[00:00.000 --> 00:08.600] How can reference, and is more stuff going to be referenced as September 1st here in the United States as legislation and laws that are going to be driven by regulators that CREST will be managing? [00:08.960 --> 00:12.660] But the things that are really interesting that you may want to reference is Assure. [00:12.660 --> 00:13.460] I'll take the first one. [00:14.080 --> 00:25.540] If you are in the avionics industry, if you're flying planes, if you're doing satellite work, if you're doing things that are going to be tied to human life on, you know, planes, there's a process there which is considered critical or non-critical. [00:25.540 --> 00:31.320] And the regulators of the equivalent for Assure is what the FAA is here in the United States. [00:31.640 --> 00:37.320] And they require these organizations to do the assessments to be able to have a certain level of quality. [00:38.380 --> 00:38.940] CBEST. [00:39.180 --> 00:41.400] We manage the program for the Bank of England. [00:41.580 --> 00:43.400] We've done that since 2006. [00:43.840 --> 00:49.260] So we manage a program for the bank and all that communicate with the Bank of England. [00:49.440 --> 00:52.920] And this helps those organizations have assurance and quality of services. [00:54.260 --> 00:56.900] NCSC, right, the National Cyber Security Center. [00:57.280 --> 00:59.460] Again, another area for incident response. [00:59.680 --> 01:00.060] Forensics. [01:00.200 --> 01:08.680] Being able to, when a buyer has the most worst day of their life, and they have to go ahead and reach out to get help because they need assistance. [01:08.960 --> 01:11.420] And getting assistance after the fact is always crazy, right? [01:12.060 --> 01:15.400] They have to know sort of who are trusted service providers that can help them. [01:15.820 --> 01:20.100] And again, our registrar helps those organizations sort of get to the right people quickly. [01:21.560 --> 01:33.000] So again, we have lots of different regulatory items that we do for governments, regulatory bodies, and of course, measurements of standards which are, again, consistent and very affordable. [01:34.400 --> 01:37.220] So the Crest community continues to evolve, right? [01:37.320 --> 01:39.320] We continue to sort of work with academia. [01:39.600 --> 01:42.980] We work with grassroots efforts like HOPE, right, as a sponsor here. [01:43.240 --> 01:47.680] We work with a lot of the universities here in the States now to sort of demonstrate what good looks like. [01:47.680 --> 01:51.200] We're doing some work with the NSA Center of Excellence across the country. [01:51.720 --> 02:00.080] The goal here is to sort of help set some syllabuses and help inject some quality items into these items that are useful. [02:00.140 --> 02:05.540] So when people come out of university, they can then get into careers or get into jobs, right? [02:05.620 --> 02:09.020] Both on the defender side and even on the service provider side. [02:10.560 --> 02:12.780] So if you came in, you may have seen two things. [02:13.220 --> 02:16.020] The first thing that you came to the door on is a little what is Crest, right? [02:16.080 --> 02:18.100] So a lot of what I just talked about is here, right? [02:18.400 --> 02:22.420] But what was released today is this document here, which is useful. [02:24.540 --> 02:27.940] My day job is the CIO for an international law firm. [02:28.300 --> 02:30.080] I spend a lot of time working with lawyers. [02:30.180 --> 02:32.980] I'm not a lawyer, but I know a lot of great lawyers. [02:32.980 --> 02:35.420] And I help them with a lot of technical components, right? [02:35.560 --> 02:40.660] Like interpreting IP issues, interpreting security issues, data breach issues, etc. [02:41.500 --> 02:48.420] And a lot of the problems that they have as attorneys, of course, is to, in a court of law, determining, you know, where liability falls. [02:49.400 --> 02:54.100] And Crest has done a really great job with trying to help align themselves with that sort of conversation. [02:54.100 --> 02:57.580] Because what is commercially reasonable security? [02:58.500 --> 03:00.680] I'm not sure anybody here can answer that question clearly. [03:01.220 --> 03:04.340] Because most organizations would need to do the following. [03:04.540 --> 03:07.080] They would need to pick a framework that they want to measure against. [03:07.380 --> 03:12.200] They would need to then measure against that framework with organizations that have the experience to do that sort of work. [03:12.480 --> 03:20.600] They would need to report on that and then take those corrective actions as needed and demonstrate the process that they are able to be commercially defensible. [03:21.160 --> 03:37.840] When organizations have problems, because everyone will, everyone does, when there are situations that get litigious with lawyers and no one likes lawyers, but when you get into a situation of pointing fingers and saying, well, what have you done to try to demonstrate your organization's ability to secure the code? [03:38.060 --> 03:43.100] You wrote code, the code was compromised, resulted in loss, resulted in human life. [03:43.500 --> 03:44.340] Let's go back. [03:44.540 --> 03:45.520] What did you do? [03:45.700 --> 03:46.920] How did you manage your code? [03:47.160 --> 03:54.920] So if an organization can come back to you and say, well, we used the OWASP ASVS version 4, we do a level 2. [03:55.220 --> 04:03.260] This allows us to take these controls relative to the OWASP guidance for software security and we're good to go because that's how we manage our software development program. [04:03.740 --> 04:05.300] You can manage and map to that. [04:05.420 --> 04:07.420] That may be useful in those conversations. [04:07.740 --> 04:13.440] If you get assessed to the center of Internet security version 8 and you use that as a methodology, fantastic. [04:13.880 --> 04:16.620] If you're using national cybersecurity framework, you see where I'm going? [04:16.800 --> 04:21.120] There's items here that businesses need to put the flag in the ground and help manage to, right? [04:21.220 --> 04:26.900] Again, CREST is there to assist in that process in the complicated cybersecurity space. [04:28.060 --> 04:34.020] But in this document, it's the CREST approved penetration tests, or CAPT, which is interesting. [04:34.280 --> 04:35.680] So what is a pen-test? [04:36.120 --> 04:43.800] Again, doing this personally and professionally for over 20 years, from source code analysis to threat modeling, etc., it's always different. [04:44.220 --> 04:46.080] Somebody says, I need a