How to use dynamic threat information from Recorded Future in your SecOps workflows
we'll go ahead and get started and let everyone catch up as they as they come aboard uh welcome so um my name is Aaron Bennett I'm a senior manager and Tech alliances here at servicenow it's my great pleasure to introduce Chris Coburn from recorded future he's a senior architect and is going to talk about the service now Integrations from recorded future today and how recorded future helps automate Security workflows in service now which is one of the I it is it is one of the Premier Integrations um provided by our partners for our security modules and recorded future is one of our Premier Partners in security so it's uh it's it's super great to have Chris here today uh Chris if you want to add anything or if you want to get started um thanks for thanks for presenting yeah thanks so much for the great introduction there Aaron yeah so same as we try to be a great partner for servicenow servicenow's always been a great partner for recorded future and uh really excited to show you kind of what recorded feature is all about and talk a little bit about how you know our threat intelligence can help you know really uh uh improve your workflows across different security operations and you know focused on the tooling that that service now provides um I'll be uh watching the questions today sorry to interrupt if you watch any questions today so if there's any um anyone who wants a little clarification about what recorded feature does how everything works or you know questions when we get to the integration demo um you know just raise hand put it in the chat and I will fold it into the presentation with Chris um yeah you gotta pause me because I'll talk a mile a minute if you don't if you don't slow me down so um you know this is the the first slide that every security company in the world kind of puts out there but it you know it still needs to be said and you guys are probably pretty aware of this as as people that work in the security industry but you know the landscape is changing and it's it's changing how we have to you know look at cyber security from an Enterprise perspective right you know geopolitical geopolitics are impacting our cyber world right now with the Russia Ukraine crisis and cyber warfare that's impacting how our Enterprises can do business you know we have evolving technology that you know talking about Ai and all of these things that we have to you know kind of continue to invest in digital transformation and we all know the digital transformation comes with its risks especially in the cyber world right we've been hearing about the talent Gap since I don't know since I started in cyber you know 10 or so years ago and we are still going to continue hearing about the talent Gap you know no amount of us complaining about the talent Gap has gotten enough kids in school to be cyber analysts so we're going to continue to have it so we need tools to help the people who are there you know get their jobs done right we've got a lot of pressure we've got regulatory pressure right the the regulations and and laws around cyber are not getting any easier they're getting harder right and so you know CEOs and csos right are not only concerned about you know protecting themselves about a Cyber attack but they have to worry about the legality of all of that as well and then the other piece of it which we'll talk a little bit here is the supply chain right like I can do everything in my power to protect my own company but then I can get absolutely crushed because one of the you know products I use or one of the vendors that I use introduces a cyber risk to me that I have no control over right so what's what are we doing now and why is it you know why is it not perfect right why are we not is as safe as we possibly could be from a cyber perspective right we've got a narrow threader or risk we we prefer to talk about risk we've got a narrow risk aperture right so we're focused on internal things we're focused on the firewall we're focused on the end point we're focused on this this and this rather than understanding the external view of adversaries and threats right we're very reactive right uh you know someone installed a piece of Steeler malware on our on a laptop I better go reformat that machine instead of thinking like well how did that Steeler malware get in into place like don't just react to the things coming in try to be all like you know try to have an insightful look at what's going on in your environment limited automation right service now lives in this game we don't have enough people we need to automate right this cannot be a people process thing all the time we need to to to help the people uh and help the process right lack of actionable actionability right like this idea that like hey this is risky but what does that mean right uh how do how do I handle this risk like what do I do with this risk right and obviously lack of business alignment right like in in too many companies the Cyber team is just the the people that say no to things and and the people that get in the way of business you know I I've I've certainly felt that way about our our uh cyber security team recorded future right that's not the way we get we we we need to do business right we need to have the alignment between the I.T teams between the the security teams between the business teams between the analyst teams between the marketing teams right we need to get all of these these these goals aligned in these and and this is this context this context of what's going on in the world a line so that we can be aligned and actually you know solve the problems and not just getting each other's way well how does recorded feature do that so if you're unaware recorded future is the largest commercially available um source of threat intelligence in the world of cyber threat intelligence in the world and you know I like to describe this of like you know there's different kinds of threat intelligence you know everybody has sort of their preconceived notions of threat intelligence there's sort of the endpoint driven threat intelligence that you see some from some vendors where you know that vendor may have billions of endpoints and they collect data across those endpoints and they provide that data uh to their customers or to to people who buy their service I mean and that's an interesting valuable source of information there's obviously open source information right these are security researchers or research companies that are taking you know the the the the the research they're doing and making it available open source which is you know valuable but has its own little niche there's sort of Boutique intelligence right so I think there's there's some people to think about that as threat intelligence right like you've got a team of