[00:32.630 --> 00:34.610] Good morning, everyone. [00:34.970 --> 00:37.330] Welcome back to our last day of hope. [00:37.590 --> 00:43.250] I know it's sad that we're here at the last day, but we've got another great talk lined up for you right now. [00:43.630 --> 00:48.490] The talk is Using Security Automation to Organize Your Cybersecurity Threat Intelligence Knowledge. [00:48.850 --> 01:00.170] It will outline how the open CTI platform can be deployed, scaled for high availability using cloud-native strategies, and utilized by strategic and technical cyber threat analysts at any seniority level. [01:00.570 --> 01:03.130] So, we have a matrix chat thread for this talk. [01:03.130 --> 01:07.710] If you have questions, especially for the virtual audience, go ahead and enter it into the matrix chat. [01:07.850 --> 01:12.650] And when we get to the QA section of this talk, we'll try and get your questions answered. [01:12.850 --> 01:14.490] We also will have a QA section. [01:14.590 --> 01:15.350] There's a microphone in back. [01:15.350 --> 01:21.130] So, when we get to the QA section, please, audience members, come back and queue up, and we'll queue you up for the speaker. [01:21.490 --> 01:24.150] So, with that, let's introduce Andrew Q for his talk. [01:24.390 --> 01:24.770] Thank you. [01:29.500 --> 01:29.800] Hello. [01:29.940 --> 01:30.480] Good morning, everybody. [01:32.660 --> 01:37.180] So, right off the bat, opinions are my own and not the view of my employer, and should never be taken seriously. [01:40.320 --> 01:41.380] My name is Andrew Koo. [01:41.660 --> 01:45.060] I'm here because I love to give presentations. [01:45.480 --> 01:47.060] Or if you speak Minyan, bello. [01:49.400 --> 01:51.200] So, a few things about myself. [01:51.820 --> 01:55.140] I was born and raised in Queens, not too far from St. John's University. [01:55.140 --> 01:58.460] I'm currently a platform engineer for the city of New York. [01:58.940 --> 02:09.500] Some of the things I do day-to-day involve Kubernetes, DevSecOps, infrastructure as a code, site reliability engineering, and incident response. [02:09.500 --> 02:13.100] And this is my second hope in real life. [02:16.500 --> 02:18.930] So, let's identify the problem. [02:20.330 --> 02:22.430] Cyber threat intelligence tooling is expensive. [02:23.550 --> 02:25.870] The licenses and subscriptions are not cheap. [02:28.870 --> 02:30.230] Let's define CTI. [02:30.570 --> 02:32.210] So, what is cyber threat intelligence? [02:32.730 --> 02:42.310] CrowdStrike defines it as, in a very loose term, the collecting of, possessing of, the analyzing of, a threat actor's motives, targets, and attack behaviors to make decisions using good judgments. [02:44.290 --> 02:50.990] Gardner calls it, hard facts backed by evidence about existing or emerging menaces or hazards to assets. [02:51.610 --> 02:58.310] So, whether it be IT, computer security IT assets, or it could be OTICS assets as well. [03:01.150 --> 03:15.970] So, in short, to summarize the two definitions together very loosely, cyber threat intelligence is in which threat actors are tracked by what they want, what they do, what they have done, and based strictly on facts. [03:19.110 --> 03:29.010] So, like I had in the first slide, or the first slide in the section, we have too many vendors, we have too many feeds. [03:29.710 --> 03:34.090] Some of these names are, maybe, household friendly, that you've seen before. [03:34.390 --> 03:36.830] Anomaly, ThreatStream, Threat Connect, Threat Intelligence Platform. [03:37.330 --> 03:40.310] Recorded Future is a big name in cyber threat intelligence. [03:40.890 --> 03:44.430] And we have Palo Alto, relatively new to the space. [03:45.590 --> 03:49.190] I'd say they're, you know, maybe less than a year in. [03:49.190 --> 03:55.210] And they integrated a threat intelligence module in their SOAR platform called XSOR, Cortex-XSOR. [03:58.050 --> 04:05.370] And, you know, these big brand names used in the enterprise, they'll charge an arm and leg to use their systems. [04:07.110 --> 04:21.330] Not only do you need, um, not only for cyber threat intelligence do you need a platform to, you know, aggregate all your data, you also need, and you also need subscriptions and feeds, you know, um, uh, upstream. [04:22.010 --> 04:25.190] So, um, here are a few that you might, you know, you may also know. [04:25.430 --> 04:27.430] Like, CrowdStrike Intelligence and Indicators. [04:27.710 --> 04:30.510] Recorded Future has wonderful streams and threat feeds. [04:30.510 --> 04:35.010] Uh, MSISAC, FSISAC, if you're into, like, the government space, financial services space. [04:35.830 --> 04:40.410] Um, Mandiant, bought by Google, and previously known as, um, or separated from FireEye. [04:41.190 --> 04:47.010] Uh, Palo Alto's Unit 42, um, third research group, has, uh, has, uh, good threat feeds. [04:47.270 --> 04:50.510] Um, and URL House, and, um, you know, there may be others. [04:54.130 --> 05:08.010] And each of these, um, each of these feeds, each of these vendors, whether or not who you pick, if you want, like, you know, high fidelity data and whatnot, um, you know, these feeds cost, you know, thousands of dollars, hundreds of dollars, um, in order to be a subscriber of. [05:10.940 --> 05:14.520] And so, um, knowledge is power, power is knowledge. [05:14.820 --> 05:20.720] You can't, you can't run, you can't do, you know, cyber threat intelligence if you don't have, uh, if you don't have the knowledge. [05:21.060 --> 05:25.760] And you can't have, you can't, uh, conduct cyber threat intelligence if you don't have the power. [05:29.100 --> 05:30.800] So, let's identify the solution, right? [05:30.800 --> 05:33.440] Enterprise cyber threat intelligence is way too expensive. [05:33.820 --> 05:35.420] So let's make it cheaper. [05:36.160 --> 05:38.240] Enterprise cyber threat intelligence doesn't have to be expensive. [05:42.080 --> 05:49.140] So the main topic that I'm going to speak about today is to introduce you guys to OpenCTI. [05:49.680 --> 05:57.580] OpenCTI is an open-source, free-to-use cyber threat intelligence platform you can find on GitHub. [05:58.740 --> 06:06.100] It's created by these lovely individuals located in France, Paris. [06:08.280 --> 06:12.640] They operate under the nonprofit organization called Luitix. [06:13.060 --> 06:17.180] And they've been working on this product for about two to three years. [06:19.020 --> 06:35.100] And they've just been making huge groundbreaking waves in this space in order to make cyber threat intelligence, you know, open-to-all, free-to-use-to-all without the limitations of, like, cost or anything. [06:37.700 --> 06:39.040] So about OpenCTI. [06:39.340 --> 06:48.040] It's an open-source, comprehensive platform that allows organizations