Bespoke Kill Chains and the End of Signature-Based Email Security
Attackers are no longer sending mass phishing runs — they are using AI to build one-off, bespoke kill chains that are architecturally designed to slip past every gateway you own. Alan LeFort, CEO and Co-Founder of StrongestLayer, joins Alan Shimel on Techstrong TV to unpack what his team found when they dissected 5,000 malicious emails that had already bypassed incumbent defenses: 36 distinct evasion techniques across five categories, and 1,400 permutations of them. Alan walks Alan through the “COVID model” that has quietly defined 25 years of cybersecurity — infect a victim, capture the signature, share it downstream — and why that model collapses the moment every attack is as unique as DNA. He explains the StrongestLayer approach: a synthetic analyst backed by forensic collector agents that reasons about each email in real time instead of pattern-matching against yesterday’s IOCs, plus real-world examples of DocuSign impersonation via SendGrid and CAPTCHA-shielded proxy pages.
Transcript
Hey everyone. Welcome back here to Techstrong TV. I'm really happy to introduce you to our next guest.
It's his first time on Techstrong TV, so let's welcome him. His name is Alan Lefort. He's the co-founder and CEO of a company called Strongest Layer, and we're going to find out all about it.
If you're not familiar with Strongest Layer, not to worry, we're here to tell you about it. But first, let's find out more about Alan. This is Alan welcoming Alan.
Alan, welcome to Techstrong TV. How are you? I'm doing great, Alan.
We're excited to have you on. We're excited to hear more about what you're doing with Strongest Layer. But before we do that, I always like to start off with helping our audience understand who it is they're watching or listening to.
So give us a sense of how you came to co-found Strongest Layer. What's your journey been like? Yeah.
Well, I'll start with my journey in cybersecurity, because Strongest Layer is a cybersecurity company. I've been in cybersecurity over 25 years. I've held a series of roles, generally in product and strategy.
But very recently, I was at Proofpoint, where I led their security awareness business. Before that, I was at McAfee on the consumer side, where I focused on protecting the- Sure ... millions of people on the planet that need protection.
And there I held roles like Chief Strategy Officer, VP of Product, and a GM for a business. And then before that, I was at AVG as a VP of Product. So just I would say I've held- That's a name I haven't heard in a couple of years.
Oh, yeah, premium antivirus. And I lived in Prague- Right ... in the Czech Republic for a couple of years, wonderful period of my life.
But I would say I've spent 50% of my time in the enterprise and 50% at consumer, which has given me a unique lens into thinking about security, and giving it more of a human aspect. So, with that background, when I had the opportunity, when I met my co-founders, who had a thesis that AI was going to drastically change how attackers operate and it would require new solutions, it was the perfect timing. I believed in the thesis.
I had the background that let me believe in that thesis, and I joined. And I've been going at it for a year and a half, happily frustrated every day. Well, that's life in the cyber world, right?
Like you, Alan, I've also been in security. We didn't call it cyber. No one called- Correct ...
it cyber 25 plus years ago. I first started in security in the late '90s, and it's been quite a journey. And you're right, AI is fundamentally changing the game.
When we look at email security in particular, right? I remember when my son was in middle school, I helped him with a science project. I did the science project.
Who am I kidding? I did the science project with my son. We tried to teach his class about phishing.
And my friends over at Carnegie Mellon University, they had spun out a company, I think it was called Hedgehog or something. And it was like a phishing awareness kind of program where they give you a test and see real or not real kind of thing. And we made a fake phishing mail with a fake site that people would click in to give their password.
And 60% of his classmates fell for it, including the teacher and the parents of the kids. Thank God it didn't really go anywhere. " But that whole game has so changed now, right?
Most of these phishing mails were written by people who used English as a second language, or they weren't that great writers to begin with, or there were so many easy telltales that would help you identify phishing. Now, even myself, and I consider myself somewhat of an expert on it, I have a tough time. I have to really go into the headers and pay attention here.
