
The Azure Security Podcast · 2026-04-30 · 36 min
Key moments - from our scoring
Substance score
67 / 100
Five dimensions, 20 points each
At RSA Conference, the threat intelligence landscape is dominated by AI adoption across both offense and defense. Shara DiGrippo explains that every major threat actor group - from North Korean actors (Citrine Sleet, Sapphire Sleet, Coral Sleet) to financially motivated crime groups, China-based (Typhoon), Russia-based (Blizzard), and Iran-based (Sandstorm) actors - are experimenting with and operationalizing AI in their workflows. Threat actors use AI to generate highly personalized phishing at scale, manage command-and-control infrastructure, create malicious code, automate ransomware negotiations with AI chatbots, and overcome language barriers. On the defensive side, organizations are leveraging AI for code audits (finding hard-coded credentials, using Anthropic Claude models), detection engineering, SOC automation, threat hunting, and processing massive datasets. Microsoft processes 100 trillion security signals daily from 1.5 billion endpoints across Windows, Mac, iOS, Android, Azure, AWS, Google Cloud, IoT, browsers, and Bing search - enabling threat intelligence teams to identify malicious indicators (hashes, IPs, domains, URLs, botnet participation) at scale. The capability evolution from the periodic table naming convention to weather patterns (reflecting hundreds to thousands of tracked threat actor groups) shows how the threat landscape has expanded exponentially.
Security signals include malicious emails blocked in Microsoft Defender for Office 365, code execution attempts detected on endpoints, malicious URLs hosting payloads, atomic indicators like hashes and IP addresses, domain names associated with malicious traffic, and botnet participation lists - collected across Windows, Mac, iOS, Android, cloud platforms, IoT devices, browsers, and Bing search results.
Threat actors use AI to create fake resumes for social engineering, generate highly personalized phishing emails at scale, create fake identities and licensing documents, automate malware and ransomware code creation, manage command-and-control infrastructure, overcome language barriers in targeting non-native speakers, and deploy AI chatbots to negotiate ransomware payments with victims.
Defenders are using LLMs like GitHub Copilot for code analysis, Anthropic Claude models (currently restricted to commercial entities) for large-scale code audits, and custom AI agents with highly detailed prompts (up to seven pages) for automated threat hunting, hard-coded credential detection, and processing sensitive security documents at scale.
Microsoft moved from the periodic table of elements naming convention to weather patterns (Sleet, Blizzard, Typhoon, Sandstorm, Tempest) in March 2023 because the organization had identified so many distinct threat actor groups that it ran out of element names; the weather system accommodates hundreds to thousands of tracked groups.
Microsoft processes 100 trillion security signals daily from 1.5 billion endpoints across multiple platforms (Windows, Mac, iOS, Android), cloud providers (Azure, AWS, Google Cloud), IoT devices, browsers, Bing search, and email systems, providing broad visibility for detecting malicious indicators and tracking threat actor infrastructure.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode delivers solid, actionable insights on threat actor AI adoption, defense strategies, and prompt engineering, with concrete examples (ransomware negotiation bots, phishing personalization, code audits via LLMs). However, it includes meandering tangents on AI philosophy and personal anecdotes that dilute focus, and some sections repeat established talking points without deepening analysis.
threat actors are using AI across the entire attack chain. We're not seeing anything right now that's fully autonomous, like fully automated campaigns. Every step of that life cycle now has some sort of AI component.
One of the favorite use cases that I really love is doing code audit to look for hard-coded credentials...AI is able to go through code bases and find those things that, hey, this is clearly a problem, you need to change it.
While the framing of threat actors as rapid technology adopters and the emphasis on prompt-engineering-as-new-literacy offer some fresh perspective, the core insights (attackers use AI, defenders should too; scale matters; natural language interfaces democratize access) are well-trodden in 2024 discourse. The specific examples (North Korean groups, weather-based naming) are informative but not conceptually novel.
threat actors are the fastest adopters of every technology because they have no legal, moral, or ethical constraints to worry about
I think we are at an evolutionary moment in computing and in technology. And maybe, I'll say it, maybe in the human race where we are at a real inflection point.