to manage, structure, store, organize, and visualize their cyber threat intelligence knowledge and observables. [06:52.050 --> 06:53.770] It uses a modern tech stack. [06:54.910 --> 06:56.930] Front-end is written in React and Node. [06:57.230 --> 06:58.530] It uses back-end Python. [06:58.830 --> 07:01.890] It uses GraphQL for its API. [07:02.490 --> 07:03.250] It's database. [07:03.630 --> 07:05.810] You can use Elasticsearch or OpenSearch if you'd like. [07:06.930 --> 07:12.690] It uses RabbitMQ for its messaging queue to designate work and tasks. [07:13.390 --> 07:22.830] And it uses Redis as a cache for, you know, non-persistent storage. [07:26.090 --> 07:29.390] And to reiterate, it's open-source, community-empowered, and free. [07:29.390 --> 07:45.630] So, you know, if you, if there's a, you know, the developers, the Lulitics, that make the program, or that make the platform, they have this policy where if there's a, you know, if there's a bug in the general release, they'll try to fix it within 24 hours. [07:47.030 --> 07:49.350] Community suggestions are welcomed. [07:50.090 --> 08:01.570] If you've, if you use the platform and you realize that, you know, there, there could be a, like a, you know, great idea that, you know, that would work really well in the ecosystem, you could just submit, like, a feature request. [08:02.510 --> 08:04.450] And, you know, they'll respond really quickly. [08:06.870 --> 08:08.330] And most importantly, it's free. [08:10.790 --> 08:16.270] So, the core, the core functionality of the platform divides into essentially three parts. [08:16.750 --> 08:19.650] The first being the ability to organize and manage your knowledge. [08:20.350 --> 08:27.270] So, you know, you as, you know, an InfoSec team may have, you know, intelligence people working under you. [08:27.490 --> 08:37.010] And, you know, your intelligence team will have to, you know, save their work, do their work, conduct their research, be able to, you know, deliver deliverables in, you know, one sense or another. [08:40.800 --> 08:45.920] The platform, the second core functionality of the platform is to visualize and graph the knowledge that you accumulate. [08:45.920 --> 08:58.680] So the ability to draw pretty pictures, make pretty relationships between your threat actors, the threat tools that your threat actors use, and the targeted entities that your threat actors target. [09:02.420 --> 09:06.920] And the third functionality is to aggregate what you know, what others know, and what you want to share to others. [09:06.920 --> 09:21.000] So the ability to essentially, you know, pull upstream from CrowdStrike, from Recorded Future, from Mandiant, from Palo Alto, and be able to, you know, save it, you know, on your premise. [09:22.170 --> 09:40.880] And also have the ability, you know, to share the data that you collect, harvest, ingest, analyze, validate to downstream clients, whether it be other InfoSec teams within your organizations, whether it be other InfoSec teams, or CTI teams, and other organizations, [09:41.070 --> 09:43.790] or parent organizations, partner organizations, and things like that. [09:47.600 --> 09:51.220] So we'll talk about the first core functionality, which is organizing your knowledge. [09:53.660 --> 10:00.860] CTI, for Cyber Threat Intelligence, you can say that you can break it down into two components, two schools of thought, essentially. [10:01.860 --> 10:04.140] strategic versus technical. [10:07.280 --> 10:19.820] Where, for strategic CTI, right, it's mainly about knowledge about your threats, the threat tools that your threats use, and related entities that are targeted by your threat actors. [10:23.900 --> 10:30.220] So, your threats could come in, you know, a variety of, you know, come in a variety of forms, right? [10:30.220 --> 10:43.680] Whether they be, like, threat actors, meaning, you know, Russian FSB, Iranian military, Korean peoples, the Korean, the KPA, you know, the Chinese army, and things like that. [10:43.920 --> 10:52.880] Intrusion sets are more along the lines of, like, your APTs, your worms, your spiders, your bears, things of that nature. [10:52.880 --> 10:59.860] Not necessarily tied to, you know, an organized, real-world entity. [11:00.660 --> 11:13.820] And campaigns, meaning, you know, things like real-world events, like, you know, government uprisings, government elections, big events in nature, like solar winds, things like that. [11:18.180 --> 11:19.000] Threat tools. [11:19.700 --> 11:22.600] So, strategic CTI. [11:23.260 --> 11:35.980] Threat tools fall under strategic CTI through the use of, you know, keeping track of the malware, which is, which are, you know, the malicious software that your threat actors are deploying, whether it be ransomware, Trojans, worms, etc. [11:36.820 --> 11:42.560] The attack patterns, which correspond to your MITRE ATT&CK framework, and things like that. [11:43.540 --> 11:54.480] Courses of action, which is MITRE ATT&CK, which is, like, you know, MITRE ATT&CK techniques and patterns, but without the MITRE ATT&CK, you know, identifying schema. [11:55.200 --> 11:55.680] Tools. [11:56.140 --> 12:05.760] So, you know, your Cobalt Strikes, your Metasploit, your Empire, your Bloodhound, tools that your threat actors use, you know, in order to conduct their business. [12:06.280 --> 12:08.820] And, of course, you can't forget about vulnerabilities, right? [12:08.960 --> 12:21.860] You have your, after all, your threat actors are, are, are, you know, using, are hitting your, are using vulnerabilities, are using vulnerabilities to their advantage. [12:22.140 --> 12:24.720] And they're tracked by, you know, the CVEs and things like that. [12:28.920 --> 12:30.380] So, targeted entities. [12:30.540 --> 12:35.760] Targeted entities falls under countries, cities, organizations, and individuals. [12:36.060 --> 12:37.460] Pretty self-explanatory, usually. [12:38.000 --> 12:45.100] These would be the, you call it the victimology, the victims of attacks and of threat actors and things of that nature. [12:48.770 --> 13:02.090] And so, we'll move on to the technical cyber threat organ, cyber, technical, the technical component of cyber threat intelligence, which is, I guess, probably what most people would, would, would allude to when you think about, you know, cyber threat intelligence and things like that, [13:02.190 --> 13:04.430] which are just observables, artifacts, and indicators. [13:04.790 --> 13:12.290] You know, your IPs, domains, URL hashes, email, email addresses, file names, and things like that. [13:16.790 --> 13:29.810] So, OpenCTI, the OpenCTI platform will aggregate all your strategic knowledge, as well as your, as well as your technical knowledge, and kind of like, you know, put it all in a single pot, and for you