Exploring the Future of Security with Fred Wilmot | Black Hat 2025
Fred Wilmot shares his journey from the Navy to founding Detecteam, discussing the impact of AI on security. He highlights the benefits and challenges of AI, while outlining future plans for Detect Team to lead in detection engineering and community collaboration. The importance of relationships and credibility in marketing for security companies is also emphasized, concluding with an invitation for further engagement.
Transcript
Hey everyone. We're back here at Black Hat, still back off the floor in our suite here, uh, studio Suite, doing videos. I'm really happy to have my next friend up.
I, I think I mentioned it on few videos today. One of the nice things about coming to Black Hat RSA industry gatherings, unfortunately it's only twice a year, but you get to meet with your friends. You get to meet with people who, you know, you've seen come up through the ranks with you and, and their careers have, have, you know, gone in really interesting places and they've done interesting things.
My next guest, here's one of those, his name's Fred Wilmont. I know Fred. Geez, Fred.
We, we know each other at least 15 years. 15 Years, yeah. Yeah.
At least. Yeah, I think maybe more, to tell you the truth. The truth.
'cause I was still, it's still secure. That's right. And I left still secure in oh eight.
Oh yeah. Okay. It might be closer, closer.
18, 20 years. Yeah. But anyway, Fred is the founder of a company called Detect Team, and we're gonna find out all about Detect Team.
But let's first let Fred, lemme embarrass Fred a little bit and tell Fred, tell, share the, your story, your journey with the team here. Uh, so, uh, I started off, uh, after I got out of the, uh, the Navy. I went to go work for IBM and, uh, moved out to Seattle, uh, where there was this burgeoning, uh, scene of startups.
com was there and all these things. Yeah. And I hadn't done any security work at all before.
Um, and I started working at this company called Rabine, which at that time was $600 million in venture funding. Dan Hassey, the CEO of at t Wireless, like whole thing. And I ran into some really interesting, uh, characters over there that were probably all on, you know, CIA work release programs, but, uh, some of the best security guys that I've ever met.
And, uh, I mean, sort of have one of those moments of clarity. First time you could follow a colonel, first time you figure out how to do something in exploited system, you know, all of these types of things. And it was just intoxicating, uh, from that perspective.
So, you know, from there on, I, um, spent a bunch of time doing that. Uh, that's managed services stuff and, you know, forensics and, and incident response and, and detection engineering. Uh, and then I went to go work for, uh, sort of like this weird curve of work for a vendor, work for, you know, a commercial entity or something like that.
That's a, that's a well-rounded career right. Going on both sides of the street. Yeah.
And I think that actually really serves you well when you try to figure out, you know, am I building something that's purposeful? And if I were a person using it, why I even care. Right.
What is that person? What's that person's experience like? What is, it's their point of view.
That's right. So, love it. A few of those curves.
Uh, I spent some time at Symantec and Disney, and then I, uh, I went to Splunk on unwillingly, went to Splunk when it was super small, and I was probably the first security person, uh, there that they hired in the field. And, uh, we started doing a bunch of work there, building products and building services. And eventually, uh, this thing enterprise security came to be.
And that was a lot of fun. And, um, we spent a lot of time with customers actually solving problems. And that was really intriguing.
Um, and then I, I sort of got hooked on this, um, machine learning, automated data science platform thing. I did some of that. Um, and I spent some time with, uh, Richard Clark and my zko, and we tried to build a, you know, sort of this, uh, ensemble model that would help find adversaries, uh, of the advanced persistent threat nature.
Mm-hmm. Um, and eventually went to Packet Sled. And, uh, which was, uh, if you could drop a packet sled box in any environment, in as an instant response tool, we could find bad guys in four, eight hours Right.
And take action. And, um, that was used widely by, you know, uh, even the CrowdStrike guys and some other, uh, Cylance guys on their forensics and, and, uh, and programs for customers. So a lot of fun there.
Um, I then went to Devo to build something to take out the Splunk product, enterprise security. Mm-hmm. Called SecOps.
And that was an awful lot of fun. Um, it was a great opportunity. I also was CISO there too.