Sherrod DiGrippo holds a genuinely senior role (Partner GM for Global Threat Intelligence at Microsoft) with 22 years of hands-on threat intel and detection engineering experience. She speaks from direct access to 100 trillion security signals and partnership with law enforcement. This is a practitioner at scale, not a career podcast guest or thought leader. Her credibility is substantive.
My official title is Partner GM for Global Threat Intelligence at Microsoft...what I focus on for the past 22 years or so is watching what threat actors do.
We look at 100 trillion security signals a day coming from 1.5 billion endpoints.
The episode provides some concrete specifics: threat actor group naming conventions (Sleet=North Korea, Blizzard=Russia), the 100 trillion signal figure, a seven-page prompt example for code audit agents, and the March 2023 naming convention change. However, many claims lack supporting numbers or named examples: no specific ransomware negotiation case study details, no data on prevalence of AI adoption among threat groups, vague on 'recent report about North Korea-based actors,' and thin on quantified defensive impact.
We look at 100 trillion security signals a day coming from 1.5 billion endpoints. So Microsoft has a broad and deep visibility
in March of 2023, Microsoft moved from threat actor group naming aligned to the periodic table of elements to weather patterns...Sleet is North Korea, Blizzard is Russia, Typhoon is China, and Sandstorm is Iran
The hosts ask reasonable opening questions and some follow-ups (e.g., 'leading edge groups or everybody?'), but rarely press for evidence or push back. Questions often veer into tangents (AI philosophy, personal coding anecdotes) rather than extracting depth on threat intelligence specifics. Follow-ups on threat actor prevalence, detection effectiveness metrics, and organizational readiness are superficial. The host acknowledges low structure ('we have zero agenda') rather than treating it as a weakness to overcome.
So I'm curious, is this like a few leading edge groups? Is this everybody experimenting? Is this... Everybody's already put it into their normal standard operating procedures. I'm curious the prevalence of this and the breadth and depth of it.
By the way, for everyone who's listening, we have zero agenda. We literally had share a join. And I said, I guess we're talking threat intel, just because I know Sherrod so well.
Computed from the transcript - who did the talking, and the words that came up most.
In this episode, Michael, Sarah and Mark talk with Sherrod DeGrippo about some of the latest tactics and strategies used by modern threat actors, we also wander into the AI security weeds! We only have one news item related to Azure SQL databases.
Transcribed and scored by The B2B Podcast Index.
Welcome to the Azure Security Podcast, where we discuss topics relating to security, privacy, reliability, and compliance on the Microsoft Cloud Platform. Hey, everybody. Welcome to Episode 127. This week is myself, Michael, with Sarah and Mark, and our guest this week is Shara DiGrippo, who is actually on the podcast.
Man, it must have been two years ago. I need to look that up. But before we get to our guest, we've got a couple of little news items. Actually, I'm the only one who actually has news this week, which is...
Kind of interesting. So a good friend of mine, an ex -colleague of mine, Peter Vanhover, who works in the Azure data team, more accurately, the Azure data security team, has published an Azure database security newsletter for April 2026. I would definitely go and take a look at that. Some of the things that really sort of stood out for me, one of the big ones is customer managed keys for Fabric SQL database.
as well as versionless keys for transparent data encryption in Azure SQL Database. And there's a whole bunch of best practices in there as well. It's really cool seeing Peter put this out because I'm just a big fan of just small... highly pointed, hey, you're aware of this and don't forget about this and there's this new feature here.
I think that really is useful stuff. It really helps people understand how they can improve their security posture as well as taking advantage of newer security features in the product. And I'm always a big fan of customer managed keys. So now they've got the news out the way, or one item of it, let's turn our attention to our guest.
