Transcript
welcome to the Security Sandbox this month. Got a great show for you today. We have some amazing guests here. We're going to be talking about our Mandiant Threat Intelligence Expansion Pack that we launched late last year. Got some fantastic guests. We've got Phil Treynor from Nozomi, who is our product manager in charge of the Threat Intelligence integration. And we've got the very talented Chris Systrunk joining us from Google Mandiant as well. Thank you for joining, gentlemen. Chris, how are you today? Hey, I'm doing pretty good, you know, recovered from the last event I was just at. So glad to be here with you both. Fantastic. Thank you so much, Chris. Phil, good morning. Yeah. Great to be here. Also, it was great to work with Chris and Google Mandiant. Fantastic. So this is something we are really excited about. Like I mentioned, this collaboration launched late last year and really want to spend some time digging into what exactly is it? How does this help Nozomi customers? How does this help Mandiant customers? And what are we actually delivering? So, Phil, you know, maybe if I can start off with you, can you tell us a little bit about this journey and how it's been collaborating with Mandiant to work up to this point? Absolutely. I mean, best people know tuning in that Nozomi Networks is the premier source for OT and IoT Threat Intelligence. And teaming up with a company with such breadth of knowledge of IT Threat Intelligence as Mandiant really gives it a new depth as to what we can offer our customers when they're really just completing the story as to what is happening in networks that are so, I guess, challenged to overcome security attacks as industrial control systems. And having those two systems just combined to offer the larger capabilities of being able to see that wider breadth of threats, it's an incredibly powerful solution to be able to do this. And we're seeing some actually very interesting results so far. Awesome. Awesome. Thank you for that. Chris, being a leader in Threat Intelligence, can you tell our listeners a little bit about why Threat Intelligence is so important in cybersecurity and how does this collaboration enable Mandiant to do more? Sure. So to kind of break things down, if you're not familiar with Threat Intelligence, basically, it basically shows what attackers are doing based on incident response that Mandiant and other teams around the world are responding to. What we see on the front lines, we want to get that information of these indicators of compromise or the tactics, techniques, and procedures that these threat actors are doing, get the word out about them and so that you can better defend yourself at a high level all the way down to a frontline defender. So that's kind of, in a nutshell, what Threat Intelligence is about. We're excited at Google to have just joined, Mandiant has joined with Google Tag and VirusTotal. So Mandiant Threat Intelligence, that's like a big group now called Google Threat Intelligence Group, and it's about 500 people. That's all they focus on is threat analysts, searching the dark web, getting information from our incident responses, working with our government and global partners. Yeah, there's a lot that's going on there to help really make this actionable intelligence. Fantastic. Yeah. So to help, how does it, the second part of your question, how does it help Mandiant customers and others, even Nozomi customers? It kind of shows you in a way of what the threats are active now, what are they going after? Are they going after exploiting, say, a type of vulnerability that was just recently disclosed or are they using living off the land type of attacks? And then that will help Mandiant customers better defend their networks and systems. And same with Nozomi as well, but now with this new integration here, you already had intelligence, but now you have some of ours now as an option. I love it. I love it. Thank you, Chris. Phil, so we mentioned that this came out late last year. Do you have any feedback or comments or stories from the field about how this is being received and how it's being used? 100%. One of the most valuable things that was combined in this one solution is all the interesting metadata and information around that. And that information, I mean, really pertains to things like first, last seen in the wild, is something exploitable, but also like what target industry or region and all those other just metrics that we're able to utilize within this. If I can share my screen and talk a little bit further in depth about it. Please do. Please do. We'd love to see live examples. So what you're seeing right here is Vantage. Vantage is the Nozomi SaaS solution. And although you can use the Mandiant add-on into Threat Intelligence in all of our products, this is really where you get the most value of it. A lot of these things are the target industry, target countries, and things. These are added to us by Mandiant. So we already had that breadth of OT and IoT Threat Intelligence. As Chris very succinctly stated, it is that known maliciousness. What are bad actors doing? How can we identify these actions being done in real time and alert users