I had the luxury of going back and forth to Spain every couple of weeks. Poor you, poor Me. VO was Madrid, wasn't it?
Diva was Madrid. And I was the only engineering leader in the us And so, um, awesome opportunity to go build rapport, you know, get culturally, you know, embedded of Some, uh, you know, black Acorn Hamon. Oh, you know, it Hamon the top shelf.
Oh yeah. Spectacular. And really olive oil, the culture of the people there.
It, It, it's a great, it's a, it is a spectacular country. Yeah. Spectacular people.
Yeah. Agreed. One of my favorite places.
Uh, and then after that I wound up at, um, a little startup, uh, uh, that's an I, uh, identity provider called JumpCloud. Um, think inherited That. Yeah.
Not too tiny anymore, but, uh, a lot of really, uh, cool, interesting problems based there. And I thought, well, I haven't done identity yet in my career, and it's so critical. I mean, and we know today, well, It just came out this week, right?
25 billion worth of critical right there. That's right. Um, of course not JumpCloud.
I wish my friend Raj the best with that. But, uh, in this case it was CyberArk and, and the folks at Palo Alto. Um, so after JumpCloud, tell Down, tell us.
Yeah. So JumpCloud then I, I, I was doing sort of just CSO work, so kind of a, in my mind, that was a part-time job, not because the CISO job is part-time, but because I've always done products and engineering and CSO things. So for me it was, um, great.
But I wanted to build something. So I went to go work with, uh, Nick Lanta and some guys to sort of build the, we, we, we built the first, uh, um, CEM platform mm-hmm. Uh, as it were.
And, uh, wanted to create this risk index and so on. And, um, that was really preparatory work. 'cause I felt there's a bunch of things that I needed to learn, even though I, you know, sort of got battlefield promoted as a CEO while at packets, there were a bunch of things I thought I needed to learn.
I thought that would be a great mentor for me there. So after leaving there, I came to, uh, to, to start this company with my buddy Sebastian called the tech team. And this was born out of the problem that a lot of customers asked us over time.
And, you know, I, I felt very guilty that we had been building rules and, you know, correlation rules and these searches and that over all these years, you know, to know that they don't actually really work all that well, or you're not sure whether they do work. And, you know, customers would ask us regularly like, what, what does this thing do? And I could show you how we tested it.
I could show you the things, but I couldn't tell you. You would actually find something with that. So we started the ideology of the tech team because of that problem.
And we got to put it in the water, uh, through the 16th Air Force at the time. We were doing something to help the help build their cyber weapons platform, uh, capabilities so that, uh, cyber weapons officers could find bad guys. So we started creating scenarios that would help, you know, identify different areas where this character risk or these behaviors and this order of operations would help signal what this would look like if this were an advanced persistent threat over time, over these behaviors and systems.
And as it scales out, um, including building, you know, hydrating the same organic size of an environment as a base or a network or, you know, JPMC or you know, whatever. And through that, um, we realized there's a path here to not only help figure out how to write great detections, but also how to make sure your responders know what to do when that happens, and that your responses work the way it's supposed to. So we found a detecting and, uh, what A great story.
It's been, it's been a lot of fun. It's been a great ride. You know, you're a humble man, Fred, right?
There was a lot of, uh, so having not walked in your shoes, but walked alongside you, let's say during all these adventures you've been on, I, I think you, uh, you underplayed your role in the success and, and kind of, uh, groundbreaking kinda work, right? When it comes to security and looking at things differently in new ways and making it better. But here we are.
Here we are, um, understood What detect team is, is about how, you know, what was the idea behind it? Did you think you'd be sitting here, black hat 2025, and you go down to that floor, you've been down to that floor, can't, you can't say a sentence without the word AI in it. Um, people are talking about replacing security people with, with AI things and, and, uh, agents.
I, I was just, yeah, I was interviewing the CEO of Qualys, my friend Sum Met Yep. About their ai, uh, agentic ai, rock risk operation center. And basically, it's funny, you bring up a page of, okay, what do you want an agent to do?
You need an agent for Patch Tuesday? You press a button, it says employ like that. You really, that's hiring someone.
