[00:00.000 --> 00:02.600] Anyways, welcome to Strength and Unity, Sharing is Caring. [00:02.880 --> 00:10.620] If you just happen to have wandered into here, and you don't even know what is going on, well, I'll just tell you in a brief little thing. [00:10.720 --> 00:14.600] This here presentation is about the Power of Threat Intelligence collaboration. [00:15.280 --> 00:18.940] I'll be your speaker, Faye, and I like video games. [00:19.100 --> 00:23.720] So if you like video games too, and you like Threat Intelligence, then this is the kind of presentation for you. [00:26.700 --> 00:27.840] And special effects. [00:27.840 --> 00:28.680] Ooh! [00:30.160 --> 00:30.580] Yeah! [00:31.280 --> 00:32.840] Now I got your attention, huh? [00:34.440 --> 00:40.380] Alright, so you're probably wondering who I even am, and why you should sit there and listen to me talk for a little while. [00:40.600 --> 00:44.540] Well, like I said, I'm Faye, and I've been around for about ten years in this industry. [00:45.280 --> 00:50.240] Which doesn't make me exactly new, but it doesn't, you know, make me a veteran. [00:50.240 --> 00:57.340] It just puts me in the perfect sweet spot to look around and go, oh man, what the what is going on here, and what can we change about that? [00:58.220 --> 01:04.820] Other facts about me is that I have a master's degree, bachelor's degree, associate's degree, all in some realm of IT. [01:05.440 --> 01:08.100] That doesn't really matter, I just like telling people about that fact. [01:09.700 --> 01:18.680] I've played many roles in cybersecurity over the years, and then I settled on this one, which is as a threat researcher, a forensicator, and hacker in my free time. [01:20.860 --> 01:31.820] I'm a video game nerd, so I spun that into my presentation, because if I'm out there and I'm listening to someone speak, I want to be amused, and not look at boring slide decks. [01:32.980 --> 01:40.160] Lastly, warning to everyone, I am autistic and I do have Tourette's, so I do say a lot of cuss words, some things fall out of my mouth, oops. [01:41.100 --> 01:45.340] Maybe I'll stutter a little bit, I don't know, if at any time you got uncomfortable, I warned you. [01:48.520 --> 01:52.060] So, this is the agenda for MATAC. [01:53.360 --> 02:01.480] Basically, we're gonna first go over the shared natures between what private and public sectors have in common with threats. [02:01.900 --> 02:05.600] Then we're gonna go into the private-public relations, which hint, they're not good. [02:06.600 --> 02:11.960] We're gonna go over the threat intelligence sharing platform, which I will be proposing to you guys. [02:12.100 --> 02:17.200] It's all open-source software that you can use in order to collaborate with private and public entities. [02:18.300 --> 02:21.440] And lastly, we're gonna go into how collaboration affects us all. [02:21.840 --> 02:24.140] So, if you're still down to clown, let's go. [02:27.120 --> 02:29.320] Here's a pretty little thing you can look at. [02:29.320 --> 02:31.920] But it's not gonna change for the next few minutes. [02:32.280 --> 02:34.140] So, just warning you. [02:34.860 --> 02:44.300] So, in the digital realm, where cyber threats loom like sneaky ninjas in the shadows of our screens, it's easy to feel like we're in an action-packed thriller. [02:45.000 --> 02:50.100] The interconnectedness of our world has brought about unparalleled convenience and efficiency. [02:50.100 --> 02:55.540] However, with this interconnectedness, it also presents a common vulnerability. [02:56.600 --> 02:57.920] Cyber-scarity threats. [02:59.540 --> 03:02.280] Private individuals are dodging phishing attacks. [03:02.480 --> 03:10.360] Meanwhile, public institutions are flexing their muscles or not, as we saw with the AT&T breach. [03:11.780 --> 03:17.000] In this high-stakes game of cat and mouse, one thing is for sure, we're all in it together. [03:17.840 --> 03:22.560] Whether we're looking really cool behind a desk or we're throwing our phone against a wall. [03:23.840 --> 03:33.340] So, whether you're a private individual navigating the depths of our Internet or a public entity safeguarding sensitive information, the dangers lurking in cyberspace are for us all. [03:33.660 --> 03:35.260] Yeah, we're all sharing in that thing. [03:35.680 --> 03:36.300] Isn't it beautiful? [03:36.540 --> 