so they can make those critical decisions? I mean, the dwell time of malicious actors and networks is really what causes the most damage. People going east-west and being able to infiltrate other things and embed themselves deeper into these networks. So we've had a lot of different groups say to us, we have this very particular need. We need to say, we are a company that's very concerned with satellites. So do you have anything that pertains to satellites, for example? So we'll say, OK, let's take a look at what we have in there. We absolutely do. So you can see in a lot of these, they'll have the Mandiant logo built right into it. So this is the enrichment of it. And you can see how many different STIX indicators that are going with it as well. What's kind of crazy is we got millions of indicators of compromise from Mandiant, in addition to all of the cool threat intelligence. And it's barely adding any additional resources to us. We had to re-architect the way that we utilize memory inside of our solution to be able to incorporate this incredible breadth of different pieces of information all at the same time. Let me move this a little bit out of the way so you can see better. What's further interesting about this, as I can correlate this to, is this on my network. So the real value is, OK, I am a company that is concerned primarily with satellites. I'm a satellite company. Do I have vulnerabilities? Do I have alerts that pertain to exactly this? This is something that you wouldn't be able to do without the Mandiant add-on pack. You wouldn't know if it pertains to a satellite company or a certain type of manufacturing company or for a certain country or region. It really makes it narrowed down very closely to what you're seeing. The relationship between vulnerabilities and alerts is a very, very key one, and it's something that Nozomi is, you know, a real bread and butter as to what we're doing. Vulnerabilities are, we have looked at all of your assets. We know all of your assets. Do your assets have these vulnerabilities? It's a very proactive approach to securing your network. While the alerts are the other side of the coin, where have I seen this thing? Being able to narrow this down to not only are these my alerts, are these my vulnerabilities, but do they pertain to this particular industry? That right there is incredible value. Absolutely, and again, in keeping with the tradition of everything in the Nozomi family, this is all real-time, and as this information is hitting our platform, we are in real-time looking for those alerts, looking for those vulnerabilities. So I wanted to open up for Chancellor Chris to add into that. Yeah, and you know, this is a really fantastic option here, and for those of you who want to dig down into the nitty-gritty, you can see down at the bottom, I have packet rules, YARA rules, STIX, and you can even see, you know, the map to MITRE ATT&CK, MITRE ATT&CK Enterprise, MITRE ATT&CK for ICS. For the ones that really enjoy this part of their job in the SOC, you can, you know, really get down in the weeds, as they say, of what things you want to detect on. This is stuff we don't need to worry about. This is stuff we do, and you can tune it even more using these things. You can see the little buttons on the left there. You can turn them on or turn them off and say, if we don't need that, no, that's really all, that's over a decade old, okay, no problem. It's one of those things that you can really leverage this however you want, and then know that it came from a trusted source, you know, like Nozomi's research team, their threat intel team, and then ours as well. A really good point that Chris brings up is the update service and the rules that are being pulled into this. This is not a static concept. The update of threat intelligence is continuous, it is all the time, and whenever something new and interesting hits the wire, I mean, our both dedicated teams are putting this thing into the product as fast as possible. And what's really cool about Vantage especially is Vantage acts as a very efficient licensing server, it scales infinitely. So if you have systems being protected by Nozomi all over the globe, and even if you have millions of assets that you're managing, the threat intelligence from both Mandiant and Nozomi networks, when we get it pulled into our licensing server, you see here we have the TX expansion pack enabled and available within this one, it will push those rules that Chris and his team are creating down into all of your sensors all the time. It's an automatic thing. It's incredibly powerful to keep that up to date. It takes a lot of folks, as Espresso. Right, right. It takes a village. And many people have said that, it just makes sense. One cool thing though, a lot of the Mandiant rules and detections are from what we see on responding to malware, responding to not just OT attacks, it's all the IT, the droppers, the back doors. If those show up in your OT environments, that should send alarm bells off. So this is a really great way to detect these IT-based attacks, and these packages, these malwares that come in. If you could detect these, that makes you even faster to respond. 