pen-test. [04:46.240 --> 04:48.040] You're like, alright, well, let's have that conversation. [04:48.220 --> 04:48.840] What are you looking to do? [04:48.960 --> 04:49.400] What's your goal? [04:49.600 --> 04:52.080] Well, I want to do a code analysis of the software. [04:52.300 --> 04:52.960] Is that a pen-test? [04:53.340 --> 04:56.600] Or, hey, I want you to scan the outside of my company and see if a bad guy can get in. [04:56.740 --> 04:57.560] Is that a pen-test? [04:57.800 --> 05:00.500] I want to send some phishing emails and try to hook the browser using beef. [05:00.780 --> 05:01.680] Is that a pen-test? [05:02.480 --> 05:04.260] There's a couple things that we need to clarify. [05:04.580 --> 05:06.940] So trying to have that laid out is very, very helpful. [05:07.080 --> 05:13.100] And it's confusing for the industry and for the folks that deliver services or products in the industry to try to align some of that vocabulary. [05:13.460 --> 05:14.840] And I blame marketing, right? [05:14.880 --> 05:17.220] I blame marketing to have all these different terms. [05:17.360 --> 05:19.680] And you throw the AI word in there, it gets real confusing. [05:19.680 --> 05:21.700] So it gets It's down to sort of competency. [05:22.580 --> 05:26.540] So the cap phases that are described in the document are really important. [05:26.760 --> 05:28.480] And again, we've been doing this for a long, long time. [05:28.700 --> 05:34.320] So since 2006, this hasn't really changed, but it helps formalize it in a document that can be referenced, right? [05:34.780 --> 05:38.040] Being able to scope, being able to do delivery, being able to do sign-off. [05:38.140 --> 05:41.040] And I know our partner here will be speaking about that, so I won't steal his thunder. [05:41.700 --> 05:45.240] But understanding that we have recognized levels of individuals. [05:45.540 --> 05:49.900] And you might agree that there's lots of different people in the room, including those with some gray hair on their beards, right? [05:49.900 --> 05:53.380] So we have the idea of the practitioner, right? [05:53.460 --> 05:55.700] The practitioner has about a year experience. [05:56.060 --> 06:01.320] You know, he's been doing his homework, working real hard in the space, and is registered as a CREST practitioner. [06:01.680 --> 06:06.140] There's a CREST registered individual that's got about, you know, three years of experience, verifiable. [06:06.460 --> 06:08.480] He may have gone out and taken OSCP. [06:08.740 --> 06:09.600] He may have done GIAC. [06:09.680 --> 06:11.340] He may have done some education work. [06:11.400 --> 06:12.380] He may have done some hands-on. [06:12.520 --> 06:14.880] But he can demonstrate a certain level of expertise. [06:15.500 --> 06:19.020] And then there's certified, which is about five years of verifiable experience. [06:19.020 --> 06:25.380] Those three things are very helpful in trying to deliver organizations to what they are asking for in the pen-test space. [06:26.380 --> 06:27.180] Also, consistency. [06:27.520 --> 06:32.380] Again, you may, as an organization, if you're a consumer, you may require things in a quarterly basis. [06:32.380 --> 06:33.560] You may want things annual. [06:33.760 --> 06:35.300] You may want things in electronic format. [06:35.420 --> 06:36.780] You may want things in a certain process. [06:36.780 --> 06:39.780] Well, what if we laid out what reporting should look like? [06:39.920 --> 06:42.140] And what if that helped normalize the industry? [06:42.460 --> 06:48.320] Because reporting vulnerabilities, reporting problems, and corrective action should be in a consumable manner that people can use. [06:48.880 --> 06:52.840] So, again, I mentioned other organizations, and I want to call that out. [06:53.160 --> 06:55.820] Because I said CREST does accreditations. [06:56.200 --> 06:58.620] And yes, we do some certifications as well. [06:58.840 --> 07:02.300] But accreditations is really what's important in the bigger picture of CREST. [07:02.380 --> 07:06.040] Because we're really helping the normalize the international space for cyber. [07:06.820 --> 07:11.340] And we recognize and we embrace a lot of our peers, right? [07:11.480 --> 07:14.980] Our peer organizations that are doing certifications, accreditations. [07:15.160 --> 07:19.420] Right across the water here, we have our New York University folks that do, you know, seesaw. [07:19.740 --> 07:22.560] St. John's is a fantastic job in our cybersecurity program. [07:23.020 --> 07:25.280] Each of the different organizations bring something to the table. [07:25.480 --> 07:30.220] And we're really trying to help map that and measure that to what good looks like and what's repeatable. [07:30.220 --> 07:34.980] So, with that, I'd like to take the time to introduce one of the CREST members, one of the CREST partners. [07:35.600 --> 07:38.160] This organization's been with CREST for a number of years. [07:38.620 --> 07:42.960] And nobody better to speak to what his pen-test program looks like than one of the pen-testers. [07:43.060 --> 07:44.280] Let me just swap over, guys. [07:44.740 --> 07:45.240] Thank you. [08:04.220 --> 08:04.820] There we go. [08:05.100 --> 08:05.500] All right. [08:05.940 --> 08:12.080] So, first of all, thanks, Tom, for having us here sharing the table with you. [08:12.920 --> 08:26.620] I'm going to give an introduction of myself, Verisprite, and how we approach the CAPT specification with a real case study of a recent engagement that we completed. [08:28.100 --> 08:29.700] That's the agenda, basically. [08:30.540 --> 08:34.960] So, I'm the leader of the offensive security practice at Verisprite. [08:35.080 --> 08:37.600] I go by WACO, which is easier than drugging. [08:38.580 --> 08:42.820] I have plus 15 years of experience doing pen-testing. [08:43.580 --> 08:47.560] So, Verisprite is a global security firm. [08:48.280 --> 08:49.800] It has a global presence. [08:50.080 --> 08:56.060] I have my team spread in Barcelona, Buenos Aires, there's people in Atlanta, people in Romania. [08:56.380 --> 09:01.400] We are CREST accredited, as Tom said, for a couple of years now. [09:02.120 --> 09:06.780] We are offensive-minded, but with a focus on risk. [09:07.100 --> 09:19.480] Actually, our CEO is the author of the PASTA framework, which is a threat modeling framework that puts customers at the center of the scene, and gives context to everything that we find. [09:22.020 --> 09:28.660] There are some cases where maybe technically an issue can be considered critical, because it is nice. [09:28.840 --> 09:39.200] You could do maybe run code on a server and whatnot, but