Transcript
and close security gaps with autonomous endpoint management. So I'm going to hand over to Abs, thanks very much Abs. Thanks Sarah, good morning everyone and welcome. So what we're going to do is we're going to run through what the chaos is, I guess what the current state is would and would be for you know a lot of organizations out there, how do we bring those pieces together and what we can do with them, making them useful, getting some clarity and then the journey to autonomous. Please feel free to put questions in, if something comes up and I see a pop-up that's relevant I'll address it straight away, if not then we'll grab them at the end. So what's the chaos? So what we've been seeing a lot in the market now is multiple data sources are out there all bringing in different data, you'll have you know information in your Active Directory, information coming from your vulnerability scanners, your endpoint management solutions such as Intune, your CMDBs, stuff like that and they differ. So you might have certain things appearing in your vulnerability scanners for example which might not be in Intune or your CMDB as they may not be seen outside of say like a network scanner and all that sort of disparate data makes it pretty hard to bring it together and make it useful. On the back of that we have increasing exposures, the amount of vulnerabilities are growing daily realistically and now with the AI driven push that we're seeing around finding these vulnerabilities and things like anthropic mythos and that sort of stuff, even before that there was you know big tools being used to find vulnerabilities in code and things along those lines. You pair that with a growing attack surface and you know you get a bit of a problem there and to compound it all a lack of visibility. You can't report on what you can't see, there's little to no reporting unless you really are targeting something, a lack of a single source of truth and all that is going to lead to broken compliance. So picking up the pieces, the first thing that we sort of look at from an Avanti point of view is starting with our neurons platform, specifically the discovery engine. So we use that to actually become the system of record, the source of truth, the single pane of glass, whichever buzzword you'd like for bringing all that data together and the way that we do that is through our active and passive discovery. So the active discovery is what you'd sort of expect it to be, we scan the network segments, find what we can, actively going out and look. We can do things around OS detection, get remote inventory from these devices, figure out what they are, build that picture. We can also do SNMP discovery as well as part of that and that's all well and good and that's typically a point in time. This is a solution that a lot of people would already have what we have as well on top of that is our passive discovery which is a real-time detection. We can do name detection, we can do remote inventory with it as well as OS detection and effectively the way that works is when you have your neurons agents out there in your network segments, on your laptops, workstations, whatever you have, through a process that we have which is a bit much to go into but effectively one machine per subject will be voted as the scanner and it will actively listen to the network, look at the ARP request, stuff like that. Once it sees something hit the nick, it goes, hey you're new to me, who are you? And go and talk to it, figure out what it is and build the picture that way. And then we take that data and we can bring it together with the multiple sources that people have. So as we mentioned in the chaos, you have multiple data sources all bringing in different information. We can bring that all in through the use of our connectors. We get that all together, we pair it together, bring in your vulnerability scanning information and we can build a picture around, oh sorry, I jumped ahead of myself there a little bit. We also have our vulnerability scan that can be used that we call the virtual vulnerability scan, the VVS. So it's not a true scanner in the sense of something like a tenable or something like that. What we use is the data that we see from our discovery to build a picture of the CWEs and map it back to CVEs to get the information and bring that together as well. So we use all these sources to bring the pieces together and we can start to build a picture of what we have in your environment and what is actually out there. So once you have all that data in, how do you make it usable? So we go through a process of data normalization and unifying the records etc etc. So while you're going to have a fair bit of consistency to be fair across your data sources, there's also going to be, so we have, because of that, there's going to be reconciliation and de-duplication. So you have the two different sources, maybe they have clashing information, maybe they're the same information. Same information, happy days, we know it's true, in it goes. So once you start looking at de-duping and reconciliation of the records, the way we sort of bring that together is we look at all, as we bring it all in, see it all, and then we'll use the data from the passive and active discovery to effectively go, okay, which one is the correct one and get that in there. And using that we can build a pretty comprehensive IT asset visibility. Then from there you can start to use that into your workflows and move it from there. So to sort of show what that looks like, hopefully the slide is clear, there is a bit on this, but this is our device reconciliation view. You can see all the sources listed out there and we've got a few clicked in and clicked out. So what we're ignoring, how many devices were discovered by, I think trying to read it on my screen is even a bit hard, CrowdStrike and I can see Neuron's passive is selected there and the data that's not in Entra or Intune and things like that. So you