Launch of AWS Multi Account Support – Toni de la Fuente, Verica
Toni De La Fuente, Leader of ProwlerPro, gives an update on the state of the business, including the launch of AWS Multi-Account support. This enterprise-grade feature automates the job of discovering, analyzing, and understanding the security posture of an entire cloud deployment across security assessment, incident responses, hardening and penetration testing automated checks.
Transcript
This is Techstrong tv. Hey, everyone. We're welcome back here to techstrong tv.
I am really happy to have, I, I don't think he's ever been on Techstrong tv. We usually interview him in person. Actually, no, you've been on Techstrong TV with me before too.
Let me introduce you to Tony de La Fuente. Uh, Tony is the creator of what, what's called Prowler, right? A very, very, very popular open source project.
And the IP of Prowler was acquired, uh, by Tony's present company. I've, I don't want to mess up the name, Tony. How do you pronounce the company?
It's Vera Veka. Verta Veka. Yep.
Da Dao. And Tony joined the company there where he leads not only the continued Prowler and Prowler Pro, right, the commercial version here of, of this. But he also, well, he's involved in a lot of things.
Tony's a a big community guy and open source and, and pretty well known in, in this space. Tony, I hope I didn't embarrass you. Welcome back to techstrong tv.
Thank you. Thanks Alan, for having me here and give us the opportunity to talk a bit about what we are doing. Cool.
Absolutely. So, you know, I, I mentioned Prowler, but yeah, people out here may not know Prowler, right? They may not be familiar.
Why, how would you, Tony, how would you describe Prowler to them? And then we could go to Prowler Pro. Prowler is an open source tool for cloud security.
So we started, I started actually back in 2016, uh, writing the tool to support mostly aws. And now we support aws, Azure and G C P. And what PRO does is to scan your, uh, infrastructure in the cloud, and it tells you if you have your infra properly computer or if it has some vulnerabilities, et cetera.
Basically how to follow the best practices. And Pro is commonly used for hardening audits in, in, uh, instant response or compliance, and also for pen testing. Yeah, the notes u used there too.
And, um, and then of course, Prowler Pro is, is sort of the commercial version, if you will, of, of prowler. Correct? Exactly.
So once we have, we, we keep evolving Prowler as an open source, as the engine of, uh, of an, this scanner of AWS security, Google and Azure security. We built on top of that scanner a service as a service called Power Pro. So now you can go to prior Pro, sign up and scan your accounts or your resources in the cloud, um, without having to, to download anything or to run anything.
So Prior Pro does it for you, um, with one or multiple accounts, you can also create, uh, dashboards, uh, et cetera. Excellent. All right.
I think we've done a good job with that. I got one more, one more thing I'm gonna throw at you before we can jump into the today's news. And that is, again, not everyone here in our audience is, is going to, is familiar.
Why don't you give them a little baseline on that as well? Yep. Uh, at ver we, we have, uh, three lines of, of, of business.
One is the C V P, which is, um, continuous verification platform, uh, that we, we have for Kubernetes and also for Kafka. We have the Void, which is a report where we investigate and we analyze the incidents in different companies, and then we, we allow other companies to learn from those incidents and the, the mistakes or the, the bad practices. And also we have Prowler Pro, which is the service that we offer for, uh, cloud security for the most important cloud security, uh, carbon vendors.
Got it. Excellent. All right.
We've got all that out of the way. Tony, some new news around Prowler Pro. Yeah.
Yes. We have some good things happening in, in Pro, pro. First one is that we, we j we just joined the, uh, a w s partner network, which is a very good, um, news for us because now we have also the support of a w s in terms of the partnership, where we are going to increase our reach to the market.
And also we are working in, uh, to list Pro Pro in the AWS marketplace, which is going to be, uh, also very helpful for us and our customers to start using Pro, pro quickly in terms of subscription. Also, we added new features into Pro Pro, which are, um, the pay tier itself, which, which makes, uh, also really, really easy to start using, uh, C S P N, uh, in for, uh, per price, let's say. And also supporting multi account.
So you can scan as many AWS accounts as you want. And, and you pay only for scan resources. Scan resources every day.
001 scan resource every day. That means, for example, if you, if you have 400 uh, resources, you are going to pay no matter how many accounts, one account or 20 accounts, whatever, you are going to pay something around $10, geez. Which is, You can have as many accounts as you want.
You pay maybe 10 bucks a day. Yeah. It depends on the, the resources.
So I think that that is the, the most fair way to charge, right? Because if you are a small company, you're going to pay nothing or, or a small amount or, uh, because we have a free tier, be below that, uh, $10. Um, if you are a big company, you're going to pay a little bit more, but also we support contracts and, and flat rate.
Yeah, no, I like that pricing too. You know, I mean, here at Techstrong, right? We're a small company.
We only got, you know, under 40, 50 employees. And, um, but we have a lot of domains. We have a lot of different websites and communities, right?
com, cloud native, now, text on tv and digital cx. And a lot of the SaaS kind of solutions that we use, they charge for every single different domain for every, you know, instance, if you will. And it's really not fair cuz a lot of them are really tiny and they just, you know, kind of feed off of the four main ones.