So, your co-founder's thesis was absolutely correct, right? Absolutely correct. In reading your background and then preparing to interview you today, an interesting sort of irony pops up.
Here you are, someone who's spent most of your career trying to protect both individuals and corporations, organizations, from a email threat that really has so morphed, so changed, right? It's almost like they're using it against people now, right? Mm-hmm.
What you thought was great three years ago isn't. So, yes, it's frustrating, but it's also, I imagine, invigorating. When you get up in the morning, what are you really thinking about with that?
I think, especially with AI, there's a couple things that happen. One, the pace of innovation that's happening on the attacker side means that you can't stand still. Things are moving so quickly, on that front of innovation.
And the power that AI represents just keeps growing 10X. We just saw it with Mythos, right? Mythos was a big release.
It scared everyone There's going to be a new Mythos. It probably won't be called Mythos, and it's going to come in nine to 14 months. " I'm like, "Don't worry about Mythos.
" So you can't-- This is not the point that you should be focusing on. You should focus on the curve and being ready for this continuous change. And so we think about that a lot in our business, right?
We know this drastic curve that we're on is just in the middle of a steep slope, so we have to keep pace with the innovation. So every day I'm like, I'm thinking about how we're going to face this threat. There was a '90s cartoon that, I wrote this in a blog, that I really feel like I live in today, which is, there was a Warner Bros.
cartoon called "Pinky and the Brain," and it was about two mice- I remember it ... " Mm-hmm. And it feels that way sometimes, right?
And then they fail, and they get up and they are taking over the world again, and it just repeats on a cycle. But that's the life of a startup. Every day you wake up convinced that you're going to bring something unique and magical to the world, and you don't quite get to your goals of the day, and you get up again, and you try again, and then you just inch your way forward.
And so, I'm motivated by the problem. I'm motivated by the possibility for innovation because we get access to these tools as well. And our output is 5X, 10X what it might've been five years ago.
So the ability to see our ideas come to life is measured in days, not quarters or years, and that's just incredibly invigorating. Pretty amazing. If I may add, I think you wake up like Pinky and the Brain, but by the time we go to bed, it's hedgehog day, right?
Very literal. There is a little of that, for sure. But when we look at this, though, part of it is what worked for us yesterday doesn't work today, and certainly won't work tomorrow.
Right? And so what is it you're doing that helps people, right? At the- Yeah ...
at its nitty-gritty, right? What are you doing now differently that helps? Well, we've had to do something differently because the attackers are doing something differently.
We actually analyze-- So we're fortunate in that our technology is literally the last line of defense. We connect to email inboxes, either through Microsoft or Google, through their APIs. So if there's any preventive technologies that secure email gateways that are policing the email, they do their thing, the email gets delivered, we get a copy.
So we actually can see what things are potentially getting through. So we looked at 5,000 alerts of things we caught that got past all these other incumbent technologies, and something really interesting surfaced. And we went in with a thesis that AI was going to hyper personalize emails, what was canonically called spear phishing, where you're targeting the person with intention.
And that that was going to be harder for existing solutions to solve for. So we looked at these alerts, and we did find that, but we found something else a little scarier. We found a system, a systematic approach to evading detection outright.
And we actually found that of these 5,000 alerts, there were 36 different ways they could evade being detected across five categories, each designed to nullify a technology in the stack of the protection. And 1,400 permutations of those evasion techniques out of the 5,000 alerts. So we expected mass- Wow ...
personalization. We found bespoke kill chains. Like a level of sophistication that was just mind-boggling.
So you might be asking, why did we see all these unique techniques? And I'm going to go a little bit into architecture because I think it helps understand. The way security is built today, the whole industry is based on the same model that we all lived in COVID.