can start to say, okay, why are those 92 devices not in Entra? Should there be an Entra? And you can start to see there where your gaps are, why those machines are not in the right place and how can we make that usable. So you can sort of see it all come together. And yeah, so it's a nice way to go. And then from there you want to start getting clarity, right? And what we're doing around that very much in around the exposure management space is we're building out these sort of views for you. So we're using Sankey charts for these, which look pretty funky, but effectively it's just like, all right, got 148 assets. How many of those are exposed? How many are not exposed, et cetera. What sources are they from? And what's the risk score? So we're using the RS3 there, which I'll explain in the next slide. So you can say, all right, if we select one, all right, let's get a medium risk. These are the assets there, where were they found? And you can start to see the gaps, right, in your data. So going back to the chaos, why do we have four in CrowdStrike, 11 in Qualys? Where's that gap there? If you're using your CrowdStrike as your EDR AV, that sort of stuff, is that missing on a bunch of devices? You can start to build that picture out and start taking action and bring it all together for yourself. And on the inverse as well, we also have the exposure view. So what is your total exposures? What are the VRR scores, which I'll also touch on? Are they patchable? And what are the remediation options and things like that? And then from there, you can actually break it in, have a look at the, sorry, it's more. Once again, you can click into the Sankey chart and see how that all sort of breaks down. And if you dive into it, you can see the asset view here. What's the source of the data? So you can see we've got a mix here between Qualys, ourselves, CrowdStrike. I believe that one's Defender, the little Microsoft guy there. And you can see, all right, these are the breakdowns, these are the scores. What's the risk on these assets? And further from there, you can actually just jump in and take a look at it, which we'll have a look at a bit at the end, we're actually in the console. So I've mentioned IRS3 and I've mentioned VRR. So what are they? So the VRR is what I'll start with. So that is our vulnerability risk rating. So we all know CVSS scores and what they're used for and how they're used to sort of judge the severity of vulnerabilities. Those are very much a point in time. So at the time the vendor announces or releases a vulnerability, that score, that rating is pretty well set. You don't see them change. But that may not almost be the case, right? So you're going to have scenarios where you'll be, okay, maybe this particular vulnerability is released as a medium, not a high score, like a six or something like that. But then a malicious actor can then take that and make it exploitable and make malware around it and use that effectively as an attack vector. Is that still a medium? Is that still a six? No. So we look at that data, what's happening that's out there? Is it being actively used? Who is using it? Is it being used by APTs, for example? We take all that data together and we have a score that's effectively live. So you can see sometimes you might see mediums or highs that we might mark as critical, or you might see a critical that's marked very low because it's just not being used in attacks for whatever reason. So that's sort of the first data point we use. We take that into account with the CVSS, of course, because you've got to listen to the vendor. They know their stuff. What's the accessibility of... So that feeds into the RS3, I should say. You look at the accessibility, how vulnerable is the asset itself? What's its potential exposure? That sort of stuff. Build that information from our vulnerability knowledge base, which has multiple feeds. Bring that all in. And then the asset criticality. That will come from you. So how critical is the asset? Is it the crown jewels? Is it just Joe Schmoe's laptop? How important is it? What's its criticality? And we take all that into account and we build a score. And the scores might seem a bit strange. You might see the numbers when we have a look at the console, say like 400 or something like that. Think of it like a credit rating. So it's basically using that spectrum to figure out the scores. So that's the RS3. And we can use that to build out a risk profile. So once all that's in place, the journey to autonomous, how do we take that data and make it useful? So the first real big part of that from our side of things is the autonomous patch management. So we can take it to remediation. So we can automate your patching deployments, run through it, do it sort of like aligned to the E8 criticality. You can import your CV lists from anywhere, whether it's directly from our version management, or if you don't have the full suite and you just want to go down the patching path and you're happy just to use what you've got, you can pull your data from, say, like your tenable or something like that, bring it in, and we can put that into a patch group that will then go out. We can also break it out into routine, which I sort of missed on that list, priority, like zero day, and continuous patch management. And then using that, we have continuous compliance. From a reporting side of things, we can come out with compliance reporting. So how are you tracking against your patch settings and your patch deployment strategy? Use risk-based intelligence out of our patch intelligence feature inside there. Vulnerability reports that you can push out to your security team. And a lot of this can be done via user survey as well. So if you want to do something on the lines, let's just say a ring deployments for your patching, you can set up a patch survey, put that on your first ring. So maybe that's your maybe your testing team or something like that. User acceptance testing, that's the word