03:37.660] Sharing threats together? [03:38.180 --> 03:39.180] I think so. [03:39.180 --> 03:44.360] So, the adversaries in the realm of cybersecurity are as diverse as we all are. [03:44.560 --> 03:47.900] Which is another beautiful thing about cybersecurity. [03:49.300 --> 03:50.940] So, yeah. [03:51.180 --> 03:58.820] Private individuals encounter these threats in various forms, from phishing scams, targeting personal information, to ransomware attacks on home computers. [03:58.820 --> 04:06.760] If you've not been doused with ransomware yet, if you have an email address and you open random emails, it is coming for you. [04:08.100 --> 04:11.760] So, public institutions face these same kind of threats. [04:12.080 --> 04:22.220] So, if you're looking at it, private individuals, private enterprises, public institutions should all really be coming together to pool our resources, expertise, and intelligence. [04:23.080 --> 04:30.940] Cooperation between sectors can enhance collective defenses, as each entity brings its own unique insights and capabilities to the table. [04:30.940 --> 04:42.440] Information sharing, coordinated responses, and joint initiatives become crucial pillars in fortifying our digital infrastructure against cyber threats. [04:43.100 --> 04:48.820] A vulnerability in one sector can quickly cascade into widespread chaos, like we saw with WannaCry. [04:49.180 --> 04:55.060] You know, it was this little thing, and then overnight it was this disastrous freaking thing. [04:55.380 --> 04:55.720] Okay? [04:55.840 --> 04:57.060] It took down so many people. [04:57.060 --> 05:02.880] Well, I remember being a SOC analyst at the time, being called in the middle of the night and being told, Oh my God, get down here. [05:03.080 --> 05:03.900] Please help us. [05:04.960 --> 05:08.520] And if you were around for that, you guys know exactly what I mean. [05:08.680 --> 05:09.620] It affected everyone. [05:09.800 --> 05:18.440] It affected everyone from a person with a banking app on their phone to the biggest institutions you could possibly think of, including our own government. [05:19.200 --> 05:29.780] So, therefore, fostering a culture of collaboration where information flows freely and cooperation is encouraged, it's essential in safeguarding for our collective interests. [05:30.620 --> 05:36.760] In essence, the battle against cyber threats is a shared endeavor that transcends boundaries and affiliations. [05:37.000 --> 05:40.360] So, if you think you're better than another person, you're wrong. [05:40.360 --> 05:46.000] That includes me speaking directly to anyone from three-letter agencies that are listening. [05:47.180 --> 05:57.280] By recognizing this shared reality and working together in a spirit of collaboration, we can strengthen our defenses and mitigate the ever-evolving threats that permeate the digital realm. [05:57.680 --> 05:59.220] Now you get to see something else. [05:59.900 --> 06:01.400] Ooh, what's coming? [06:01.860 --> 06:03.100] That's right, game over. [06:04.900 --> 06:12.660] All right, let's go into the different ways that the public and private have both been screwed over by different digital threats. [06:13.820 --> 06:15.660] All right, you guys ready to break into the song? [06:16.700 --> 06:17.580] I'm just kidding. [06:17.980 --> 06:18.120] Okay. [06:18.440 --> 06:21.860] But really, here are some big examples of our prior shared threats. [06:22.620 --> 06:23.020] Ahem. [06:25.740 --> 06:26.520] Thank you. [06:27.060 --> 06:28.480] Not pet your ransomware. [06:29.340 --> 06:30.460] WannaCry ransomware. [06:30.820 --> 06:32.120] SolarWinds supply chain attacks. [06:35.020 --> 06:36.100] Equifax data breach. [06:36.840 --> 06:38.260] Stuxnet, also really fun. [06:38.700 --> 06:43.020] The Ryuk ransomware that pillaged our lands about two years ago. [06:43.320 --> 06:44.820] They're back, by the way. [06:45.320 --> 06:45.720] Yeah. [06:46.400 --> 06:54.820] So, nearly every advanced threat that you can possibly think of, anything from, like, APT28, which is Phantom Bear, to, I don't know, Wandering Spider. [06:55.480 --> 06:56.560] We all got it, man. [06:57.620 --> 06:58.060] Yeah. [06:58.540 --> 07:02.260] So, you think about WannaCry, or you think about Stuxnet, and you're like, ugh. [07:02.580 --> 07:03.400] Oh, God, I hate that. [07:03.480 --> 07:04.320] I hate