logo

NJP

ServiceNow and Threat Intelligence with TruSTAR - Introduction and product demo

Import · Mar 30, 2021 · video

welcome to this webinar on threat intelligence management with servicenow security incident response and true star i'm deepak kalingiwadi i'm the director of products here at servicenow handling security incident response and i will be your host today and joining me are partners from uh truestar patrick coughlin who's the ceo and co-founder of truestar and elvis hoerr who's the vp of product at truestar welcome patrick and elvis we are excited to have you here today great to be here thank you back awesome so we have a riveting agenda that is going to be fast paced i will start off by providing an overview of the threat intelligence module that is packaged into the security incident response product and how it sets the stage for partners like truestar to work with it i'll then turn it over to patrick who'll talk to us about true star how they are setting themselves apart in the threat intelligence domain elvis will then do an exciting demo of a new integration between security and response and true star that was released to the store some unique use cases on offer through that release that you will see so as you all know security incident response is a sore offering in the market today and soar is security orchestration automation response which brings together uh three distinct domains of incident response platform uh the technical orchestration capability and the threat intelligence as defined by uh gartner and really our endeavor here with the security incident response is to be that strategic soar for your organization and what that means is we want to operate your security operations for efficiency help you deal with the run-of-the-mill incidents like phishing malware eliminate the noise so that your analysts can focus on um you know what's more important we also want to be automating for scale and what that means is you know you know incident response is seldom done in isolation you know depending on the severity of the incident you may have to transcend organizational boundaries and involve resolver groups across your enterprise so so servicenow is the perfect platform that helps you do that and the third is you know we just don't want incident response in your organization to be a reactive function we want that to bolster your proactive capabilities which is where our mission is also to enable your overall security function maturity uh where we can leverage uh uh kill chain frameworks like mitre attack and help you understand what is your cyber defense posture against adversarial tactics coming at your organization and finally uh you know we also want to help you overall manage your cyber risk not just the reactive piece but also helping you with attack surface management and managing uh enterprise risk with other capabilities that reside on the servicenow platform like our vulnerability response offering or our grc and and the mission of uh how we help uh you know to be your strategic sore is accomplished by not just kind of you know dealing with uh you know traditional use cases uh for soar but but really you know going over and beyond uh and some of the tenets of that uh still remain uh you know kind of fundamental to how we do uh how we work flow things within the platform by helping you first organize all of your incident response procedures into playbooks help you speed up your response by doing the investigation uh the containment and the eradication of threats and helping you recover quickly helping you capture all of the after-action reviews for posterity learning as well as you know escalate incidents as needed for a cross-organization collaboration and then uh you know capture your whole incident response rhythm through optics and surface them as dashboards to help you report on metrics uh you know trends and uh bottlenecks everything built on top of innovations uh that uh are already you know gone into the servicenow platform and if you look at the building blocks of uh security incident uh response you know there are primarily like four building blocks the first is uh the integrations with the security ecosystems uh that we've built um you know literally every uh vendor technology out there the whoso we built out of the box integrations with those be it your sim threaten dell providers with your edr tech or your firewall and then we help you orchestrate response by putting the whole response procedure on rails through our playbooks and we would also leverage uh contextual intelligence within the servicenow platform on asset related information uh threat intelligence which we'll talk more about is a key piece to help contextualize your threats as well as help you become proactive as we get indicators of compromise through feeds you can put workflows to go ahead and block them ahead of time before you even see instance and finally the management piece which enables you with the ability to monitor measure and track your whole incident response process and like i said you know you know the threat intelligence module is the one that we are going to deep dive uh into uh and and if you really kind of peel the the layers there there are six key capabilities within our threat intelligence module the first is an ioc repository uh which is where we collect all of the uh uh the indicators of uh compromises and the sources that they come from it's built on the stixx model and then we help you bring that data into the repository through out-of-the-box capabilities we have a built-in taxi client as well as rest api capabilities through our low code no code engine we help orchestrate with several uh third-party uh uh you know services threat intelligence services uh to bring enrichments uh back as well as to containment uh and then finally uh you know integrate uh threat intelligence uh in the services of ir for a multitude of use cases for doing triage for investigation uh you know for blocking and also for sharing which we will see in elvis's demo case management helps you track adversaries over a longer period of time creating a dossier uh for specific adversaries of interest and finally the kill chain surveillance piece which is where we would embrace uh frameworks like mitra attack so so those are six capabilities uh the partners like