in reality, for the business, it's not that urgent, maybe, to go and take care of that. [09:39.320 --> 09:42.640] So, we use PASTA to give context to everything that we do. [09:44.720 --> 09:50.940] So, yes, I was saying, I've been pen-testing since I was 18 years old, I think. [09:51.640 --> 10:01.440] And I can definitely say, as Tom was commenting before, the definition of a pen-test is, right now, broader than ever, I could say. [10:01.640 --> 10:02.920] There's no single definition. [10:03.080 --> 10:08.640] There's no one that can actually say or define for everyone what a pen-test is. [10:08.640 --> 10:20.660] We even have, as Tom said, I mean, marketing created this nice thing here, telling customers or potential deals how we interpret each of the many services, right? [10:20.820 --> 10:29.380] Vulnerability assessment, penetration testing, red teaming, each one with their own testing methodology, each one targeting different targets. [10:31.400 --> 10:49.500] But despite having this kind of broad interpretation of what an exercise could look like, I think, and I'm going to use a quote from one of our customers that I think was quite nice to do a recap on everything here. [10:49.700 --> 10:52.780] It's about the process behind the methodologies. [10:53.260 --> 10:58.240] And that's what, actually, the specification for CAPT comes to solve, right? [10:58.240 --> 10:59.560] The process. [10:59.880 --> 11:09.280] It focuses on the process for scoping, the process for delivery or the execution of the engagement, as well as the signing off of the testing. [11:09.660 --> 11:18.680] So, with that, I wanted to bring a case study of a real engagement we completed. [11:20.080 --> 11:27.380] Customer was calling this when they reached out, a cloud security operational assurance for ACME. [11:27.520 --> 11:28.460] I'm using ACME here. [11:29.280 --> 11:33.520] And basically, I mean, the word assurance was there. [11:33.520 --> 11:40.600] So we knew that customer was going to most likely be using this to show they are doing things right. [11:41.800 --> 11:43.100] They are being diligent. [11:43.540 --> 11:51.580] And they may be also be using this for regulation purposes, because customer was coming from a healthcare industry, right? [11:51.740 --> 11:56.960] So, we already knew this was serious matter, you know? [11:57.100 --> 12:00.540] I mean, there was going to be people taking a look at the results. [12:00.540 --> 12:06.780] So, we wanted to do our best along the entire three phases that we have here. [12:07.860 --> 12:12.480] And the first thing that we have to do is to talk to the customer, as Tom said. [12:12.700 --> 12:18.180] I mean, you're calling this a cloud security operational assurance, so what do you mean by that, right? [12:18.360 --> 12:19.520] What's the scope of work? [12:20.000 --> 12:21.060] What are the goals? [12:21.220 --> 12:21.940] What are the objectives? [12:22.020 --> 12:23.360] What do you have in mind, right? [12:23.360 --> 12:25.740] What are you going to be using this for? [12:26.080 --> 12:31.660] So, when talking to the customer, we defined a couple of things. [12:32.020 --> 12:40.720] We identified they were looking to assess the overall infrastructure, but with a big focus on the cloud portion. [12:41.240 --> 12:49.140] They were looking for adversarial exercises, so we already knew we would take kind of a red teaming approach here. [12:49.140 --> 12:57.520] They were not willing to share any information, so definitely a black box approach, more of a red teaming, not so much of a pen-test. [12:58.520 --> 13:07.260] We were free to actually touch on everything that was public, so the targets could vary a lot. [13:07.420 --> 13:15.680] I mean, they were talking about public infrastructure, but we also found they had mobile apps in the stores that we could take a look at, and so on. [13:16.480 --> 13:17.840] Broad the scope here. [13:18.160 --> 13:26.520] They were also looking to determine how we could abuse everything that could be found publicly, via OSINT or some other means. [13:27.340 --> 13:30.900] And then we discussed about some rules of engagement, which are quite important. [13:31.500 --> 13:37.380] They wanted daily updates, obviously, specifically around critical findings. [13:38.680 --> 13:45.300] And they were not looking for us to do any kind of extraction during the proof of concept for post exploitation. [13:45.700 --> 13:52.600] They were just looking for us to show the potentiality of the issues. [13:53.060 --> 13:59.420] Of course, as with every single engagement, avoid at all costs disruption of services, because we were testing production. [13:59.420 --> 14:00.700] So that's good. [14:00.880 --> 14:02.480] I would say that's normal nowadays. [14:04.520 --> 14:11.680] So, once we knew what this was about, we started working on the team assignment. [14:13.340 --> 14:20.560] We really needed skilled people, not only during the scoping process, which I was part of, also Courtney here from Sales. [14:20.560 --> 14:29.940] And the way we worked with the team was having a principal security consultant leading the whole engagement. [14:30.260 --> 14:36.120] And this was a teamwork because of the size of the scope and the time we had to do the work. [14:36.120 --> 14:39.760] So, we then assigned a senior consultant, a security consultant. [14:40.160 --> 14:44.020] I was overseeing the entire engagement along with a team lead. [14:44.180 --> 14:48.160] There's a PM, project manager, and we also have a client success manager. [14:48.520 --> 14:57.100] And we work as a team during the whole stages of the project lifecycle, which I'm going to tell a little bit about now. [14:58.500 --> 15:00.220] So, this is the process, right? [15:00.340 --> 15:05.760] I was talking about no matter the methodology that you follow, the process is key here. [15:08.220 --> 15:16.260] And everything starts, I mean, once the SOW is signed, everything starts with a preparation time. [15:16.740 --> 15:18.860] There's a kickoff call that takes place. [15:19.460 --> 15:21.780] We review everything that was agreed on. [15:22.180 --> 15:36.680] There's an initial OSINT for us to see maybe if we can purchase a type of domain or do something that needs a certain time of maturity before going to use it. [15:37.340 --> 15:52.940] We do a quick risk-based analysis, trying to learn more about the customer, main business use cases, vendors that they have, a little bit about the size of the company and whatnot. [15:53.460 --> 15:57.480] And we obviously do the initial setup of the attack service. [15:58.140 --> 16:05.160] Then we go into the