Kunal Modasiya, Qualys | Qualys QSC22
Kunal Modasiya, the VP of CSAM at Qualys, joins Alan Shimel at Qualys Security Conference 2022 to discuss EASM capabilities in the Qualys Cloud Platform, and the unique approach to EASM that Qualys takes, as well as what differentiates Qualys from competitors.
Transcript
This is texturong TV. Hi everyone. We're back here live in Vegas for the qualisqsc show.
Glad you're tuning in on techstrong TV. We're getting good the afternoon of our second day here and our next guest. I'm happy to introduce you to the Kunal modasia.
Yeah, right you ride right. Madrasia. Buddhasia.
We're good. Yeah Kunal is VP of products here. And there's two actually two products that he is managing.
We're gonna hear about it. But first of all could now thank you for coming on the show. Thank you Alan for inviting me so our pleasure.
So before we get into the products wanted to give people a sense of kind of who you are your background how you came to this position in Wallace totally so good totally. So hey guys, I'm Kunal and I'm VP of product management for cyber security asset management and external attack surface management. So I'm actually qualities boom brand.
So I was at a college for three years from 2018 to 21 and then during the Great resignation period you and I moved out to Israeli cybersecurity company for 10 months and then I decided to come back since I love the quality so much the platform approach the people the culture and the leadership under Sumit thakar, right? So I decided to return back and I rejoined as a VP of a product management for two products that I said and I'm extremely proud of launching the external attack surface management and before College I was at a company's like a juniper and the sun microsystem signed the extreme networks. Yep.
So being done engineering role. I have built a product and then when I was boarding the code I decided to get into the product management part where I don't have to write the code, right so I accidentally become a product manager and then I enjoy every single day on the work. So yeah, I'm super excited to come back to Forest absolutely right?
It's a great story, you know, it's actually See I've heard I was talking to somebody about this The Passion of the management team. Not only I've only spoken to the management team. Sure.
I don't know if it goes I'm assuming goes all the way through but the passion of the koalas Workforce. For what they're doing and how they're contributing. It's not right because if people are excited about their work.
It's a big difference from people who just feel like it's ensure Right Toyota. Totally totally It's always a mix of the latest Cutting Edge technology that you got to work plus the people that you collaborate with right and the third thing which is obviously the stock price right you look at it. The other companies their stock price have actually 70 to 80% gone down.
But if you really look at the college talk, right it is still holding up on the 52 week high. So people are making good money while working on The Cutting Edge technology plus the people that they would like to work with so it's a win-win absolutely right and that's look we're not touting any stocks on here. So we don't want anything we don't we'll get in trouble.
But anyway, so now let's talk about you too. You're too products that you Shepherds that you your managing. First one is you is one that you really brought forth.
It's brand new. Yeah fairly new. Let's start with that one.
It's the attack. First sure so external attack surface management. We call it as a esm acronym right?
So we launched this product at the blackhead Las Vegas here two months. But yeah sometime August and I think so the external attack surface management product basically helps organizations in discovering and finding out the previously unknown internet racing internet facing external assets, which is sort of we call it as outside in attackers view, right whatever the assets that you have internal behind firewall that are not directly Exposed on the internet, right, but then you have some assets part of your organization assets that are exposed to the internet, right which means the attacker could see through outside in and there could use those devices find those gaps in those devices use those as a launch pad to launch an attack in your organization. Right?
So the external attack surface management is a part of our quality Cloud platform and included with the cyber security Asset Management solution and it helps with the discovery of the previously unknown internet facing devices. You know. Old Axiom you can't defend what you don't know absolutely and it's never been you know, this whole thing.
You mentioned the whole covid thing. It's never been more true than since these covid times that we've lived through where look people work for anywhere on anything and they stand stuff up. In This Cloud that cloud on using that sass or that you know, and so I think one of the biggest problems that organizations have and really I mean bigger organizations have it as a bigger problem, but even small organizations have this is Just getting a handle on what is the what what is their surface?
What totally what a devices do they have totally this make total sense and your spot on that especially for the last couple of years with the covid with the push on the the digitization effort right where employees were working remotely and the organizations were adopting the SAS services and the remote Workforce and all with that there is a one thing that has happened. That is the organizations internet exposure has increased everything is now on the internet, right and second point that he brought up the developers, right? They are spinning up the cloud instance is containers here and there they are taking on open source software into their environment productivity Tools in there environment, right which the IT team traditionally had a visibility but now no longer visibility because everything is in the cloud, right?
So this is where the organization how gone through there internet facing perimeter where they have a lot of devices. There and this is where what we have seen and there are some Market studies where 69% of the recent breaches that have happened in the organization. All of them like 69% the breaches were unknown assets.
Unknown internet facing assets where the one that were used as a launch paired. Yes, right. So this is the key area where the esm external attack surface management is helping organization in finding out what is out there.
First thing is that I said you need to know what is out there in order to defend yourself, right? So let's talk a little bit about that. How does it find?