Yeah. You want an agent to do this? Boom.
You hit the employee button for that. They have names the agent, Sarah, for Patch Tuesday, Debbie for this, and Tom for that. How does that vision and where this is taking us, where's that lead tech team?
Is that something you guys piggyback ride? Is it something, Hey, when you're done playing with that, come over here. What, what, how does this all fit in?
That's a great question. There's a lot of promise in all of the capabilities that AI can help materialize. Mm-hmm.
Some of those things that we see and we talk about all the time. Yeah. If you've done it 15 times and 15 minutes, then that's an automation problem that should be solved.
Right? If you have something that you spend the same logic, uh, uh, filters on the understanding of this problem space, and you do that over and over again, also Automateable, right? Uh, soar automatable, okay.
Those types of things that are process automation problems. Great. Some of the inference, uh, things also great.
However, uh, the challenge is today, the bar is pretty low. Uh, to do something impactful, I think to optimize, uh, a low bar of process achievement, to operationalize a better way to look at intelligence data or to grasp more information and more context or more semantic analysis of a set of data we didn't have access to before. But fundamentally, that doesn't make you any more secure.
And part of the challenge that, you know, we look at here, we, we use AI too. Sure. Uh, we've got a very small team.
If we're not using ai, that's not very smart of us. However, validation, confirmation, and transparency, all those problems we always used to talk about governance and provenance have to be front row seats. If you're going to say anything is evidence.
Yeah. So if we're going to prevent, you know, certain things from happening or detect certain things that are happening, we have to have. Cause otherwise, how do you know what you did when you did it and when it changes again.
Yeah. Context, window of promise is not that big. And the number of tokens you spend to do certain things right, has an effect on how high quality it is, which model you're using, how many parameters, all the things.
But the bottom line is there's an awful lot of value in helping automate that process to reduce time, increase expertise, apply to the problem. But it's pretty critical to make sure you have smart security people doing the real work. And, and I don't think, excuse me, I don't think that's changing anytime soon.
I don't think so either. And I think pretty smart security people will leverage AI 'cause they're smart enough to do that, not run from it. So I I, I think that's gonna make a big change.
Um, as you sit here though, let's, okay. We look back, we looked at where we are. Let's look ahead, how do you see the mission at detect team changing, morphing, evolving, short term, six months, 12 months, longer term?
Can't go too long 'cause we can't see more than 24 bet. But t there's a horizon 24 months. That's the horizon.
Where do you, where do you see detective? So we Are really interested in becoming sort of the arbiter of truth around detection, engineering. We have a platform that we think everyone can use.
We understand everyone's languages, a Rosetta Stone. Mm-hmm. And while it's interesting to say those things, it's more interesting to say, help me understand accuracy, help me understand quality.
Help me understand coverage. And if an industry can rally around a single way of scoring, measuring, evaluating, and deploying a rising tide will raise all boats. So if we thought about it, we would say every SIM should use us internally, all customers, their ability detection should use us.
It doesn't have to be built in ai. You can use text objects, you can write your own things. Yep.
You can craft anything you want. But most importantly, it's a harness. It's a testing harness.
And so when we decide that we wanna build a detection or I wanna take a, some finished national intelligence from or something, I turn that into a scenario. I generate all the data from every class and type of data that it, it should generate based on the TTPs. I can send those anywhere they need to go.
I can send those everywhere they need to go. I can send that from multiple clouds into every place. It needs to go in every place on the planet.
And then we can generate detections that are illustrative of the context of your environment or don't turn the context on. 'cause you want none of that information to be mm-hmm. Involved.
So when we think about that, uh, there's a lot of, I think, hyperbole around generate me a thing, right? Go get me some cloud code action here and generate a bunch of detections or generate a bunch of data. And there's a lot of challenges in making sure you have the right answers, not just answers.
So we think if we give the community an opportunity to build right answers, right, they'll, they'll go out that and take charge and that will, you know, that will help the industry in that sense. And so we think that's a great opportunity. Love it.
Hey, I'm gonna pivot a little bit. Um, this is not necessarily your security com a security question where they're gonna give you a CEO question. Sure.
