Open Source Intelligence Community – Nico Dekens, ShadowDragon
Nico Dekens, director of intelligence and collection innovation at ShadowDragon, shines a spotlight on the heroic role the Open Source Intelligence (OSNIT) community plays in helping to combat cyberattacks.
Transcript
This is Techstrong tv. Hey guys, thanks for the throw. We're here with Nico Dickens and we're talking about Open Source intelligence.
Nico is a director of intelligence and collection for Shadow Dragon, and he can explain exactly what Shadow Dragon does as part of this conversation. But there's a lot of folks out there helping, uh, figure out who's actually launching all these cyber attacks that we're dealing with. We don't know much about 'em.
They probably don't want us to know much about 'em, but the point is, is there's a lot of good things happening out there. Nico, welcome the show. Thank you and thanks for having me.
Describe if you would, what Osmond's all about and how did this whole movement get started and, you know, are they the unsung heroes of cyber intelligence? Well, of course I like the think so. So because it's my main profession.
Um, just to give you a very brief history on open source intelligence, um, I think it gained the most traction just around World War ii, where people started to acknowledge that they can use information coming from open sources in at that point in time, uh, radio communication, uh, TV shows started slowly popping up, um, newspapers. So there was a lot of information, let's say at the early 45, just, uh, at the end of World War II where people figured out, hey, there is so much open information that could be turned into actionable intelligence when someone else can learn about, um, at that point, mostly gave toward conflict zones. Then the internet came, and when the internet came, people started sharing information.
So criminals did the same thing, um, sometimes unknowingly. So they left behind traces about their computer devices, their digital fingerprints in essence, and you can use techniques and methodologies to acknowledge that, to tackle that, but also to simply address certain intelligence requirements. So to sum it up real quick, open source intelligence is, uh, information that's derived from publicly available sources, which means that it has to be accessible for anyone around the world as long as you have an internet connection or you have access to open sources.
So it's not limited nowadays for the internet. Could also be a library, again, a TV show, a newspaper, academic research. Basically anything can be used and utilized to address an intelligence requirement.
Are the folks who use that sharing that information amongst each other and are they collaborating together? Because we certainly see the bad guys are highly specialized, so are the good guys getting specialized? Yes, most definitely.
So I think it's safe to say that the past, particularly the past five years, uh, government as well as private, uh, the private world started to team up because, um, maybe some large 500 fortune companies will have certain capabilities that governments do not have due to budget constraints, but also they may have a different interest and a different perspective. So I can definitely acknowledge that the, these companies are exchanging information as well as what they call armchair online, uh, investigators. They are using these techniques to, to collaborate.
For example, I briefly worked at a company called Bellingcat, which is an online journalistic journalistic collective that tries to investigate, uh, wrongdoing all around the world, mostly geared towards accountability for let's say war crimes and such. How do people get involved with this? Do I have to get vetted to join some group?
Is there a double secret handshake somewhere or can anybody just kind of start doing this? Well, that's a very interesting question and that's my biggest concern at this moment in time since the internet is so open, in essence, anyone who has a laptop and an internet connection can join, um, can join this fight, uh, for good, um, which also brings a lot of noise or let's say not so structured investigators with different ethics on board. So yes, the answer is yes, they are collaborating, they're working together.
For example, I'm from the Netherlands and the Dutch law enforcement reaches out to the community in the form of hackathons where they say, Hey, we have an unsolved case or a cold case. Now we want the help from the community to help investigate that particular case. And of course then they will vet the individuals that decide to say, Hey, maybe I can help.
And I can see also, uh, projects in the United States that do a similar thing. For example, trace Labs is a company that um, uses uh, cold cases, missing person cases where they ask the help for the community in order to find those little nuggets that can solve that case, which get handed over to law enforcement again, uh, to potentially, uh, find suspects or those missing persons. Again, This kind of sounds like the old west version of where the Marshall calls the townspeople together and forms a posse and they go after the bad guys.
So is this kind of the digital 21st century version of this? Yeah, I think so. And, and, and I think the power comes from that.
Um, there are no boundaries anymore, so you could be asleep while I'm working on your case here, in your opinion time zone and vice versa. But also now you have the power of people that can speak different languages and understand that and extract that information, but also understand, for example, um, the concept of reading between the lines, uh, understanding sarcasm, figure speeds, idioms because that's also the hard part to try and address those, um, maybe pieces of falsified information or disinformation because we are living in an age where disinformation and fake news is very common. Mm-hmm.
So how do you know that the people participating in this don't have some malevolent intent of their own and they're engaging in some cybersecurity disinformation? Yeah, that's a, yeah, and that's hard, that's hard to tackle. This is why I think it's so important.
Um, when you do this, when you ask the public for help, um, you must vett them again. So maybe you might ask them to show their government ID to verify that they are actually who they say they are, but also to do a background check on what can you find out about this, let's say alleged investigator and if they are the real deal with the right intentions. So yeah, that is super challenging because yeah, there are a lot of people that have a lot to hide, but also there are a lot of people that wanna ba basically implant those false pieces of information maybe in your ongoing investigation.