As I mentioned, our guest this week is Sherrod. Sherrod, so why don't you take a little moment and reintroduce yourself to our listeners? Thanks, Michael. Hi, it's me, Sherrod Grippo.
My official title is Partner GM for Global Threat Intelligence at Microsoft. But my unofficial title is Vibe Merchant, and I've got the vibes, and I'm here to provide them. What I focus on for the past 22 years or so is watching what threat actors do. and talking about it and disrupting them and imposing cost on them and doing detection engineering to stop them.
And that's what I do here at Microsoft. Hey, Sherry. So, well, I saw you a couple of weeks ago talking about threat intel and what's going on in the world back up in San Francisco. So tell us, tell everybody else here, like what's occurring in threat intel land.
Yeah. So, Sarah's talking about how we had a lovely time in San Francisco at the RSA conference. Probably the biggest, I think, show for information security, everyone talking about threat intelligence and obviously AI. If you've heard of that, it's this new thing that everyone is interested in.
AI is big on the landscape right now because obviously everyone is talking about it, everyone is using it, and that includes threat actors. So what we're seeing is So groups of people with malicious intent, either in order to have a financial gain or to perform espionage or disruption for their respective government employer, is using AI across the entire attack chain. We're not seeing anything right now that's fully autonomous, like fully automated campaigns. Every step of that life cycle now has some sort of AI component.
We're seeing threat actors do things like create fake resumes to get jobs. They're doing things like obviously creating social engineering. They're scaling out fake identities so that they can generate paperwork and get licensing and documents. They're using it for communication.
Of course, they're creating malicious code like malware, malicious scripts. We have even seen threat actors go all the way to the step of automating ransomware negotiations so that the victim who is under ransom is talking to an AI agent. I'm going to just have to say wow on that last point. Is your ransomware negotiator is a chat bot?
That's right. While that does seem a bit of a dystopian future, it makes sense from an automation perspective. I'm not arguing the logic at all. It hadn't even occurred to me.
Threat actors are always trying to be more efficient, do more with less. And I think they've found that if they can get lots of organizations under ransom, they have to negotiate with all of them. So why not put an AI agent in front of them? Yeah.
I mean, I like to say that they're the fastest adopters of every technology because they have no legal, moral, or ethical constraints to worry about. Yeah, exactly. And they want to go faster. They want to scale.
They want to do more. Threat actors tend to be ambitious. So when accelerating tools come online, they take advantage of them. And we've seen that.
perennially for decades. Threat actors use what's available to them and AI is no different. One thing I saw recently was threat actors actually creating highly personalized phishing lures using AI, which was really fascinating to see. So the AI would do all the background research that it had to do and then craft something that was highly, highly personal.
We've seen that and we've seen that for a while and I think When I look at it, I use AI to sort of refine the emails that I'm sending or to help my messages come across with a different tone or more clearly. If you think about, as well, the language barrier, a lot of these threat actors don't speak the native language of their targets. It gives them this advantage where they can have a casual conversational tone that maybe just a basic translation app wouldn't be able to provide for them.
They can do this at scale. So they can feed an LLM a list of targets and say, go research them, figure out the way that they communicate, figure out their style, and let's create some social engineering that really speaks to each of these target individuals. So I'm curious, is this like a few leading edge groups? Is this everybody experimenting?
Is this... Everybody's already put it into their normal standard operating procedures. I'm curious the prevalence of this and the breadth and depth of it. In 2023, we released a report about how we're seeing a variety of nation -sponsored actors use AI.
The report that came out about a month ago really focuses on some of the North Korea -based actors. So the actors that we refer to as sleet, so citrine sleet, sapphire sleet, coral sleet, those actors. And it goes into some case studies of what we see, for example, coral sleet doing. They're doing AI on development platforms so that they can manage web infrastructure at scale, for example.
So they are able to put together staging infrastructure, test it. operate their command and control for their botnets, and they use AI and AI agents to do all of that. So I would say that there are leading edge use cases and there are leading edge novelty from some of the threat actors, but all of the threat actors across the board, including crime for China, Russia, North Korea, and Iran, we see leveraging AI in some way. Gotcha.