true star work across these uh capabilities and and drive uh outcomes for our customers and i'm really excited to be uh introducing uh patrick uh coughlin uh ceo of truestar who's gonna take us through uh you know what two stars doing how are they working with us what is setting themselves apart in the space so patrick take it away great deepak thank you very much we're we're super excited to be here and and talk about how we've teamed up to address some of the biggest challenges around intelligence integration and automation for our shared customers i'm i'm patrick as deepak said i'm the co-founder and ceo of truestar i'm going to give you all a quick overview of our platform of our principles that went into developing and continue to drive our innovation and looking at how those manifest in terms of use cases and outcomes for our customers and then i'm going to turn it over to the main event elvis hover vp of products here at truestar to go deeper on the integration and as as deepak said please we love questions so fire stuff into the to i believe there's a q a box in the uh in the actual zoom here and we'll leave plenty of time for questions at the end so truestar's been in the market for for over five years and we work with global companies across multiple industries every industry vertical we work with managed security providers we work with isacs and isaos or communities of companies that have come together to use truestar to integrate and automate intelligence into every stage of their incident response process our product is an intelligence management platform whose mission is to transform intelligence to make it actionable for automation we abide by a few first principles here at truestar and i think the one that's probably most important for the conversation today is the idea of being api first when we build product here at truestar we build for our ecosystem of integration partners like servicenow and that means we often speak more in things like api contracts than we do in terms of you know user interfaces and colors of buttons and that's really important because the majority of our users customers and shared community members here with servicenow they experience the value of intelligence through the platforms where they are already living and the outcomes that they experience as deepak said is acceleration and core operational metrics like reducing mean time to detection and reducing mean time to resolution taking a step back the the challenges with threat intelligence are are certainly known by many folks on the call here today uh intelligence is supposed to be the oxygen for automation but if it's not properly normalized and operationalized it can become the primary barrier on the road towards your automation goals for your security program and where truestar fits into this is to help be the normalization engine that brings to bear the value that is trapped inside of your internal and your external intelligence sources your subscriptions your open source intelligence feeds uh your isac and isil relationships unlock the value in that so that you can really drive outcomes in terms of automation and for us here everything has to roll up to a use case and you'll you'll hear a little bit more about this from elvis here in a couple of minutes but uh you know at the end of the day we we have an ecosystem driven platform where we integrate with these intelligent sources um we normalize them we drive the value into what we call applications but these are the core tools for detection and response obviously servicenow being such a critical partner for us um and and and then ultimately affecting the outcomes uh and and those outcomes really are measured in terms of efficiency and effectiveness uh the purpose of intelligence and enterprise security is to accelerate automation and security operations that is the primary purpose and and true star keeps that front and center for each of our customers three core differentiators i'm going to unpack here in the next couple of slides the first one being you know i'm unpacking these because you're going to hear from elvis uh about these in the next part of the presentation the first one being enclaves uh these these are the core foundational elements of the truestar platform this is how enterprises and communities are managing cyber intelligence in the cloud they manage not just their external sources the intel subscriptions and communities that they belong to but they also manage their own local historical events and kisses cases and tickets and alerts and suspicious emails that may have come into the sock those are stored in enclaves on truestar and are referenced for future enrichment all too often we see redundant investigations uh because you know there was a signature or a signal that sat trapped inside of a sim system or was closed in a case on the night shift but using enclaves to to to manage your internal intelligence helps bring those to bear on future investigations as well workflows for us this is all about how we provide normalized scores normalized context to the analyst in the tools where they live and these this kind of normalization is what is really helping our customers get orchestration and automation off the shelf because you manage that normalization upstream in a platform like truestar and all the sudden the orchestration tools that you have and primarily you know servicenow and the sir module tapping into the orchestration and automation capabilities becomes that much easier and finally as i said before uh ecosystem is front and center for truestar we build for the partners that occupy our ecosystem and that are the core building blocks of our customers security operations stack everything's built here on what we call a unified intelligence api uh and what you'll see flexed here by elvis in the integration with servicenow is is part and parcel to that so our customers uh you know when we look at customers with truestar uh we look at technical fit or how they align with the sources and the tools uh that that are in our ecosystem today um and you know a couple examples of that you know log me in being being a fantastic reference customer uh who also is a servicenow customer and really getting value out of the integration between truestar and and servicenow to accelerate both uh enrichment and