I was thinking of, UAT. Push it through to them. They get a little survey, pop up in their teams. We've patched your machine. How did it go? Anything broken? Blah, blah, blah. And based on the sentiment from that survey, we can then move to the next ring. So that's something that we can do as well. So keep it automated, but also make sure it's being done off good data coming from your testers and users. So risk-based prioritization. So very similar to some of the few things I've mentioned here. Traditional CVSS approach, as I was explaining, the RS3 and VRR. It's patch everything marked as critical. Fine. That's an approach you can take. Is it the right approach? Don't know. Majority of patching effort is spent on low-risk items too. Is that something you really want to do? And then, you know, we've got something here about the CVSS9. No attacker is targeted given blah, blah, blah. So there's a bit of research being done around this. And a lot of the attacks that are being done are not targeting the critical vulnerabilities. Yes, they were, you know, initially if there were a zero day, because that's going to be used by an APT or something like that. If you don't know that vulnerability is there, the vendor doesn't know it's vulnerabilities there. Once it's public and being a zero day, the vendors are going to be very quick to get that patch, get that sorted. People are going to patch it. Everyone patches critical. Attackers know that. So you'll find that a lot of malware, a lot of attackers, when they're going through their processes, what they're targeting is more often than not the medium and highs, right? And you can see that using our patching through patch intelligence, which I'll show in a sec, what has, you know, active bugs, what's actively being exploited out in the wild. We can use that as part of the approach too. So with that risk-based approach, you can prioritize, you know, the vulnerabilities attackers are actually exploiting, you know, using, you know, AI-driven prioritization. So we bring all the data in, we figure out what we've got there. We can tell you, hey, you know, this particular vulnerability or this patch, we'll sort out X, Y, Z vulnerabilities, which are being actively exploited. And that's going to help you just effectively protect your platform and lower your attack surface. And that also flows into continuous compliance. So we know with patching, we'll have a look at in a sec, we've got the three different ones we've mentioned. Continuous compliance is, I guess, the best way to look at it. It's bringing things out of band up into specs. So a lot of enterprises or companies or whatever, they're not building laptops to demand. They're not brand new images. You know, they build them in bulk. They might throw them in a cupboard, give it to the new starter. It's been off for three months. It hasn't had its patching. It's going to be at risk. It turns on, it checks in. We look at that and you go, mate, you're out of compliance. And then we effectively out of band, we'll bring it in and take it from there. And the way that it sort of builds that. So you've got the two devices here and your patch policy. Patch A is deployed to those devices. Patch B gets deployed. For whatever reason, it doesn't go to patch device two. So in this sense, maybe it's been off. Maybe somebody's on leave, something like that. And you can see patch A and B are now sitting in the policy as part of our compliance. So we can quickly look and say, all right, we know what good looks like because that's what we have set up for the policy. Device A, good. Device two, not so good. But then from there, once it turns on, we'll get there. So we're just going to quickly jump into the, excuse me for one sec while I find my button. Oh, here we go. Sorry. Excuse me. I'll have to just quickly, I think, stop that. Go to here. There we go. Cool. So this is our advanced neurons platform. And what we're going to actually quickly look at, what we're going to start with is around the exposure management side of things. So this is what we were looking at before in the slides before. This is the exposure management insights. You can see our asset visibility here as well as our exposure overview. Let's give it a sec to load up. This particular tenant is not local to me. So it does take a little bit of time. So you're going to have to bear with me. So we can see here the Sankey charts and all the information, pretty much what we saw before. So you've got, if we just go straight to the RS3 or even like down to tiers like CrowdStrike or whatever, we can see those. But let's have a look at the, based on the RS3 scores. What do we have at critical risk? We've got four assets at critical risk, but zero of those we've actually deemed as business critical assets. Nonetheless, you probably don't want that. So you can drill into that. What are those four devices? These are the ones we have here. Where do we find them? We can say, all right, we found these devices ourselves. These are Avanti. You can see when, and then we have these ones here from CrowdStrike. We can see their risk score. So as mentioned, it's like in the hundreds sort of listed similar to a credit score and what the exposures are there and what the business criticality is. So you can see this particular device is listed at 3,682 exposures, quite a bit. You can just drill into those, give that information straight up, and you can see here all the different ones we've got. Bunch of VRR10s. So if we say, all right, let's have a look at this particular CVE, which is quite an old one. You get all the information that you'd want to see about it. The CVS V3, V2, everything that you'd sort of want to see around this information. We can see here that we've marked it as a 10, and the three scores, this is a 9.8. So you can start to see where that difference comes from, what it is, what it looks like, what it came from. So this one was found by CrowdStrike, for example. Exposure tags. So this