Validating Security – Arik Liberzon, Pentera.io
Arik and Alan discuss why companies need to validate their security. Every day CISOs face the near-impossible task of identifying their organizations’ exploitable security gaps in real-time across an ever-growing attack surface. Despite the large sums invested in a variety of security solutions, they still don’t know if their security is actually effective or what in their organization can be actively exploited.
Transcript
This is texturing TV. Hey everyone, welcome back to techstruck TV Our Guest for this next segment on test tech strung TV is Eric libazone. Eric is with Pantera, but he has an interesting background and we're going to hear all about it.
We'll hear more about Pantera Eric. Welcome to text junk TV. Thanks, Adam.
Great to be here. Nice to have you here. Sorry, I you know, I spoke a little bit about your background, but I didn't say anything.
I'm letting you tell them give us a little bit of your background. great, so If you ask about my background, I need to go back, you know to my last role in the IDF. I actually founded and led and the computer were Warfare group in one of the most classified unit in Israel.
because that classified because of you know with that with a very unique Technologies. And cyber was a really, you know, really relevant. But you know as you probably know for the past more than 20 years the best practice in the industry in IT industry in general.
To test yourself whether you're secured or not is actually to do red teaming in pen testing and all that. So actually found that this group. In the classified units and what we did, you know for our living was to pen test and Red Team our special infrastructures and networks and you know, surprisingly you find that.
Although it's really really secured. Yeah, all those networks are really really secured still time and time again, you're able to get to the crown jewels of every Network. Which you know makes you think or realize that testing is really powerful activity, right and it's something very unique that you can actually go and Pen test yourself like ethical hacker.
See if there are any vulnerabilities and if there are. No problem. Give the report tell the security guys where they need to you know, what they need to do in order to hygiene their Network or environment and then you're free to go and it's a good thing that you as a haptical hacker found those vulnerabilities and all the bad guys.
So, you know, yeah, so while doing this where you know, me and my guys. We got to realize how good it is, but still. It has many drawbacks, you know, it takes a lot of time.
The coverage is quite poor. It costs a lot of money and the results are actually relevant only for a point in time, you know. Environments and networks.
You know, I would say organic they change all the time day by day. So after one month, it's actually a different environment, but you cannot go back and Pen test it. Because you have many other projects to do.
And this is where you know, I got to this idea that you know what maybe? It's possible to automate this powerful activity and then you eliminate humans. And use you keep on the the good thing of fantastic and this is how you know, I decided that I quits the Army it was back in 2015 and I want to found my or start my own company.
With this exact idea to build an automated and testing platform. Okay, which will able you know, my future customers to have continued security validation. with a click of a button Yeah.
So, you know, yeah, I'm sorry. Okay, that is Pantera. And this is been there.
So the company was founded back in 2015. Today we are around 300 employees. We actually concluded in last December.
Our 5th fundraising rounds were backed with yeah with the great VCS and private equities like inside Partners. Awzi, Blackstone K1 evolution. give or take with you know with they invested in us around 200 million dollars so far.
Selling around the globe, you know in America Latin America Europe APAC Africa Eastern Europe the Middle East whatever and the product is actually relevant, you know to every kind of company no matter what the size is. And no matter what the industry is because it's actually relevant to everyone because this is fantastic. Yeah.
so look as we spoke off camera. I've been involved in security 25 years myself. Fantastic is not necessarily new.
red team blue team Has been around a long time. I swear. In fact, I remember my friend, Tony.
He worked at NSA and he was working on their red team blue team stuff. Years and years probably 15 years ago. And I don't think any our audiences of security audience known in our audience is gonna say, oh you don't need pen testing.
I think, you know the idea of whether you want to call it the hackers. I view the pen test, you know, people know it I have many friends who travel around the world doing in essence pen testing and and that kind of stuff. That prevent pen testing.
Let's call it pen testing. It's scale. number one There's more than just that pen test scan.
Right whether you're using go what did HD mortgage HD more Metasploit or or something like that. Yeah, you could do that and say you did a pen test, but that's not really up a real right it generally speaking. You needed someone like you or the people who worked with you who would really you know, in their hands are too like Metasploit or other tools really becomes a tool but on top of that it was more than the skin.
It was the social engineering it was the physical security aspects. It was the whole you know, how how can I hacker get in here? How can a bad guy get in here?
And it was always sort of labor-intensive people intensive. It wasn't the kind of thing. You could order me.
How do you order you know? How do you order me dropping USB keys in the parking lot and wait to see who brings them in and plugs them in, you know, and and what you can get how do you automate those things and then? Just the eye but even just forget the social engineering just doing the pen testing the automation of it is.
It's hard. It's no, you know, it's not been done. I get for instance our friends and Cobalt.
I'm sure you probably compete with them, you know them they do pen testing. It's crowds like crowdsource pen. Testing pen testing is a service but what they're really doing is matching up with a pen tester.
Who does the pen testing right? So without I realize you can't give away the company Jewels, but how do you automate this? Wow, so it's a great question.
Listen, when I started, you know Pantera formerly. It was called Sciences. Most people told me listen you cannot automate this.
So and it sounds so reasonable because it's a kind of Arts right pen testing and hacking and attacking but you know, if you I think that everything could be automated. And but you need to understand, you know, the the process okay of pentester of or actually hacker Dentistry is actually a hacker. It's only ethical right they start with scanning.
They need to know what is the you know the environment. What's the scope? And then after I realizing what the scope is, they need to enumerate each and every device.
Figure out whether it's a router switch a Windows machine a Linux server, whatever. After that, you look for static vulnerabilities. CVS, okay.