So it's early adoption, but it's widespread and everybody's kind of trying their own ideas. That's where we are right now. There's a lot of experimentation, but we're absolutely seeing workflows being created the same way you or I would. I know Michael was talking about all the agents that he's been deploying for his work every day, and threat actors do the same thing.
Let's be honest. The barrier for entry is really low. It's low. I don't mean it in a negative way.
It's good that it's low because it can be used for good. I made a joke the other day, but I was actually dead serious. I was talking to a bunch of... kids who are graduating school.
And jokingly, I said to them, what's the hottest programming language right now? And they threw out Python, Rust, not JavaScript, TypeScript, and a bunch of others. And I said, no, you're all wrong. I said, the programming language right now that's really hot is the written word.
It's the ability to write unambiguous prompts. is the programming language right now. That's the hot programming language. And I mean that sincerely.
And to your point, I mean, even things like AI agents, at their heart, I mean, it's the LLM itself, but also the ability to craft a very efficient prompt is really, really important. But yeah, as long as you can do that, I mean, you can get a lot done. I think so, that's right. And something I think about too is from a computer evolution timeline, most of us, you know started with a command line interface where you had to actually type commands not you know prompts you had to type the actual command to move around within your data and then you know the next step that we got was the gui which i think most people are familiar with which is a graphical user interface where you can point and click and you know you see icons and now we are at an interface with our computers and our technology we interface with our data now with natural language if we want to.
I can ask questions about my data. I can talk to my data. And I think that that's a huge democratization of the ability to compute, of the ability to use technology. But it also means that people have access to tools that they don't understand or have skill in using.
And so that can be dangerous in a variety of ways. It can be good though as well. And I'll give an example. So I basically live, in GitHub Copilot.
And I had this horrible, horrible merge conflict on GitHub. And I was trying to work it out. And I'm not going to pretend that I know Git upside down, inside out, the wrong way around. I don't.
I know it well. But some of the corner cases I'm just not good at. Just told GitHub Copilot precisely what was going on and it did it for me. And it did it correctly.
Would have taken me quite some time to probably get it wrong. Whereas GitHub Copilot got it right quickly and correctly with just a human prompt. So I agree 100 % that people are using tools they don't necessarily understand. I mean, let's look at OpenCore, right?
But when it's used well, it can be a real time saver. By the way, I didn't realize this. By the way, for everyone who's listening, we have zero agenda. We literally had share a join.
And I said, I guess we're talking threat intel, just because I know Sherrod so well. That's the only thing I know about. That's right. And AI.
And AI. But the point is that, you know, I think it's good that we can take it in relative, you know, different directions as needed. So, Michael, I actually have an... identical experience.
So I was updating a website and I can code, but I'm pretty rusty. And I couldn't believe how quickly, even compared with a year ago when I was updating the same code, how much the LLMs have improved because there was a year ago it could not fix. It was a really annoying justification thing on the website. And this time it fixed it in one prompt.
So Yeah, it's incredible what you can do with the AI and the LLM. So I'm not surprised that actors are taking advantage because I sure am. I am too. And the workflows that are available and the resources that are there, it's incredible.
I really do think that we are at an evolutionary moment in computing and in technology. And maybe, I'll say it, maybe in the human race where we are at a real inflection point. Yeah, it's kind of interesting because, of course, security people are all critical thinkers, right? And we always look at, hey, what could go wrong, right?
Yes. And you triggered me a little bit because I created a slide that talked about... And for several of my workshops, it talks about how AI basically brings to life the old dream that, you know, I have this vision in my head of like a dude wearing a cardboard box spray painted silver, right, in a black and white TV show. And like, we've dreamed that these computers would talk our language.
And now they do. And we're like, oh, crap. Yeah. Yeah.
And I do think that, you know, I love. Marvel, I love the MCU. And those early films of Iron Man with Jarvis, I feel like it's here. I feel like Jarvis is here.
