Transcript
My name is Brian Dietsch and welcome to my TED Talk. It turns out this is not a TED Talk, they haven't invited me yet. This is actually going to be a three-part mini-series called, If It's Reachable, It's Breachable. And we'll be looking at this through the lens of like the bad guy, the bad girl, the adversary that's trying to come in here and take advantage of your network. We'll be talking about how they find you, how they classify you, and how they exploit you, but how they leverage AI to help accelerate this. And yeah, you guessed it, we're also going to be talking about how ZStore can help prevent all this from happening. So follow along with me, I think you'll have a good time. Just about every breach kind of starts off the exact same way, which is you have some type of asset that's connected to the internet that you forgot about. It could be like standard like this, like you know, the cloud, whether you have an east or west, same thing with the data centers, HQ, factory, branch office, maybe you did like a merger or acquisition, we have some assets that are out there, maybe even like a developer environment that's coming through. And at the end of the day, the bad guy, the bad girl, the adversary is trying to come in here and find that attack surface, and they're using a bunch of different tools to do so. Now, some of the tools that they can be using, like maybe even Nmap, Snowden, Census, ZoomEye, what they're doing is they're looking for IP addresses, host names, admin portals, production environments, test environments, other domains that are out there. Now, the unfortunate fact is like you can use all these tools, be a little bit time consuming, but from an adversary perspective, there actually is a better way. Now, let's be real, the attackers, they can come out, use these different scripting tools that are out there, there could be a little bit of a learning curve. So it could be a little bit challenging, and sometimes even those apps, they just get so old, they just break. And so AI is helping, unfortunately, the adversary kind of do their evil deeds as well. So when it comes time to finding your attack surface, the attacker can just go out there and be like, hey, I'm interested in Acme, and I want to kind of know everything about it. And then in a series of prompts, get a good idea of like where all of your locations are, where all of your ASNs, things like that, and be able to map out your network externally, that external attack surface. And what they're going to get at the end of the day is your IP addresses. And again, if it's reachable, it's reachable, that's inbound traffic that's sitting there. And then last but not least, to be able to maybe find out some of the domains that you're using, not even your, not just your production domains, but even like your test dev environments as well. And where AI really helps accelerate this is it kind of diminishes that learning curve. But then too, let's say it scans your entire network, finds all this stuff, and you have like 100,000 IP addresses, these endpoints that are externally facing. Normally, you'd have to sit there and try to figure out like how to prioritize it. Or you can just ask AI to prioritize the top 100, 200, and then set your target on that. It's a whole nother world to find the IP address or the domain. It's a whole nother world to come back through there and figure out what is the service that's running behind that IP address, which is in our next video.