that so much. [07:05.460 --> 07:08.240] Well, everyone else was having the same exact reaction. [07:08.420 --> 07:24.600] I can guarantee you, behind closed doors, inside of different organizations, whether it be somewhere like a bank, not to name any, or a government institution, not to name any, everyone was sitting there thinking the same thing. [07:24.840 --> 07:30.600] And at some point, behind those closed doors, some people were like, you know what we should do? [07:31.400 --> 07:36.080] We should reach out to other people and see if they're experiencing the same thing. [07:36.080 --> 07:38.600] And then maybe we can track down the threat. [07:39.360 --> 07:40.940] Well, that's exactly what happened. [07:41.160 --> 07:44.980] So, Bob over at IBM reached out to Carl at Carbon Black. [07:45.220 --> 07:46.220] I don't know these people. [07:46.300 --> 07:47.200] These are made up names. [07:47.700 --> 07:53.440] And they reached out to Susan over at the NSA, and they were all like, oh, my God, we have the same exact information. [07:53.620 --> 07:55.460] Wait, no, I have this other piece of information. [07:55.640 --> 07:57.920] Oh, my God, that was the piece of information we were missing. [07:58.120 --> 08:01.240] And then they took all that information together, and you know what they did with that? [08:01.240 --> 08:02.800] They brought them down. [08:03.740 --> 08:04.140] Yeah. [08:05.040 --> 08:09.900] Just as quickly as WannaCry had come, they were freaking gone so fast. [08:10.680 --> 08:11.820] Why do you think that was? [08:12.260 --> 08:19.620] Well, it's not because some girl over at the NSA, Sally, Susan, whatever her name was, was like, well, let's do this thing. [08:19.760 --> 08:23.480] And it's not because Carl at Carbon Black was like, well, let's employ these rules detections. [08:23.620 --> 08:27.260] No, it was because they all came together and they said, let's beat the shit out of these people. [08:28.320 --> 08:32.160] And, you know, we've done that several more times in the past. [08:32.440 --> 08:34.940] So why not make it an official thing? [08:35.260 --> 08:37.200] Why not make it an organized thing? [08:37.320 --> 08:47.740] Why not make it an open-source thing, where organizations don't have to pay an obscure amount of money or have an obscure amount of funding in order to collectively share threat intelligence? [08:50.060 --> 08:51.540] So, how are we going to do that? [08:52.580 --> 08:53.880] Well, we're going to get into that. [08:53.880 --> 09:00.200] Yeah, I'm going to share with you a platform that I use in my own home to bring in threat intelligence. [09:00.860 --> 09:04.760] But for now, we have to talk about the private and public relationship. [09:05.180 --> 09:12.260] Because like any girlfriend, boyfriend, boyfriend, boyfriend, girlfriend, girlfriend, girlfriend, whatever, relationship, girlfriend, girlfriend, girlfriend. [09:12.640 --> 09:13.780] We go on forever. [09:13.980 --> 09:14.580] Tourette's, sorry. [09:15.740 --> 09:20.120] You know, it can have some unhealthy things in it and some really good things. [09:20.120 --> 09:25.020] So, you know, let's have some relationship counseling right now. [09:26.380 --> 09:33.680] So, navigating the cybersecurity landscape often feels like walking through a minefield, where one wrong step could lead to disaster. [09:34.300 --> 09:44.300] Unfortunately, the public and private organizations, when it comes to sharing cybersecurity information, is often characterized by hesitation and reluctance. [09:44.300 --> 09:55.020] Both sectors have their own concerns and priorities leading to a lack of proactive collaboration and information sharing. [09:55.260 --> 09:57.260] I mean, you can really imagine it, right? [09:57.340 --> 09:58.780] The government agency has... [09:58.780 --> 10:08.380] If you guys have ever worked with a government agency or in government, they have all these sensitivity labels like confidential or private or private confidential or top secret secret. [10:08.800 --> 10:09.700] Those kind of things. [10:09.820 --> 10:11.900] And they don't want those things getting out into the public. [10:12.220 --> 10:23.600] Which is kind of stupid, because from the things I've seen, it could be really good to share that information with each other, to help protect each other, especially if you're working in