I don't think he's fully here, but we're not that far away. We're a significant percentage of the way there. It's really close. Hey, how about I bring us back down to Threat Intel?
What a concept. That rabbit hole we just went down was all my mistake, my fault, because I said the barrier for entry is so low and it is. And threat actors are taking full advantage of that. That leads to the next question, if the attackers are using AI to help them be more efficient, so what's happening on the defensive side of the house?
I think defenders are so well placed right now to be able to scale and accelerate their capability. The thing I've been saying a lot lately is A and AI. almost stands for accelerate more than artificial. You can go so much faster as a defender.
You can get resources so much more quickly. And we really are seeing incredibly innovative and talented people put AI automation into detection engineering, into the SOC, into hunting, into looking through huge pieces of data. One of the favorite use cases that I really love is doing code audit to look for hard -coded credentials. Michael, something you and I have talked about quite a bit, don't do that.
But AI is able to go through code bases and find those things that, hey, this is clearly a problem, you need to change it. And it finds it really quickly and you can take care of it very fast so that you're releasing code that isn't vulnerable to begin with. Yeah, it's more than that. It's not just hunting for credentials, right?
I mean, again, you and I have spoken about this at length. You know, you can use LLMs to do huge code audits. I mean, we see that now with the new anthropic mythos models. You know, they're basically right now being restricted as to who can access them because, you know, they're good at what they do.
And so, you know, I don't know what the policy is long term, but for the short term, they're going to be restricted to a small number of commercial entities. I think... Again, I use LLMs every day for doing code audit, but we also have a whole bunch of agents that do the majority of the work. I don't actually write the prompts.
I may nudge the prompts, but I don't actually write the prompts and do the actual review. Some of those prompts are huge. I was one of the agents that I've been working on. I'm not going to go into all the details.
It takes a whole bunch of very sensitive documents. and produces a whole bunch of sensitive output that's used by a completely different team at Microsoft to help them drive what they do. And the prompt for that is seven pages long. And it produces very high quality output.
You know, that would take me, if I was to review these documents by hand, it would take me weeks to be able to review the documents versus 15 minutes, you know, for my agent to actually do the work. But again, the secret sauce there is really the prompt itself. And that prompt that I use, as I mentioned, is at least seven pages long. And that's kind of the thing we're learning, right, is that for defenders, you have a new tool that can do a lot for you.
And you need to really understand how to skillfully use this tool now. And I think a lot of defenders are starting to realize. power, like you said, of really good prompting, whether that has some metric around length or specificity or constant refinement or whatever it may be. I think it's really interesting seeing defenders learn how to communicate differently.
And essentially, a lot of us have social engineering backgrounds or social engineering expertise. You need to be able to social engineer the LLM that you're talking to. And so get really good at talking with urgency, talking with emotion, giving constraints, giving consequences. What will happen?
How is this going to work? Being really specific and innovative with the way that you use these tools is going to get better results. Like AI persuasion. Absolutely.
I really like about the AI technology because I know there's a lot of, hey, it's going to take my job and all those kind of fears. At the end of the day, it's task automation. It doesn't change the critical thinking or the objective of what jobs have to get done. It just makes them happen more automatically.
But the thing that I think a lot of people overlook is there's a bunch of stuff that people don't like to do. No developer likes to... document their code. No analyst wants to stop in the middle of an investigation to write up a report, to give to their manager, to give an update and up the chain.
Like it's really good at the crap that we hate doing as people. And so that's, that's one of the things I think a lot of people overlook when they're sort of looking at this and they, they, they keep looking at it like it's like classic automation or classic machine learning and data analysis, but it's like, this actually does something different. And I love that in the SOC or for Defenders overall, we've always felt like we don't have enough people. We don't have enough resources.
