Corelight’s Mission: Data-Centric Security in the Age of AI with Greg Bell
Corelight leads in network detection and response, with Greg Bell discussing his shift from government to co-founding the company. The mission targets advanced cyber threats, while the evolving role of AI and ML in cybersecurity is explored. Customer perspectives on these technologies vary, and challenges in integrating AI into SOC operations are highlighted. The need for defenders to adopt AI tools is critical as attackers utilize these advancements.
Transcript
Hey, everyone. Welcome back here to Techstrong tv. My next guest is Greg Bell.
Greg is the co-founder, chief strategy Officer, chief Bottle, uh, bottle washer, uh, dishwasher, bottle washer over at Core Light. Hey, Greg, welcome to Techstrong tv. It's great to have you on here.
Hey, great. Thanks for the invitation. I've been known to wash a dish or bottle or two, uh, so that's entirely correct, Whatever it takes to get the job done, man, that's, that's, that's the real titles, whatever it takes.
That's right. Greg Bell, whatever it takes over at Core Light. You know, Greg, we, um, we introduced our audience to Core Light during Black Hat over in Vegas, I guess, geez, a month, more than a month, almost two months ago now that I'm thinking about it.
Early August. Um, and correlate, of course, are the people running this sock at Black Hat, you know, a real high profile job, but not an easy task there. Right?
You get a big target on your back. And, and, we'll, we, and for anyone who hasn't seen it, we have the videos up on Text Drunk TV there. We did some great interviews and had a good look at the soc.
Go check that out. But we're here more to talk, Greg, about a bigger mission of Core Light. Yeah.
Not just the sock at Black Hat and, and help people understand Core Light too. But before we do, Greg, you know, how, how did you come to be co-founder, chief Strategy Officer here? Give us a sense of your journey.
Sure. Um, Alan, I didn't expect to found a technical startup, actually. gov and my email address at Lawrence Berkeley National Lab.
I'm sitting here in the, in the flats of Berkeley, uh, right near the lab and near campus where I went to grad school. And I had a very, um, interesting job managing the Mission Network for the Department of Energy. So that's the, the global ISP that interconnects the National Lab System and the Nuclear Weapons Complex.
Two very different kinds of customers. You know, one all about discovering, uh, and producing new scientific, um, uh, data and, and output and sharing it with the world, and the other about keeping everything secret and assuring nuclear non-proliferation. And in that environment, the, the software that coolite, um, is commercializing was invented and became very popular.
Uh, so about 10 years ago, some friends of mine, um, were, started a little company AER in a services mode just about provide services around the software. And I became the first customer. And I saw that there was a tremendous, not only commercial opportunity, but an opportunity to make a difference to the tens or hundreds of thousands of organizations in the world that were using this open source software.
Uh, it's called Zeke. Uh, and, um, I jumped in first cautiously, and then I left the lab, left a pension, uh, and leaped into startup life was CEO for about five years. Um, we've had very, and then transitioned, uh, voluntarily, which is a bit unusual in Silicon Valley to the role of Chief Strategy Officer.
And given my federal background, I also lead, I'm CEO of the federal subsidiary. We have a great deal of federal business, uh, and our progress has been Gratifyingly Rapid. We're the fastest growing, uh, and have been for about five years in our category.
And we continue to especially help large organizations, government entities, but, um, utilities, financial organizations, manufacturing, uh, large scale tech, um, solve problems associated with very advanced forms of attack. Uh, so that's correlate, that's my background and a little bit of Correl light in a nutshell. Love it.
I'm gonna dig in a little more to correlate, if you don't mind, but before I do that, you know, I had a little experience selling cyber to the DOE. Yes. Back in the day when I was doing that.
And I, I learned a lot of things. One of the things I learned is that almost all the d well, back then anyway, almost all the DOE employees were actually employ over the labs, were actually employees of the use of University of California. Right.
And I, you know, there was that relationship there, so not unusual to hear that you was so closely affiliated with Berkeley. Um, Yeah, that is the model FF the F-F-R-D-C model. And so most numerically, I think most DOE employees are contractors, and I was a contractor as well.
Some, some worked directly for the federal government, but it's just been an, it's a little understood and astoundingly successful model of, of, um, a partnership that's generated Yeah. Across the complex, depending on how you count about a hundred Nobel prizes. So it's been responsible for a massive impact, um, on the economy and, and, and our quality doubt of lives.
Oh, no doubt. It's just an amazing Institution. Doubt, no doubt.
Proud To have been affiliated with. The other thing I realized though there, Greg, was exactly what you hit on. There were some people who had sort of almost that NSA attitude Yeah.
If you will. Right. And, and for good reason.
Yeah. You know, you're talking about, you know, crown jewel secrets that the whole world, you know, I mean, you needed security, but the, but then there were the scientist who said, Hey, we're scientists and we don't wanna hold information here. We we share our information with our colleagues.
