ROCon 25: Qualys Unveils TruRisk Eliminate and New Compliance Innovations with Lavish Jhamb
ROCon 25 introduces TruRisk Eliminate, a new remediation module from Qualys that includes patching and compliance options. Lavish Jhamb discusses File Integrity Monitoring (FIM) and its importance in compliance, especially with the new PCI 4.0 requirements. Organizations are urged to monitor file access to prevent unauthorized access. The concept of a remediation buffet is presented, highlighting various strategies for addressing vulnerabilities, including a new feature for assessing patch reliability.
Transcript
Hey everyone, welcome to our day two coverage of Qualys Rock on, uh, conference here in Houston. I hope you enjoyed, if you had a chance to look at yesterday's, uh, interviews and stream, it was pretty good. If not, the on demand versions will be up early next week and you can check it out there.
We're gonna kick off today's coverage with lavish. Say it for me again. Um, John Lavish.
John from Quais. Lavish. First of all, welcome.
Thanks for coming on. Lavish. If you wouldn't mind, look to this camera, let people know, what do you do at qualis?
Okay, so at Qualis, I, um, I'm the product manager for Tour Risk Eliminate, which, uh, is a, I mean, which is a remediation module, and it gives you not just patching, but other elimination options as well. So it's an entire remediation buffet that we provide, uh, with the truist ate, it's patching, mitigation, isolation, a lot of other options. And, uh, my other part, uh, I mean the other part that I do is, uh, compliance centric.
0 FIM specific requirements. Okay. And not, it's not just limited to PC four Oh, because FIM is a key requirement of other regulatory mandates as well.
For example, it could be NIST, HIPAA and uh, GDPR. Right. So, depends like what, what organizations are complying with.
We provide FIM for FIM to, for providing that particular coverage. Got it. You know what, there are people out here who don't know what FIM stands for.
What does FIM stand for? Oh, So, uh, FIM stands for File Integrity Monitoring. So anytime the, uh, critical files, if they're changing an alert should be sent.
So that is the primary requirement of any, any compliance mandate pertaining to fim. 0, now it's evolving. 0.
And there are new requirements that are coming in. For example, it's not limited to integrity monitoring, for example. Right.
It used to be just a check sum. Yeah, yeah. Integrity Monitoring was like, if it changes, file content changes, gimme a notification.
But now it's more of FAM file access monitoring. Okay. Even if I access it, make no change.
Make no change. I just access, see the sensitive data, close the file. I made no change.
So FAM wouldn't have given you any alerts, but FAM will. Right. So call F covers FAM area as well.
So, and Fam, FAM is new to PCI four Oh oh, yeah, yeah. 'cause I, I remember the fm. Yeah.
You know, the, it was basically a check sum. Mm-hmm. That's what it was.
If the check sum changed, this Is one new thing. I mean, it expands so much. For example, earlier it was just on post based machines.
Now they've expanded to containers as well as, uh, network devices. Well, they had to do the containers. I mean, it was wind up missing half, half the infrastructure at that see Containers, the life of container is what the average life, I'll tell you, it's 54 minutes or something, right?
Mm-hmm. So if a device is living for this much time, only an hour or so, you make the change, it'll never be tracked. But if FI is there on that container, it will track that change.
Even if the container goes away, that change will still be there for 15 months or so with Quas. Got it. And when did four O go into effect?
Oh, it was, uh, March 31st, 2025. So that's six months now. Yeah.
Yeah. Um, what do you seeing lavish from, like, from the, you know, from the public, from the customer base? Because this, this is a big change, right?
Oh yeah. At any time anything's accessed, I mean, they're using Qualys to monitor for compliance, but are, are they doing anything to make sure less people access these files? In other words, you know, you don't do compliance for compliance sake.
They do, they put this into encourage a behavior. The, the behavior they're looking to encourage is less people accessing this file. Are you seeing less accesses over time?
Oh, yeah. Yeah, definitely. So earlier, all the accesses were going unnoticed, right?
Right. And, uh, there are a lot of automation processes as well in place that access the file. So amongst those automation processes, the, the unwanted users, or I can say the unauthorized users who were accessing the files in between those changes were getting unnoticed.
So, um, I mean, if it is unnoticed, it's, uh, nobody's caring about that. But now with FAM in place, those changes are, and being noticed. So the automation changes are whitelisted already, but those changes which are by the unauthorized users are flagged now since it is getting noticed they've stopped accessing those things.