I wish we had headcount, all these things. And I think that if you're smart about the way that you leverage these new tools, you can get rid of some of those complaints and constraints and frustrations and actually have a much more seamless operation. Yeah, you wanted to get to threat hunting, but you couldn't because you were doing all the investigation stuff. Well, now it takes 80 % less effort to do that, and you have time to get to the other alerts, to do more threat hunting, to do more threat intel research.
All the things that you've wanted to do, because there's always a list, that you couldn't do. Yeah, I think that's great. That's one of the things that brings me a lot of hope and excitement. I consider myself an AI optimist, so this is one of the points that I like.
Yeah, I'm definitely an AI optimist. I really am. I see the huge opportunity. I mean, don't get me wrong.
I mean, from an attacking perspective, I mean, obviously there's some big risks there. But it's like anything, right? I mean, books in the library can be used for good and for bad. I mean, it's just the way things are.
So we talk very generally about... threat intel and sort of ai and ai in general where where are we at with microsoft in terms of threat intel like what is what is front and center with uh with what's going on at microsoft around threat intel and potentially even ai well so microsoft has a really as you're aware has a really big and robust um machine around threat intelligence we have a variety of teams that do um hunting they're specialized malware reverse engineers there are language experts We look at 100 trillion security signals a day coming from 1 .
5 billion endpoints. So Microsoft has a broad and deep visibility with which to make inferences and have insights into what's happening in the landscape. And that's sort of what the reality is like for us. Microsoft looks at those signals and then determines where we can best use the information.
that we have coming in. And a lot of times that's used to protect, obviously, Microsoft itself, but also, of course, we put those detections into products or we work with our partners for doing things that are disruptive, for blocking botnets, or working in a variety of ways with various public and private partners to make sure that the threat intelligence that we have is being used to increase the security posture of Ourself, our customers, the world. I have a really silly question.
I have a silly answer. Fantastic. Actually, I hope your answer is better than my question. So I hear the term, look, this is really naive.
I hear the term, you know, N trillion signals. Give me three examples of signals. A signal would be malicious email is blocked in MDO. A signal would be...
A piece of code attempts to execute on an endpoint and Defender detects and blocks that. A piece of signal would be a URL that is hosting a malicious payload and getting people to click on it and download that malicious payload. Give me another one. A security signal that comes in is...
Atomic indicators, hashes, IP addresses, domain names that have some association with serving malicious traffic of some kind or being used to communicate malicious. Like a reputation or a URL? Like reputation, yeah. Like a list of IP addresses that are part of a botnet, for example.
Okay, got it. Cool. Okay, so it's actually known relevant to security or attacks, not just raw data. Correct.
Wow. The scale of that is stunning. It's crazy. But you have to remember too, we're talking about IoT devices.
We're talking about multi -cloud, right? So Microsoft has cloud protections, not just for Azure, but also for Google Cloud, for AWS. We're talking about IoT. We're talking about multi -platform.
So not just Windows, but Mac, Android, iOS. The visibility is huge and we're talking about malicious signals that are in the browser, malicious signals that are in search with Bing, malicious ads that are serving ad payloads that lead to malware downloads. It's broad. Yeah, the analogy I like to use, I haven't presented a threat intelligence slide in a while, but when I do, it's like you're trying to catch a unicorn running through a dark forest, and you want as many cameras as you can so that you have a better chance of finding it, but you can also say, hey, there's a hoof, there's a horn, there's a tail.
You know, connect the dots. I normally don't like analogies, but that's actually a pretty good one. So, Sherrod. I'm curious, you know, I have sort of my perspective from sort of the field of, you know, how our threat intelligence evolved and that number keeps going up, of course.
Can you talk a little bit about how like the program and the way we approach threat intelligence has evolved over time and the kind of things we've learned as we've, you know, been managing these, you know, whatever it was, 12, 15, 58, 72 to 100 trillion signals. Like, are we learning things, doing things differently? Curious, curious your perspective on that. Yeah, I think, and it's really interesting to me too.