Yeah. 'cause that's how we learn more. That's how science advances collaboration.
And so fashioning a security program for those two sort of extremes, right? Yeah. I, I had a very similar experience in the Department of Interior, like US Geological Survey.
They wanted to make sure all the seismic sensors on top of Mount Everest or Mount McKinley or what have you, and on the bottom of the sea were wide open so that everyone could share in that data. You know, not thinking that the bad guys might want to take it down. So it is, uh, not naive, but the, the, the quest for science versus the need for security was interesting.
And I could see how Core Light would be born out of that. Greg, when you say CORREL Light's, one of the leaders in their category, what is that category? The category has been, uh, named network detection and response.
And in dr And in a way, it may not be the name we would've chosen exactly, but it's a useful name because most people in our field know what EDR is. Endpoint detection and response. Right.
So, one way to think about the category, it is the, the, um, the version of EDR that's focused not on endpoint signals from endpoints, but signals from networks. And that can be networks anywhere that they exist. The modern network is, is hybrid multi-cloud.
It's in Kubernetes environments, it's in OT environments. Wherever there is network traffic, we wanna be able to analyze it, make sense of it, and use it for the defensive ends of our customers. And the neat thing about network traffic is it's a signal that attackers have to leave.
They have no choice. They, they, whatever they do, e even if it's stealthy and difficult to detect, to make sense of, they're creating a trace that we can observe. And, um, that trace is in the form of data.
We're a very, very data centric security company. And among all the NDR companies, I think the most data-centric. Uh, and we wanna use that data and apply lots of techniques, including ML and ai, um, to improve the security outcomes for our customers.
I love it. I love it. com?
And we're small enough that I can also give my email address, address. com. Excellent.
Alright. And Core Light, by the way, is C-O-R-E-L-I-G-H-T. That's Right.
Exactly. So, Greg, let's segue what pivot into what we've, our topic of discussion, if you will, and that's around AI and ML use in, in the cybersecurity, and specifically within the context of your knock and soc. Um, you know, traditionally SOC teams were focused on, you know, detection, investigation and response.
Mm-hmm. Right? And, and that's, you know, barely standard.
I don't think surprising anyone out here. But, you know, in, in this age of A IML, there's a fourth discipline that each SOC team needs to, um, excel in. Um, and, you know, and that is using these new technologies, right?
Because at the end of the day, they're tools. Yeah. Humans use tools.
That's right. Talk to us about it a little bit. Yeah.
We've been, I've been talking to lots and lots of customers about their fears and hopes in regard to the adoption of AI tools in the soc. And, and honestly, I think it's quite a polarized landscape at the moment. There's, there's folks who are, um, within security and outside too.
There's folks who have a lot of fear about accuracy, efficacy, about job displacement, and there's other folks who have a great deal of hope. And I'd say at correlate, we want to thread the needle between those extremes. We're a very data-centric company.
We don't believe in, in, in faith so much as proof. Uh, and so we, we want to, um, isolate, um, use cases where we can genuinely make a, a big difference. Um, and, and I'll tell you, our customers are pulling us too.
It's not just our own innovations. 5, which seems like, you know, an eon ago over, over two years ago, is that our customers, one of our big financial customers, was immediately using chat GPT and then after that chat, chat GT four, um, to do alert triaging on our data. Well, and, and the reason for that was that our data, because it comes from an open source project, um, all the large language models have been, uh, have been trained on it on the decades of discussion about the format and the internet.
So they already natively understand it. That was a very pleasant surprise for our customers and, and for correlate itself. Um, the models really, all of them, because they're trained on the public internet, have a good understanding of how to work with our data and, and what it means.
Um, so immediately we saw that most interesting use case in triage, but we've seen others too, um, in explainability and helping analysts try to quickly understand, um, what a rule or signature might mean, what the implications of a particularly vulnerability are, um, uh, how to take the next step in an investigation. Um, so these are not fully autonomous workflows. They still involve the human in the loop, but they have the promise.
That's where we are right now. But they have the promise to remove a lot of toil and drudgery from the work of SOC analysts. And, and that's what we're trying to, um, accomplish in, in the short term.
Ultimately, we'll move towards, um, I think fully closed loop workflows, but we're not there yet. And we don't, we don't want to push past what the technology allows, right. Because we, we still want to assure a high degree of safety and efficacy, um, in the soc.
Agreed. Agreed. Greg, as I mentioned, I, I sold into the federal government when most truth be told, most of it was DOD and agency work.
Yeah. And, um, you know, there's a, there's a wide disparity in, in, when you look at socks, SOCs, not, not socks you wear when you look at how socks sock teams, uh, their mission and how they operate from within the government to outside of the government, from large enterprises to, you know, to SMEs, the small medium enterprises. And also, you know, I'm of the opinion that quite frankly, most SMEs don't have the resources to, to run their own soc, which is why we have such a big MSSP channel, right?