to draw relationships, or automatically have the platform draw relationships for you, [13:29.950 --> 13:31.250] in order to organize your data. [13:32.330 --> 13:33.990] But how can it be done, right? [13:35.070 --> 13:40.010] And this is where we, we take, you know, DevOps into the mix. [13:40.010 --> 13:49.270] How can we deploy OpenCTI, you know, whether it be on your home lab, for your organization, for your own use, for that matter. [13:51.530 --> 13:57.010] So, this core ecosystem, like I mentioned before, you know, uses open source tools and technologies. [13:57.570 --> 14:01.310] We have Elasticsearch or OpenSearch for your, for your persistent database. [14:01.310 --> 14:05.930] You know, everything, everything gets written and read into it. [14:07.590 --> 14:12.850] Redis keeps track of your, your, your cache, your non-persistent storage. [14:13.010 --> 14:16.690] Storage that, you know, that doesn't need to be saved. [14:17.430 --> 14:23.750] We have MinIO, which essentially is just like a front-end for, for S3 buckets. [14:24.430 --> 14:29.110] But anything with like a, you know, XML, S3, XML API can work as well. [14:29.150 --> 14:30.890] So, you could use Google Cloud Storage. [14:30.890 --> 14:31.810] You could use Azure. [14:33.510 --> 14:39.130] We have RabbitMQ, you know, open source AMQP platform to handle events. [14:40.510 --> 14:50.430] And we have a few OpenCTAC components, which are made of the React front-end, GraphQL back-end, Python connectors, and Python workers. [14:50.430 --> 14:58.650] So, for the last few bits, you know, everything is, strives to be like a microservice-oriented environment. [15:04.340 --> 15:05.960] But wait, how can it be scaled? [15:06.240 --> 15:07.100] How well does it scale? [15:10.320 --> 15:19.420] So, yes, it can, everything that you just saw in the, in the graph, in the graph in the, in the previous slide, could be scaled for high availability, for high availability. [15:19.740 --> 15:36.120] For example, Elasticsearch, you could use a multi-node cluster, multi-regional cluster, you know, to prevent outages, you know, pop up as many replicas, primaries as you want, rollovers and things like, set up index rollovers, you know, snapshots, hot and cold, [15:36.280 --> 15:42.440] hot, warm and cold indexes, in order to keep your, you know, the most frequently accessed data, you know, in hot. [15:43.440 --> 15:49.240] And keep your, you know, less used data in cold, so that you aren't, you know, using crazy amounts of resources for Elasticsearch. [15:51.840 --> 15:55.120] Redis can be also configured for high availability, high availability. [15:55.500 --> 15:58.180] You can use a multi, multi-node Redis instance. [15:59.000 --> 16:00.140] That's perfectly fine. [16:00.380 --> 16:06.600] It will be resilient to, you know, regional, regional downtime or zonal downtime if you're in the cloud. [16:09.620 --> 16:21.940] RabbitMQ, like I, like I said before, you could, you know, you could also set up a multi-node cluster for RabbitMQ in the event you don't want, you know, just cause your RabbitMQ goes down doesn't mean that your platform would stop, you know, would stop processing tasks and things like that. [16:23.960 --> 16:46.840] And MinIO, which you can, you know, if you have the ability to, you know, have access to an S3 bucket, whether it be like AWS, GCP or Azure, you'd have, you know, the cloud platform's word of like, you know, 99.9999% availability uptime, which translates to about like, [16:46.900 --> 16:48.940] you know, a handful of hours of downtime every year. [16:51.620 --> 16:58.900] And the OpenCTI ecosystem itself, meaning the platform, the workers, the connectors, they're all stateless in nature. [16:59.120 --> 17:00.240] They don't hold any states. [17:00.500 --> 17:03.980] If they go down, your data won't, you know, disappear. [17:04.300 --> 17:13.100] As long as, you know, everything's being written into Elasticsearch, as long as you're saving it to a persistent disk, you won't have to worry. [17:14.360 --> 17:23.380] The OpenCTI ecosystem is essentially built off of like container technology, so that, you know, everything is microserviced, everything is partitioned. [17:23.380 --> 17:26.720] You can spin up whatever you want, however you want. [17:27.100 --> 17:32.700] You can configure, you know, however you need, you know, a hundred front ends to service your clients. [17:33.040 --> 17:33.780] You're sure, why not? [17:33.960 --> 17:39.640] It's fine because, you know, the data is being written and, read and written into Elasticsearch anyways. [17:40.000 --> 17:56.200] If you need, you know, if you see a spike in, in the demand of your, of your CTI team, you know, if they need to do, you know, something resource intensive, you can spin up more workers, more consumers in order to get their work done during, you know, [17:56.260 --> 17:56.600] the rush. [18:00.630 --> 18:01.850] So adoption, right? [18:02.350 --> 18:06.550] I talked about how to, what our, what the problem was, what the solution is. [18:07.290 --> 18:13.990] I gave you guys a little bit of, of a brief, a brief introduction about the OpenCTI platform. [18:14.710 --> 18:24.170] And I also, you know, I'll describe to you guys how to briefly, you know, deploy it in your home labs, you know, organization, workspace environments, and things of that nature. [18:24.450 --> 18:40.550] Let's talk about, you know, if you, even if you didn't have a CTI team in your organization, or you're thinking about, you know, spinning up a CTI team, how would you operationalize OpenCTI within your CTI teams or InfoSec teams, if you don't already have a CTI team? [18:44.830 --> 18:51.890] So, this is what, essentially what the platform would look like the moment, you know, from a clean slate, you essentially have nothing, right? [18:53.590 --> 19:09.270] How would you, the main question would be like, you know, how would you pull data from upstream, from your vendors, from your subscriptions, from your threat feeds, have it all, you know, pumped into the platform, and then have your, you know, technical analysts, [19:09.370 --> 19:13.110] strategic analysts, you know, go on the platform and be able to, you know, conduct their work? [19:14.190 --> 19:29.990] Because at the end of the day, right, you want your platform to look something like this, where, you know, you have, you know, pretty graphs, pretty lines, big numbers, things to show, you know, upper management, you know, prove to upper management, you know, [19:29.990 --> 19:41.230] You know, thousands of threat actors, thousands of threats, and, you know, have a running database of, like, all the tools that you've seen, that you know, that your partners know, and things of that nature. [19:46.710 --> 19:49.390] So you can't have a home