kickoff, where we send a kickoff email detailing all the things that we agreed. [16:05.960 --> 16:11.620] We go into this PASTA framework, taking a look at different stages of it. [16:12.780 --> 16:15.500] We do the OSINT and RECON. [16:15.960 --> 16:25.220] And then we go into the in-flight phase, where we are basically doing the entire methodology for whatever we are testing, right? [16:25.220 --> 16:29.520] Here, the targets were quite different. [16:30.140 --> 16:35.580] We had APIs, we had web applications, we had mobile applications, we have cloud infrastructure. [16:36.000 --> 16:41.000] So each one of those could use a different methodology when it comes for testing. [16:41.500 --> 16:49.320] But more or less, it was like the full assessment, the manual testing and full analysis, exploitation, post-exploitation, and then reporting. [16:50.380 --> 16:54.520] There's a winding down phase, where we work on documenting everything that we did. [16:55.640 --> 17:05.280] On the report, we also tell about the attempted attacks, maybe some observations that didn't end up as an issue, but are worth mentioning. [17:05.960 --> 17:08.880] We have a wrap-up stage. [17:09.620 --> 17:16.560] And when we have this cleanup process as well, we don't want to keep anything about the customer once we complete the testing. [17:16.560 --> 17:18.880] And then we have the closing. [17:19.320 --> 17:21.320] With the closing, we deliver the report. [17:21.520 --> 17:23.280] We go into a technical debrief. [17:23.440 --> 17:27.380] For this particular exercise, there was also an executive debrief. [17:27.980 --> 17:33.080] There's a retest coordination, and then the customer satisfaction follow-up. [17:35.500 --> 17:40.900] So, I'd like to show you about one of the attack patterns. [17:41.420 --> 17:47.600] And especially, we are going to be taking a look at how the methodology work on this area. [17:48.500 --> 17:50.280] And then we're going to have a demo. [17:50.420 --> 17:59.940] So, to give you some context, first with OSINT, we discovered an Android mobile app that we reviewed. [17:59.940 --> 18:04.340] And we found an endpoint that we had missed during the OSINT. [18:05.100 --> 18:07.420] It was quite shady. [18:07.620 --> 18:10.220] It was just being used for user statistics. [18:11.120 --> 18:15.700] So, with this new endpoint, we then do some further recon. [18:16.240 --> 18:19.680] We try to brute force directories and paths. [18:19.940 --> 18:24.980] And we found three new endpoints from this host. [18:24.980 --> 18:32.300] One of those had a JS file that we statically review, manually review. [18:32.860 --> 18:35.860] We were trying to find more endpoints. [18:36.280 --> 18:41.320] And we finally found three that caught our attention. [18:41.480 --> 18:43.100] I'm going to show you in a sec. [18:43.100 --> 18:49.360] And for one of those, when we went to... I can show you here. [18:50.360 --> 18:52.300] So, basically, we have here... [18:52.300 --> 18:53.000] I don't know if you can see that. [18:53.320 --> 18:56.660] We decompiled the Android app. [18:56.840 --> 19:01.780] We took a look at the Java code. [19:02.540 --> 19:03.340] We found... [19:05.680 --> 19:09.380] We fused some of the endpoints that we found here. [19:10.000 --> 19:12.760] And then, finally, came across these three... [19:14.180 --> 19:16.460] Endpoints that caught our attention. [19:17.100 --> 19:18.720] For one of those... [19:18.720 --> 19:23.420] That was the REST API invoke teams. [19:24.420 --> 19:27.340] When we were calling that with no credentials. [19:27.580 --> 19:28.660] Because this was black box. [19:28.760 --> 19:30.200] And we didn't have any so far. [19:30.980 --> 19:34.660] There was a stack trace that caught our attention. [19:34.880 --> 19:37.460] Because, basically, we were seeing a token. [19:37.680 --> 19:39.240] An authorization bearer. [19:40.200 --> 19:42.900] For an endpoint that was saying... [19:43.840 --> 19:45.580] Graph.Microsoft.com. [19:45.880 --> 19:48.060] So, what we did was... [19:48.540 --> 19:50.440] Like, okay, what's Microsoft Graph? [19:50.760 --> 19:52.560] And I'm going to read this literally. [19:52.860 --> 19:53.140] Because... [19:53.140 --> 19:54.360] This was insane. [19:55.560 --> 19:57.060] The Google search was saying... [19:57.980 --> 20:04.080] That MS Graph is the gateway to the data and intelligence in M0365. [20:04.320 --> 20:05.760] And this is nice. [20:05.940 --> 20:06.680] It provides... [20:06.680 --> 20:09.560] A unified programmatically model. [20:09.740 --> 20:10.860] Which is basically a REST API. [20:12.040 --> 20:17.820] That you can use to access the tremendous amount of data in Microsoft 365. [20:18.620 --> 20:19.060] Okay. [20:19.300 --> 20:20.640] So, that was... [20:20.640 --> 20:22.640] Certainly something interesting. [20:23.080 --> 20:24.860] And I'm going to show you... [20:26.280 --> 20:28.940] We tried to recreate the issue here. [20:29.660 --> 20:31.160] And I'm not doing a live demo. [20:32.020 --> 20:32.540] Because... [20:32.540 --> 20:34.660] They don't always end up good. [20:34.940 --> 20:36.240] But we have this recorded. [20:36.800 --> 20:40.600] To show you a little bit about what we were able to achieve with this. [20:41.480 --> 20:43.940] Here you can see the REST API. [20:45.140 --> 20:47.840] Being called with no credentials. [20:48.520 --> 20:49.900] There's a stack trace. [20:50.900 --> 20:53.000] On this staging environment. [20:53.640 --> 20:56.240] Which basically looks like... [20:56.240 --> 21:00.580] It had some kind of trust relationship with whatever was in production. [21:00.820 --> 21:02.440] Because there was a token there. [21:02.440 --> 21:06.460] So, naturally, we want to see what's in the token. [21:06.620 --> 21:10.480] And what kind of roles or privileges it supports. [21:11.860 --> 21:13.400] And we have a bunch of them. [21:14.280 --> 21:14.360] Right? [21:15.460 --> 21:17.520] There's a sites read all. [21:17.900 --> 21:18.960] User read all. [21:19.240 --> 21:20.060] Mail send. [21:21.360 --> 21:22.520] Call initiate. [21:23.600 --> 21:29.660] There was even an option to read all the Teams chat. [21:30.120 --> 21:30.800] For any user. [21:31.260 --> 21:31.900] Crazy. [21:33.060 --> 21:33.800] So... [21:33.800 --> 21:38.020] Here we are trying to learn about how to call the MS Graph. [21:38.380 --> 21:40.460] We were not sure at that time... [21:40.460 --> 21:41.520] I mean... [21:42.140 --> 21:44.100] How big the MS Graph was. [21:44.300 --> 21:47.100] And the amount of data that it could contain. [21:47.100 --> 21:48.000] So... [21:48.740 --> 21:53.020] We are here trying to see how