response in in sir but also bringing indicators back into splunk for hunting uh using the truestar platform as the automated way to to connect the dots just a little bit of a deeper dive on what log man looks like when you pop open the hood and you look at the ecosystem of sources that they are operationalizing from from open sources from isac data for premium intelligence feeds and government subscriptions uh and then ultimately the core tools that make up their detection and response stack in service now being the system of record for case management uh and truestar helping to both operationalize the external sources and also the internal sources the historical data that makes makes it possible to to reduce any reinvestigation time wasted reinvestigating cases that have already been seen across the security operations team with that i'm going to hand it over to elvis again who's our vp of products and and is going to take you through a deeper dive on the integration over to you elvis the main event thank you patrick i'm excited to be here two stars integration with servicenow focuses on two use cases like patrick said these two use cases are core to the two star platform we enable analysts investigate their sir incidents and also seamlessly and securely share data and iocs between tools teams and other trusted partners in the demo i will show you how the truestar integration enables the enrichment of sirs and observables with normalized intelligence data and scores from truestar i'll also highlight the industry leading configurability that we have built into this integration allowing users to customize the experience using the true star service noun integration before i dive into the servicenow ui to walk you through that true star integration um let me list out a few system requirements and and you know links to get started on using this integration as prerequisites servicenow integration the new version v2 works with paris and quebec you also need to have these plugins installed to be able to use it you need the security incident response plugin and the thread intelligence plugin downloading and using the truestar v2 app is as simple as visiting the servicenow store and downloading our plugin or navigating to the applications funnel within servicenow looking for true star and installing that the configuration is where the change starts right the configuration is where the fun stuff begins um you know two stars capability when you look at the configuration here of course we've set it up in a way that um you know the defaults allow you to be able to auto submit um your incident into truestar but this is configurable if you're submitting your um sir events into true star this enables you you know return or get enrichment a lot quicker and i'm going to talk about how that works you know very soon you can also share indicators or sir reports with other trusted partners this data that you submit goes into your enterprise enclave but you can have other enclaves that you can use for sharing purposes and sharing can be between different teams or trusted partners or your isaac isles now let me walk through um you know the day in the life of an analyst imagine you wake up in the morning you get your coffee get to your desk ready to work on um an incident that has been assigned to you right the incident details have been put in there either in the short description or the description or maybe the indicators have even been put into the ioc table um the first thing that an analyst will want to do which was quick will be to quickly triage or eyeball triage this incident to see the criticality or the importance or the priority that he needs to be able to put on there if you've enabled the truestar integration and you have enabled the automated submission of events into truestar what you would get is a high level um you know enrichment within your work notes what does this do for the analyst it really quickly lets the analyst know based on the indicators that are in here and the intel sources that i have within truestar my open source feeds or my premium intelligence feeds i can quickly eyeball this and say that this the indicators within this have high priority uh you know indicators that i should be able to focus on what truestar does here is we take sources and the scores that are coming from multiple sources that you've subscribed to and we normalize those scores into a true star normalized score of one to three so you can very quickly when you look at this determine that the indicator um this specific indicator which is an md5 hash um you know has data that's coming from crowdstrike intelligence and data that's coming from ibm x-force both of these sources claim that it's a high which is their own pass-through score truestar normalizes that score into a simple three for you to be able to look so you can very quickly look at this and get a sense of what that you know incident that you're about to investigate should be prioritized as let's dive a little deeper into why the score matters and how we are bringing the context from your intel sources into your servicenow ticket like i said the data is all moved into the observables table so if you look here these are the indicators that were submitted the user can choose to put all their observables within this observable table star will true style would allow you to be able to enrich these observables by running the enriched observables action when you run the enrich observables action what is going to happen is that your threat goes down here your thread lookup results will be updated let's dive a little deeper into the third lookup results truestar here now is telling you the findings on this on the indicators that you submitted within this sir incident we are telling you that two of these are malicious and we give you the context as to why it's malicious i'm going to dive in a little deeper and talk about some of the context that we are bringing back or it would tell you that you know it's unknown there's no real score that's coming from your intel sources to be able to um help you triage this but one thing that is important here is that we give you things like tags that would you would have submitted or you would have attached this indicator um you know from historical intel and we still tell you um that context here let me dive