Enhancing Security at Black Hat NOC with James Pope | Black Hat 2025
James Pope discusses the preparations for Black Hat NOC, focusing on building a secure network with ISPs, firewalls, and security measures. Corelight plays a key role in monitoring traffic and identifying threats. The rise of AI applications raises concerns about information leaks, prompting the use of detection techniques like Yara signatures and machine learning. Partnerships with companies like Cisco strengthen security efforts, and organizations are encouraged to adopt better detection systems.
Transcript
Hi, I'm James Pope and welcome to the Black Hat Knock. I am the SOC leader here for the Black Hat Knock, and I'm also the Technical Marketing Engineering Director for Core Light. We start prepping a long time before this conference to get ready to make sure that we can build an entire network from scratch.
We bring in the ISP, we bring in switching firewalls access points, and then we bring in all of our security tools on top to make sure that A, it's available and B, that it's secure. Part of the security part is we have core light doing full pcap and network visibility of all the traffic that is here, or threat hunting, finding the really bad and the bad. We call these black hat positives.
Those are things where they are a legit bad thing, but we're gonna let it happen on this network. A student comes to learn about some how to run a malicious tool or carry out an attack, and they get taught that and we see that across the wire, and we let that happen in this environment. We care about the things that are truly bad in that bad students attacking students, somebody attacking registration or backbone.
So we have a lot of eyes on a lot of screens paying attention to make sure that we are spotting those things. We're alerting on it and we're responding appropriately to that. Some of the findings and things that we find every time is users who have, uh, green checkbox in the bottom corner, so everything's secure, but they have a VPN that's leaking out credentials.
They got some sassy tool that is sending all the proxy of all their information out in Clear Text. Uh, I'm calling it the rise of, uh, ai, you know, everybody's calling it that, but the rise of Vibes, vibe Coding is taking off and we're seeing a lot more apps, whether that be a weather app or whether that be, uh, leaking out all the GPS information or, uh, this year a few different chat applications that are sending out all the corresponding information of that entire chat, including their voice and translation. So we're just seeing way more stuff in clear than we would like to see, especially at a security conference or let alone from any of these corporate laptops in this environment.
We do that with a lot of different ways. We use detections, search based alerts. We have Yara signatures.
We're leveraging Zeke and CTA on the back end, and then we're using ML hits and also AI detections. We work with our partners. We do truly call them partners here.
No, no tool out there can decide. It wants to be a part of the Black Hat Knock. We go and choose the best of the best and we ask them to come, bring their tools, bring their people, and, uh, make sure that we have a good experience.
Those partners are Cisco, Palo Alto Networks, Arista and Core Light. This year we're leveraging a lot more with ai. We're using Palo Alto Networks XIM to do a lot of summarization and categorization.
We're also using a core light MCP server that lets us directly from an LLM client, whether it be Gemini or CLO or anything else, or a a Slack bot where you can ask it, tell me about this incident. Tell me about this IP address, MAC address, FQDN. And we're leveraging that MCP server to go into the raw data, give us I relevant pieces of information and bring them back.
It's working amazingly well for tier one, tier two people who might not know how to write SXQL queries or SPL queries or insert some version of QL queries. They can ask a question, get the results, and then they can start acting on that information, uh, quicker and faster. Uh, this year we also had two different organizations.
One was a bank, one was a Fortune 50, who their security tools were actually giving away information about their machine, their patch level, their logs through misconfiguration, or just not enabling TLS. So we are in the year of vibing, but vibe and verify, validate that the things that you built are good. I have the luxury of having all these expensive tools where I can look at it and validate that my stuff is good, but Zeke is free.
Crac cot is free. TCP dump is free, Wireshark is free. Go and validate that your stuff is not leaking out things before you send them to conferences or even just to go to your coffee shop or fast food where they're on any hotel network and also leaking out that same information.
While we do have a very highly customized network here that's very purpose built for this conference, there's a lot of things that people can do in their organizations they can take from this and use at their orgs. One is all the detections and alerts we see. If a, somebody gets up and does a presentation on a brand new thing that they find, inevitably somebody turns around and tries to do that.
So we want to look for that. We create detections for that, and then we build those integrations with other partners and those detections that help our customers going forward. But yeah, organization, you wanna make sure that your stuff is secure.
Your people are secure on their end points, not just for Black Cap, but for all conferences everywhere where they're operating that they're doing in a secure manner. Thanks for coming and visiting us in the Black Hat Knock. And we are here for the US Show Europe and Asia.
You wanna learn more? We do have a Twitch stream. You can watch us live in our fishbowl, but if you come to the conferences, you can come in and do a tour and see what's happening in here.
Come learn more about Black Hat Knock and come learn more about Coral Light.