we create the request. [21:53.420 --> 21:54.800] And try to use that token. [22:02.760 --> 22:05.320] This one, in particular, is to list users. [22:05.800 --> 22:06.800] On that tenant. [22:07.720 --> 22:08.400] For that tenant. [22:09.100 --> 22:10.180] Azure ID tenant. [22:15.750 --> 22:19.590] And, of course, we are adding the token that we found on the stack trace. [22:20.370 --> 22:21.650] And there you have it. [22:21.790 --> 22:22.690] I mean... [22:22.690 --> 22:26.890] It was on a station app that was disclosing this token on a stack trace. [22:27.430 --> 22:34.450] And it had this huge trust relationship with their own O365 environment. [22:37.570 --> 22:39.450] We now have the users. [22:39.690 --> 22:41.090] Each user has a user ID. [22:41.310 --> 22:47.450] And with that, we will be able to use or to call some of the other methods. [22:48.250 --> 22:51.110] Here in the demo, we are showing just a few of them. [22:51.110 --> 23:00.410] There is one here that you can use to list anything that that user has on their OneDrive drives. [23:02.950 --> 23:09.210] And there is another example that we then used to expand the exercise. [23:09.210 --> 23:20.070] Because, basically, we found a way to send emails directly from this REST API impersonating any user, basically, on Azure ID. [23:20.270 --> 23:21.830] So, it was crazy. [23:29.840 --> 23:38.740] So, here we are trying to see how to create the entire request and get one file as a proof of concept, basically. [23:39.960 --> 23:52.700] The interesting thing here was that the response was given a direct URL that you could use to grab that file. [23:54.000 --> 23:56.420] And you could just put that on a browser. [23:56.760 --> 23:59.340] And it would download the file for you, here. [24:00.640 --> 24:01.860] That's the name of the file. [24:04.400 --> 24:07.000] And this REST API was given that for free. [24:11.680 --> 24:13.200] We are using the Excel report. [24:14.820 --> 24:15.840] That looks more juicy. [24:21.300 --> 24:22.000] There you go. [24:24.970 --> 24:29.970] So, a couple of things here that I wanted to talk on. [24:29.970 --> 24:37.750] The next proof of concept is how we managed to send emails impersonating any user on their O365. [24:40.130 --> 24:40.850] Challenges. [24:41.410 --> 24:44.690] Obviously, this was a broad attack surface. [24:45.250 --> 24:48.370] So, many different methodologies that we used during the engagement. [24:48.950 --> 24:52.270] Having a defined process, tested process, right? [24:52.530 --> 24:55.930] That focused on all three main areas. [24:55.930 --> 24:55.970] Yes. [24:56.330 --> 24:56.510] Scoping. [24:56.710 --> 25:03.610] Obviously, if this hadn't been scoped correctly, we wouldn't have the time to do things properly, right? [25:03.730 --> 25:05.770] Because the scope was quite broad and large. [25:07.230 --> 25:15.170] This project lifecycle that ensures the whole engagement is delivered accordingly. [25:15.170 --> 25:18.530] And then, obviously, the way you present all of these, right? [25:18.630 --> 25:21.110] Because you have to connect a lot of points. [25:22.870 --> 25:24.850] That was a big challenge. [25:26.550 --> 25:35.350] Then, also, I mean, despite we have a clear, defined project lifecycle, you still have to account for any surprises during the engagement. [25:37.150 --> 25:43.950] Here, what happened was that we had to immediately inform the customer about what was going on. [25:44.090 --> 25:47.750] Obviously, this was production, and we found this with no information whatsoever. [25:47.750 --> 25:50.050] So, it was out there for anyone to exploit. [25:50.590 --> 25:53.970] And they asked us to pause the testing. [25:54.730 --> 25:56.490] They did some remediation. [25:57.830 --> 26:02.510] They wanted to make sure that this wasn't exploited before. [26:03.350 --> 26:04.490] And then, we could continue. [26:05.370 --> 26:09.850] So, accounting for maybe roadblocks or hiccups. [26:09.970 --> 26:10.790] That's also important. [26:11.330 --> 26:14.510] Keeping a fluent communication with the customer across all phases. [26:15.450 --> 26:16.210] That's key. [26:18.870 --> 26:28.570] So, this is the last proof of concept where we are sending an email impersonating one of those Azure AD accounts for our customers. [26:34.370 --> 26:35.190] There you go. [26:42.490 --> 26:44.410] So, that was the demo. [26:44.790 --> 26:55.430] And, yeah, I just wanted to show you, I mean, despite being framed within the CAPT specification, that doesn't mean that you cannot do cool stuff, right? [26:55.530 --> 26:57.850] I mean, this is not boring stuff at all. [26:57.850 --> 27:03.970] And, you do need this kind of specification when it comes to doing assurance activity. [27:04.590 --> 27:05.210] So, yeah. [27:06.070 --> 27:07.570] So, thank you for that. [27:07.730 --> 27:08.010] Thank you. [27:11.810 --> 27:12.570] No, we're good. [27:13.030 --> 27:19.210] So, again, I think that, you know, one thing that that speaks to is the example of it's not a movie, right? [27:19.390 --> 27:24.170] Like, it takes time to look at the controls relative to an organization being assessed. [27:24.170 --> 27:28.170] It takes people that have the knowledge and experience to do the testing. [27:28.870 --> 27:37.330] And, you know, the CREST layout of what should look like to the end buyer is very helpful in all organizations, sort of forming a process that's somewhat repeatable. [27:37.550 --> 27:44.370] To demonstrate how that technical example becomes a reality for everybody in the room, I'd like to play a quick game. [27:44.570 --> 27:47.870] It's the same game we actually played in 2010 at HOPE. [27:48.510 --> 27:50.870] But, I think you might get some giggles out of it. [27:51.890 --> 27:54.430] So, imagine for a moment that you walk into a room. [27:54.830 --> 27:55.190] Okay? [27:55.270 --> 27:58.410] What I want is I want people to shout out the answers as quickly as possible. [27:58.570 --> 28:00.130] I'm going to give you a short amount of time to do that. [28:00.670 --> 28:02.250] You walk into a room and there's a light bulb. [28:02.570 --> 28:04.070] The light bulb is in the middle of the room. [28:04.430 --> 28:07.690] There's a switch on the wall, but you're not allowed to touch the switch. [28:08.210 --> 28:09.550] How do you shut the light bulb off? [28:09.810 --> 28:10.130] Go. [28:10.130 --> 28:11.230] Screw it. [28:11.610 --> 28:12.170] Screw it. [28:12.790 --> 28:13.850] Ask someone else to do it. [28:14.110 --> 28:14.630] Pellet guns. [28:14.970 --> 28:15.430] Smash it. [28:15.710 --> 28:16.350] Throw a rock at it. [28:17.150 --> 28:17.770] There you