Matt Peters, Expel | KubeCon + CloudNativeCon NA 2022
Matt Peters, Chief Product Officer at Expel, joins Alan Shimel to discuss Expel, a managed detection and response provider that focuses on giving high quality forensic response across a disparate technology stack. They also talk about how Expel has announced its support for kubernetes as a first-class offering.
Transcript
This is texturing TV. Hey everyone. We're back here.
We're live in Detroit at kubecon wrapping up our third day of coverage. You know, I think this might be our last interview for kubecon Detroit. It'll be a wrap.
I think we've probably done something like 40 interviews in three days 40 something. So we hope you've enjoyed it. From what I'm told from our production staff.
We've had tens of thousands of people viewing over the three days crazy at 11,000. I know yesterday and more than 11,000. So we hope you've enjoyed it our last guest.
Is Matt Peters he's with a company called expel? And and that first of all, welcome to Texas TV, you've never done this. Oh, no, it's great beer.
Well, we haven't lost in three days. I haven't lost one yet. Okay, it's a good you'll be okay.
I'll make sure but Matt, why don't we you know, give people a little background. Who are you? What do you do?
Yeah, so I am the chief product officer at expel. We are managed detection response provider. I've been doing security work for about 25 years getting my start building appliances and actually writing software and then went into incident response.
I worked at Mandy and helping out with their managed service and then after that after the actors for my fire we a couple guys and I went out and we decided to help out the industry and found it expel where we do detection and response and sort of managed to hear. So is it endpoint detection response or just it's a great question. So when we started the company that the theory that we had we had we had been doing think nation-state focused response.
And so you think like that's primarily endpoint based but we had a network sensor as well and that the light bulb went off for us that if you're really responding to actors that know what they're doing or real threats having a lot of different Telemetry is much more useful than having a particular like a single thing. So, you know endpoints great data and I would love to have it but also being able to look at Network signal and things like this. So when we started we said it would be great if we could give the Defenders access to all these different telemetries in a way that isn't overloading.
So one of the reasons a lot of teams will focus on endpoint or their Sim or something like this is it's just a lot of cognitive blow to think about like, okay. Well here I'm in my sim. I'm looking at these logs now, let me pivot over and let me look at the end point things like this.
What we said was we think that we can do this high quality forensic response. So like really getting into the what when why and how often of a breach but we can do it across a just for Technology stack and the way you do that is you build a sort of a technology layer that helps normalize some of that helps you respond and that sort of the core behind expel love it. How long have you?
Been how long is extol been in business? So we're we just crossed over our sixth year, which is crazy to think. So the three founders had the idea about six years ago and you know built the initial team.
We've been we've been selling ever since and we're about to cross over 500 employees which just blows my mind. That's like, you know, I was employee number one. So it just freaks me out whenever I see.
Yeah. No, I've been through that. That's crazy.
Really New York growth. Yeah, you know that comes a point where You know you started company. And and this book's written about this ain't that initial stages were all family.
Right. I know everyone and there and it's much of your co-founder. They're your family, right you treat them and then you start hiring employees and their employees but you know everyone and you know, everyone's story.
Oh, yeah. That's Matt has two kids Matt, you know, but then you start the next stage, maybe a hundred a hundred and fifty people. You're probably still know everyone's name.
And you think you know what department they're in. But you really yeah, you know. Especially in this day with remote, you know really know a lot about them other than yeah.
He's in product management or something. Then you get to about three four hundred five hundred and you know what? You don't know everyone's name anymore.
It's hard people come people go, you know, so it's a very interesting it it kind of, you know, it's the circle of life. What can I tell you? Let's talk.
What do you do? What do you guys doing here at Cloud nativecon? Kubecon?
Yeah. So one of the things that we've been doing is, you know, we started out protecting sort of traditional infrastructure think desktops laptop servers that kind of stuff and over the last couple years. We've expanded we've got a cloud offering where we'll protect people's Cloud infrastructure because that was where a lot of the risk was moving and then a couple of years ago, we started, you know, seeing the first set of customers begin to adopt kubernetes as a place where they really run production infrastructure.
And so we looked at it. We're like, yeah, there's something that we can do there because the number one thing that we identified and this is going back to the initial Founders that expel really saw the security problem and they said the real issue here is not necessarily a technology when it's a people problem, right? It's having enough skilled people to be able to do detection response this sort of stuff.
Right? So what we've done is here at kubecon is we're announcing our our support for kubernetes as a first class offering where if you're running kubernetes in any one of the the cloud hosted Services, we can go ahead and connect up and watch it for you. So Have security incidents.