It's a crowded floor out there at Black Hat Security. You know, the last time I looked, I think it was 6,000 or 6,500 venture backed security Companies, right? Or public, you know, commercial security companies, AI changing the game in marketing go to market, not just in how we're using it for better security.
How do you as a CEO make sure that the tech team gets its fair share? That's a great question. I believe, uh, at this stage of the company, um, and maybe my whole career, the proof is in the pudding to start with.
So you have to be able to operate with your friends, your peers. You've established credibility over the course of your career by doing the right thing and doing something purposeful, meaningful that you can stay in mind. Uh, we've been fortunate to have a lot of communication with folks that have seen that have done that and participate.
Um, that indirectly answers your question because all of the AI first companies that are now using AI to build their marketing, right? Uh, I did an exercise the other day where I took five marketing messages and put them next to each other and ask people which products they were for. And of course the most of them are wrong.
Um, and the rationale is because everybody does, uh, sort of a good click through on on that builds their slides this way, right? They're building websites in the same way, uh, hiring people with resumes. Same problem.
And so what do you do? It's actually rolled the clock back. And so just like a handshake, just like a phone call, right?
These are the ways that, you know, we know people are starting to Business. Relationships matter. Relationships matter.
Turns out. Yeah. It's always true.
And I think that's the thing that we've, we've sort of leaned into heavily, um, down the road. I think this is going to become a little bit more chaotic and obviously more of the traffic that's been generated around marketing, messaging, uh, communication on the internet. You know, as more and more bots, you know, continue to communicate with one another.
I I believe there's gonna be sort of a turnoff moment here for some of those behaviors. And people are gonna have to figure out how to sell something that matters of value to people that they know and that they don't know in new ways. Yeah.
So it is a challenge. I don't, uh, I don't see anybody's No, IIII think, I think there's a lot of marketing people in security that're just kind of pulling their hair out if they have hair, you know, that, that said, how do you, how do you play in this field? I mean, it's a different, it's a different stadium.
Anyway, Fred, we're gonna wrap up, but for people who want to get more about detect team, where should they go? com. Uh, feel free to reach us out there.
You can get us on, uh, on Twitter at uh, detecting Inc. Or feel free to send me an email, Fred, at detect you, uh, rap with you for sure. Absolutely.
And if you like listening to Fred, he's usually on Friday mornings. Friday Mornings? Well, we record Friday mornings, but it's Monday.
He's usually on Monday mornings. It's we record. Oh, by the way, we record Thursday.
It is on Friday. Yeah. But you could see him on the text on gang.
How you Good, who are you? Oh, can you come back? We're just recording something.
Yeah. Oh, okay. Nothing.
We're good. Okay. bye-Bye.
What The f**k was that? Housekeeping. You wanna wrap up Again?
The land shark? Yeah. Let me, let me just do, just do the last round.
Alright, let me wrap it up and we're done. So you are on Fridays, the place Monday's or you're on Thursdays? The place Friday.
I'm on Thursday because usually you're on with Ira. That's Right. Yeah.
I love it. That's my good security day. We're The, we're the tandem, right?
The yin And yang. I, Iris, I was of, uh, of Yeah, he's, he's, he's here. I saw him yesterday.
I All right, gimme come back. Counts him back. Oh, I thought that was your wrap.
No, no. Well, but yeah, but housekeeping came the land shark, you know what I'm saying? But you just Hit, oh, no, no, go ahead.
Okay. Three, Two. All right.
And you know, and if you like listening to what Fred says, and Fred, Fred always has a lot of good stuff to say. He's a regular on Textron gang, he could catch a most on our Friday morning shows. And he is usually on with Ira Winkler, which makes for a real powerhouse cyber team on, on the gang that day.
So check that out on wherever you're watching. Text on Gang. On.
Until then though, this is Alan Shimmel. We're gonna head one more time back to the floor at Black Hat. Uh, we'll wrap up from there.
And, uh, we'll, we will call it a day on our Black Hat 2025 coverage. Hope you've enjoyed it. Take care, everyone.
Bye-bye.