How do you how do you know the unknown? How do you find these unknown devices great question. So in order to find the unknown internet facing devices, we have a three different methods sort of right the first one we have our own internal research team, which is a 30 member strong team and their job is to look into the organization and types of the m&a's merger and acquisition that they are doing it looking to their public financial information.
Look through the Wikipedia to find out what are the other organizations or subsidiaries that are part of this organization and their research our produce something called as a catalog so it knows okay quality says acquired a layered inside qualities as acquired a blue heads are gone. So the build sort of a catalog database, right that is with our research team. That's a first second one.
We use a bunch of the open source technology plus the paid third party sources, for example, Showdown right shodani sort of internet search engine for all of the external internet facing. Is right so Eddie in addition to The Showdown we use the who is XML registry where all the domains and the devices are registered. Right?
We look into the DNS information, right? We look into the service provider information in additionally. We have some paid sources like our and many other sources which basically gives us a feed about what is happening on the landscape for a given organization, right?
So that's a second one. And the third one is something that we are currently working on which is a light weight internet scanner, right which is going to augment all all up to right. So that's the our approach now and now once we start our customers, we have make it very frictionless for them.
So they can start with the top level domain name. com. com and say Discover, right?
And then internally, we basically look into that top level domain sub domain and we enumerate their subsidies and vertical domains and all and then we have attribution process which includes our research teams catalog that I just mentioned and then we identify those assets and then we attribute them to particular organization, right? So that's how we look into all of the external assets and attributed to the particular organization. Excellent.
Thank you now. I don't want to be Elementary. But so now we've we've we've developed this asset list.
That's a map. Whatever. What else does the product do from there?
Excellent great question. So this is this very great question and many of our customers who are in trial with us 200 plus customers. So they said that like there are some standalones siled attack surface management tool out there and they were using that for a discovery purpose.
But then the question is once you discover those assets find out what is out there. That's a first step. But then what do you do with this information what next right and that's where qualis comes and we shine it there.
For example, in order for you to make the risk prioritization decision. You need to know the context complete contextual information about the asset like who owns it which department what is running what kind of vulnerabilities there what kind of a risky Port it has right? What kind of a certificate expire certificate is running now, we in order to get this context.
We have a customer who have to have a resources to manually gather this information across the different console and then correlate in a one place, right? But with us after you discover, all of the context is readily available and that's because the power of the platform right with our platform. We have already collected this information, which is already there.
So as soon as the new device is discovered Then we are adding this context. So that's the first key differentiator right for us, which is different from other. Now.
The second part is once you discover this external unknown devices, then the question that the vulnerability management team or a web app scanning team that they are asking is dude. How do I get those devices into my VM program? I want to scan them on a regular basis so that I can remediate that risk right now that's where with our quality integrated platform.
They can select those one to many devices and simply say one click and add to VM. Or if the if the external asset has a port 80 open, then we classify as a web port and then you can automatically launch the web app scanning right. Now.
Imagine if you have to do accomplish all of this after discovery, you have to spend time in building the contacts which is a huge time-consuming laborious things plus now, you have to bring those devices from a third party tool into the college because you have well number management with college, right but with our customers they get everything in a one. Great deal could now we're running low on time. I want to talk a little bit about the other part.
I know the first one is your baby, right? You kind of inherited the the other product but that's my product. Yep Side by security Asset Management.
Yep. So now I'm glad that you brought it up. And this is where sort of ours is a unique differentiation, right?
So the cybersecurity asset management we launch it, I think last year. And this product was designed to bring the visibility into the customers internal known infrastructure, right and with those known assets that you already know, but there are some risk on those assets for example configuration gaps or open ports or expired certificate, right? So that is all about internal known.
Second with the external attack surface management that we just launched. Now I am giving them a visibility and a context into the previously unknown external internet facing assets. So now you see internal known external unknown together.
We are giving them a visibility into entire attack surface. That's the beauty that's the key differentiator. We have had a customers who were looking into some Silo tool just for external part and then building the context they had to use some other tool for the internal known they were using us or some other vendor and now with the cyber security asset management and the external attack surface management, which is included.
customer gets everything in a one place That's the beauty right and see Sam has been shipping for I think more than a year now tremendous success record. And now this the external attack surface management is running a lot of traction and the key differentiator. Like I said, right is Discovery context and that context comes from our power of a unified platform, right?
That is right. So that's the thing. I wanted to end on which is this a theme we've heard two days, right the the Wallace platform.
hyperscale and with that kind of power with that kind of You know numbers that you can bring to the situation. It allows you to have insights and do things. that we only dreamed of actually earlier, you know in the last years security.
Anyway, keep up the great work. We love to hear what more you doing. And and thanks for being our guest on Deck strong TV.
Thank you so much Island for hosting me good now our pleasure. Thank you. com.
com/cm is where you can go and and register for the free trial for the external attack surface management and you just put your top level domain name and you see what is out there on the internet, right? It's a free trial. Okay, then easier than that.
All right. We'll be back here in a minute. We're live in Vegas.
Thank you so much.