cybersecurity. [10:24.280 --> 10:26.160] If you think about it, CISA... [10:26.160 --> 10:27.480] You guys know CISA, right? [10:27.920 --> 10:28.220] Yeah. [10:29.100 --> 10:36.140] They reach out to plenty of organizations, small ones and big ones alike, and they ask for threat intelligence, and they're like, hey, have you seen this? [10:36.320 --> 10:45.860] So why not make it easier for CISA and other big places, and for CISA to give us information, we give CISA information, and then we go, oh my God, we know who these bad guys are. [10:45.980 --> 10:46.660] Let's get them. [10:48.400 --> 10:48.880] Yeah. [10:49.160 --> 10:55.020] So imagine a scenario where a government agency and a private company need to exchange crucial cybersecurity information. [10:55.460 --> 10:56.840] How is it currently done? [10:57.280 --> 10:59.840] Most likely through emails, which isn't very secure. [11:01.840 --> 11:06.320] It's like a diplomatic dance, with each party cautiously guarding their own interests and secrets. [11:06.700 --> 11:15.760] There is a palpable tension in the air, scrambling, and you're screaming, and both sides are weighing the risk and benefits of sharing sensitive information. [11:16.420 --> 11:20.420] Meanwhile, cyber threats are continuing to evolve, and they're doing it fucking fast. [11:20.720 --> 11:23.740] They're lurking in the shadows, and they're waiting for the right moment to strike. [11:23.940 --> 11:25.680] It's a constant game of cat and mouse. [11:26.800 --> 11:30.700] And there we are, trying to stay one step ahead of our adversaries. [11:31.360 --> 11:32.480] But here's the thing. [11:33.180 --> 11:42.320] Waiting until a major cyber incident like WannaCry or NotPetya incident occurs before fostering collaboration is giving them the advantage. [11:42.980 --> 11:50.660] Proactive engagement and information sharing between public and private sectors are essential for building a stronger defense against cyber threats. [11:50.660 --> 11:59.780] By breaking down silos, I said it, break down the silos, and establishing trust, organizations can create a more resilient cybersecurity ecosystem. [12:00.380 --> 12:02.900] It's not just about protecting individual interests. [12:02.900 --> 12:18.120] It's about safeguarding the digital infrastructure that underpins our society as a whole, whether that be from our nuclear sites, which real damage would happen if they were hacked, to our hospitals, which we've seen the deaths that have occurred here in the United States from that alone. [12:18.120 --> 12:21.560] Not to mention like Australia who, oh, they got hit hard. [12:23.820 --> 12:25.100] So how are we going to do that? [12:25.460 --> 12:26.340] Oh, I don't know. [12:26.480 --> 12:27.560] How about we talk about... [12:30.080 --> 12:31.520] Intent intelligence sharing. [12:31.980 --> 12:33.040] Thank you for the drum roll. [12:33.480 --> 12:34.560] I like this. [12:35.800 --> 12:39.260] So navigating is a minefield. [12:39.860 --> 12:54.200] And now that we've covered that and our shared nature of threats and how important it is to come and collaborate together against those shared threats, remember that pooling resources and expertise enhances analysis capabilities and makes us stronger against threats. [12:55.680 --> 12:58.680] Let's get into sharing and how it would look like. [12:58.800 --> 13:02.840] I'm going to propose a very simple, completely open-source way of doing this. [13:02.840 --> 13:08.980] This makes it so everyone, anyone with any budget, or every budget, can collaborate. [13:08.980 --> 13:10.800] We're taking away the financial barrier. [13:16.180 --> 13:18.260] Ooh, you guys don't get to see this yet. [13:18.580 --> 13:19.260] That's right. [13:20.340 --> 13:27.000] So before we get into this, I'd like you guys to imagine a farm or some plants, whatever you like to do in the city, out on your little terrace. [13:27.000 --> 13:28.760] You're planting a nice little herb garden. [13:28.760 --> 13:29.780] You're going to use that for dinner. [13:29.960 --> 13:30.560] Mmm, delicious. [13:33.460 --> 13:35.220] Yeah, all right. [13:35.480 --> 13:44.480] Okay, so we're using a plant-based analogy here to explain how these components work together in a cyclical fashion. [13:44.760 --> 13:45.360] It goes like this. [13:46.740 --> 13:48.060] So whatever that word is. [13:48.940 --> 13:50.440] We start out with the raw data. [13:50.680 --> 13:52.220] So think of raw data as seeds. [13:52.520 --> 14:01.120] These seeds come from various sources, each as logs from, like, firewalls, intrusion detection systems, and threat feeds on their own. [14:01.820 --> 14:07.140] They can be great, but they're just a potential waiting to be realized, like a seed. [14:07.840 --> 14:12.580] So then you have elk stack, where it acts as the greenhouse for the seeds. [14:12.840 --> 14:15.460] This is where it's planted, nurtured, and grown. [14:15.640 --> 14:17.000] What composes of elk stack? [14:17.140 --> 14:20.840] Well, we have elastic surge, which would act as the fertile soil where the seeds are planted. [14:21.140 --> 14:25.980] It stores and indexes the data, allowing for healthy growth, like fast surge and retrieval. [14:26.520 --> 14:36.180] Then you have log stash, the L and elk stack, acts like the gardener who prepares the soil and plants the seeds, transforming the raw seeds into sprouts, otherwise known as structured data. [14:36.800 --> 14:40.760] And cabana, which is the sunlight and water that helps the plants grow. [14:40.960 --> 14:51.920] It visualizes the data, providing dashboards and analytics to help identify patterns and anomalies, like spotting which plants are thriving and which need more attention. [14:54.180 --> 14:59.220] The next part in the cycle is open CTI, which is literally my favorite thing in the world. [14:59.400 --> 15:05.120] I was introduced to open CTI a while back when I was doing digital forensics for a big old firm. [15:06.380 --> 15:07.360] It was amazing. [15:07.540 --> 15:14.800] I mean, the way that you can use open CTI to collect your threat intelligence and then use it to attribute different threat actors. [15:15.500 --> 15:16.860] Absolutely beautiful. [15:17.940 --> 15:25.960] So, open CTI and this analogy is like the botanical garden where plants are carefully labeled and arranged. [15:26.460 --> 15:37.300] It takes the plants, otherwise known as process data, from the greenhouse and adds additional information, like context and enrichment, organizing them into beautiful and informative displays. [15:38.060 --> 15:39.760] Structured threat intelligence reports. [15:41.400 --> 15:52.860] Gardeners, otherwise known as the analysts, use open CTI to correlate data, identify patterns, and map out intricate relationships between different plants, like threat actors and threat vectors. [15:53.380 --> 15:58.520] Finally, you have MISP, which is the malware information sharing platform and threat sharing. [15:59.300 --> 16:01.560] It acts as the seed exchange platform. [16:01.980 --> 16:05.260] So, you have the gardeners from your organization. [16:05.300 --> 16:09.080] They share their seeds and their plants with other gardeners. [16:09.260 --> 16:10.520] This is where they would do it. [16:10.860 --> 16:11.320] MISP. [16:11.420 --> 16:13.080] It's where the seed exchange happens. [16:13.500 --> 16:18.680] So, you take all the information that you have from open CTI, these beautiful plants that you have. [16:18.980 --> 16:23.960] You then go to the seed exchange, otherwise known as MISP. [16:23.960 --> 16:25.800] And you're like, hey, you see these? [16:26.020 --> 16:26.840] You want some? [16:27.220 --> 16:28.020] Have some. [16:28.360 --> 16:28.580] Yeah. [16:29.840 --> 16:34.920] So, this exchange program facilitates the sharings of the seeds or the threat indicators. [16:35.420 --> 16:41.660] And things like IP addresses, domain names, other things from file hashes to you freaking name it. [16:42.740 --> 16:45.120] Other gardeners can also contribute their seeds. [16:45.480 --> 16:50.500] Literally anyone can go onto this bad boy, create their own galaxy, and share this information across with each other. [16:50.920 --> 16:52.260] That's how freaking cool it is. [16:52.260 --> 16:54.000] So, that's the cycle. [16:54.360 --> 17:04.660] It goes from raw data, collecting the seeds, elk, planting and nurturing, open CTI, organizing, and then MISP, the sharing seeds and plants in the seed exchange. [17:05.140 --> 17:14.440] This process ensures that the plants, otherwise known as threat intelligence, are continuously nurtured, refined, and shared, enhancing the overall diversity and resilience of the garden. [17:14.440 --> 17:16.440] Cybersecurity