So yeah, there are some, um, models and techniques and methodologies where you can ask the right question to those individuals to at least try to make sure that they are not influencing your investigation with falsified or misinformation. Mm-hmm. We hear a lot about AI these days and everybody's worried about the bad guys are gonna use ai, but what do you think the good guys will use AI for?
Oh, um, so how I see that people use AI and machine learning for, uh, so artificial intelligence and machine learning for good is um, uh, for example to tackle um, deep fake imagery or deep fake videos. So if you can use those algorithms to, um, so this might be a little bit technical to count the pixels in a picture or a video, and with that you can determine if that picture was actually making with made with a camera device instead of being generated by an algorithm or something. So this is how they use it, but also they use it how to, to analyze maybe, uh, malicious pieces of code.
So you can find, let's say a piece of ransomware or a piece of, uh, malicious content in the form of a Trojan horse. You can put that code into a form of ai, for example, in chat G T P, and then you ask it, Hey, examine this piece of code and point out to me where it communicates maybe with a secret server or where it tries to execute something on your local machine that could intru your machine. So yes, you can definitely use those, um, technologies for good as well.
What kinda resources do you think this community needs? Uh, should governments be making more tools available to them or is, you know, all I need is a laptop and I'm good to go, but do you have a wishlist? Oh, my wishlist is so long.
Um, no, I'm, my wishlist is mostly that platforms that claim to be open and free, so freedom of speeds that they keep it as is. So as soon as larger platforms like the big tech companies start moderating stuff, it will make it harder for investigators like me to find what is real or not, or it prohibits me to finding it because now it creates a water bed effect where people, let's say the bad actors go to more decentralized platforms, which are way harder to find because they are simply not indexed by those sure engines that we use on a daily basis. So yeah, it's, it's basically a constant rat race nowadays where you try to keep up with the bad guys and vice versa.
They try to learn from us as well. Basically the more we chase them, then harder they become defined. So maybe we should make it easier for them to participate in the world so we can recognize them when we see them.
Right. Yeah, that's, that could also be a trade craft where, well, it could be the case, but I think the challenge here is that we are almost immediately when it comes to this working cross boundary. So that also has those legal I implications things that may be legal in my country may very illegal in your country.
So for example, this week, um, I noticed that uh, some people figured out that they could use, um, deep fake imagery to generate, um, child pornography content. Um, so that is very disturbing now for a fact. And there are certain countries where it's not illegal to create deep fake imagery in the form of child pornography, but for example, in the eu, um, making and spreading that information, even knowing that it's fully fake, so it's not a actual person or a child in a picture, it's just coming from AI generated content is still very illegal and we'll get you jail time.
And that's the challenge for me. So someone might upload a picture in, let's say, out of my jurisdiction and now I can do nothing. It's just there out of there.
So yeah, it's, it's interesting and challenging. What is your sense of the bad guys? Are they getting smarter and more sophisticated or fundamentally is the attacks are so, you know, they don't really need to do much, so they don't see the need to get more clever about these attacks, cuz we make it too easy.
Yeah, it's a two-sided source. So there's a fairly large group that are in my book, lazy bad Actors. So they tend to reuse someone else's malicious code, maybe altering two or free lines to suit it their needs also with the use of ai.
Um, so five years ago there was little to no ai, ai available, available, uh, publicly for anyone. But now they can use, uh, for example, chat GTP to write malicious codes on their behalf. All you need to tell Chet d p, this is my goal and it will write that script in a programming language that you can now execute.
So yeah, it makes some people more lazy, but also it will make certain groups strive for more perfection and make it even harder for people like me or the cyber defenders in general to detect them and tackle them because yeah, uh, they have something to lose, they have something to hide, but also a lot of countries stepped up the way how they could prosecute those, uh, suspects. So 10 years ago jail time was little to nothing because there was no law for internet related or cyber crime orientated stuff. And that's slowly starting to change, which makes them need to step up their game and have, let's say, better operation security, uh, to hide themselves from the internet or write the code in such a way that it's hard for me to acknowledge that that's that threat group for example.
Alright. What is that one thing you see cybersecurity teams doing that you kind of shake your head and go, guys that may not be the best use of your time or is kind of a pointless exercise is there's, what's your best advice to some folks out there that are trying to fight this fight alongside you? Um, my advice is always critical thinking.
So I see too many companies, uh, blindly trusting or relying on the tools that they build or buy. Um, uh, it's a concept that we call within our company Buttonology. We are not huge fans of buttonology.
We are fans of methodology. So if you know where to look and how to look by creating, for example, playbooks, you don't necessarily need very expensive software or tooling to tackle the issues that you want to address. So critical thinking and proper intelligence analysis is still the key to success in most cases.
All right folks. Well, you heard it here. The key to success in all endeavors is thinking and cybersecurity is no exceptions.
So with those thinking hats on and see where we go. Nico, thanks for being on the show. Thank you.
All right. Back to you guys in the.