Democratizing Security – Brendan O’Leary, ProjectDiscovery.io
Brendan O’Leary discusses his new role as head of community at ProjectDiscovery.io, which is on a mission to democratize security. Learn more about ProjectDiscovery, open source as a business model, and where the security market is headed.
Transcript
This is texturing TV. Hi everyone, welcome back to text drug TV, you know, I've been waiting to do this interview for it feels like two months already or more, but, you know first time long time or whatever. It is from Radio.
He's a Long Time guest on our show. He's been on it. He had his own show on here with us, but it was always a gitlab and he's had a new place now, and I'm excited to tell you and have him tell you all about it.
Let me hear you reintroduce you to my friend Brendan O'Leary. Hey Brendan, how are you man? Hey Alan.
Thanks so much for for having me back on and yeah, I feel like it's this might have been one of the longest times we've gone without talking, you know with me in my transition and the holidays and all that. Yeah. It's yeah.
I know I I get it. I kept saying didn't we have didn't we schedule with bread and I yeah, yeah, it's coming up and then, you know life gets in the way. Anyway, it's good to see you.
United get lab you're at project Discovery. Is that like the official name? That's correct.
io. Is that yeah. That's the website.
Yeah, exactly. Yeah. So tell us what what's the deal here?
Brandon? What's it about? Sure?
Yeah. No, I'm really excited. I you know got the opportunity to head up the community team here project Discovery and we're we're you know a small Venture back startup in the security engineering space.
And the thing that got me excited about it is there's already a huge community of users that use our tools. So we're probably best known for our tool named nuclei which is a kind of a dash scanner plus plus does a lot of template-based scanning. So you basically devant Define a animal template and it runs scans against your infrastructure based on that.
Then we have a number of other tools that are used kind of throughout the bug Bounty and penetration testing community. And so for me, it was really exciting to like join this community of people and hopefully, you know help grow it and then also, you know a very important space and security, you know, it's something you and I have talked about for years. And I'm really excited to now be kind of on the red team.
If you will right in with the penetration testers and Bug bounty hunters and those folks that are really focused on the modern security engineering stack. And so it's it's exciting. Absolutely, you know.
So I I love kind of that. Aspect of security. It's something I've seen develop over the years and what I really like about it too is there's also sort of this.
sort of a crowdsourcing model to it at some level, right it the best example is is my friend Carolyn Wong who's over at koboldt Iowa, right? Kobold does pen testing and very much in a crowdsource. Type of model and I I think it's a great model because you you engaging that community.
Yeah, I agree. And you know that's part and Cobalt's good good friends of ours. And yeah, I think that model is critical right?
It's something we've seen such success with in devops and you know bringing together developers and operators and I'm hoping that we're gonna see that success again in really finally bringing together developers and Security Professionals, right? Our mission actually is to democratize security, which is a big, you know, hairy audacious goal. But it's you know, our tools are all open source, and that's a little bit unheard of in the security industry.
Right? The traditional security vendor is a very close Source proprietary vendor, which makes you kind of beholden to them right when a big security change like a log for Jay comes out you have to you know, wait and and hope that they quickly get, you know, a new signature push to their proprietary system whereas for for us when that happened within an hour to of that being announced there was a nuclei template that you could then go use to scan your entire infrastructure to say, where are we vulnerable to this vulnerability and that didn't come from from Project discovery of the company. It came from our open source Community, right?
And so that sure that power of the both crowdsourcing right? The most advanced Enterprises are using bug Bounty programs to crowdsource folks looking at their external attack surface and then You know open source is the ultimate crowdsourcing right? Just get all of all of the best and brightest security Engineers together to to work on security together.
And I think that's something that we saw, you know, I've seen in the devops industry in my time there, you know spent a long time there and I'm hoping that we can make that successful, you know and security and you know, people say deaf secops and you know kind of roll their eyes, but I do think that is the right way to think about it. Right devops was very successful in getting everyone together everyone around the same table. And really focused on solving the problems together rather than each trying to solve them in our individual silos.
I think that's what we need to really solve the problem of security and in software and in the Enterprise. You know Brendan is someone who who's been involved in security Now for 25 plus years. It's what's old is New Again.
Right because when I when I first got into security. Right, even even the commercial vendors when you looked under the covers. They were using things like nmap and nessus and snort and clam AV.
Right, and then they built successful commercial product on top of that like my friend Marty Roche who started sourcefire Marty resch. I called him Roche all these years and found that it's really rich, but Marty started sourcefire. You know would snort and and you know kept snoring open source.
But the the rules the snort. You know checks. Yeah, this became sort of the not proprietary but proprietary not only monetized around sure.
Yeah, they monetized it my friend Ron gouler from tenable who had nurses they did it separate thing, right? They they kind of stopped. Production of necesses and open source school around two point seven or something and and kind of closed it up there.
But you know so many other companies, you know forked it from there and we're still using in essence National scripts sure, right every time a cve came out or something and you know Then it seems like somehow the security industry made a left turn and got away from all that open source. Kind of, you know foundational stuff and and now to hear it coming back it it's good. It does my heart good.
Yeah, I like it. I'll tell you something else. Devops is SecOps.
I don't think anyone Rose and people who there might be people who roll their eyes, but the people who roll their eyes at it are out of touch. I am looking forward in April will be at RSA conference. Right and I put on the deficit cops event there every year on the month.
Usually well covid screwed things up. But we're back to Monday of our I'd say week again at the Moscone Center. We're there all day and and the theme of this year's deaf secops is devops is SecOps.
And I actually got it from Ashley Cramer from gitlab who yeah was very boldly saying that I had done a panel with I think it was actually it was a Fred Fred Prince from one of the co-founders of Jay frog and the CEO of cloud bees. And I had one other person who I think was Tracy Reagan you you probably know as well from lending stretch. Well.