ecosystem. [17:17.100 --> 17:17.320] Cybersecurity ecosystem. [17:18.360 --> 17:19.840] By working together... [17:19.840 --> 17:20.840] I got so distracted. [17:21.320 --> 17:31.260] By working together, gardeners' organizations create a more vibrant and secure environment, where everyone benefits from the shared knowledge and cultivated plants. [17:33.060 --> 17:34.160] And it's all free. [17:34.740 --> 17:35.220] And it's all free. [17:35.220 --> 17:35.300] Yeah. [17:38.860 --> 17:40.340] I hope you guys like this. [17:41.560 --> 17:47.720] I'm proposing here that collaboration is the cheat code to beating these guys for... [17:48.260 --> 17:50.240] Just take a minute to look at it if you don't get it. [17:51.320 --> 18:01.900] In the increasingly interconnected world of cybersecurity, the need for a unified global response to combat threat across borders is not just contagious, it's imperative. [18:02.420 --> 18:11.660] Cyber threats, whether they originate from state-sponsored actors, criminal organizations, or malicious hackers, they all transcend geographical boundaries. [18:11.660 --> 18:15.740] They target governments, industries, individuals, all indiscriminately. [18:15.920 --> 18:16.720] I don't give a fuck. [18:17.580 --> 18:21.960] They all exploit vulnerabilities inside of our interconnected digital infrastructure. [18:22.520 --> 18:27.220] Efficiency is paramount in cybersecurity defense, and collaboration is the key to achieving it. [18:27.420 --> 18:34.540] By pooling resources, expertise, and intelligence, nations and organizations and individuals can maximize their defensive capabilities. [18:34.860 --> 18:37.060] Sharing threat intelligence... [18:38.430 --> 18:39.320] Someone yawned, sorry. [18:39.320 --> 18:41.480] It's contagious, oh my god. [18:42.420 --> 18:43.700] Yeah, I see you. [18:46.200 --> 18:53.120] Sharing threat intelligence and best practices allows for quicker identification of emerging threats and more effective mitigation strategies. [18:53.440 --> 19:00.140] This collaborative approach ensures that defenses are not only robust, but also adaptive and responsive to all the threats that we're gonna face. [19:00.660 --> 19:04.080] Moreover, cost-effective defense strategies are within reach. [19:05.540 --> 19:06.260] That's it. [19:06.600 --> 19:07.240] It's within reach. [19:07.240 --> 19:09.400] Literally anyone could do it because it's free. [19:10.340 --> 19:16.880] So, if you're gonna go back to your boss and you're like, hey, I know this great way to share threat intelligence and he's gonna go, well, we can't do that. [19:16.960 --> 19:17.820] We don't have it in the budget. [19:18.460 --> 19:19.160] Yes, you do. [19:19.880 --> 19:20.480] Don't lie. [19:21.280 --> 19:22.720] We know what you're talking about. [19:23.720 --> 19:24.360] All right. [19:26.260 --> 19:34.220] During cyber attacks such as ransomware outbreaks or data breaches, swift and coordinated responses can significantly minimize damage and disruption. [19:35.160 --> 19:44.860] Shared incident response protocols, coordinated exercises, and joint threat assessments enable faster identifications of attack vectors and ensures proactive defense. [19:44.860 --> 19:47.580] Learning from peer organizations. [19:47.580 --> 19:50.380] Learning from peer organizations experiences is invaluable and fortifying defenses. [19:50.740 --> 20:00.440] Case studies, incident reports, and collaborative forums provide insights into tactics employed by threat actors and vulnerabilities exploited. [20:00.720 --> 20:02.620] Imagine there's a vulnerability out there. [20:03.140 --> 20:03.600] Okay. [20:03.920 --> 20:03.960] Okay. [20:04.040 --> 20:04.940] Let's put this down. [20:05.520 --> 20:05.760] Mac. [20:06.500 --> 20:07.780] Everybody's like, oh, Mac. [20:07.980 --> 20:09.120] You can't hack Mac. [20:09.360 --> 20:09.700] Wrong. [20:11.400 --> 20:15.140] Well, let's just say, big vulnerability exists in Mac. [20:15.260 --> 20:16.260] Mac doesn't know about it. [20:16.340 --> 20:18.000] Mac hasn't published anything about it. [20:19.100 --> 20:21.580] Next day, your computer won't turn on. [20:22.040 --> 20:23.180] Your Mac is dead. [20:23.740 --> 20:24.840] No, it's dead dead. [20:25.200 --> 20:28.240] Like, even if you replace your laptop battery, it's freaking fried. [20:28.560 --> 20:29.920] Yeah, the