one, it's an exploit kit, Trojan download of Trojans. This one's quite bad for remote code execution. So this one can be used in attacks, right? From that CVE, you can also say, okay, how many of my assets are there? Luckily, in this case, it's just one. What are the threats? All those sort of listed out here. All the information. So you can say, all right, what is Microsoft saying? What's, you know, like all that sort of stuff about it. What the exploits are. Fixes and recommendations. So what you can do to sort that out as well. This one being Java, obviously it's more than just going to be Windows. It can also be Mac, it can also be Linux and stuff like that. So if we dive back over to Insights. Now we've also got a bit more information here. So overall risk score. This one is not populated in this particular environment, but effectively it trends. So you can say, all right, my environment as a whole, what's the score? You know, are we looking good? Are we looking bad? It'll give you that same type of score that you would have seen just before. You'll have a bit of like a chart here as well around how long have some of these been open for? Obviously you want not many open for more than 90 days, right? That means we'll be pretty slow to resolve them. So what's new? How long has it been there? That sort of stuff. And then a bit more basis down here, like your top five vulnerabilities. We can start to see some of the changes we're talking about VRR. So we can see here, we've got this, I marked as a 10, it was a 7.8. This one was a seven. So now what is that one? You can go into it from there. All right. This one is elevation of privilege. So obviously a pretty bad one. It was originally marked as a seven. Now it's a 10. So based on what we've been saying and the data that we have sort of feeding this information, we can say, all right, based on those scores, I feel a load. There we go. So when I was playing the VRR, this gives you a bit of a picture of that. I'll leave it on the screen if anyone wants to have a bit of a read. But as mentioned, we look at the base CVSS metrics. Are there exploits? Who's a threat actor? Are there threats? Any malware? And is it trending? So that's what we take into account more than just the CVSS. But you can start to see the picture of what this builds and how you can sort of approach that. So if we go back to here, a few more bits and pieces that you've got here. So this is sort of like a breakdown, call it a funnel, of the assets to exposure sort of breakdown. So you've got 89 exposures that are potentially vulnerable to ransomware. How many are exploitable and what's the criticality? So critical, high, medium, and then open exposures in general. So really you want to focus right down at this slide. These three assets are obviously not in a good place. You'd want to get those knocked out first, a bit more than three. So you get those ones sorted out first, right? Then move on to what's exploitable and then move down that way and just sort of take it by a risk approach and get it moving that way. And then just a bit of info around your assets. What are they? What's the breakdown? What's your asset versus exposure timeline? Just give you a good view of all the data coming in from all your sources. If you want to just have a look at your assets in general, they're all going to be in here. What are the sources? Where did they come from? Or if you want to look at the exposures, they're all here too. So that's the sort of view from the exposure management side of things and what we do with the data that we get from the chaos that's out there. And when you want to go down the path of remediation, if you move into our patching, we'll look at patch settings. We mentioned that we have the breakdown of, say, routine, priority, and zero day. And you can see that here. So your routine may be something on the lines of maybe weekly, maybe you want to do these as patch Tuesday with an offset of x amount of days, something like that. And maybe you want to use it as a ring deployment, as previously mentioned. One ring, sorry, two rings or three rings. Do you want to do an automatic promotion or not? Do you want to use a sentiment survey, as we mentioned before, to move it forward? That sort of stuff. So I'll just click that off for now. You can get a few options here too, around your scheduling. When do you want to stage your data? Do you want to do it by severity? Personally, I think doing it by risk is a more appropriate way to go. So maybe you want to do in your routine patching, you just want to target six and up. These are the ones that are going to happen, you know, out and about. Happy days, that's going to get that sorted. You also have the ability to do specific include or excludes. So maybe you want to build a patch group of excludes. So while it is a lot of vulnerabilities in Java, Java is a good example of this, where if you update the wrong version, you can start to break out applications. So maybe you want to do an exclusion list or something like that in there. Do you want to include the enabler packages? And, you know, to get that sort of free to do your feature updates for Windows and stuff like that. Do you want to hit everything or specific products and vendors? Obviously, it's a very big list. So it depends on how you want to approach it. And then how do you want to do your reboot schedules? And then from there, maybe you want to move to priority. You'll see a very similar breakdown here. These ones, you'll say, all right, we're doing patch Tuesday in that one, we're going to do weekly in this one. And with this one, we're going to have a look at, say, eight and up, or something like that. And maybe also want to do that for specific products or something. You can say, all right, this will run weekly, we'll get that sort of locked in. And then finally, with zero day, this one, we sort of do daily. So if we're thinking, ASC 8, for example, you know, Apache criticals within 48 