like, I'm just going to get in you, you know, hope I'm gonna stay there for 30 days, collect my first paycheck and, and run away. Um, but if you think about the scale of it, like if they get 3, 4, 5, we see the same individual getting like, you know, being hired by maybe three or four different organizations. That starts adding up.

Speaker A: Yeah, good point. And, and you had mentioned, uh, specifically that when, uh, at least for some companies, that we had observed some unusual behavior, reached out to companies and said, hey, we, we, we want to let you know we feel like there may be something amiss with one of your workers. And like the, the managers, when they were, when they were like, oh, yeah, it turns out that's North Korean actor. We actually have to fire that person. They were like, disappointed because that person was one of the best performers on their team. Is that, can you tell me more about that?

Speaker B: It's, it's, you know, it's like the,

Speaker A: the,

Speaker B: the part that I think is worth highlighting really is the fact that when we don't know exactly how they structured that on their site, we can have some suggestions and suspicions. I don't personally think that the people who are interviewing are uh, the same people who are then performing the actual jobs and tasks. So when you think about the capabilities of some of the operators, uh, who perform intrusions, if it happens that those will be the same individuals who are then becoming engineers within your environment, I would think that their skill set is extremely high. So the value that they can provide to those organizations is probably also pretty good. And therefore the people that they report to probably are really happy about the, uh, value of the work that they provide. Yeah, absolutely.

Speaker A: That's crazy to think about that. Oh, we hired a, you know, company might hire a North Korean threat actor, uh, who is just fraudulently gaining access to, to, to do the work, but then does such a great job that when they find out they're like, shoot, this was one of our best performers in terms of the Quality code, the amount of code that they were able to produce, um, you know, and then are frustrated when they have to fire because now they got to go out and find a, you know, a regular, real employee.

Speaker B: Well, they can always offer them a remote position. You know, I guess it's always a decision that they.

Speaker A: Goodness gracious. Oh, my gosh. Yeah, we were. We were talking about this yesterday with, um, with our boss Mike. Uh, and he. He was also sharing some, um, you know, some. Some opinions on this feeling like in many cases, the. Because we've. We've. We've observed lots of, um, uh, you know, applications that appear to have come from North Korean threat actors. Ah. And. And we're starting to flag those and. And actually conduct the interviews anyway. And. And, um, I think you've been a part of a few of those. I know our. Our boss Mike, has done a bunch of them, and, uh, he says it's really interesting, though, uh, the. The information that they can get out of this and then share that with, uh, with leaders. But he. He believes that the. The folks that are interviewing to your point aren't necessarily the ones doing the work. These are almost like. It's a cellular, uh. Like. Like terrorist groups. It's a cellular organization where, oh, these are basically the SDRs. They apply for jobs and then interview for them. And then if they. If they get the job, then that's a different group that actually performs the work, and then all of the money is funneled back to North Korea, uh, to fund their operations.

Speaker B: Yeah, I. Like I said, I. I don't have. I don't have specific details on that to confirm or deny it, but one. One thing from my own experience I can share with you is that, um, I run into similar, uh, problem or similar observation with. With some of the Chinese productors, because one time, going back to the stories, uh, I had a privilege of working with an organization that was pretty much compromised by China for a very long time. And I was with their security team on site, pretty much working every day. And they got to the point that they would just monitor which systems they would compromise on a given day. And the Chinese product pretty much use their network as a training ground, or what looked like a training ground for some of their analysts. So you would see, for instance, on a given day that you would have someone who was like, literally struggling to move laterally from system A to B, and it was like, net space use, trying to figure out, like, well, how do I write that command? You know, what was the syntax? And then the Next day you will see someone like, pretty much blowing for those systems like crazy. And it almost felt like you had like an L1 analyst, you know, sitting there learning from a script like, this is how I do it. And then you would have like an L3, probably doing like a little presentation to everyone. Hey, here's how you do it.

Speaker A: Go.

Speaker B: You know, we've been watching for like months. Uh, it's, it's been, it's been eye opening and I can envision like, you know, a SOC in China to some extent, where you have this pretty much like folks in their uniforms performing those, those actions and, you know, and, and, and tooling and capabilities and escalations and all this stuff. So. Yeah, why, why not, why not North Korea? That would work too.

Speaker A: Okay, I have to ask. I'm just morbidly curious. Have you ever seen anybody, uh, like, reference the man pages? Bad actor. Reference the man pages. They're in there. They're like net you shoot. I can't remember which switch is it to, um. Let me man this.