100%. Actually, there's a bunch of other interesting things that are built into these. If you look at some of the individual attacks on some of these, like these YARA rules individually, it goes infinitely deep into the different techniques being used by different users. It all ties in also, as Chris mentioned, to MITRE. And what's really cool about this is, this is jointly curated. So Nozomi absolutely does MITRE attack for both Enterprise and ICS, but having it combined and curated with the Mandiant information just increases the breadth of it. What I would love to show right now is this solution right now without the add-on and with it. But I only have one to show folks, but it's got all the built into one and just the increase of that information, including the map showing those targeted countries, where it's going, what it's doing. And furthermore, we have another concept called workarounds, where you're able to go in and see if there are actionable things that you can do to fix the vulnerability that you have in there to be more proactive. I'd say one of the biggest tenants of what the joint offering from both Mandiant and Nozomi is, we're trying to get people to be more proactive and to fix things in the network before they're exploited. We want vulnerabilities closed, not alerts noticed. Absolutely. Absolutely. Good point. Great stuff, Phil. And I know we've only launched this roughly a quarter or so ago. Can you talk a little bit about the adoption here? And in fact, can you even give us a little bit of insight as to what we had to do as Nozomi at the product level to be able to facilitate this influx of a huge amount of threat information? Definitely. Well, it's definitely no secret that Mandiant has a lot of threat intelligence to offer their customers. What's challenging about this, and it's a really good point, Cindy, is that we have physical sensors. You cannot have a car manufacturing or a pharmaceutical pill manufacturing plant in the cloud. You actually have to have a physical location that's performing these physical actions. So we have physical sensors doing this. So we have to push all these rules down and all this concept to our physical sensors. We've solved this in a number of ways. We've adopted a new concept called hardware as a service, and hardware as a service right sizes the solution to the customer network. So they don't have to say, I want two of these or four of these. We have our field people who are just very adept at understanding the needs of an OT network, be able to right size that with hardware as a service. But furthermore, our engineering team took immense steps to optimize the work being done inside of this. We had to create a separate database just for the indicators of compromise that Chris was talking about earlier, before it would be completely in memory. And now the solution has a fast read-write database that allows us to expand to, I believe the number is over 2 million new indicators of compromise and sticks. And to be able to do that and do that without having to swap out hardware, it's a huge accomplishment because we want users to be able to do that. I mentioned earlier that from within licensing, if you are a Vantage customer and you want to try it out within licensing, you just say, I want to try this for 30 days. I've already enabled it in my system and being able to do that will instantaneously via that update service that we showed a little bit earlier, grab all that content that Chris and Chris's team curated over years and years of just expert knowledge of the industry. That'll be pushed down to all of your sensors to try out. And like I said, it's not just the rules, Mandiant brings all of that curated metadata such as industries, countries, all the extra sticks rules. It's a lot of information plus the workarounds as well. It's a lot of information and we can do infinite things in the cloud, but pushing it down to the sensor. That was something that we're very proud of. Awesome. I can imagine huge value in this from a forensic analysis and incident response perspective. Just to remind our viewers out there, we will be doing some questions and answers after we wrap up here. So, please feel free to type those in and we'll make sure we get those addressed. Chris, I've got a great one for you. So, someone who spends a lot of time in the field, a lot of time with customer base, can you talk about any use cases or lessons learned that you've seen with this? And most importantly, how can this help Mandiant customers in an IR situation or an ICS assessment? Oh, great question. We've been partners with y'all since 2017. So, we've been using the ZOMI Guardian on our ICS assessments to help us in addition to some of our own tools and others, but we've been using the ZOMI Guardian since 2017 while we come to an ICS health check, also ICS compromise assessment, and maybe a few others. It's a really great tool and it helps save us a lot of time when we're coming through network packet captures and trying to get an idea of a customer's network that we need to get up to speed really quickly. Unfortunately, not everyone has good diagrams or up-to-date asset inventories or things like