a little deeper into some of the details that we are pulling back so if you look in the thread lookup result details we list out the reason why we are changing this finding or we are signing this finding of malicious if you look in here crowdstrike falcon intelligence gave it a malicious score of high and this is crowdstrike's pass-through score they also we are also pulling out of the crowdstrike report things like attributes like you know actors malware families etc right and we are taking that and assigning a severity level to it this is two stars normalized score that is being assigned to it but it wasn't only true star which was the intel sources that you have access to that had data on it ibm xforce was another one that had some data on it truestar is taking this and giving you the summary of those reports from ibm x-force ibm x-force is also telling you that it's part of a malware family and the malware family is clop um and the severity level that they are assigning to it um is you know is n a so malware ibm x4 does not assign any severity level to it so it doesn't show up for you to be able to see but then you get a high level severity level that tells you that you know true star essentially uh you know is looking at all these individual scores that have been assigned and it's assigning it to um you know that indicator in servicenow for you this is nowhere it ends right true star we take the data the indicators submit them into true style we give you that context and the scores and all this context and scores are summaries of reports that we have from your intel sources within truestar we keep or we preserve a link to the full context for the analyst to be able to view so if the analyst wants to dig in and see more details they can click this right here this url link and it will send them into that report inside of true star as you can see the report would have all the details about those indicators in here and you can go in and read the full report that came from servicenow so these are the descriptions that was written in this is the short description and of course this is all configurable um through the configuration page and setup page for the integration another core use case for us is the ability for you to be able to submit this report um you know into an enclave of your choice or share reports with your isaac's trusted partners or you know any users within your organization that you choose to start gives you the ability to be able to share this report redacted or not so if you wanted to share a report in this case you know you wanted to share this report with trusted partners but you want to take out things like the affected partners and the company name you can go ahead and put the list of affected users in in true star as reduction terms and anytime truestar sees that report with those names in it's going to redact is going to redact those names out in this case i've added all these affected users in and i've added the company which is acme company into the redaction list if i share this out into true star i'm going to get a link back that sent me to that report into my shared enclave i created an enclave specifically to be able to share with my partners and called it the share enclave second if i jump into the share enclave in true store this is what i get i get to see the report which has been redacted like i said the organization acme has been redacted when you look at the full report you also notice that the names of all the affected users have been redacted from that this is not your only option you can also decide to share only the indicators that you want to share this is as simple as selecting those indicators and then sharing them into truestar you can do a little bit more with these indicators before you submit an indicator you can decide to tag this indicator and then use the tag that you've associated for it um you know within later investigations that you're going to do or share that as part of the tag that you're trying to send to your trusted group all right um you know just to wrap it all up like i said truestar's main core or two stars core use cases for the servicenow app is to help the analyst very quickly investigate sir events by bringing in enrichment from their intel sources and it can be your premium intel feeds or your open source feeds the other one is to be able to help them disseminate this information securely across their trusted partners um you know any other teams and the sharing groups or ice and ice house and we do we give you the ability to be able to do this by redacting the report before sharing or sharing just atomic iocs all right um this is a quick demo i'll just pass it on to deepak if you have any questions or anything else to add awesome that was uh that was slick uh elvis uh thank you for that and and uh threat intel sharing right you know that is that works both ways right you know so you share so that others become immune but you also receive malicious indicators back and become more resilient and defensible or create a more resilient and defensible environment so so i believe there is also the ability to download uh malicious indicators in bulk is that true uh elvis yes you can um you can download these indicators that you're sharing with your private trusted partners or indicators that they also have shared into an enclave directly into servicenow and you can do that you know either using the two-star app or using the servicenow taxi client all right okay so like the servicenow platform is always uh build your own venture so we have more than one way uh to do things so yeah the built-in taxi client is a great way um as well as the truestar app and and the best part is ask that information comes down you can employ workflows on the servicenow side uh to to kind of you know go to work with it right you know so based on a risk or or the severity level you could choose to go take some of those and maybe push it to a watch list in your sim or maybe even block them or sink hold them in your gateways so so there are those capabilities as well um uh that could be lit up so so great uh so so what's on what's in store for the future uh elvis so what are you looking at next you know yeah you have it here so take us through it yeah definitely um so we're looking at making this even more industry-leading um