without any furniture, right? [19:49.490 --> 20:01.890] You can have a bare metal shell, but if you don't have your... you don't have, like, connectors or enrichment or ingestion, you won't be able to function, really. [20:02.710 --> 20:10.190] So a few ingestion connectors break into three parts, which are internal enrichment, internal import, external import. [20:10.470 --> 20:20.930] So internal enrichment essentially just means that, you know, you have an IP or a domain or a URL, you're unsure, you know, you're unsure if it's, like, benign or malicious or not. [20:20.930 --> 20:27.410] Yeah, you can, you know, go on VirusTotal, you can type it in, whatever, but, you know, we want to try to, like, automate the process. [20:27.690 --> 20:42.550] So like, if the IP, if the URL, if the domain, is already on your platform, you know, from somewhere, whether it be, like, uploaded from somewhere or, you know, manually put in, you'd be able to, you know, run a like a VirusTotal query lookup. [20:42.650 --> 20:49.530] You'd be able to query any service that you have, that you have an API key for, for the For the most part, you know, to learn more about your entity. [20:50.770 --> 20:58.050] We have internal imports, which means that, you know, in the event, your team is not as super technical. [20:58.290 --> 21:03.430] Like, the way that you guys receive information is through, like, newsletters or, like, email or something like that. [21:03.470 --> 21:08.830] Or maybe you have, like, PDFs or documents that people send you about threat reports and things like that. [21:09.150 --> 21:15.930] Internal import just means that you can take, you know, knowledge and reports manually. [21:15.930 --> 21:21.430] And you can upload them onto the platform for the platform to, like, you know, ingest, break down, and parse. [21:24.290 --> 21:31.490] We have the external imports, which, as it implies, will communicate upstream, you know, to your vendors. [21:32.910 --> 21:49.710] You know, it will constantly pull for your vendors, like, threat feeds and subscriptions in order for you to get the most recent indicators, the most recent threat actors and relationships, and how...and even reports as well. [21:54.380 --> 22:05.760] And for e-gestion, because, you know, you have...you know, OpenCTI shouldn't be your...shouldn't be the, you know, last station of the routes in which your data flows from upstream to downstream. [22:06.460 --> 22:13.060] OpenCTI could be in the middle ground where other...other instances, other clients...it doesn't have to be OpenCTI. [22:13.220 --> 22:21.060] You can use, you know, any of the other vendor...you know, vendor paid programs, products, to hook into OpenCTI. [22:21.340 --> 22:33.100] OpenCTI has, like, a cool functionality where you can essentially just, like, spin up, like, a taxi, you know, threat feed, and be able to, like, whatever...whatever data that matches whatever filter that hits your platform, you can just, like, ship it off, [22:33.420 --> 22:37.640] you know, export it, you know, put it in your...put it in a feed to be consumed downstream. [22:47.760 --> 22:54.780] So...this...this...this...this diagram here just kind of breaks it down even further, where, starting with on the left side, we have the external input connectors. [22:54.780 --> 22:57.520] So these are the connectors that will listen from upstream. [22:57.880 --> 23:11.800] So if you need, you know, an updated, you know, uh, you know, they put up...they put out, like, a new MITRE ATT&CK technique, and you need, you know, you need your...you need your platform to, like, run the updates, your platform will automatically be able to pull the MITRE ATT&CK techniques, [23:12.160 --> 23:20.660] um, uh, the CSVs, the JSONs, you know, hosted by MITRE, um, from their GitHub, you know, every day or something, so you can get the most up-to-date information. [23:20.660 --> 23:34.340] If you need, like, um, you know, whatever taxi servers that you have subscriptions to, whatever taxi servers that, um, that you...that you pull information out of currently, you can hook that into as well as an external input connector. [23:37.780 --> 23:53.720] Um...if you need an, uh, updated list, a running list of, like, your CVEs, um, you know, CV, 2022, whatever, um, uh, you can also hook that into the, into the platform so that your platform gets updated vulnerabilities and knowledge about them. [23:55.460 --> 24:08.340] We have, on the very top, we have the internal import file connector, um, which essentially allows you to what I just described before, the ability to import, um, your PDFs that you receive from, you know, partners over email or stuff like that. [24:08.500 --> 24:17.480] You could receive, you know, the, the, you know, you could turn the latest, like, bleeping computer article or something and ingest that into the platform if it is, uh, relevant to you. [24:17.760 --> 24:22.500] Um, and it'll be able to parse out your, your PDFs into sticks to JSON. [24:22.820 --> 24:29.220] Um, it'll be able to parse out your CSVs into sticks to JSON in order for it to be ingested by the platform. [24:31.060 --> 24:34.840] Um, right underneath, we have the internal enrichment connector. [24:35.200 --> 24:47.680] Um, and essentially, it just, you know, it calls out to whatever vendor solutions that you have, whether you have, like, a, you know, virus total API key or something, or if you have, like, a, you know, Palo Alto API, Palo Alto autofocus wildfire API or, [24:47.680 --> 24:53.360] or something, um, and be able to, you know, uh, ask your vendor, you know, what do you know about this IOC? [24:53.620 --> 24:55.300] And they'll come back to you with all sorts of data. [24:55.480 --> 25:00.820] And for that, you can, you know, uh, with a click of a button, you'd be able to, like, save all that information onto OpenCTI. [25:01.960 --> 25:13.060] On the right side, we have the internal export connector, which just parses CSVs and PDFs into 6.2-friendly JSON. [25:14.740 --> 25:38.840] And of course, if you have an in-house dev team to assist your CTI team, your in-person dev team would be able to write any custom code, write any custom configurations to hook into your firewalls, to hook into your SOAR, your SIMs, in order to fetch whatever data your SOAR and SIMs are, [25:39.020 --> 25:46.520] whatever is sitting on there, and be able to respond back and forth, like, hey, the SIM found something, let's look it up on OpenCTI. [25:48.380 --> 26:00.700] If your OpenCTI platform doesn't know about it, you can just write a connector to constantly pull your, you know, your aggregators from elsewhere about, like, new entities, IOCs, threats, and things like that. [26:05.800 --> 26:06.900] So external import. [26:07.120 --> 26:08.340] Open the