hardware in it is fried. [20:30.040 --> 20:30.720] You wanna know why? [20:30.720 --> 20:35.000] Because someone exploited that vulnerability overnight during one of the latest updates. [20:35.300 --> 20:40.800] And now millions of Americans, not just Americans, let's go, let's, let's go out about it. [20:41.180 --> 20:49.820] Millions and millions of people across the United, the whole globe, all of them, they're all screwed. [20:50.160 --> 20:51.200] Their laptops are dead. [20:51.500 --> 20:52.500] How are they gonna get into work? [20:52.560 --> 20:53.960] How are they gonna play their video games? [20:54.140 --> 20:55.700] How are they gonna go about doing anything? [20:55.700 --> 20:56.540] They can't. [20:56.540 --> 21:02.920] Because this vulnerability was exploited overnight through one of their mandatory updates that were pushed out. [21:03.140 --> 21:05.280] Nobody knew this was coming at all, except for Bob. [21:05.940 --> 21:09.760] Yeah, Bob, over at that security company that you never heard of. [21:10.240 --> 21:11.760] That little startup that happened. [21:11.980 --> 21:13.720] You see, Bob was ahead of his game. [21:14.840 --> 21:17.880] He's just a kid, straight out of college, maybe 18 years old. [21:17.880 --> 21:23.260] He works for this little company as an intern, but he's been studying different hardware hacking techniques. [21:23.540 --> 21:26.260] And while he was looking over his MacBook, he was like, oh, you know what? [21:26.320 --> 21:27.940] That would really suck if this were to happen. [21:28.200 --> 21:30.260] I should probably reach out to Apple about this. [21:30.360 --> 21:32.180] So he reaches out to Apple, doesn't listen to him. [21:32.660 --> 21:33.760] Who cares about this kid? [21:33.980 --> 21:36.060] Straight out of college, 18 years old, doesn't know anything. [21:36.560 --> 21:37.700] So no one listens to him. [21:38.340 --> 21:41.020] And he doesn't really have a platform to share this information. [21:42.060 --> 21:43.300] So there he goes. [21:43.700 --> 21:45.380] He's the only one with this information. [21:48.020 --> 21:49.100] Everything is destroyed. [21:49.820 --> 21:52.220] And Bob's over there like, well, I tried to tell Apple. [21:52.960 --> 21:57.760] So then, I don't know, CNN news picks it up and they go, well, Bob knew about it, Apple. [21:57.880 --> 21:59.260] How come you didn't know about it? [21:59.380 --> 22:03.360] And Apple goes, well, I don't know why we didn't know about it. [22:03.560 --> 22:04.140] You know what? [22:04.180 --> 22:05.200] That's a really good point. [22:05.340 --> 22:07.200] Or whatever bullshit they're going to spew, right? [22:07.320 --> 22:08.780] Their little marketing talks, whatever. [22:10.220 --> 22:11.900] What could have changed that? [22:12.040 --> 22:13.560] That's right, intelligence sharing platform. [22:13.760 --> 22:14.220] That's right. [22:14.360 --> 22:16.600] Breaking down the walls between private and public sectors. [22:16.840 --> 22:19.400] Not looking at each other and going, well, you're seven years old. [22:19.640 --> 22:21.300] What do you know about hardware hacking? [22:21.920 --> 22:22.880] Probably a lot. [22:23.100 --> 22:26.420] That kid had a freaking iPhone in his hand the day he was born. [22:26.700 --> 22:27.120] Okay? [22:27.700 --> 22:36.540] So I don't believe in looking at people and going, you know, we probably shouldn't listen to them just because they're not like 70 years old and hacking. [22:37.300 --> 22:38.660] Which would be really funny. [22:39.680 --> 22:40.220] No. [22:40.460 --> 22:44.680] We should all be able to collect this threat intelligence. [22:45.020 --> 22:46.940] And we should all be able to share it with each other. [22:47.160 --> 22:49.620] And people should be taking it seriously. [22:49.880 --> 22:51.660] Like organizations like Apple. [22:52.280 --> 22:55.020] Organizations like CISA who have a global reach. [22:56.120 --> 22:57.020] So yeah. [22:57.300 --> 23:02.640] Learning from peer organizations is essentially invaluable in fortifying everyone's defenses. [23:04.520 --> 23:05.960] And yeah. [23:06.220 --> 23:10.420] In conclusion, the benefits of a unified global response is pretty clear. [23:10.640 --> 23:13.060] It enhances resilience, operational efficiency. [23:13.300 --> 23:14.100] It's cost effective. [23:15.620 --> 23:18.560] It helps