that. So, this can help us get up to speed to help that customer understand their systems, understand their communications. And in some cases, we've even found problems like TCP replay transmission issues where there was a broken switch on a conveyor line that was causing conveyor issues. And that engineering team had tried to solve it for quite a while and they were puzzled. They did not know much about network analysis, so we were able to use the ZOMI to find the broken switch and they got it fixed and it fixed their issues. And that's not even a security issue. But on the other hand, we were able to do an incident response on several customers in manufacturing environments that already had a ZOMI and Guardian in place. In one case, it was the first alert for that company to know that there was a different new version of or a broken version of WannaCry that didn't actually encrypt anything. And it was brought in on an engineering workstation through a remote access. And so we were able to leverage the Guardian there, run additional queries that the customer needed help with, and we were able to run queries, create a few new dashboards for that customer during the IR. And then after the malware and the threat actor was removed, we were able to validate these things, you know, no more unnecessary communications and made it part of their validation plan as well. So it was really great. In another instance, we were able to find an old malware that someone had brought in over a USB that was on a bottling line HMI and it was just reaching out. And we were able to find not only that the IT never alerted because they were blocked by the firewall. These attempts to communicate out with DNS were blocked by the IT OT firewall. But we were able to leverage the ZOMI to find out where all these HMIs had this malware. They were old, you know, Windows 7 with no antivirus, unfortunately, but we were able to have them look at the network and confirm that the ones that were beaconing out did indeed have some old malware. They were able to clean them and make that part of their detection, even though there was no, you know, successful connection to the internet. So that was a good thing. We were able to leverage the ZOMI in many ways, whether you have an IR or not. Incredible. Love hearing those kind of stories, Chris. Love it. Thank you. Thank you. Bill, I want to turn it back to you. I think you've got something interesting on the screen here. I wanted you to walk us through this, if you don't mind. And following that, Chris brought up a great point about dashboards, wondering if you have any threat intelligence specific dashboards you could walk us through after this. Sure, definitely. You know, it's very cool to have conversations with, like, you know, the CISO different groups where they like to have things become real, especially because they're having a lot of conversations with the CFO or other groups who are not as, you know, savvy with cybersecurity. Being able to say not only do we have an alert for, you know, we have seen this attack in our network, but I'll say, okay, who's the attacker? What else do they do? Is there, you know, naming conventions? Is there a way that we can make this, you know, tie this to larger groups? Can we understand the threat better? And that's really what the have alerts and have vulnerabilities do. Have vulnerabilities is that proactive nature, the have alerts is, you know, this has already taken place on the network. So for this particular, now this is a staging network. This isn't a real network. Obviously I couldn't show a customer network in this, but if we were to go into this staging network where we're trying out different scenarios and say, okay, what are the alerts for this attack dragonfly actually happened to place in this staging network, I'm going to see all the associated malware with it and learn more about the origination of it. We'll see where it is on MITRE. This conversation you can have is further up the chain. It's a less nuts and bolts conversation and a more, are we being proactive about new threats from China? Are we being proactive about new threats from Russia? What are we doing to hedge our bet? And these are the kinds of conversations that we want to empower our users to be able to make. And those higher level conversations lead to better awareness, better outcomes, and also just in general, safer organizations with respect to incredibly valuable assets that could be targeted. I mean, one of the most interesting things about the industrial control system and cyber physical networks is there are serious consequences to different attacks. These are pipelines that could be ecological disasters. These are pharmaceuticals are creating pills, the precision and the execution of these machines could hold our society together. And any failure on these on the catastrophic level could be a ecological or loss of life scenario. It's important to take things as seriously as possible. And we're very pleased to have Mandy and Chris working with us to get those better outcomes. And also, Sandeep, you mentioned dashboards. Let me scroll over to dashboards. We have a number of them. What's neat about