floodgates, essentially. [26:08.940 --> 26:12.440] You know, you'll get a ton of data from threat feeds, from upstream. [26:13.020 --> 26:17.700] You know, hundreds of thousands of indicators every hour, depending on, you know, what you're tapping into. [26:17.700 --> 26:25.660] And you have to, you know, you don't want your CTI team to go through each indicator and figure out, you know, what is useful, what isn't useful. [26:26.000 --> 26:31.240] You want to make sure that, you know, the indicators, they stay fresh, they aren't stale. [26:31.540 --> 26:36.720] You know, they're not very useful if they have come in, like, you know, a year ago. [26:37.100 --> 26:44.700] You need something to, you know, auto-offboard them off your platform, just because, you know, indicators get stale over time. [26:49.180 --> 26:52.200] You could get external threat reports. [26:52.420 --> 27:06.400] So whether you get, like, a CISA advisory or, like, a weekly report from, you know, from whatever government entity that's giving out reports for free, whatever roll-ups, whatever white papers, newsletters, and things like that. [27:06.640 --> 27:17.240] You know, if it comes in PDF form, you know, just pump it into the platform, have the platform, you know, be able to, like, you know, pull out the relevant entities, threat actors, indicators, and save it all. [27:20.160 --> 27:25.980] And if you have data sets, you know, right, because, like, the platform is just a shell by itself without any data. [27:26.540 --> 27:33.720] If you need, you know, references to your MITRE ATT&CK techniques, your CV database, you could pull that from GitHub as well. [27:38.310 --> 27:39.550] So internal imports. [27:41.330 --> 27:47.650] It's just, like, the importance of reports from your vendors, from your government entities, from partnerships. [27:47.950 --> 27:59.370] If CrowdStrike, if Mandiant, if FireEye, if they're sending you, you know, reports about threat actors and things like that, and you want to keep track of it, you know, you don't want to, you know, you don't want to, like, print it out or whatever and just, [27:59.430 --> 28:01.590] like, leave it to the side or, like, file it in their file cabinets. [28:01.590 --> 28:05.650] Just put on OpenCTI, it'll be your, like, it'll be your file cabinet for you. [28:09.720 --> 28:14.460] And, you know, whether it be from a taxi feed or, like, a newsletter or a white paper, it'd be able to store it. [28:17.140 --> 28:29.460] And the way that it would essentially work is that it'll parse through the PDF, it'll grab, you know, it'll be able to grab all the domains, the URLs, the entities, and be able to save it. [28:32.420 --> 28:33.620] So let's take an example, right? [28:33.720 --> 28:37.880] Let's say you got this report, right? [28:37.980 --> 28:44.740] CrowdStrike, every year, they'll give out for free if you, like, give them, like, your name, your house number, your email, or stuff like that. [28:44.820 --> 28:47.460] They'll give you, like, a global threat report every year. [28:47.680 --> 28:51.300] And usually these threat reports, they're rich in nature, you know, they're, like, 50 pages long. [28:51.660 --> 28:55.800] You know, they've got, you know, the CrowdStrike stamp on it, so you know that it has to be good. [28:57.860 --> 29:09.380] But you don't want your CCI team to, like, you know, you don't want them to, you know, they could read it from cover to cover, but, you know, unless they're, like, taking notes or whatever, you probably want to, you probably want to automate this process better. [29:12.020 --> 29:12.380] Right? [29:12.620 --> 29:14.920] So, fairly simple. [29:15.260 --> 29:18.580] You just, like, once you get your PDF, you just, like, upload it to the platform. [29:18.840 --> 29:36.280] The platform will have, it will be constantly waiting for, waiting for new work, essentially, once it receives that upload PDF, which you store it in your S3 buckets or minio gateway, it will be able to, like, parse through the PDF and be able to give you, [29:39.600 --> 29:42.380] it will be able to give you, like, entities that it found throughout your reports. [29:42.620 --> 29:49.140] So, the CrowdStrike report that I just uploaded will give you, you know, this kind of breakdown. [29:52.060 --> 30:05.360] And the breakdown could sometimes be, I don't know if it, it doesn't show here, but, you know, out of that 52-page reports, you know, there could be, you know, 500 entities, 500 relationships about how entities relate to each other and things like that. [30:06.720 --> 30:24.700] You don't want to take CrowdStrike's word for granted and have the platform just, like, you know, what if you need somebody to hold your, hold its hand and walk it through for a little bit. [30:24.780 --> 30:28.760] You want to, you want to be sure to validate whatever findings that CrowdStrike is sending over. [30:28.980 --> 30:41.040] Because after all, you know, there are ones that are writing the reports, but you're the ones that are ingesting it and you don't want your, you know, your ingestion to be, you don't want your data set to go bad just because you're ingesting it the wrong way. [30:41.040 --> 30:47.900] So OpenCTI, it gives you the functionality of pre-validating anything you ingest into it, whether it be from, like, a newsletter or a PDF. [30:48.920 --> 30:54.400] You know, it'll give you, it'll give you some, some drop-downs and things like that. [30:54.540 --> 31:03.840] And you can always have the option to choose not to import something, ingest something, to choose not to build a relationship between two entities if you do not want to. [31:08.490 --> 31:25.950] So, after you ingest something, after it runs through the pre, after you upload something, after you ingest it, after you pre-validate it and validate it, you'll end up having, you know, a huge list of entities, you know, typed to their entity type, which matches corresponding to their sticks to, [31:26.090 --> 31:28.470] sticks to type. [31:33.260 --> 31:45.620] And using your API calls, you know, if CrowdStrike tells you, you know, here are five URLs that are known to be bad or malicious. [31:45.980 --> 31:53.020] You can have your security tools, you know, re-verify the data that CrowdStrike is sending you. [31:53.400 --> 31:57.400] You know, upload your URLs, upload your IPs and domains to VirusTotal. [31:57.660 --> 31:58.880] You know, check your sandboxes. [31:58.940 --> 32:04.220] Hey, have our malware analysts, have our reverse engineers seen this before? [32:05.620 --> 32:07.300] You know, if so, like, let us know. [32:08.120 --> 32:16.720] And you'd be able to make the community, you know, you'd be able to have OpenCTI, the platform, be able to make the call-outs for you in order to do the enrichment. [32:18.360 --> 