you know we are showing you right now within you know your sir events things like you know the context and normalized scores from your intel sources we want to go beyond that and start affecting the priority of the whole ticket by assigning you know um you know scores based on your intel sources um to the full sir event right the full event and have that affect the priority of of your um you know of your sir cases another thing that we're going to focus on is you know the mitre attack framework within servicenow we've built capability right now to be able to extract these minor attack stages from the intel sources for you know specific iocs um we are looking at building this more um you know or building an integration to work more with the servicenow framework so that any minor attack faces for indicators will be reflected within servicenow also but overall we're looking at building you know deeper uh you know deeper integration into the servicenow so our capabilities awesome yeah we are really excited for this and uh we are never done with an integration um you know as they say right you know you know we release it and we constantly you know refine it advance it um and support uh more and more use cases like uh what we are doing with uh truestar so that's a good segue into uh q a and i'm sure one of the top questions in people's minds is hey you know where do i go ahead and uh you know grab this particular integration so i'm sharing my screen here to show you know how you could go to the servicenow store look at the the next version of the the truestar app and you can uh you know read up all the details uh around pretty much the features that elvis did a demo on so uh so i wanted to preempt this and just show you it this is where you can go grab this latest integration let me look at the the q a window to see if there are other questions looks like there is one in elvis or patrick you can take this would the normalized score take into account business context hey i can jump in here if you want uh just to just mix it up uh so the the short answer is that the normalized score is normalized across your external sources so one of the biggest challenges as it relates to automation is that all of these different external sources have different as elvis explained have different scoring constructs and that makes downstream automation that makes things like human analyst eyeball triage really really difficult when you have to compare apples to oranges instead of apples to apples and so what truestar does is we take those scores no matter how they are framed whether it's high medium low or zero to a hundred or or zero to ten and we normalize that to a single severity construct that can be easily compared apples to apples what it doesn't do what it doesn't take into account is anything anything that's going on you know internally for the enterprise that's that's not the mission the mission is to normalize the external sources so that you can really harvest the value from them faster and better and more efficiently um there's one other thing i just wanted to add and it doesn't it doesn't have to do with this particular question but but deepak you and elvis talking about intel sharing and i think i think there's there's so many use cases that we're already starting to see here that go even beyond the isac um which is which is so important to us and and i know is important to you all in the different isac communities that we support and that our customers are engaged in but but the sharing capability we're seeing it even at the enterprise level where where you know the different security teams are starting to converge together and all of a sudden the indicators or signatures or the opinions that are being found in these different teams are helpful to each other great examples are between fraud and security operations we see so much fraud that is cyber enabled now um ips and emails are so critical to to cyber enabled fraud and they have really helpful uh um impact on security operations and vice versa so using this sharing capability doesn't necessarily have to mean that it is you know from one company to many in in an isac it can also be you know intra company sharing too uh that we have use cases and then similarly managed security providers a lot of managed security providers are all in on servicenow capability we know that you know that and they use truestar to help facilitate the exchange of indicators uh with their broader customer base you know passing passing indicators over the wire so to speak but using enclaves so that they can more easily be connected into downstream tools of their customers no matter what they that may be and also taking data back and bringing that into the to the sirs so there's a number of different use cases here that that we're seeing in intelligence sharing um that go beyond just the kind of one-to-many isac model as well yeah yeah absolutely and and then you know operationalizing on that uh threat intelligence right you know so obviously you you want to take the humans out of the loop uh when you share basic uh tactical threat intelligence uh by automating uh you know what how you want to handle it and then there is a strategic aspect to it uh you know which is important what you touched upon is uh i think the goal is to really force the adversaries to change most if not all of their uh you know tactics uh and infrastructure and make it like collectively make it harder for them to uh to succeed that's right i mean like you like you said you know i think maybe it was in a previous call but you know immunity by community or whatever the phrase is now that that's what we're seeing and so many of these isac leaders are trying to move the ball towards automated sharing bi-directionally because that's the only way we're going to keep up with the bad guys right right right one other question i get uh when it comes to sharing and and maybe uh pertinent to the concept of enclaves is um is data kept private within an enclave or can you just reserve an enclave just for that particular customer's instance and how do you then open it up for sharing with others what about data coming from third-party sources you know how are they stored in enclave uh can you give give us a little bit more color on that great question elvis you want to take that one yes