And then you can start actually exploiting one by one. Or you can actually trap users or quite dynamic in the organization or in the network. if one of these You know is successful then you can move on to the post exploitation phase and then let's say that you grab some passwords from a service in the operating system.
Great. Now you have new data that you can use to actually propagate your attack. So what actually told you here is very Dynamic step by step, but this is exactly how hackers and dentisters are working.
And this is exactly the way Pantera works. We actually modeled, you know, the scanning phase after that the enumeration phase after the vulnerability scanning phase the exploitation the post-exploitation and so on and so forth. So today we know that it's possible.
I can tell you that back then in 2015. Most people thought it's not it's not feasible. but indeed it is But you know if you would ask me so.
No need for humans human pen testers, I would say absolutely no, of course. We need human pen testers. Why?
You still have some exotic, you know infrastructures. Or products some new products that will not yet models by enter. For example, okay.
And for this you still need humans. But you know the the bread and butter. You can actually use automated.
products and you have great coverage. Okay, so don't forget that now that we've actually successful to automate all this. Look at the good, you know the half glass full.
The coverage is enormous. You can do it on a daily basis. Which you know, whatever fantastic type you want whether it's applicative web infrastructure, whatever.
You can do it day after day. You can actually train your sock team whatever just because it's here and it's with a click of a button. Yep, you know I'm reminded so back in 2003.
I started a security company in 2001 Boulder Boulder 2003. We launched vulnerability scanner. And back in those days.
You never found Stone a tenable. Koalas, you know rapid 7 wasn't even. born yet And in those days you would have to put a scanner inside the network.
You had to have all your logons to show anything and then all of a sudden it was qualis was actually storing stuff. There was no Cloud, but Carlos was storing stuff outside, but they really started scanning from outside. Not quite pen testing, right?
This is it is before Matt is point that kind of thing. And we started getting that so-called hackers. I view.
right and but I see the same sort of thing here now where you know, what would started out as a very what's the word? I'm looking for like a cottage industry a very labor intensive. Onesies and twosies kind of business.
Is now scalable. Because of something like this. I guess my next question is okay.
That's great. I could do a once a week once a quarter once a month. pen test scanning service If it follows the same path as we saw in vulnerability, the next question is what do we do about the pen test results?
Can we automate closing down these holes? Can we automate you know stopping bad guys from exploiting this stuff? Great question.
Listen Vulnerability scanners are great. Okay, but the problem with vulnerability scanners if they are they're lacking the context and they don't show you attack chains. And there are only looking for CVS, okay.
But hackers work a little bit different, of course, there are looking for CVS because you know, then maybe they have food in the door. But most likely they will try to track or use some promiscuous behavior of employees. Right or users?
And this is something that scanners don't really do and let's say that something was exploitable you found out you're using the scanner and something was exploitable who said that this you know, this specific server is really important for the organization. Maybe it's not maybe it's only you know a lab. server You know connect connected to nothing.
Okay, so So what if the CVSs of this vulnerability stand out of 10? What's the context and when when you use an automatic pen testing platform now, you have the context and you have you can relate to the business aspect. Of our of the client or of the network, right?
You can show the attack chains. Starting from starting point hoping to a different server and then to a remote desktop whatever but you're very Dynamic exactly like human hackers and they're the enemy right? Second thing is that vulnerability scanners are lacking, you know the prioritization just as you mentioned, right if I will use vulnerability scanner and see 50,000 vulnerabilities.
What can I do with it? Right I guess nothing. I wouldn't even start touching the first vulnerability because then I would be left with 50,000 minus one.
So we need some prioritization mechanism and if you show the attack chain. They actually get to realize what are the root causes of your environment or your you know your posture. Let's say that then vectors actually started from the same vulnerability.
3 out of 10 still it's a root cause go and fix that that one and maybe after that you don't need to fix additional 200 vulnerabilities because you actually cut you know the chain. just a different perspective and it's much more fruitful, you know when my if you know, it's more bang for the buck, right? How do you get you're the most bang for the buck?
You know, I'm reminded. I don't know if you know a giddy Cohen, right Skybox security. Do you know getting yeah first time I remember they drew those Maps the attack Vector Maps the first time I saw that I don't know 2005 2006 something like that.
Wow. It opened like it that was a whole new world to me right in the idea of you didn't even really have to fix any, you know, you didn't necessarily have to fix a vulnerability. You can just close the access to that vulnerability right over a poor or however you want.
so there's a tremendous amount of intelligence in there. The problem is is the Automation and and the and the and the issue is as our networks have gotten bigger and more complex in the cloud and here and there and everywhere. It's very hard to get humans wrapped around all that.
It almost demands automation. So it I mean, that's why I'm sure you know Pantera's success is Right very closely into that. Anyway, hey, we're we're past time but for people who want to get more information about Pantera.
Where can they go? They can actually reach us, you know through the the website. com or interior dot Io Io okay.
They can request a demo or a POV, you know running it will be for us takes only a few hours from start to end. The results that they're gonna see our you know, mind-blowing really they will see exactly how the attack is propagating. They would get so much value and so it's very easy, and we will be happy, you know.
You a business question. What like, how is the price? So it's a subscription model, you know, an annual license.
We have products. We have the core for the internal the surface from the external there are somewhere ready module and the credentials exposure. So we depends on the size of the network.
And and it's based on you know, the number of endpoints you have in the organization very very simple easy to digest. Make a lot of sense. Actually Eric, thanks for coming on and talking to our audience a little bit today.
Good luck with Pantera. Keep us posted on what's going on. Okay?
Thank you Allen. Thank you. My Eric library is on from from Pantera here on Tech strong TV.
We're gonna take a break. We'll be right back.