So I'm going to tax it misconfigurations this kind of stuff we can help you to respond to that so that you don't have to build a 24x7 monitoring capability because if you're really focused on using kubernetes for what it's for which is like rapid deployment of software and like software. It's scale to help a business. You don't really want to be thinking about like well what happens if something goes bump at two o'clock in the morning, right?
Because it's always 2 o'clock in the morning on like Thanksgiving that the bad one hits, right? And so that's what we do. Yeah it is that is so damn true.
Um, is this the first time you've come to Quran or no? So actually before pandemic I've been here several times really always enjoyed it as a show because I'm also I'm a technologist at heart. So like, you know, go to the sessions this sort of stuff see the technologies that kind of thing obviously pandemic was a little bit of a break so this is but this is our first time exhibiting here.
So that's super exciting. and how I mean so look, this is People don't see it. They see this but you know the things that spread out it's less dense, but there's still a lot of people here interested in what you're hearing from the crowd about sure.
Yeah, so a couple of themes that I'm hearing and then some things I'm seeing from some of the other vendors as well one is people being concerned about risk in things like kubernetes, but it's a little bit I'll use the word in kohate. It's kind of unformed it reminds me actually of going to say reinvent and talking about security six seven years ago, right people that this was a problem. They know that something was hurtling toward them, but we didn't really know what the shape of the asteroid was and so right now what I'm seeing is I'm seeing a lot of people talk about things like Opa and configuration drift a lot of coffee.
Yeah, you know, it's interesting. I was just talking to my friend Steve from James frog they came out with something called Advanced security, which is You know, it's part of this. developer LEDs not developer LED the developers are an attack surface at some level right and and targeted and how do we I see so many parallels like so I'm also in security 25 30 years right from when I we were doing vulnerability scanning 2003 2004.
To app scanning and now the kinds of scanning we're doing as part of our cicd processors. You know as much as things change they say the same a little bit. Yeah, we want to know not only is something vulnerable.
Is it reachable? Yeah. What what did the consequences what's it connected to what apis is it calling?
You know these kinds of things so I I do think as you said it kind of does feel a little in terms of security anyway like AWS before 78 maybe even 10 years now because a message I would get at it this year show is security is primary. Oh, yeah. Well, I mean, I think one of the things that I've seen having been doing security for a while is that you're facing we're facing determined adversaries, even if it's not necessarily say a nation-state actor what they're gonna do is they're gonna Target and try to find places to get in so when there's a new technology and the potential for it to be Miss deployed is really really high that forms a really really good barrier.
The other thing I would say is that there's kind of a complete story here too. One of the things we talked about a lot of our customers about is let's say you're running all of your infrastructure in the cloud. That is an attack surface.
Absolutely, but your users are still in a tax surface. So like if I can get the credentials by, you know fishing someone I'm gonna get them through fishing someone so you've got to kind of think about all of the different Avenues and when there's something new it might give you tremendous new instrumentation as we see from something like kubernetes and all of the different infrastructure. I can I can use to pull signal out of it, but it's also gonna potentially open up some new avenues and and the attackers are gonna go where the easy is, right?
So if we if we recall back a number of years ago where you know, You could you could basically find unpatched vulnerabilities on Windows servers connected the internet all day every day, right the necessity to develop high quality other attacks was was significantly lower and you only really saw that information States as people got their patching games up. We saw an increase in BEC and account takeover and that sort of stuff because that's where we're gonna go right as more and more people are deploying kubernetes. If we don't handle the risk on that front, you're gonna see a spike in kubernetes until we Tamp down on that and then they're gonna find a new place to go.
It's like basically I like in it too for opportunistic attackers. Someone going down the street and testing car doors right when they find the open door, they're gonna steal the stuff, you know, It always was I say was going down the hotel. com is our website.
com is our website and we've got our bunch of announcements up there. We also have a Blog that she's subscribed to up there and that's where we're at. Yeah, cool.
Hey Matt. Thanks for joining. Thanks so much.
Alrighty. Hey, we are gonna wrap. Our Cube card Cloud nativecon here for Detroit 2022.
We hope you've joined it. If you missed any of the days our entire, I know they probably 40 something interviews will be replayed over the coming weeks on Tech strung TV. You can check it out there.
You can probably catch them on demand there as well until then though Monday. We will be back on Tech strung TV from Studio a back in Boca Raton. So we'll see you there this Alan Shimmel.
We're out of here.