Got it. Yeah. Got it.
Um, I would imagine like when it first went into effect, there must have been a spike because he went from FIM to fam. Yeah. And then the, the, you know, the, the administrators realized, Hey, we gotta cut access to these files and that spike goes back down.
That is, uh, as the same thing I'm, uh, doing in my session today as well. Really? Yeah.
4 million events for FAM when we released fam, but when we saw how many are for the unauthorized users, 98% of the events were not, Were authorized, not Yeah. Were worthy, not not worthy of attention. Yeah.
Right. Were authorized events by some automation processes, and then we saw how many, um, of unauthorized access attempts are for sensitive data only. It remained less than 1%.
So that is where my focus should be, and that is the kind of noise cancellation that we have today. Yeah. I wonder if the PCI council could somehow get access to Europe's slide Yeah.
And understand that what we should be, you know, focusing on is on unauthorized fam. Not, not all fam I would imagine this is going to cause a lot of heartache for people. Oh Yeah, definitely.
You're right. So PCI has a specific, uh, note in their requirement. 2 requirement.
They specifically say monitor only the files, which do not regularly change. Right. And you should have a mechanism to differentiate between good and bad changes.
So they say it on a high level, but it's how you interpret it. Right. So other solutions I've seen, I do a lot of competitive analysis.
They just do fam, sometimes very less of them do it because it generates noise. Right. But if you have a way to differentiate the unauthorized ones, then it becomes really good.
Excellent. Alright, let me pivot a little bit, because another part of your duties here at, you know, responsibilities at Qualys and what, and what you know you're presenting is around, I I think, uh, Summa summed the Qualis, CEO sum, aka yesterday referred to it as re a remediation buffet. Oh Yeah.
He said, he said some funny things yesterday, the remediation buffet, the, uh, the, uh, dashboard, uh, dashboard tourism. It was good stuff. But what we're really talking about, look, there's more to remediation than patching.
Oh, yeah. Right. And that, and this has been something I think the security industry has tried to bring out there for a long time.
Not every remediation needs a patch. Oh yeah. Not every vulnerability you find is necessarily patching the way to remediate it.
Give us, let's start with this Lage. When we go to the buffet, yes, the patching is gonna be a big plate, but what is some of the other plates at the buffet? Okay, So when this is sumits clearly his idea with the remediation buffet uhhuh, because see, there are a lot of patching tools out in the market a lot.
Yes. Right. And they provide patches, I mean, um, provide patches for Windows operating system, Linux, Mac, and the third party tools like Chrome, Firefox, all of that, Adobe WinZip.
So patches are there, but, uh, that's the only thing they provide. Now what happens is, what we have observed is even after having the patching tools in place, all the different patching tools in place, still a lot of vulnerabilities are still open. A lot of Tuesday patch vulnerabilities are open.
A lot of, uh, third party, uh, vulnerabilities are open. So we saw like why, I mean, we talk to our IT as well. That why it could be the case.
The thing is patch is available, but doesn't mean I'll apply it all the time. Right. It could be a not reliable patch.
Mm-hmm. Right. So if patch is breaking something, if it is known to break something, I would not deploy that.
Rather I would need a mitigation there. Right? So if I, if I, uh, if I, if the patch deployment is breaking something, but the mitigation like, like blocking a certain port is making the vulnerability unex exploitable, I'll rather deploy the mitigation in that place.
So q what we, at q what we do is we see the vulnerability and there's a research team that writes a mitigation majors for it as well. Mm-hmm. So you don't have to write it.
So with other products, what, why the vulnerability remain open, is it team cannot deploy the patch due to certain operational risk reasons. Right. Or maybe the chain management didn't agree, so IT team cannot deploy that patch.
Now they have to research on that vulnerability, write a mitigation measure by themselves. And this takes time and increases the MTTR. Yes.
Right. What we did is we, we asked our research team to write those mitigations. Now, customer just has to deploy that.
Imagine the time that is saved. Sure. So from three months of MTTR, it has reduced to what, like some days now or a week.
And this is one part of mitigation where patches are available, but you cannot deploy it. The other part is the patches are not available. So there are vulnerabilities like SMBV one win verify trust, the vendor did not even release the patch.