go. [28:18.110 --> 28:20.510] So, you know, we've had feedback about pellet guns. [28:20.830 --> 28:21.790] Have somebody else do it. [28:22.110 --> 28:24.810] Maybe shut off the power, don't pay your bill, throw a rock at it. [28:24.890 --> 28:24.930] Right? [28:24.970 --> 28:26.630] There's all different ways to approach the same goal. [28:26.870 --> 28:31.310] And I think that's really the spirit of what we do in the space of security. [28:31.310 --> 28:31.590] Right? [28:31.930 --> 28:36.630] We look at what I call loose approaches and say, okay, so here's kind of what we're going to do. [28:36.710 --> 28:40.410] We're going to walk in and we're going to assess, we're going to look, we're going to make sure we're approved to do those type of things. [28:40.710 --> 28:42.130] Now let's go deal with the right guys. [28:42.510 --> 28:48.150] So however the end goal is reached, that's sort of one of the very important parts of the penetration testing side. [28:48.330 --> 28:55.350] But you'd imagine if you were on the other side of that and you had a really bad day and you had instant responders walk through the door, you're looking for them to save your ass. [28:55.470 --> 28:55.550] Right? [28:55.650 --> 28:59.390] You're looking for them to give you answers to questions and help you identify where the problem was. [28:59.550 --> 29:01.150] So you don't really have a lot of time to waste. [29:01.210 --> 29:03.990] You don't really have a lot of time for, you know, them to figure it out. [29:04.090 --> 29:06.990] You want sort of the best and brightest to go do the job. [29:06.990 --> 29:12.510] So, as we look at, you know, that sort of piece, again, just pulling back to what Crest is all about, right? [29:12.890 --> 29:16.370] On the back of your program guide, you know, it has a little summary of what Crest is. [29:17.330 --> 29:22.310] For those that haven't heard about us, I wish you taken an opportunity to learn more about what Crest does. [29:22.490 --> 29:28.430] If you're a buyer, if you're a service provider, if you're academia, or if you're looking to, you know, go on your career journey. [29:28.910 --> 29:33.810] You know, we have a lot of opportunities and a lot of member companies that have, you know, internships and jobs. [29:34.410 --> 29:39.610] So, it really becomes sort of a holistic approach within the community to try to make things a better place. [29:39.910 --> 29:50.590] So, with that, if there are any questions about Crest, or penetration testing in particular, or the Crest approved penetration test specification, I'll be happy to answer that. [29:50.690 --> 29:52.650] And I know there might be some, maybe, questions online. [29:52.950 --> 29:58.030] We're also in the nice, cool, air-conditioned supporter area over by the registration booth. [29:58.170 --> 30:01.270] So, once the talk's over, please feel free to stop by and say hi. [30:02.190 --> 30:05.130] Back to Denise, is there any questions from your side? [30:13.130 --> 30:13.490] Excellent. [30:17.150 --> 30:23.370] So, please, certainly lots of resources to talk about any questions that you may have. [30:23.490 --> 30:24.690] We'd be happy to answer them. [30:25.130 --> 30:26.110] I'll give you our opinions. [30:26.310 --> 30:27.750] Again, there's lots of tools out there. [30:27.990 --> 30:29.290] We can recommend a lot of them. [30:29.510 --> 30:33.850] But obviously, I always say to my wife, I can't paint the house or fix the door. [30:34.030 --> 30:36.150] But if you're walking to Home Depot, there's a whole row of tools. [30:36.150 --> 30:38.270] Tools don't make anything happen, right? [30:38.370 --> 30:39.970] It's the intelligence behind the tools, sir. [30:40.830 --> 30:41.810] Question for Wacko. [30:44.110 --> 30:45.370] This demo was good. [30:45.510 --> 30:56.950] But what are the actual deliverables that you produce for the C-level executives at that firm to the end client that is not as technically savvy as most of the crowd probably would be here? [30:57.130 --> 30:58.270] This is all good for us. [30:58.830 --> 31:00.230] How do you take that? [31:00.470 --> 31:01.310] What's the methodology? [31:01.550 --> 31:07.090] What are the deliverables and different final results that you give to them on that level, basically? [31:07.410 --> 31:08.510] So, there's two pieces there. [31:09.210 --> 31:14.090] From the service provider perspective, his opinion or his answer is going to be the right one for his company. [31:14.730 --> 31:28.270] In the guidance that is available for you, Crest does outline what that does look like for the purposes of mapping it, for the purposes of being able to feed it up, to be able to be demonstrating due diligence, due care. [31:28.630 --> 31:32.490] At the end of the day, your reports may be slightly different, so please speak to that. [31:32.890 --> 31:38.010] But the goal with all the Crest assessments is to follow somewhat of a standard process so that they're consistent. [31:38.110 --> 31:38.890] And that's the issue. [31:39.070 --> 31:40.150] It's the breadth of it. [31:40.410 --> 31:40.810] Yes. [31:41.190 --> 31:41.250] Yeah. [31:41.630 --> 31:43.210] No, that's a good question. [31:43.570 --> 31:46.030] Obviously, this was a technical demo. [31:46.030 --> 31:53.650] So, the way we present the issues on the report, basically, we do have two main sections. [31:54.010 --> 31:56.010] Three main sections, I would say, on our report. [31:56.370 --> 32:04.970] There's an executive summary where we speak at a level that can be understood by anyone. [32:05.230 --> 32:08.970] There's like no deep technical wording there. [32:10.110 --> 32:12.370] Then we do have a technical detail section. [32:12.370 --> 32:16.070] And the last one is for every attempted attacks and maybe observations. [32:16.570 --> 32:25.750] On the executive summary, the way we try to convey ideas is from this business risk perspective. [32:26.030 --> 32:28.110] And to give actionable items. [32:28.730 --> 32:29.590] So, there's a... [32:29.590 --> 32:37.290] I mean, after we go through the PASTA methodology and the risk-based threat modeling, there's a risk analysis that we do at the end. [32:37.290 --> 32:40.370] So, we give to the customer like, hey, you know what? [32:40.490 --> 32:45.850] I mean, we try to summarize everything that happened here at a higher level. [32:46.050 --> 32:53.350] So, you had basically a staging server that was public. [32:53.970 --> 32:57.030] It had a trust relationship with your Azure ID. [32:57.310 --> 32:58.670] It wasn't been tested. [32:58.670 --> 33:04.010] So, we tried to let them know when they are not doing that good. [33:04.330 --> 33:06.470] You know, like given actionable items. [33:07.250 --> 33:09.650] We also say where they are... [33:09.650 --> 33:12.410] Where we tested and they were doing right. [33:12.690 --> 33:12.930] Okay? [33:13.230 --> 33:17.190] So, that's the idea that we have when it comes to the executive summary. [33:17.890 --> 33:20.190] And if that answers your questions. [33:21.130 --> 33:21.690] Yeah. [33:21.690 --> 33:26.830] So, that's probably the number one problem for the buyer. [33:27.010 --> 33:27.490] Right? [33:27.650 --> 33:28.870] Is getting a consistent output. [33:29.150 --> 33:37.830] And if they have a regulated need to comply or provide data reports, then digestible format, which is similar, is very important. [33:38.070 --> 33:39.910] And also, each of the different service providers. [33:40.090 --> 33:42.590] We have about 300 of them, by the way, worldwide currently. [33:43.550 --> 33:49.290] As we make strong recommendations for a process to be followed, you might agree. [33:49.490 --> 33:51.250] Then it becomes sort of soft touch as well. [33:51.750 --> 33:54.270] Service providers should be doing a soft touch output debrief. [33:54.370 --> 33:55.770] You know, debriefing with their client. [33:56.090 --> 33:57.670] Should be making sure that their... [33:57.670 --> 34:00.990] The check signer is very clear as to some of the goals. [34:01.330 --> 34:04.090] And probably even along the way, the threat modeling piece that was mentioned. [34:04.250 --> 34:05.690] What's the dollar value of the impact? [34:05.870 --> 34:06.030] Right? [34:06.130 --> 34:07.490] So, we can kind of bring it back to there. [34:08.490 --> 34:10.110] Most of us that do technical work, right? [34:10.370 --> 34:11.510] We're kind of in our own world. [34:11.610 --> 34:12.850] We don't really care about that. [34:12.990 --> 34:13.070] Right? [34:13.170 --> 34:14.630] So, it's like here's a technical report. [34:14.750 --> 34:15.730] You know, go fix that. [34:16.070 --> 34:17.490] Then there's another layer. [34:17.490 --> 34:19.930] Usually the other layer is, okay, so what was the impact of this? [34:20.010 --> 34:21.370] How does it really affect your business? [34:21.610 --> 34:23.290] And then sort of doing the downstream effect. [34:23.630 --> 34:28.990] So, Crest definitely calls those items out for our organizations to address. [34:29.330 --> 34:32.950] And again, we do our best to help level up the organizations. [34:33.130 --> 34:43.270] Now, one thing that's a suggestion is if you do happen to go to the Crest website, which... and you do look at the member list of companies, which is completely free to the buyer, right? [34:44.410 --> 34:46.050] You're going to come up with a list of organizations. [34:46.050 --> 34:48.010] Some of them you may know by brand, by name, right? [34:48.130 --> 34:49.330] So, there's a lot of great companies. [34:50.710 --> 34:53.110] When you inquire with them, you need to be very clear. [34:53.990 --> 34:57.470] If you're looking for a pen-test, you're looking for a Crest pen-test. [34:57.970 --> 35:06.530] And the reason why I say that very clearly is because every member of the Crest organization that provides services, that's accredited and certified, has a Crest ID. [35:07.150 --> 35:12.250] And many organizations will provide a pen-test or a Crest pen-test. [35:12.490 --> 35:16.890] So, my point is, you know, buyer needs to understand some of those things as to what they're looking for. [35:17.130 --> 35:24.650] And then, of course, Crest does get involved in any sort of contract issues, any sort of issues with these deliverability of the information. [35:24.650 --> 35:26.750] And we serve as a mediator, right? [35:26.830 --> 35:28.110] Because we are the accreditation body. [35:28.970 --> 35:35.650] The best thing that we can do for the buyer is help quickly solve issues that are going to be popping up between buyer and seller. [35:36.030 --> 35:41.510] And for the service company, if they are grossly negligent, they will be removed from the accreditation list. [35:41.710 --> 35:46.670] And then they will be globally removed from those procurement opportunities, which is usually significant for them. [35:46.670 --> 35:49.010] So, there's a win-win for people to work together. [35:49.650 --> 35:51.010] Hopefully that answers the question. [35:52.250 --> 35:52.770] Sir? [35:53.250 --> 35:56.770] So, I also, I work for a Crest accredited partner. [35:57.530 --> 35:57.830] Yes, sir. [35:57.970 --> 36:12.290] But I am curious, and I think this would be valuable for everybody else in the audience, is do you have any stats on the percentage of organizations that come to be accredited by Crest that are turned down because they don't meet requirements and I think that would really demonstrate to the audience how valuable and strict the fact that they don't follow a certain, [36:12.490 --> 36:21.190] you know, requirements or procedures and stuff to really show how valuable or how... [36:21.910 --> 36:22.450] Oh, yeah. [36:22.930 --> 36:23.510] Sorry. [36:24.950 --> 36:35.510] Do you have any stats to really show, you know, the number of organizations that come to Crest to be accredited but are unfortunately turned down because they don't meet requirements? [36:35.510 --> 36:45.250] And I think that would really demonstrate to the audience how valuable and strict the Crest requirements really are in, you know, making the cyber world more secure. [36:45.630 --> 36:46.210] Sure. [36:46.510 --> 36:49.350] So, the organization does produce that material. [36:50.010 --> 36:52.570] As an accreditation body, our group is not... [36:52.570 --> 36:55.690] We're not an audit, pass, fail type of organization, right? [36:55.910 --> 37:08.170] We're there for an organization to understand what they're going to be measured against, have them submit their materials, have an organization get audited and come up with a answer to the question of, are you doing commercially reasonable standards? [37:08.850 --> 37:17.050] So, when there's deficiencies, our Crest team, which is like 50 of us around the world, we focus on helping that organization understand where some of the deficiencies are. [37:17.290 --> 37:20.010] If you have the greatest pen-testers in the world, that's fantastic. [37:20.210 --> 37:22.630] If your back office is a mess, that's a problem, right? [37:22.710 --> 37:28.810] If you have the greatest pen-testers in the world and you're not securing client data, you don't have good contracts, you don't have appropriate controls in place. [37:28.950 --> 37:29.530] That's a problem. [37:29.770 --> 37:37.730] So we would basically