Microsoft has, I think, in many ways kind of followed the evolution that most information security vendors and threat intelligence vendors have followed, which is over the years, you know, the past five or 10 years, the landscape has exploded. More and more threat actors have come online and Microsoft threat intelligence as a group, as a capability, as a function within the company. has had to evolve along with the landscape. Some of the notable evolutions are breaking out our own team to be Microsoft threat intelligence or mystic.
And then some that some of the listeners might remember is when in March of 2023, Microsoft moved from threat actor group naming aligned to the periodic table of elements to weather patterns. And it caused a great consternation amongst the threat intelligence cometariat out there in the world. But the reason for that was we ran out of elements and there were just so many threat actors that we ran out of names and there was no choice but to move to a new naming convention. And just quickly for those who aren't aware, Sleet is North Korea, Blizzard is Russia, Typhoon is China, and Sandstorm is Iran, with Tempest being financially motivated or crime -based threat actor groups.
So when you hear one of those words, you can kind of associate what its origin is. We've had to realize that there are hundreds up into the thousands of threat actor groups, and new ones come and go and disband and reform, and we track all of that. And particularly in the crime ecosystem, there are threat actor groups we track that do just one little thing. Maybe they don't deliver ransomware.
Maybe they just make a toolkit that a lot of threat actors then use. Well, we want to track that group and see who they're selling that toolkit to, what the evolution of the toolkit is. Are they running a sale this month, which they do. We want to understand the full landscape and all of those players.
So that means that we have to evolve the way that we name them, the way that we track them. Sorry, I just have to interrupt you there, Sherrod. Did you just say that they have a sale? Yes.
So there's a variety of threat actor groups that have full customer service style help support. You can email, you can get chat support for your attacker in the middle, MFA bypass. fish kit landing pages, for example. They run sales.
That is wild. Every time I hear stuff about bad actors and these groups, obviously, I know some of them are very sophisticated. The idea that they have a sale, like a real shop, some kind of actual commercial thing is always still blows my mind. They're fully operationalized.
And we see the marketing materials that they send out to their existing customers saying, you know, if you If you're enjoying the product, we're having a sale, you can buy a year's license for last year's price, for example. I just have this vision in my head of those infomercial pitchmen that are sitting there saying, yes, but wait, there's more. It comes with this. It's true.
I have another one of my silly questions. You said that there are suffixes to denote countries, but also financially motivated. So what takes priority if it's like a Russian financial operative? So those alignments are generally around...
the motivation or the end goal of the threat actor. Some countries do have an interesting relational overlap between their military intelligence and espionage capability and their criminal groups. We see that some. Really what takes precedence is we try to focus on how we can best secure Microsoft customers.
That really is the focus, is where can we use this information best? What threat on the landscape today is the most concerning? But that changes all the time. Threat actor groups are constantly evolving, constantly changing.
New ones are showing up all the time. It's a daily desk reality where if I take vacation for a week, it's hard to miss out on what's going on. But I come back and I'm sort of like, okay, I need to go read all the backlog of what all the actor groups did over the week so that I'm caught back up on the landscape. So one of the thoughts that I had earlier with the conversation was so interesting, I kind of put it to the side.
One of the observations I've made about the AI models is triggered by your comments on how easy it is to write code and applications and get it to do stuff. I've realized that AI is overcapable in a way. We used to have to build every piece of software brick by brick. And then, yes, we learned how to use other bricks and reuse components and open source and all that kind of stuff.
We got efficient at it. But if you didn't write the code, it didn't do the thing, right? That was the old rule. But with the AI models, it comes with hundreds of thousands of skills that you probably don't need on any given thing.
And so it feels like AI is really like a constrained by default mode instead of build by default. It feels like it inverts the thing. And I was just kind of curious on your experience of that, because that introduces all sorts of interesting security things. But curious your thoughts.
If you have any reactions to that. I certainly do. I mean, you know, LLMs are definitely highly capable and we do spend a lot of time constraining the models as well. We being the industry, I don't mean necessarily Microsoft, you know, with all sorts of content safety, which the fact that content safety exists means that the models are capable of producing something that's air quotes.