certainly um i'll start and then you can pile on um so you know like patrick explained in the slides right um enclaves is essentially the cornerstone of data governance for truestar all the data that comes into true star b at your open source feeds your closed source feeds it's stored in enclaves and it's stored in enclaves specifically for us so we can wrap around the you know the user protections and you know role-based access controls that we want for that very specific data so within your own organization you can have intel feeds or your own uh you know um your own data that you only want to keep within certain teams but not share them fully across but you want to see when there's a correlation across both of that both both sources of data this is a good way of being able to achieve that so to answer your question yes um you know the data that you submit um for your internal team would go into your enterprise enclave and that enterprise enclave will be credentialed in a way that only your enterprise users get to see it um you can also share data be it tactical intel or atomic iocs into a different enclave which is going to be for trusted partners and the trusted partners that are credentialed to that enclave will be the only ones that get to see it so all of this is built and kind of you know modeled into our process of enclaves yeah great you know this too deepak enterprises demand data sovereignty yeah and and the enclave is the vehicle that we give them to manage that and also balance automation and programmatic integration and so uh whether that's keeping the enclave private um keeping that enclave private to a single user or to a team or to a particular tool that is all driven by the enterprise by the admin user at the enterprise and and similarly creating more shared enclaves maybe go beyond uh the four walls of your corporation so to speak and include customers or peers and partners uh supply chain members um all of that is is that power is put into the hands of the enterprise user yeah yeah absolutely and in in addition they also demand governance so that uh they can control what gets shared when who's gonna improve uh you know the sharing uh is there a threshold that needs to be set uh so that you know you're not like bogged down by governance for every sharing you only do it where it's material enough and that's where i think uh the power of the servicenow platform uh also comes into play is we would handle the governance around the whole sharing uh you know process uh you could send approvals um you know in and and even if there are like change requests that you'll need to tackle uh from the sharing that you would receive that you want to kind of you know defend in your environment uh either in a deny list uh you know by putting it into some kind of a sinkholding mechanism you'd be able to kind of you know still do that um you know adhering to governance process so so that's perfect right you know the governance on one side and sovereignty on the other side so coming together uh through these um through these solutions uh and and i'm also excited about uh the uh elvis when you mentioned um uh you know more mitre attack use cases right now we are really seeing mitre attack resonate uh you know quite a lot uh within the service now customer base we just did a release recent release of uh uh uh the mitre attack capabilities not just kind of arming the defend the analysts with more information about attacker behavior but the entire organization also to come together and and stare at a heat map to look at all of the different tactics and techniques coming at them through incidents and then enriched by intelligence coming from providers like true star is so so crucial for that picture actually so so so we are really excited uh that you are furthering that uh you know those capabilities as well uh through your uh through your roadmap yes certainly yeah just to add quickly to that um you know we you know we i think like i showed earlier um part of the data that we pull in terms of summaries from our intel sources and you know your historical intelligence is you know the ability for us to be able to pull things or attributes like matter attack stages right or the tactics that are being used so this is data that exists within true star and and some of our users find value to it some some actually assign their own attack stages these are important things that our customers are already doing and the fact that it can be more useful and amplified for the full organization within service now it just makes it really more exciting for us to be able to integrate on that level um because we are going to take things that are supposed to be just at you know your intelligence level and bring it all the way through to your from your you know intel level all the way through to your tickets to the organization um to get a better view of what's happening um you know within the organization so to me that's just exciting yeah yeah absolutely i think um yeah no no single player um can can really um you know work on this i think it will have to be a joint uh fraternity effort uh to really help our customers there so so i'm really excited for what we are doing uh and what we are said to do jointly there um so so for time to wrap up uh quickly i just wanted to remind you again about the survey um so we're going to be showing up the survey but the survey is also available in the chat window you can always return to our community to ask questions and you can subscribe to our different forums in the community uh to be up to date on on how we work with with partners like true star um and and if you're interested in talking to us um one on one uh you know please use the survey to express intent there and we would be happy to uh to talk to you and and help you succeed uh with the use cases that uh was just shared so with that i would like to say uh thank you to all our attendees and thank you to uh to truestar uh it was awesome to have you guys take us through what you do and then the demo was like attention grabbing so we're really really looking forward to doing more so thank you deepak and it's always a pleasure working with you and the team so thanks for helping put this together and again excited to do more in the future

View original source

https://www.youtube.com/watch?v=fb_7q-DdwJc