Moving Beyond SOAR – Bob Slapnick & Lawrence Pingree, BrazenCloud
Alan speaks to Bob Slapnick, Co-Founder and COO at BrazenCloud, and Lawrence Pingree, CTO at BrazenCloud, about making the case that we need more than SOAR (Security Orchestration, Automation and Response) and move beyond just the sock automation that we’re doing today.
Transcript
This is texturing TV. Hey everyone. Welcome to Tech shark TV.
I am really happy to have a cold. Well, he's not old but a friend I'd known for a long time. Within and he's now with the new company.
It's the first time we're gonna have them on here on Tech strong. And with the new company. Let me introduce you first of all to my friend Lawrence finnegree Lawrence.
Welcome to Tech strong. Joining Lawrence. And I today I want to introduce you to Robert slapnick Bob Bob slap Nick.
He's the CEO and co-founder of grazing cloud and Bob. Welcome to text on TV. Nice to have you on here.
So, thank you. Lawrence we're gonna you know, I'm gonna point to you Lawrence. Why don't you know, I mentioned that I knew you a while.
Why don't you tell people a little bit about your story and then a little bit about how you came to come to the company here here well, so I said 14 years roughly as a as an analyst or or MVP managing VP at Gartner, you know, I worked with the product managers product marketing folks go to market strategist CEOs over the years and I you know my myself and my team we we looked at what was emerging Tech coming along and I came across the company that I thought had really instrumental Tech and the way I look at it is, you know, there's a there's inflection points there right in the market right you had Splunk with analytics that was a huge, you know change in the way that we look at logs on. I saw this this opportunity and embrace and Cloud as another inflection point on. The endpoint and on the workload side and because ultimately what what Splunk or those folks did is they they created a Swiss army knife for logs.
Right? What what Brazen Cloud brings to Market is kind of a Swiss army knife for automations on the workload. And so, you know what?
That's what drove me to this product but it's also when you can do so many things like raising Cloud can do. Um, there's also a challenge of that and that is you know, how do you position such a broad amazing platform that with with capabilities to automate everywhere? And so that's what what sort of drove me to join Brazen Cloud.
I'm excited about our future and I wanted to come to the show to say today to talk about what I think is needed in the security industry. And we I one of one of the things I think is key is I think general purpose automation needs to be brought to the security market and I'm not talking about just sore products which automate in the sock. I think that we need to go broader with General automation.
I think we need to build to you know activities that are not only just in the sock but also in Engineering in in the cloud and other areas Security where we can automate tasks and make people more efficient. Absolutely. com about eight years ago.
One of the things that attracted me to the whole devot's movement was the idea that we can get sort of another bite at the Apple in security to correct some some mistakes that would meet early on in the security world that would still paying the price for either the whole shift left thing in all of that, but here's the fact that we've learned, you know through 20 years of agile and now, you know 10 years nine years of devops is that Technology in general is moving towards automation. Yeah an order and automation to the point that it's happening so fast humans can't keep up anytime. We put a human in the mix it by almost by definition slows it down.
Yeah, right. So it's For a lot of for a lot of what we see going on in the software world today. It's it's automate or die.
Right right and and very I think it's very true for security Now look some of our security friends May disagree with that, right? They have to have that security person in the middle. I get it but If if you're not automating today, you're not gonna keep up with the pace of software deployment.
Right? Right. I mean the reality even if you look at, you know, folks like, you know, my full my former employer analyst firms even the media we all are having trouble keeping up because you have the, you know, you have the pace of you know, drag and drop interfaces to build applications you have, you know, the the landscape of cloud making things that are more agile.
Um, I actually think that Well, this might be controversial but I actually think that we need to recognize we've been automating a long time. In fact, you know, you know, it's it's been a long time since since you know anyone's had to really do, you know, Mass malware analysis on every workload, right? We use scanners for that that's automation.
You know, what I would actually yeah. What I would actually contest is that we automate a lot. On but we don't focus on the corporate automation.
From a general sense. We don't look at it and go. Hey, how can we be more efficient through automation.
We actually use tons of automation. If you can you can use almost every vendor as an example of this. I mean all of the the major competitors they offer automation, but what they do is they offer only Automation and one use case right or two use cases or maybe as much as five but um at the end of the day we shouldn't be scared of this.
I mean, we've been using malware scanners and EDR and other tools with automation for a long time. What I think we need to focus on is things that are disruptive to our manual procedures, right? We we do far more far too much with manual procedures not I'll give you an example.
I know that when log4j came out that I have friends that that had to you know, instantly go in and try to create scripts and their environment figure out, you know ways, you know, yeah where it was and all that. And that's a great example of where you can Target Automation in a way that gives you an edge and security right? And and I I don't think that you know, if I if I may for a moment postulate that sore products really haven't delivered on on the automation that we really need on and the scale in which we need it, but let's be fair.