reject the application and point out where the problems may be and that they can go ahead and fix those and resubmit. [37:38.190 --> 37:40.470] The point is to have everyone sort of level up. [37:40.650 --> 37:50.050] And that's kind of where we take the regulatory approach of what we're doing for regulators and governments and say, these are the programs that have been managed, that we manage on their behalf. [37:50.470 --> 37:53.590] In order for you to be on that program, that's how it works. [37:53.870 --> 37:53.970] Right? [37:54.070 --> 37:55.330] It's kind of like here in New York. [37:55.330 --> 37:59.030] If you ever run a New York State contract, as an example, there's certain things you got to do. [37:59.210 --> 37:59.410] Why? [37:59.550 --> 38:00.350] Because New York says so. [38:00.630 --> 38:00.890] Great. [38:01.090 --> 38:04.290] If you apply and you don't meet the requirements, you may not be on that contract. [38:04.290 --> 38:07.850] Or you have a certain amount of time to sort of meet that goal. [38:08.090 --> 38:15.130] But from a perspective of numbers, I would say at any given time, there's a hundred or so applications. [38:15.450 --> 38:21.470] And those organizations are typically getting coached along the way until they're able to mature and then be able to be on that list. [38:21.830 --> 38:23.030] Also, they're reassessed. [38:23.430 --> 38:25.310] So individuals are reassessed every three. [38:25.330 --> 38:26.270] years for competency. [38:27.070 --> 38:28.490] Organizations are reviewed every year. [38:28.610 --> 38:28.790] Right? [38:28.890 --> 38:30.310] They have a business review. [38:30.830 --> 38:39.390] Any significant change to the business, acquisition changes, people in the organization, those type of things may result in the organization no longer being on the approved list. [38:40.830 --> 38:46.110] Also, organizations like yours are potentially global. [38:46.510 --> 38:47.870] They're accredited by region. [38:48.070 --> 38:50.910] So there's a global accreditation and there's regional accreditation. [38:51.110 --> 38:57.810] So organizations that want a CREST accredited assessment here in the United States from your company as an example, your company would need to be a CREST accredited company in the U.S. [38:58.330 --> 38:58.670] Make sense? [38:59.010 --> 39:00.650] So that's sort of how that all flows out. [39:01.030 --> 39:10.930] It's super important to just understand what CREST gives to you, the consumer or the buyer, to protect the end customer, which ultimately is for privacy and security. [39:11.110 --> 39:16.230] So it's sort of a, you know, we're trying to help level up as a helping hand in the space. [39:16.330 --> 39:17.210] Hopefully that answers your question. [39:17.870 --> 39:18.270] Cool. [39:18.930 --> 39:19.230] Sir? [39:19.230 --> 39:19.850] Hi, thanks. [39:20.050 --> 39:22.730] I'm a practitioner and this is my first hearing about CREST. [39:22.930 --> 39:24.070] So thanks for sharing that. [39:24.530 --> 39:26.590] My question maybe is to Joaquim a bit. [39:26.750 --> 39:32.030] When you found that credential, was there guidance in the CAPT that that was going to be a critical finding? [39:32.690 --> 39:35.670] And to, was there any guidance about how to handle that? [39:35.770 --> 39:39.330] Like, I noticed you kind of tried to explore the capability of that credential. [39:39.730 --> 39:41.070] Was that the correct approach? [39:41.310 --> 39:44.430] Or should you have gone back to the client right away and said, hey, I have a credential. [39:45.150 --> 39:45.930] What's it all about? [39:46.890 --> 39:47.410] Yeah. [39:47.650 --> 39:47.930] Yeah. [39:48.030 --> 39:48.890] Yeah, that's a good question. [39:50.410 --> 39:57.730] When we saw the potential things that we could do, I mean, we actually had to test them. [39:58.310 --> 40:05.230] I mean, when we tell the customer we're going to let them know about something critical, we cannot go with a false positive, you know? [40:05.750 --> 40:16.830] So, as we craft a working proof of concept, and we understand what the impact is, because we have done this previous threat modeling, on their business. [40:17.510 --> 40:20.390] We can share that with some context, you know? [40:21.770 --> 40:22.650] So, yeah. [40:22.650 --> 40:25.030] So, validating the credential would be the appropriate... [40:25.510 --> 40:27.030] Yeah, yeah, yeah, yeah, yeah. [40:27.210 --> 40:28.750] We needed to do that. [40:28.910 --> 40:37.370] I mean, because we couldn't go with, again, a false positive or false sense of maybe criticality, you know? [40:37.370 --> 40:37.490] So... [40:37.490 --> 40:42.350] And also, I think, lends itself to the maturity of the organization requesting the requirement. [40:42.610 --> 40:44.070] So, it's two-sided, right? [40:44.210 --> 40:45.670] And you're in a practitioner, you get this. [40:45.670 --> 40:53.710] If the service provider is going to speak to their client about how they prefer to do the work, and the buyer is interested in that, and there might be some conversation there. [40:54.290 --> 40:57.070] I know from fire and forget sort of offensive testing, right? [40:57.150 --> 40:59.490] I'm very much focused on, okay, am I approved for this? [40:59.550 --> 41:00.110] Am I approved for that? [41:00.170 --> 41:00.690] Am I approved for this? [41:00.810 --> 41:01.270] Am I approved for that? [41:01.310 --> 41:01.490] Yes. [41:01.630 --> 41:02.130] Fire on target. [41:02.250 --> 41:02.390] Go. [41:02.610 --> 41:06.310] So, as long as we understand what the terms are, we're good. [41:06.630 --> 41:08.270] Commercial sector, a little bit more fuzzy. [41:08.430 --> 41:11.490] Obviously, the government sector has a little bit more gates to cross. [41:11.710 --> 41:16.250] So, we bring those worlds together a little bit, give a little bit of what good looks like, and people can operate. [41:16.470 --> 41:17.250] Thanks for the context. [41:17.430 --> 41:17.570] Thanks. [41:18.570 --> 41:24.590] I think we are just about out of time, but if there's any more questions, please grab an ice-cold beer or... [41:24.590 --> 41:25.450] It's a towel, right? [41:25.530 --> 41:26.370] Grab an ice-cold water. [41:26.710 --> 41:29.850] Go over to the sponsor, and we'll be happy to talk some more. [41:29.990 --> 41:30.610] Thank you for your time. [41:30.930 --> 41:31.470] Thank you, guys. [41:53.760 --> 41:54.740] Welcome to our next speaker. [41:55.440 --> 41:59.560] As a reminder, please, when you're indoors in conference spaces, please remember to wear your masks. [41:59.600 --> 42:00.000] Thank you. [42:00.000 --> 42:00.040] Thank you.