with the accelerated response capability. [23:18.560 --> 23:20.720] And it allows for continuous learning. [23:20.980 --> 23:26.460] By fostering collaboration across borders, across nations, across freaking everywhere. [23:26.780 --> 23:32.920] Organizations can collectively navigate the complex cybersecurity landscape with greater agility and effectiveness. [23:33.420 --> 23:38.560] Together, we can build a more secure digital world. [23:47.990 --> 23:50.050] I will be answering questions at this time. [23:52.030 --> 23:52.850] Young girl. [23:53.350 --> 23:54.850] So, I have a question. [23:55.390 --> 24:04.270] Is this cybersecurity sharing platform, is it a thing where you like publish your intelligence and everyone in the whole world can see it? [24:04.330 --> 24:09.110] Or do you have to be like in the industry or have some sort of credentials to access it? [24:09.110 --> 24:11.390] So, you can access it. [24:11.550 --> 24:12.830] Anyone at home can access it. [24:12.950 --> 24:14.890] You don't need credentials in order to access it. [24:15.330 --> 24:18.170] Specifically, what I'm talking about is MISP and OpenCTI. [24:18.450 --> 24:23.690] Those are both the platforms where you can go publish your threat intelligence and other people can go and find it. [24:24.750 --> 24:28.010] With these two tools, you can select who views what. [24:28.190 --> 24:30.370] So, whether you want to keep it private or public is up to you. [24:30.490 --> 24:33.590] But people, you know, if you want it found, people can find it. [24:35.910 --> 24:37.190] Stand, I can barely say it. [24:37.730 --> 24:38.410] Stand for? [24:38.650 --> 24:39.210] Hold on. [24:39.330 --> 24:39.810] It's really long. [24:42.630 --> 24:44.390] I mess up my words all the time. [24:44.510 --> 24:46.890] So, I have to... [24:46.890 --> 24:50.790] Malware information sharing platform and threat sharing. [24:51.870 --> 24:51.970] Yeah. [24:59.130 --> 25:00.790] I'm writing that one down for later. [25:03.370 --> 25:04.390] Yes, it's open-source. [25:04.530 --> 25:06.310] All of this is open-source, completely free. [25:06.310 --> 25:08.270] You can find all of this on GitHub. [25:09.390 --> 25:10.750] Literally, it's freaking awesome. [25:13.150 --> 25:13.630] Yes? [25:15.190 --> 25:17.150] Do you have for elk in this scenario? [25:17.870 --> 25:19.110] For elk in this scenario? [25:19.550 --> 25:20.910] This is a great question. [25:20.970 --> 25:28.830] Especially for people who don't work in a SOC or don't have the cost, whatever, to have a SOC. [25:29.510 --> 25:30.570] Elk is really cool. [25:30.570 --> 25:37.230] For those who don't work in a SOC, what happens in something like elk is it visualizes all of your data. [25:37.390 --> 25:44.850] So, it's ingesting the data, ingesting these logs, anything from like your web filter logs. [25:44.850 --> 25:51.770] So, we're seeing anything from like, let's say there's an attack happening over on HTTP. [25:52.670 --> 25:54.850] You're looking at HTTP log data. [25:54.990 --> 25:55.870] So, that's where you go. [25:55.950 --> 25:56.910] You look into elk. [25:57.050 --> 25:59.030] You're searching for that data in elk. [25:59.150 --> 26:00.050] That's where you go for it. [26:00.090 --> 26:01.350] That's where you visualize the data. [26:02.110 --> 26:06.570] So, overall, you're looking at... let's say there's an attack that happens, I don't know, last month. [26:06.710 --> 26:09.770] Client comes to you or whoever comes to you or you notice this on your network. [26:09.910 --> 26:13.570] You're like, wow, I'd never noticed this application before where this application to come from? [26:13.690 --> 26:14.690] Well, you go into elk. [26:15.030 --> 26:16.650] You look for the application's name. [26:18.010 --> 26:21.750] Over whatever period of time, you find that it's all the way back from April. [26:21.950 --> 26:24.650] You're like, well, how did that get in here from April? [26:25.190 --> 26:27.250] Well then you can look even further back from that. [26:27.330 --> 26:29.010] You can look at the log surrounding that. [26:29.010 --> 26:33.250] And that's what it's used for, it's looked for incident drilling, basically. [26:41.000 --> 26:41.640] Sick. [26:43.740 --> 26:44.720] Well, that's it. [26:44.780 --> 26:45.160] Who's hungry? [26:46.500 --> 26:47.140] Me. [26:47.760 --> 26:48.400] Sick.