Whatever unsafe means, right, in your context. But yeah, 100%. I mean, LLMs are incredibly capable and they know a lot. I like to try to constrain my models, not...
necessarily because of any danger, but I think I've mentioned this once before. If I'm talking to an LLM about rust, I want it to know that I'm talking about the programming language and I'm not talking about iron oxide. I'm not talking about a movie. I'm talking about the programming language.
Imagine if you're a lawyer and you want to use an LLM that knows about legal precedent, not about all sorts of other stuff because that will help the LLM help the LLM. force the LLM to potentially start hallucinating, right? If it's got more stuff that has nothing to do with the legal landscape, then it can start hallucinating about stuff that have nothing to do with the legal landscape. So yeah, I think you do want to constrain them anyway, but yeah, they are potentially unsafe in certain types of contexts.
I mean, Sarah, you've done some stuff on AI safety, right? I have. It's, well, I have worked with the much smarter people than me in our AI Red team and stuff. Sherrod, so since you came on last time, we now have a new fun question that we ask everyone who comes on our podcast, which is, what does a day in the life of Sherrod look like?
Every day is definitely different. I love all the different things. I definitely think that my role is You know, I make the joke that I wear like a helmet and a catcher's mitt because people just throw things over the wall at me and say, hey, you seem like the right person to handle this. And I look at it and I think, well, yes, I don't know who else this could be.
I guess it has to be me. So things like, you know, we're partnering with another information security vendor and we want to release really great disruptive threat coverage and we want to do it all at once. And so we'll vet. the data that we have against the data the partner has, make sure that it all makes sense, wrap it up all together and do like a co -timed release, even with our public sector or law enforcement partners that we've had a great success with something.
I spend a lot of my time, as I said, on the daily desk. I try to read and look through everything that's happening in our data and in our platforms to see what threat actors are doing. That's something that I think in this kind of role you really have to do. I love reading indictments.
I feel like they give these incredible insight and picture into what threat actors are doing that maybe we don't see because of our visibility, you know, is only a certain way. They might have a lot of information and detail that I can look at. And I try to catch up with a coworker or two. I try to, you know, put the fun, cool people into my day when I can.
And Microsoft has an interesting culture. I'm only here three years, but something I've never experienced before is people just call you on Teams. Your phone just starts ringing and you click it and there's a video of a coworker saying, hey, listen. And that is...
still something I'm getting used to, but it is sort of fun to just get a random phone call with somebody on the other line saying, hey, I want to talk to you about this thing. So it's different every day, but I really love the variability in all the different projects. And it's all about, for me, understanding what threat actors are doing and then taking what we know about those threat actors to make the world safer. I guess I get to ask the old fun question.
Final thought, like what would you like to leave our listeners with to sort of really kind of burn into their brain? And this is the most important thing. I think as technology practitioners, regardless of what your role is day in, day out, you really should be thinking about what threat actors are doing and how your work is threat informed. how you're making threat -driven choices in the code that you're writing, in the systems that you're configuring, in the technology that you're deploying, making decisions based on what a threat actor might do if they were exposed to that.
And I think it's important for our software developers, our new vibe coders, welcome. You are terraforming the battlefield that defenders have to fight on at some point. And so all we ask of you is to give us the higher ground and create a battlefield that we can fight on and win. And if you're doing that, then you're doing the right thing.
All right. Well, with that, let's bring the episode to an end. Share it as usual. Thank you so much for joining us this week.
And we need to get you on the podcast more often. It's always a delight having you on. We love having you on. And you always have a whole bunch of insights.
And to all our listeners out there, we hope you found this episode. enjoyable and useful and with that stay safe and we'll see you next time thanks for listening to the azure security podcast you can find show notes and other resources at our website azsecuritypodcast .net if you have any questions please find us on twitter at azure set pod background music is from ccmixter .
Other episodes covering the same guests and topics, from across The B2B Podcast Index.