32:21.640] You can also use, like, Shodan if you want. [32:21.980 --> 32:33.900] You know, look up your URL, see what Shodan knows about you from its lens and viewpoint, and have it come back with whatever data that it knows that you think is relevant to you. [32:38.820 --> 32:51.680] So, for the e-gestion portion, it's mainly catered towards, like, you know, other teams, partners that you have, that you work with, or, like, other vendors, or even vendors if they want as well. [32:52.100 --> 33:07.400] So, if you partner with, like, industry partners or, like, segmented IT teams, you know, if they have their own instance of OpenCTI, or if they have their, you know, if they use another vendor product or whatever that accepts, like, taxi feed streamings, [33:07.400 --> 33:09.260] they could hook up into your platform. [33:14.880 --> 33:27.900] And if you ever, in the event that, you know, in the event that there's, like, a high-level, high-severity incident, you need something done quick, and you need to be able to give it to, you know, give a deliverable, give a presentable to your C-suite, [33:28.000 --> 33:42.200] to your upper management folks, you'd be able to, like, ad hoc on the fly, be able to export everything you know about, you know, an entity or a threat group, a threat actor, a threat tool, in order to, you know, write a report about it. [33:47.370 --> 34:00.930] And the one thing that I want to, you know, emphasize is that, you know, you'd be able to, like, freely share and export anything that you have on the platform, as long as it's, like, on the platform already, and without, like, you know, without limitations. [34:01.300 --> 34:13.220] And if you run into, you know, if you encounter the issue of, you know, of, like, resource restraints or resource consumption restraints, then, of course, you just scale out. [34:17.620 --> 34:30.960] So after you have all these streams that are being tapped into your platform, you're getting all this data from upstream, what should your CTI team do with it, right? [34:31.220 --> 34:33.200] So they could run analysis, right? [34:33.700 --> 34:57.780] As a threat analyst, ideally, their job description would be to keep track of emerging threats, keep track of threats that are persistent or have been hitting relevant sectors and things like that, that may be harmful for you, for your organization, for your parent organization and things like that. [34:58.520 --> 35:17.840] You can integrate, in the event of a high severity incident, your incident response plan hopefully would... there would be a section in it to engage your CTI team to have them threat hunt about any bad actors in your environment. [35:21.650 --> 35:24.030] A popular thing to do is to use Maltego transforms. [35:24.830 --> 35:47.630] So you can use Maltego, hook it into every environment that your InfoSec team uses, including OpenCTI, to draw the relationships between your source, your SIM, and of course your tip now, in order to enrich whatever that your CTI team is trying to investigate or threat hunt. [35:50.980 --> 36:08.920] And of course, at the end, you can have the option to write a report to share findings within your community and, you know, on a, you know, on a, on a granular basis be able to share it as like a data stream to your, to whoever is hooked into your platform. [36:11.970 --> 36:20.750] And what's most important, that is a, is a big proponent of the, which is a core functionality of platform, which is to visualize your knowledge graph. [36:23.970 --> 36:26.670] So this is what like a knowledge graph looks like from a report, right? [36:26.970 --> 36:29.350] We have, we have, you know, we have a ton of clusters. [36:29.550 --> 36:30.570] We have a lot of relationships. [36:30.950 --> 36:35.070] Um, the clusters, you know, should be pretty easy to tell what a cluster is. [36:35.190 --> 36:40.410] And you also have like, you know, these, these long blue lines that connect cluster to cluster, um, and things like that. [36:41.350 --> 36:41.710] Right? [36:41.910 --> 36:43.990] But, you know, it's way too, it's way too complex. [36:44.450 --> 36:58.810] Um, and so the, the platform makes it really easy for you to, you know, uh, uh, adjust the graph, adjust the view of the graph, whether, you know, if you're not like a, um, visual thinker or, or visual learner, if you want like the hardcore, you know, [36:58.890 --> 37:04.830] the hard facts, the hard IPs, you, um, the hard, the hard data, you can obviously choose not to use the graph. [37:06.390 --> 37:25.370] But zoomed in, we can see that, you know, I don't know if you guys could see, um, but, you know, we have using color coordination, we have, uh, malware, um, related to different, um, file, file hashes and things like that, and how different malware relates to other malware, [37:25.550 --> 37:29.410] how, how it references other malware, or how it targets other, um, other entities. [37:29.730 --> 37:44.070] So you'd be able to zoom in and out of the graph and play around with it to see, you know, on the grand, on the grand scale, you know, what does CrowdStrike know, you know, from their 2021, you know, global threat report or whatever, and be able to draw a graph from their PDF reports, [37:44.290 --> 37:47.290] um, to, to understand what they're talking about in a visual way. [37:50.610 --> 38:06.930] So usage, um, let's run through, like, a demo use case, um, let's say, um, you want to learn more about, like, the cack bot, the quack bot, um, uh, malware, which is, like, uh, like a banking Trojan that targets, like, financial services companies and things like that in order to, [38:06.930 --> 38:12.930] like, harvest, like, user credentials and, you know, um, uh, do malicious things. [38:15.470 --> 38:18.270] So, you'd look up, you'd probably just, you know, go into your platform. [38:18.450 --> 38:23.070] You see, hey, like, you know, I want to learn, you know, what has QuackBot done so far. [38:23.150 --> 38:27.310] So, you look it up in your platform and you see what your platform has to say about QuackBot. [38:28.250 --> 38:36.350] You know, all this data, the platform itself isn't making it up, but it's getting from upstream from your, you know, from your threat entail feeds and things like that and your enrichment. [38:39.370 --> 38:47.090] You'd be able to see, you know, how often has QuackBots been seen by our, by your partners from upstream? [38:47.450 --> 38:53.130] You know, how often has it been referenced in a report that you have ingested? [38:53.490 --> 39:04.670] You know, how often has it been, you know, how many indicators has it come from, like a, like a, like a threat feed that has drawn the relationship between that indicator and QuackBots? [39:05.910 --> 39:06.910] And things like that. [39:07.150 --> 