dashboards, as you can see, these are some of the folks that work at at the Zoey, I had to create one terribly sorry about this. But dashboards are a instantiation of anything you could possibly view within the product. So if you want us to create a custom query, and the custom query would be, you know, alerts, for example, and you had a very particular criteria of the alerts that you wanted to go after, you could do so create a widget dashboard for it to always pair back to it and get incredibly granular with the scenarios and say where and then start digging into regions or IP addresses or types of equipment. I want to see alerts for all of my Rockwell PLCs that are in the plants that is in this certain location. And what's really cool about this is that those alerts and all the certain tells information will seamlessly be enriched with all the information coming from Google mandates. So if they have that metadata saying, I want to see what country I want to see what industry I want to see all these different things, you can create a widget dashboard based off of that. And that's a very powerful thing. Yeah, that's the really good thing that how flexible Guardian and Vantage are, you can really custom tailor your hunting and your searches. And if you have someone up, like you mentioned earlier, Philip, if you have, who was it who did it? Well, you know, the frontline engineers are not gonna care about that they're gonna care about the packets, the sticks and taxi and what does it mean for how do we pretend this from any attack, not just from a certain country, but then your CEO is gonna go well, which group was this group name and then you can give that information out of that intelligence to them and give them the information that they need, even though that may not be your main role. So it gives you the power to really look at the different ways to ingest this threat intelligence, gather the things that make sense for you and your environment and your location. And then also have a plan for connecting these and making the dashboards and alerts and all that stuff. Fantastic, fantastic. I've got a couple of questions coming in here. We have a good one from a Robert L. Robert is asking, how does an existing Nozomi customer go ahead purchasing this? Do we work with our Nozomi team or with our Mandiant team? Phil, maybe I'll toss that one over to you. Sure, no problem. You can sit before you can try it out for 30 days for free, if you just click on the expansion pack within Vantage. But I know that something being offered by the Nozomi team and the Nozomi sales team is selling this. And I believe this is embedded into the Nozomi product at this stage, that is the best way to go about doing it. Perfect, perfect. And again, just to clarify, you don't have to be a Vantage customer to take advantage of this. We've got a number of our traditional critical infrastructure customers that operate in air gaps and they can still take advantage of all this additional threat intelligence. That is correct. Awesome. Awesome. Chris, I have a question for you here. So with respect to the Mandiant TI feed, is that something that gets pushed to the Nozomi environment directly from Mandiant or does that get brokered through Nozomi and end up as part of their overall threat intelligence feed? Oh, I think this is more of a Philip question. I think it is actually. I got to the end of that one. Phil? So we've had a number of customers ask us if we could pair this out. So Nozomi does have a taxi feed that you can grab that is exclusively our data, but we are not selling an autonomous Mandiant solution paired out right now. So those things are, they're only combined inside the product. Perfect. That makes sense. That makes sense. Awesome. Well, I know we are at the bottom of the hour, gentlemen. I know it's been a quick 30 minutes. I want to thank you both very much for being guests on the show today. Phil, thank you for being on for the first time. Hope to have you on much more. I know there's a lot of other work you're doing with product management that aligns with what our customers want to hear about. So hopefully you'll come back to talk about something else. Yep. Happy to be here. Thank you. Perfect. And Chris, always a pleasure. I love it when I get to see you in the field. We often run into each other at conferences and seminars. So thank you very, very much on behalf of all of Nozomi for advocating for this expansion pack and alignment. And thank you for being an amazing guest. Glad to be here and glad to see that your customers wanted some of this stuff because that's what it's all about. It's about helping our customers defend their networks better than they did the day before. And that's what helps us sleep better at night, right? We're helping protect critical infrastructure at the end of the day, even solving small problems like a broken switch, creating havoc on the network. So this is a really great thing. Glad to be working with everyone at Nozomi, including both of you. And we'll see you next time. Absolutely. Thank you very much, gentlemen. Thank you for joining us today, everybody. Have a wonderful rest of your day. See you next month. Bye, guys.