Where you have one SOC managing multiple clients, multiple networks. Um, when we look at core, I mean, and AI ML is a great tool for all of these, but it's a different tool Yeah. In each of these situations, if you know what I'm saying.
Yeah, I think that's right. The, um, the way AI and ML will be consumed will vary a lot by the size of the soc. Some SOCs, and a lot of our customers are so large that they've got teams of data scientists and they're running their own.
Um, they may be training their own models or fine tuning models, um, or using open source models and adapting them, building their own, um, MCP servers and other technologies to integrate their tools. Um, and they have really sophisticated, sometimes even classified, um, detection approaches. And for, for those customers, actually, when you spoke to James Pope on our team, uh, at Black Hat, we had just released our Gen AI accelerator pack for those sorts of, with those sorts of customers in mind.
It's an MCP server plus playbooks that enable them to get the best use of our data, you know, which, as I explained already, is well understood by large language models, um, and allow them to integrate that into their ecosystem. So we're not forcing an architecture on those large customers. They're very sophisticated and they know how they want to consume the data and how they wanna build AI solutions.
Um, but if you click down, uh, a level or two into the soc, it's unlikely there'll be dedicated, large, dedicated data science teams. Um, there may be part-time threat hunters, um, but most people focus in on incident response. And those folks are likely to consume ai, but differently from SAS platforms like our investigator offering, we're gonna infuse AI features into investigator again, in a way that's sensible and helpful.
We're, we're not here to hype or to express doom, we're just here to be factual. Um, but we wanna give analysts immediate contextual help in the form of, um, you know, a, you know, agents, uh, that can perform discrete tasks like triage or partially automated investigations, or explain what a Certa alert actually means just in time so they get the context that they need without having to think very much or click very far to get it. So that's, um, the experience that we're designing for a big set of our customers, those that use our SaaS offering.
Um, but those two cultures are really different. I completely agree with you. We're we're trying to support both.
Absolutely. Um, yeah, I was talking to someone the other day, Greg, and, and their attitude was, um, even if we don't achieve super intelligence and we don't keep it, this breakneck pace of ai uh, discovery, what we have right now is pretty damn good, and it's gonna make a huge difference. Let me ask you, let's put, let's look at that through the lens of a sock and sock operators.
Yeah. I, you know, um, I often, I do find this, um, thread of discussion around a GI or, you know, um, superhuman, uh, AI to be a little distracting, and it hardly matters what the definition is or how long it will take for us to get there if we have a lot of point solutions, as you say, that are really startlingly good, um, at the moment. And that's true not just in security, but in lots of domains.
Uh, and they're also startlingly bad in some respects. So one of the things, um, that's really incumbent on humans to do is to figure out where the AI has strengths and where it has weaknesses. And we can't use our human instincts necessarily to do that.
We have good human instincts about where humans are likely to be strong and, and, uh, challenged, but the AI isn't human. And, and sometimes we're, um, we can be confused by its incredible efficacy in some domains to believe it's fantastic at everything, and it's not. So, uh, to your point, even if it never got any better, um, it still would have a transformative impact across many human domains that's just beginning to be understood, in my opinion.
But of course, it will get better. We don't know if it's gonna get better on the linear scale or exponential scale. We don't know if hallucination is going to get worse or better.
I think it'll probably get better. Um, and, you know, there's lots of other things we don't know, but we can't let that, um, blind us to the need to act right and to the need. And part of the urgency and security is that attackers, um, are obviously adopting AI tools.
They don't have some of the barriers that defenders have, right? They don't have to go through legal review. They don't have to think as much about accuracy, about the ethics of, um, job displacement.
They can just jump in and they are doing that. There's lots of evidence now to show that. I, I wouldn't have said that nine months ago, but I think today it's pretty obvious attackers have the lead.
And that really raises the urgency on defenders to begin wherever, wherever ASA is in its journey to begin taking steps forward. Whether it's highly data centric and, and AI enthusiastic or somewhat skeptical, it's important to start moving, moving the ball forward, taking on steps to begin to integrate the, the tools, because as you say, they're already pretty darn good. Absolutely.
Hey, Greg, we're about outta time. I want to, first of all, thank you for coming on here and, and, and my pleasure. Thanks.
Well, just talking to me. Thank you. But secondly, you know, getting us a little smarter about core light, you guys do more than the socket blackout, right?
And, um, there's a real mission there, a real strong leadership team, a real, I mean, as you said in your field, a real, the, the team to beat. Um, keep up the great work, come back and keep us posted. Okay.
Hey, I'd love to thank you so much, Alan. It was a pleasure talking with you All. Greg Bell.
Thank you. Greg Bell, chief Strategy Officer Co Light here on Tech Trunk tv. We're gonna take a BA break.
We'll be back.