And that was the theme that they all came upon is that today devops. It's SecOps. And it's all about that.
So I I think you're right in the right place at the right time here. Yeah, we know a project discovery. Yeah, I agree.
And I think yeah our our approach when we're looking at that open source world is to to keep anything that individual user cares about open source, right? Because that gives us that power right our community that power and and like you said it goes back to the very first days of you know Computer and Network Security of any type right it was it was crowd sourced at the time right the early days of DEF CON, right? It was the folks in the room that knew what they were talking about getting together and understanding and sharing and text Files about you know, how things worked and it took industry a while to accept that right the large software makers to accept that, you know, they were gonna have to have a part of that whereas today you see, you know, but large Enterprises embracing bug bounty hunting, right?
And and so it's it's it is very interesting that what's old is New Again like you said. Yeah, what we want to do is we want to monetize around again, the things that an Enterprise would care about the things that are you know, Make nuclei powerful at scale, right? And so that's what we're doing with nuclei Cloud that we actually just recently announced the private beta of and we want to focus on those things that you know, go beyond the individual but talk about what the organization cares about right?
So that's like time to remediation, you know direct two-way integration with ticketing systems being able to run nuclei at scale without having to you know, spin up your own hardware. And so I think that you know resolution and Remediation cycle is the thing that you know, a bug Bounty Hunter wants to find the bug report it and then, you know get paid by the organization the organization wants to find it and then be able to remediate it. And then also make sure it doesn't happen again.
So include, you know, that scan that found the bug include that now in every regression test and every CI/CD pipeline so we know it doesn't come back again. And so that's that's really what we're looking to do so that we hope that we can both You know build a sustainable business model that then is able to sustain our open source, you know indefinitely. That's that's kind of our goal.
Absolutely, very cool. io, but it's nuclei, right? Nuclei is the main product right yet.
So right I just you can find all of our products we have other open source tools outside of nuclei are offering that brings them. All together is called nuclear iCloud. And that's the cloud.
Yep, but I'm assuming you they can find nuclei on GitHub or yeah, you can get go to get hot you. Of course. io, you can find all of our things click click right through to get Hub.
But then also it's project discovery on GitHub. So if you look at our organization there you can see all of our open source projects. So we have you know ones that are around Port scanning we have projects around, you know, attack surface management, right so big a big challenge for a large Enterprise or or someone trying to do a bug bounty hunting against large Enterprises what assets exist out there on the public internet, you know, what external assets exists that I can scan against so we have tooling around that and then some other specialized tooling for things like DNS and TLS and and, you know kind of more specific vulnerability scanning very cool so Brandon Your Role is that I had of community is not share with the audience.
What what do you how do you view your mission as head of community there? Sure. Yeah, so I think you know.
I I believe in and you know our investors and our your leadership believe that the community is one of our greatest if not our greatest assets, right? And so that makes the head of community role really important because my job is to both protect and nurture and also grow that asset so I think you know it's we've had this great organic Community come out of just you know, the kind of Picturesque open source story right our Founders met on GitHub. They didn't even realize they were both living in the same city in India at the time because they met their GitHub and worked on these tools together and then we're convinced by actually the CSO Robin Hood to You know quit their day jobs and start the company and so that was really exciting, you know, and the community grew really organically around that.
But I think we have a huge opportunity. You know, when we look at our mission of democratizing security to make sure that we have a really open and welcoming Community. The security Community is really opening and welcoming, but you don't always know that until you walk in the front door.
And so we want to make the front door be wide open for folks to come in, you know, if they're just getting started with bug Bounty or if they're you know in advanced pen test or at an Enterprise we want all of those folks to feel really welcome. And so I think my number one job is that making sure the front door is wide open and then after that, I think it's you know, making sure that we're delivering on our promises to the community about, you know, sustaining our open source tools. There are a lot of tools in security that get written and then not maintained and so we want to really focus on that not happening for us, right and and that would probably be an you know, the secondary goal for me right is to make sure that we're sustaining and and giving back to the community that's given so much to us.
I love it. It's excellent, man. So Brendan, you also had several chairs positions with Linux Foundation foundations and projects.
That carry over or you kind of putting that on the back burner as you focus on this new role. Yeah, so I I did leave my governing board seat on the cncf when I changed my role, but I'm still gonna be heavily involved with with those groups. I'm also hoping to get more involved with the open ssf right as we look at software security.
And so again, we're really new and we're still kind of exploring that environment but I really hope that we can be a force, you know there in the security engineering space and bringing that to you know, the cncf the open ssf and the Linux Foundation as a whole, you know, you know that I have great friends there. And so yeah, they're not going to get rid of me that easy good. Relations on the move.
I think it's a excuse me. I think it's a great. Role for you.
I think they're very lucky to have you there with your many talents. But I think there's a bright future for project Discovery and make the most of it man. Yeah, I appreciate that.
And yeah, I think I'm I'm working on I'll announce it for the first time in public on your show. Go ahead. I'm trying to put together a happy hour at RSA.
So if you're there, I'd love to invite you probably I'm committing to it because I'm putting it on here. The problem Brandon is there's nowhere to make it everything's closed around there. So I that that problem I've solved actually already so one of our investors I've secured their space actually already so I might hurt let me know when it is and you know, we will Pub will publicize it.
Obviously we'll be there all week. Sure as long as you're gonna be there come visit us on broadcast alley as well. Yeah, definitely gonna be there so that would be all right.
Fantastic Brendan. It's great to catch up with you. Don't be a stranger now.
Come on. Yeah, great. Thanks Allen.
All right, Brendan O'Leary ahead of community a project Discovery nuclei item few other open source projects. Check them out of project Discovery. Dad IL, we're gonna take a break and we'll be back in a moment.