39:15.230] And you can see, like, you know, which vendors are the ones that are mainly supplying you the data about what you, about what the platform rules about QuackBots. [39:18.830 --> 39:25.130] We got a few more, you know, a few more bar graphs, some pretty charts for you to, you know, enjoy. [39:26.710 --> 39:41.130] You can see, you know, which, which, based on the knowledge found on the platform, the platform would be able to graph it, graph it to you in a visual way to indicate to you the, you know, which countries are being targeted by QuackBots, which countries are, [39:41.270 --> 39:46.110] are related to QuackBots, based on all your findings that you have on the platform. [39:50.800 --> 40:05.520] And again, you know, if you choose not to, you know, if you're not a visual, visual thinker, if you're not a visual learner, you can always just use, you know, plain text in order to figure out how QuackBots relates to like any of the other pieces of entities on your platform. [40:07.640 --> 40:15.240] But wait, you know, like I said before, I think the first couple words in my, in my title of my presentations say security automation. [40:15.560 --> 40:18.400] So, how does security automation fit in? [40:20.000 --> 40:29.180] Whether or not you're, you know, your team has like a SOAR platform or whatever for your SOC, security automation, you know, fits in very well with, with OpenCTI. [40:29.480 --> 40:43.260] So, you know, your SOC can, if your SOC identifies like an IOC, that, that they believe is malicious, they'll have the ability to look it up in OpenCTI and run through, you know, all the CTI related tasks in order to make a determination. [40:44.480 --> 40:59.900] If you have a sandbox and your sandbox, you know, spits out some, you know, spits out some entities that have found, some hashes that have found, you want it to, you know, look it up internally on your OpenCTI platform to see what OpenCTI knows about the, [41:00.120 --> 41:04.480] about your, about your hashes and things like that from upstream. [41:05.620 --> 41:14.420] If you have a SIM, you know, you can, you know, write a custom connection, you could use a custom, you could use an existing connection if there, if someone has written it out already. [41:14.920 --> 41:20.540] You know, whatever your SIM sees, just look it up in your OpenCTI platform to see, you know, what does OpenCTI know about it. [41:21.520 --> 41:39.440] And one cool thing that I use day-to-day is that, like, you know, in the event, there's like some hot topic, whether it be like SolarWinds, whether it be like, you know, OTICS, whether it be, you know, whatever, Log4J or Spring4Shell or whatever, you know, [41:39.480 --> 42:01.200] if those keywords appear in the reports, if, if any of those keywords appear from a, if any new relationships are being created from upstream, from, from a threat feed on the platform, you want to be sure to, you know, alert, alert your, your, alert your security teams like via like Slack or something or like Microsoft Teams chat or whatever. [42:01.660 --> 42:11.780] And that'd be a pretty cool way to like, you know, get that 24 by 7 eyes on glass without actually having someone 24-7 eyes on glass, you know, refreshing, refreshing the UI of the platform. [42:14.200 --> 42:14.560] Oops. [42:17.220 --> 42:23.560] And, um, just because I'm like a platform engineer, so I have to like, you know, show this portion, you know, use infrastructure as a code for everything, right? [42:23.860 --> 42:26.040] You could use deployment tooling to automate the deployments. [42:26.180 --> 42:31.160] If you're on a home lab, you could use like Docker Compose, you could use like Ansible, Puppet Chef, um, things like that. [42:31.380 --> 42:33.000] Um, I mainly operate in the cloud. [42:33.000 --> 42:39.860] So I'm a huge proponent for like, you know, container technologies like Docker, Podman, and using Kubernetes in order to orchestrate your deployments. [42:39.860 --> 42:52.400] You know, you'd be able to use like, you know, um, cloud technologies in order to make a really robust open source, um, straight from the ground up, um, cyber threat intelligence platform for like your InfoSec teams to utilize. [42:53.080 --> 43:03.740] Um, and of course, you know, like anything, um, implement guardrails in your CI CD pipelines and your deployment pipelines to make sure that you aren't like deploying like bad code, bad builds, um, and things like that for deployments. [43:03.740 --> 43:10.520] Cause you don't want, you don't want to purposely, you know, fat finger something and like, you know, disrupt your, um, your, uh, your, your service. [43:13.580 --> 43:13.940] Cool. [43:14.200 --> 43:26.380] So, um, wrapping, wrapping it up, you know, if you, if, if you didn't, if you lost, um, attention, um, OpenCTI is an open source community supported, um, platform. [43:26.380 --> 43:32.460] Um, Boston community, they have like a, you know, a very robust, highly, um, highly active Slack chats. [43:33.100 --> 43:38.760] Um, many people are, um, are on, it's many newcomers are asking questions and many veterans are, are responding back. [43:39.420 --> 43:44.900] Um, you know, it's a community supported, um, uh, environments, uh, and made by Lulitix. [43:46.040 --> 43:49.260] Um, OpenCTI organizes your cyber threat intelligence knowledge. [43:50.220 --> 43:57.800] It connects upstream to vendors and feeds, um, for your CTI team to like, uh, to parse and ingest and correlate on the platform. [43:59.300 --> 44:14.340] And it can be connected as like, uh, um, it can be connected downstream to your sims and source, um, in order to, um, get, to, uh, enable alerts and, um, and logs, um, uh, for whoever has that 24, 24 seven eyes on glass SOC team. [44:15.880 --> 44:33.720] Uh, and OpenCTI can be used, um, um, to track relationships between entities, you know, has crack bots, um, targeted France, has crack bot targeted, you know, Canada, um, has, has it targeted, has it, has it targeted like your, um, you know, your IT organization or whatever. [44:34.020 --> 44:35.020] Um, and things like that. [44:35.300 --> 44:43.740] Um, and most importantly, you know, OpenCTI is used to allow your CTI team and allow your InfoSec teams in order to make good decisions. [44:43.740 --> 44:45.180] Um, using good judgments. [44:47.240 --> 44:47.980] So, thanks. [44:48.420 --> 44:49.200] That's all I have. [44:56.370 --> 44:56.850] Questions? [45:02.080 --> 45:03.600] Hi, uh, great talk. [45:03.800 --> 45:06.240] I appreciated the narrative structure of the whole thing. [45:06.360 --> 45:11.660] You started with a clear description of the problem and it looks like you've engineered a pretty robust solution for it for your team. [45:11.960 --> 45:12.940] Uh, I was curious. [45:12.940 --> 45:15.480] You