I'd much rather pay across the entire portfolio based upon the usage, right? And, and I, and I think that's a much fairer way of doing things than charging people for every single domain or different instance that they spun up. Yeah, I think it's, it's a very hard exercise to do when it comes to figure out what is the best way to charge users for the SaaS or for Security sa.
So we have done a long research on how others are doing this, and many companies, they say, okay, we are democratizing the cloud security, but they're charging you 300 K a year. It's like, okay, Yeah, that's very, that's, that's a good democracy. You know, that's, as someone once told me, Richard Poor, it's nice to have a lot of money and, and, you know, so that, that's where that comes in.
But yeah, 300 Ks not bargain. And we, and by the way, we've gotten hit with some of those too. Um, so, so I hear you.
You know, Tony, the whole AppSec kind of world is, is maturing, right? I mean, we've come a long way, I think in the last, let's say three years to five years. Um, what is, you know, from a business model, I get what you guys are doing.
We're pro or pro, but let, and, you know, and, and being part of the AWS marketplace and a partner is fantastic, but what do we, from a technology point of view, what, what do we new, what's new and prowler that, you know, to keep up with today's thread environments? So in, in the, in the cloud world? So we have so many ways to, to visualize or to gain, uh, some, um, um, access to the information.
So I think the key part here is how to show that the information that we get and how to mis minimize false positives, the noise. Mm-hmm. Um, I still think that next year and in two years, we're going to have more or less the same type of issues, but in, in terms of misconfigurations, et cetera, you know, the, the thing line between what the cloud provider has to take care and what you as an user, as a customer have to take care.
That thing line is always moving up and down, but the part that the customer has to do if they, if you as a provider rely, uh, realizing the customer to make changes, those changes are probably never going to happen. So what, what is going to happen from uh, security vendors like us is, okay, I'm going to do this, this for you. I'm going to remove all the noise.
I'm going to make you focus in the important things. And what is an important thing. The important thing is what has more impact?
So one thing is the, the severity, okay, this is important. This is, um, high, uh, critical, low, medium, whatever, but how does it impact in your infrastructure, in your applications? So I think that is, that is key.
So you, you have heard probably many times, uh, context aware, security and all that stuff. So kind of like that because knowing if this resource is important for you, for your application is probably going to be, um, um, higher in your list of fixes or what to do, right? So understanding and giving the customers the proper and straight type of information is key because we see, um, ransomware attacks in the cloud, we, and we will see that next year as well.
So this is not going to change. Probably we're going to see even more, um, because the customer are not taking proper care of the hardening. And I think we have to provide them how to do that automatically on how to do that some sort of manually.
So, you know, give them the tools to harden and secure, uh, and secure the infrastructure. Excellent. Excellent.
You know what, everything, everywhere you go, it's ai, this and generator of AI that any plans around AI for Prowler? Uh, we have done some, some research in the, uh, in that front. Um, this is going to help us, uh, and other companies on how to explain information that we gather.
So if we, if we get something important, we, when you run pro or with Pro, pro is that we have a big data set and the AI is going to help us how to explain that customer in a dynamic way. But I don't think this is going to solve any problem for the customer hardening directly or for the customer security directly. Uhhuh, it's going to be to help to understand what's going on and to generate some code instead of you having to, to code itself.
But I don't see that direct way data way to, to take advantage of it right now. Doesn't mean that it is not going to happen, but right now it's like, okay, I think we're rolling. I scan an account and the, the, the account, the audits that I was doing a year ago are exactly the same results and as now, and it's going to be probably next month.
So we, it is going to take time. I gotcha. Let's, um, well, yeah, we'll see what happens there.
Anything else new in the, in, in the world of Prowler and Prowler Pro that we haven't covered? Yeah, we are, we are working with customers to improve Prowl Pro, adding more and more features. So new features are coming up, uh, soon, like multiple users, um, more detailed compliance re uh, reports, et cetera.
So I'm also integrations with third parties, which is what we are doing now, also in product and Broad Pro. pro because good stuff is coming up. Excellent.
All right, Tony, for people who may be, haven't started or haven't looked at PROWL or a prowl or pro yet, what, what's the easiest on-ramp for them? How do they, how should they engage? pro, and you can sign up and start scanning your account in five minutes.
You have a whole report of one account. For example, today we onboarded a new customer this morning, and it is started with three accounts in literally five minutes. It's a re plate, you add the account done, but if you want to do it by yourself, you can go to, um, Prowler op, open source in GitHub and install it.
Like, for example, with p i p install Prowler, and you run it and you get the results in, um, different formats to see the, your, your security posture. So love it. Product Pro is the way to, so from there, you can go to the open source or the, or the service.
Excellent. Tony, I want to thank you for coming on today. Continued success with Prowler and Prowler Pro and all the Verica folks.
Say hello to Casey, come back if I, if I don't see you in person soon, hopefully come back here on Techstrong tv. Keep us posted. Okay.
Uh, we will. Thanks Helen. I'm the team.
All Right. Thank you. Tony Deonte, uh, from PROWL or prowl or Pro here on Techstrong tv.
We're gonna take a break. We'll be right back.