hours, stuff like that, this is the target. So potentially, with this one, you might not want to do a deploy by severity, maybe you want to do deploy by group. And you want to do a deploy by group, and you want to do a deploy by group. And you want to say, okay, we'll say this group, for example, is one that we want to do. And we'll use that as the baseline for this. The other ones that we've done, we need to get done. And then the continuous compliance. So as mentioned before about hitting those ones, executes daily, finds anything out of compliance and gets it going. This one's pretty straightforward. There's not a lot of information in here. As it builds, what good looks like for you based on the routine patching that occurs. And as well, we have patching here for Mac and Linux as well. So I'll just say, we'll call this a webinar and give it a save if I can type. There we go. So we didn't include for patch groups there, right? Give it a second to save. There we go. So how do those patch groups work? So we can move into patch intelligence. What this is, is effectively a massive list of patches and when they were released. So we can see we've got ones here from June 17th. So that'd probably be, I think, US time. So these are pretty recent, today-ish. Most of these are Mac related. You can see what you've got in there. You can also hit the magic effects more environment button. These are the ones that have been released. So what they're looking at. Reliability. So using our information, what we see from patching, we got reliability in place there. Do we see it getting rolled back? Do we see it moving? Are there reported images? Sorry, reported issues with the patch. So if you click that, we can say, all right, there's a reported issue here. Do we see it get expiration? That sounds pretty bad. Might not want to roll that one out. You might have to, you might get BitLocker issues or something like that, right? So we have all that information there for you. Let's wait for this to come back. There we go. And also, when I was talking about the CVE count, we can see this one here. It fixes one CVE, and it has a little bug. And that bug means there's an active exploit for it. So this one, this threat type is uncategorized. But if it was being used actively in, say, like a remote code execution type of thing, we'll see that there. We've got the scoring here. So the CVSS, so in this case, the CVSS is actually higher than the VRR. So while this one has an active exploit, we're not really seeing it being used. We're not seeing it being used. May not be as big of a problem. It is 7-zip. So, you know, may not be everywhere. And once you see those patches, and let's just say these are the ones that you want to do, we're like, cool, what we're actually going to do is do it based on this. Let's just say I want my criticals. All right, let's add some highs in it as well. There we go. So for that zero-day group that we mentioned, that daily one that we want to run, we've got three patches of windows, four patches of windows, one for Adobe, one for 7-zip. We want to add that to our patch group, and that's going to start, that's now going to become part of that daily patching that you're going to see there. So that's sort of how we get it together and bring it all together and get you from, you know, the disparate data to a more automated solution of getting everything sort of patched. And a quick, one last thing to look at, I guess, here at the top, we also have a breakdown here of your known vulnerabilities, what are your patch types. These obviously can be filtered on the inside of the API, what are your patch types. These obviously can be filtered on the information below, and what devices are exceeding SLA. The SLA is configurable, so you can set that to whatever you'd like it to be. Cool, so if we head back over here. So one thing that we want to just point out at the end here, we're seeing a lot of what we're calling the patch apocalypse. I'm sure we've all seen it, I mentioned it before, the Anthropic Mythos stuff, with more and more and more sort of, I guess, vulnerabilities being found like, you know, daily, what people are doing about it, what's everyone saying about it. So a bit of information here around that. So AI is outpacing defense, it's being used by vendors, it's also being used by attackers. And I'm not sure if you guys have been keeping up, but there has been some recent exploits that have been made by AI. So it's now finding the exploits and then making an attack for it. So happy days. What's happening around this is going to get pretty interesting, right? So what are you going to do about it, I guess, is what you have to figure out. But this is what our sort of approach and what we're looking to do. And what we're offering as well is we're doing what we're calling the CVS sort of thing. So critical vulnerability, what's called like scans out there, it's no obligations. So if you guys would like to basically see what this does in action, you can reach out to us and we've got a couple of options there for you. So we've got endpoint hygiene. So we'll do like a full asset discovery and up to 25 devices, do a bit of a risk-based patch approach demo for you, have a look at compliance reporting, all that sort of stuff. Or we can do the full posture where we actually get the edge intelligence information out there, get the AI healing bots out there, do some external attack surface sort of information for you and build a full report for what we discovered, how's it all looking. An executive readout, little glossy one-pager that you can have a look at, see if you're happy with it or not. It might just be some good information for you to have. If it's something that you want to look into further, we're happy to take that further as well. So if that's what you're looking to do, just reach out to us, email me, email us in general, we'll be able to help you out. Thank you guys and enjoy the rest of your morning or afternoon now.