had a lot of different stuff in your tech stack. [45:15.780 --> 45:19.460] What were the guiding principles that you kind of followed in making those selections? [45:20.400 --> 45:24.840] So, um, those selections, um, you, you're kind of locked into them. [45:25.000 --> 45:26.920] You have to use a lot, you have to use Elasticsearch. [45:27.040 --> 45:29.520] You have to use, um, you know, RabbitMQ. [45:30.020 --> 45:37.280] Um, if you choose to, you can, you can use their, um, uh, publicly built images of the platform and workers and things like that. [45:37.520 --> 45:42.160] You also have the, you know, you have the options to like, you know, fork your own and build your own images and things like that. [45:42.160 --> 45:47.760] But, um, uh, you aren't, you know, if you wanted to, if you choose not to use Elasticsearch, you can use OpenSearch. [45:47.960 --> 45:50.620] If you choose not to use MinIO, you can use your own S3 bucket. [45:50.840 --> 45:51.880] You can use Google Cloud Storage. [45:52.020 --> 45:54.340] You can use Azure as your, um, Azure storage as well. [45:55.600 --> 45:55.960] Great. [45:56.200 --> 45:56.400] Thanks. [45:59.920 --> 46:01.140] Uh, thanks for the talk. [46:01.340 --> 46:05.280] Um, so the platform seems really interesting and it's nice that it's open source. [46:05.580 --> 46:11.420] Uh, but it seems to me it's going to be a limited usefulness, uh, unless you have the upstream feed. [46:12.280 --> 46:16.620] So, what would you suggest for someone who was not, you know, in an enterprise? [46:17.320 --> 46:22.560] Um, which, which feeds should they subscribe to to sort of play with this? [46:22.740 --> 46:25.120] And, like, how much would that cost? [46:25.860 --> 46:34.460] Um, off the top of my head, um, there are, you know, there are open source, um, uh, you know, open free to use, like, reports that you can find on the Internet. [46:34.740 --> 46:37.800] You can, you know, always use, like, you know, PDFs. [46:38.040 --> 46:40.580] Uh, you can use, like, let me try to think. [46:41.020 --> 46:42.480] I think alien vaults. [46:42.840 --> 46:44.520] Alien vault may, might be free. [46:45.120 --> 46:51.160] Um, there are definitely some, like, TLP white sources that you can use, um, that pull from upstream. [46:51.280 --> 46:56.020] I know MITRE has a, MITRE has a good, um, good, uh, good feed. [46:56.300 --> 46:58.840] Um, and it's connection is already built into open CTI. [46:59.180 --> 47:03.500] Um, for you to pull, like, MITRE reports about threat actors and intrusion sets that MITRE knows about. [47:04.100 --> 47:13.520] Um, but other than that, um, you know, you can always just, you know, generate a PDF from, from, like, a, from a report. [47:13.640 --> 47:19.360] Like, maybe bleeping computer or something, or, um, I don't know what, what another, uh, good news source is. [47:19.500 --> 47:20.560] But you can just pull a PDF. [47:20.800 --> 47:26.340] If you, if you, if you like it, you know, you just pull the PDF and just import it, ingest it into your platform and see what your platform thinks about it. [47:28.820 --> 47:31.040] All right, we've got two questions from our matrix chat. [47:31.420 --> 47:33.840] So, uh, we've got a number of them, but we'll start with two. [47:34.020 --> 47:39.580] If you have a threat actor taking actions in your environment and you take action, can you record that in open CTI? [47:39.860 --> 47:42.020] Or do you just have to use a separate ticketing system? [47:44.760 --> 47:59.060] Um, so, you know, open CTI, unless you explicitly tell it that, hey, like, you know, a threat actor, you know, conducted some kind of, you know, operation against your, your, your, you know, your organization's assets, your own personal assets, unless you explicitly tell that to open CTI, [47:59.200 --> 48:00.540] open CTI won't know about it. [48:01.300 --> 48:15.540] Um, if you had, like, uh, if you integrate it with, like, your store or sim, um, you know, obviously you get on a security alert and a security alert tells you that, you know, some, some tool is, is, was, was used in the past, like, you know, you know, [48:15.840 --> 48:24.120] hour, um, to hit, like, you know, one of your systems, you know, open CTI would be smart enough to be able to draw the relationships And say, hey, we have seen this hash before. [48:24.600 --> 48:27.980] We have seen this signature before. [48:29.340 --> 48:37.220] And RecorderFuture or CrowdStrike or MITRE attributes this hash to this threat actor. [48:37.480 --> 48:39.140] Like, hey, you might be in some deep trouble. [48:40.560 --> 48:54.620] But other than that, unless you explicitly tell OpenCTI, hey, I have been hit by the FSB or by an APT group or whatever, OpenCTI wouldn't be smart enough in order to, like, make that decision, that determination for you. [48:54.760 --> 48:55.240] But you can. [48:56.980 --> 48:57.620] All right. [48:57.840 --> 48:59.380] And last question, I think. [48:59.600 --> 49:01.580] Have you done sharing with industry partners? [49:01.600 --> 49:03.940] And what challenges have you faced in doing so? [49:05.700 --> 49:12.560] So definitely, I think, generally, like, people don't, like, unsolicited... I don't know. [49:13.180 --> 49:19.920] People outside of your organization or, like, people that you don't work with day to day, they might not be receptive of, like, unsolicited data. [49:20.100 --> 49:24.100] Like, they don't care about, like, you know, what's happening in your neck of the woods or whatever. [49:24.540 --> 49:31.820] But I think that because, you know, CTI, the whole industry of, like, counter threat intelligence is all about, like, information sharing. [49:32.180 --> 49:38.880] Sometimes, like, you know, someone says something, and it's listened, and it's heard by someone else. [49:38.980 --> 49:45.900] And that person quotes the original author, and someone quotes the original, the author that quoted the original author, you get, like, this loop. [49:46.300 --> 49:47.400] So that's not always good. [49:48.280 --> 49:55.780] But definitely, I think one of the big proponents of, like, cyber threat intelligence is just, like, you know, just be open. [49:55.880 --> 49:58.440] Be able to, like, share amongst, like, those you trust. [49:59.460 --> 50:02.680] And if they, you know, if they want it, they can have it. [50:02.800 --> 50:05.300] But if they don't want it, you know, the door's always open for them to connect. [50:07.380 --> 50:07.660] Excellent. [50:07.840 --> 50:08.040] All right. [50:08.160 --> 50:11.260] Well, thank you for the wonderful talk, and thank you for the audience for participating. [50:11.260 --> 50:11.400] Thank you. [50:16.310 --> 50:21.910] And come back in 10 minutes for their next talk, Electronic Warfare on a Budget of $15 or less.