Speaker B: No, not man pages. I saw it in windows of like the question mark when I list. I didn't see like, with my pages. No, see this in this DNA, like with ChatGPT, like, it would just give you all the. We don't even have to do it yourself. So, yeah, it's. Yeah. You don't get the same level of intimacy, Intimacy with the, with the threat actor anymore.

Speaker A: That's funny. But that would, that would, that would crack me up if, if you watched a threat actor, like, stumble through and have to reference the man pages again. Showing my age a little bit. Yes, exactly. I love it. All right, Pio, this has been such a fun conversation. I'm so grateful. Um, but here's the thing, right? We've had, you know, a good almost an hour of a great chat. We. Not everybody could, could take everything away, but if, if someone. What would you have someone take away? As. As one main point to take away from our conversation today, I think what

Speaker B: I'm going to go with is as, as this is, you know, as we're talking about security, operations centers, and hopefully like, you know, a lot of the audience that that is following this is also like, naturally part of that. What, uh, I'm going to say is that, like, I do think we live in the extremely exciting times, uh, because what used to be pretty much unavailable to me without proper degree, without years of learning, without a number of books, and extreme amount of time that I have to devote to learn is now available at the fingertips of your command and of your prompt, uh, with pretty much, um, LLM. So ultimately, you don't have an excuse today to not live to your greatest potential. You can really do amazing things, uh, being supported by AI and really leverage AI to elevate your game to the next level. Elevating your game to the next level with AI and with your potential, that is only going to make all of us safer. Use this technology. Leverage this technology. Learn from it, Work with it, partner with it. Uh, you can build tools, you can build capabilities. You can ask questions that you would normally have to have teachers and mentors for to ask. Like, you can. You can literally elevate your game in a way that was not previously possible. Uh, and it just makes so, such a big difference at the end of the day. So don't be afraid of it. Leverage it, and you will make yourself successful, make your security program successful, and you will make this entire world more secure. So do that.

Speaker A: I love it. You heard of here, folks from P. O? Uh, don't be afraid of A.I. use it. Use it for everything. Uh, it's incredibly powerful and can help you level up your game. So. So, um, Piot, I just want to say thank you so much for being on the show. This has been a blast. Uh, what an amazing conversation that we've had.

Speaker B: So thank you. Thank you for having me.

Speaker A: You're welcome. Well, folks, this has been another episode of Sock Unlocked. Tales from the Cyber Security Frontline. I'm your host, Mick Leach, reminding all you cyber defenders out there to keep fighting the good fight. You're the tip of the spear, so stay sharp. Uh, thanks for tuning in. Don't forget to like and subscribe and check out our other Sock Unlocked episodes. We'll see you all next time. Until then, uh, have a great day.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Mastercard CEO: AI Shopping Agents, Machine-to-Machine Payments, and the New Infrastructure of CommerceMotley Fool Hidden Gems Investing · on Threat Intelligence88 / 100
  • Less about Models; More about ArchitecturePractical AI · on Large Language Models (LLMs)85 / 100
  • Microsoft Fabric: The Platform That Turns Data into Competitive AdvantageLeading IT - APAC Insights · on Large Language Models (LLMs)85 / 100
  • How to Sell Against a Competitor Already in the BuildingSales Leadership with Fexingo · on CrowdStrike85 / 100
  • Episode 7: AI & the Power of a "Thin Core"Architecting the AI Enterprise · on Large Language Models (LLMs)82 / 100
  • #194 Brian Donohue: Intercom threw their playbook out the window when AI got good - A case study on questioning your mental models.The Way of Product with Caden Damiano · on Large Language Models (LLMs)82 / 100

More from SOC Unlocked: Tales from the Cybersecurity Frontline

All episodes →
  • How AI Is Rewriting the CISO Playbook with Michael Myint64 / 100
  • From Offense to Innovation: What AI Teaches Us About the Future of Cyber Defense with Dave Kennedy
  • The Science of Breaking In: How Curiosity Drives Cybersecurity with FC
  • Testing, Learning, Evolving: How Practice and Precision Strengthen the SOC with Marty McDonald
  • From Alerts to Automation: Lessons in SOC Resilience with Steven Dumolt
Explore the best B2B Engineering & DevTools podcasts →
All SOC Unlocked: Tales from the Cybersecurity Frontline episodes →