Sore wasn't meant as a general automation tool it's you know, part of being a grown-up adult as you realize using the right tool for the right job as a godsend, right? It's all about the tool. Yep.
Soar. Was it meant to be it does it does what it was what it's supposed to do in a very narrow sense, right? But Laurence really that one of the things we haven't mentioned but it really is driving all of this.
Is we're drowning in data. We're drowning in information with almost drowning in metrics. You know, right you and I come from a world and Bob I bet you too where we would taught everything could be measured and we measure everything.
Yeah and damn the torpedoes Full Speed Ahead. Let's let's gather all the info we can to now it analyze it. Well now we're in a point.
Especially in security where we have so much. God darn dated to analyze we have so much metrics and logs and everything. How's a human going to go through that?
Exactly and they can't I mean I just to your point. I sat in a multibillion dollar company looking at a thousand alerts an hour and having to triage each and just think about that. I've got 60 minutes in a day in an hour doing a thousand alerts.
That's just it's humanly impossible to do. Well. Yeah, you can review it but you really can't do much about you're not doing Justice to it.
That's for sure. And then and then there's automation that we need that you know where we're trying to make investigations faster or you know, we're trying to do triage or we're trying to do a deeper investigation than that. Then what I would call the the osint kind of you know layer of things and you know, there's a lot of additional data that we still don't enrich in the sock on that that investigators have to have to do third level triage, right?
And so, you know, I think We're we're inundated with data that sometimes is meaningless machine learning has helped refine some of the scoring some of the modeling but actually in a lot of cases machine learning is created even more data for us. Right? So like now it's not we we know this one thing happened and you know, it's bad now, it's well, we think it might be bad.
You should look at it and then investigate and that creates a whole series of activities that I think, you know need deeper automation on and Beyond just the sword, you know, sock triage type type activities that we do today on and I also think that sore needs to be a little bit more affordable too. Um, it's an expensive add-on. Well, yeah, I mean, but look, I remember it was probably you making the same argument about about Sims.
Yeah, 10 years ago, right 12 years ago. Yeah, it's expensive and hopefully it comes down. Let's talk about raising Cloud.
How does it help with this? What brazencloud is is a security orchestrator that provides the framework and the ability to automate across any workloads. So we do use an agent service it can it can function as you can execute tasks within a workload or it can also extra execute things like scripts Powershell python it you know laterally in the environment if you wanted to call apis and gather data, you know, and we can run what we call run books.
So in the song in in the sock or in the sore realm people call it a Playbook. We call it a run book because we're about we're about end and automating right? We're not we're not about let's insert, you know humans more into Every process and require more workflow what we're what we're about is you have a specific problem.
Let's say I want to hunt the entire environment you you know, you go in configure a runbook and you pass push the runbook out to go do that activity. Right? Let's say I want to you know, do some troubleshooting on every host.
I can instrument that in a run book hit go and instantly get data back from my environment. And and this is the power of our platform is the ability to kind of take all of the mute major human activities, not the stuff that's really very, you know, clearly automatable but something that where you know, what why am I doing this function over and over again and going out to systems and logging and cutting pacing and all these other activities? Those can be Consolidated into a run book?
And so that users and administrators investigators sock professionals go directly to a platform click a few buttons run and run book and get the data that they need. Right. So if I'm doing an investigation, I can instrument raising cloud with binaries that I need to use for that investigation.
Whether it be doing a forensic capture doing a threat hunt evaluating, you know with API calls to some other, you know service offering for enrichment. Things are possible under our platform the the second major benefit to our platform is we can do pinhole connectivity between workloads and what that means is you can create during the the process of an automation. Let's say that you're you want to you know, move forensic data around.
Okay, and you want to remove it from a DMZ that where you're doing your analysis to some other location we can do that directly over our it's an SSL session, but we can create pinholes for the duration of the process to execute in that run book and close the connectivity. So we're not actually having to you know, go out and create a workflow go out and execute and wait for humans to go make changes in in let's say DMZ environments or firewalls or oh, you know VPN architectures and we're not pinging up connectivity, you know on a continuous basis leaving more Holes for the environment to be exploited in so what we can do is we can create connectivity. Let's say move files or or transact, you know, execute the process and close it down.
So we're calling it kind of a zero trust, you know kind of pinholes that we can create between between applications. Large I I apologize, but we've got people in waiting room. We're going to need to close Loops here.
Now people who want to get more information. Where can they go? com and you wouldn't mind Breeze en prison.
com, correct? and is there a trial? How did they get started?
Yeah, they're they're welcome to request a trial on the website. We'll send them a demo account. We'd be happy to get them into the platform and automating is as soon as they would like to.
Love it. Hey. Guys that were a little shorted today my fault.
No, thank you very much for your time. We look forward to having you back. Up.
Thanks for joining us. We're gonna take a break here on take strong TV. Thank you, sir.
Take care be well you do.