You need to have some victims where you analyze the logs, the evidence, the what have you, the medical records, to understand what went wrong, to devise a signature, in this case, it was truly an antivirus, that would be pushed out. And so when you think about that and you say, okay, you need to have seen it before, understood it, to stop it. Which means you need to have a group of data that says, "Okay, I see what's going on.
" But what happens when AI allows you to personalize the content to the person, personalize the attack chain to the person and their infrastructure, then these attacks stop being marketing campaigns and start being as unique as DNA. And if the existing technology needs to have seen it before, and there's only one copy, and you get one chance, they're effectively blinded. So the only way to solve it is to think from a perspective of, if every attack was unique, how would I solve it?
How would I prevent it? And that's through reasoning, where we've created a very powerful synthetic analyst with a group of forensic collector agents that are getting all the evidence, feeding it to this analyst, who then is looking through all the evidence as if they were a judge and weighing the positive and the negative and making a verdict. And we built that very reasoning platform that's allowing us to stop these attacks that are unique.
So part of it is almost, back in the day, we'd call it crowdsourcing, right? You're crowdsourcing what you're seeing across your base of customers, and looking at the traffic here and there, and that creates, I want to use the word intelligence because that's a loaded term these days, right? But that creates the knowledge base, if you will- Well, we- ...
that helps you identify these kinds of attacks. So yes, but differently. Good.
Traditionally, reputation is, "Hey, I've seen this URL before. It was bad," right? So we would call that indicator of compromise, and then we'd put it on a list.
" And they have a list of known bad links. Here's the challenge. Those evasion techniques I spoke of, one of them was to abuse trusted services.
And so, for example, one of the biggest attack types that we see in the business world is DocuSign impersonation, a very fake-looking signature request on a contract. net, which is the same service DocuSign uses. net, they just got their credit card out.
Right? So now the system says, "SendGrid, oh, that's a trusted site. All DocuSigns come from it.
Let it through. Oh, let's look at its authentication, DMARC and DKIM, where we say, 'Is this a legitimate domain? '" That all comes out clean because, again, SendGrid, perfectly good.
Now, the other thing they've weaponized as well, is to evade the scanning, is to do multiple hops. So often it'll be a link that's very trusted from Microsoft or Google that will then go to a Cloudflare CAPTCHA or another CAPTCHA. Then behind that CAPTCHA is the malicious page, a proxy or some other thing that's trying to steal your credentials.
And because most of these systems are trying to go fast and in real time, they see the first link, they see it's clean, they'll let it through. Maybe they'll follow the next link, and maybe they'll solve the CAPTCHA, but most won't. And with these new techniques, they've effectively blinded reputation-based systems.
Wow. That's so funny. Actually, so I've been using this email program, I'm not going to mention it, I'm not here to plug them.
It actually crashes on my Mac. It only runs good on my iPhone and iPad. But what it does do, I've been noticing, is it strips out the SendGrid, the SendGrid trackers, and the SendGrid following things.
Now, I wonder if that is a security, I assume it's some sort of security thing, but it's interesting. That is the world we live in today, right? What you just described, those hops, and it goes through a Cloudflare.
We also use Cloudflare, and I see that manifest itself as well. This isn't your grandma's email anymore that we had when I was setting up a Sendmail server in 1998 to do our own email in-house because we didn't want to pay Microsoft to set up an Exchange server back then. These are very sophisticated attacks.
Allan, we're almost out of time, but for people who want to get more information, give them the on-ramp here. Yeah, absolutely. Well, everything I've told you, we disclose fully on our website.
We're not a stealth company. We want everyone to know what we're learning, and we're sharing it in real time. com, you will find a lot of information.
org, all of that thing I talked about, the evasion techniques, the new way that they're attacking, it's all laid out, with excruciating detail of how each attack works and why they work. So we're very proud of sharing that with the community. So that's another way to learn about everything we talked about today.
Excellent. All right. Strongest Layer.
Check it out. Allan Laforte, co-founder, CEO, here on Techstrong TV. We're going to take a break.
We'll be back.