What do you do in that case? Now, honestly, we have seen those MTTs for the vulnerabilities with, with no patch available. The MTTR was nine months in customer's environment.
So for nine months, a vulnerabilities open, and that one's, that one is in the CSAC cab, but it's open since nice nine months. So what we do is we create the permanent fixes for those vulnerabilities. We create it, we research on those ones.
We permanent fix could be modifying the registry key or uninstalling the EOS software. So we create it, we just need to deploy that fix and fix the vulnerability. Got it.
I just feel like I, if some people may not understand MMTR is minimum time to re remediation. Yeah. MTTR is a meantime to remediate.
Right. Mean Meantime not hit 'em up. Yeah.
Meantime to vulnerability. So that, that's an important part of it too. Yeah.
And, and here's the other thing. Look, I, I've been in a vulnerability management space a long time. Just be, I, I could do some remediation now that kind of, you know, blocks access to that port or something like that, and I might patch something later that fixes the underlying software vulnerability.
So, you know, not you, you could do sort of a, I we used to have a word for it, not a temporary patch, but It's a temporary mitigation. A temporary mitigation, yes. Until it's done.
And you know, this all goes into the, the remediation buffet as they call it, right? Yeah. Um, leva, you know, we're living in a world where we're seeing more vulnerabilities than we've ever seen.
Oh, yeah. Right. AI generated code.
I'm not saying AI code's bad, I'm just saying there's a, there's vulnerabilities in it like every other code, but AI is, is causing us to generate more code. So of course we see more vulnerabilities. Yeah.
Do you see the remediation capabilities of Qualys? Like does it scale, I guess is the question? See, a lot of big enterprise solutions are using Qualys today, and it's very much scalable and not just the patching.
So if you just see the patches, one 40 million patches were deployed last year. Right? So that's a big number in itself to tell you that how many assets were patched and, uh, about the mitigation, it was just released still.
What we saw was one 50 k plus mitigations have been deployed. Just the medications. Right.
And, uh, the, there is another, uh, feature to it that is isolation. So if there is no patch mitigation, also you don't want to apply. There's a breach state of breach or something.
You can isolate the host two in order to stop the breach. So that whole buffet gives you a complete visibility in your, in, in your, you know, um, area, what you're doing on top of it. It, uh, it is, it is pretty scalable that I can confirm.
I mean, with the number of patches you can know. Yeah. Right.
So if it is a one 40 million word deployed, and they, there are a lot of enterprise level customers with us. There are big names, right? Oh, I know.
So, yeah. And they, uh, they are deploying patches left, right, and center. So It's, they have to, I mean, in this thing, you know what the, the, the role of v vulnerability remediation is, is somewhat of a thankless job because it just gets harder.
Yeah. But, and this is why you need automation. Yeah.
To do a lot of this too. So regarding that, you brought a very good word, patch automation. So the thing is, um, we have Iran announced it yesterday.
Yes. We have come up with something which is called patch reliability. So now we are also telling you if the patch is reliable or not.
We are doing all the AI assessment we are doing, there is a call proprietary algorithm behind the scenes that checks if the patch is reliable or not based on vulnerability reopen rate, the AI assessment, what's the word on Twitter, Reddit, et cetera. We're checking everything based on that. We know if a patch is reliable or not.
Now, if the patch is highly reliable and the assets are critical or not critical, doesn't matter. Right? If the patch is highly reliable, I will put that patch under patch automation.
Now imagine I just have one token that tells you patch reliability, high colon true. All the patches are listed. I said, put them in patch automation this, and if the patch of liability is low, don't deploy it.
Put it, put mitigations there. Right. That is where, That's real intelligence.
That's beautiful. And that is what we have developed actually. It's not like farfetched goal.
It's there. It's there And there now, and You can start using it tomorrow. That's, That's great.
com and then what section is all this under? com, just search for tourist ate or just say Tru Eliminate for, uh, Tru Eliminate module of call. And you'll see all the information.
There are data sheets available. 0. File Integrity monitoring, which specific requirements sets all the use cases, what are new requirements?
What are old, older ones? You can search under call blogs and blogs by where the author is me. Uh, and you can also go to our website, uh, on call dot coms, uh, and just search for the film module.
You'll have, get all the information data available. Thanks for coming on. Thank you.
Good luck with your, I know you're still doing a visitation today. Go to it. We're live here at, uh, rock On.
We'll be back with more in a minute. Thanks.