very Advanced analysts creating finished intelligence for specific subsets or sub use cases in the cyber world right like they're focused on Russian cyber underground or whatever and they create intelligence and then there's the way we do it and the way we do it is we try to collect as much of the internet as we possibly can so it's about a million technical sources that we're collecting every second of every day and when I say a million sources this crosses open web right so we're collecting from security blogs and GitHub and social media and news sites and not anything you can imagine on the open web the the Deep Web right things that may be behind uh Forum access or or maybe special access or maybe you know lesser known areas of of the of the internet and then of course of the dark web right what's going on in the Tor infrastructure so we try to get access and we maintain personas across the dark web so we can see what the threat actors and all of the people that you know Converse on the dark web from a cyber perspective are talking about we collect all of this across any language we do full deep language learning across 14 languages we apply entity relationship mapping and ontology analysis and that's what creates this giant Corpus of data and I and and for the data Geeks here that may be listening like it's hard to describe how uh massive our data set is uh to be honest it's hard for us to even track it's larger than the Google search index now that's how big it is and it's just just massive massive amounts of data and so what we do is we take this massive thing of data and we split it into use cases that are our customers need right whether that be you know security operations use cases around indicators of compromise whether that be third party and supply chain risk customers looking to understand you know are the vendors I'm working with risky you know vulnerability intelligence for vulnerability teams trying to understand what they're doing you know geopolitical identity you know we have tons and tons brand intelligence tons and tons of different ways to use this fast a knowledge graph of data um to help you with your cyber concerns and your cyber your cyber workflows we also take that data and push it into Integrations and this is sort of our kind of main topic of conversation here servicenow is a great example of a place where we can take our data and make the tools that you're already using better right yes we have a portal to access the data I'm not even going to show you a screenshot of that today but in my view if you never go to our portal but you get all of the value of our intelligence across the tools you use every day that's more valuable to me than someone that just goes to the portal right we need to get you the intelligence that you need in the tools that you're that you're using and that's a big focus at recorded future and you can see that by our vast vast library of Integrations so when I talk about these Integrations what am I talking about well you can see there's a few servicenow ones here so I'm talking soar tools right I'm talking Sims I'm talking vulnerability management platforms identity and access tools tips edrs ndrs xdrs qdrs whatever Dr I'm sure you know RSA next week I'm sure we'll see some new DRS you know the idea is there are a lot of places for this intelligence to exist so we built reported future with Integrations in mind we have a robust set of apis and we really focus on building the best Integrations we possibly can with the with the tools that that uh that your you know customers are using um as you can see servicenow is is very well represented here they're a big Focus partner of ours and so anytime service now comes out with some new interesting thing that we can integrate with we usually try to figure out how to get it in so the three Integrations I want to talk to you about today really are fit both within the security operations Work World of of servicenow but also the vendor risk management now I think that's a super underutilized uh uh area of cyber understanding your supply chain risk and while you know I don't think a servicenow kind of considers this a security operations type of module it can absolutely be impactful to your to your uh um security operations so here are the three Integrations so for servicenow what sir a security incident response what are we doing well first off recorded future generates alerts especially if you have one of our modules called brand intelligence which focus focuses on things like credential leakage monitoring brand mentioned on the dark web typo squat domain detection uh executive impersonation on social media that types of thing you know we generate alerts for all of those types of things but again our platform is not the greatest place to interact with alerts right you want to interact with those alerts in the place you want to interact with alerts which is servicenow right and so we bring in those alerts with all of the context and all of the capabilities right in the service now so you can manage them as part of your overall you know incident response life cycle the big you know one of the most valuable things that we can provide in security incident response is indicator of compromise enrichment right so if you have an IP domain hash or URL and I'm going to show you this you know what is it is it risky why is it risky if it is risky what is it you know uh uh what is it Associated to like what minor taxi codes threat actors Etc and so the idea there is is very much like giving the incident responder all of the information they could possibly need to make a decision as quickly as possible before they even open the incident right they don't even have to open the incident and it's already there ready to go they don't have to go search they don't have to go Google they don't have to go do anything it's the data is there they can make a decision and then the last thing is we we also bring in large lists of indicators into servicenow so that you can use those as part of workflows right so if you want to take those large list of indicators and push it to another tool or maintain it in service now as kind of intelligence architecture um that is available too so where it's not just about single indicators we can do kind of larger lists of of our known indicators as well the other integration I'm going to talk about today is is vendor uh is a vulnerability response so recorded future is has a big focus on vulnerabilities um we're a very outside in perspective of vulnerability so everybody understands CVSs so the the you know the the what comes out of the nvd um CVSs score is very much like how bad is this vulnerability to this specific host and that's extremely valuable and we're not trying to take away from that what our scoring is more about is like How likely is this supposed to be attacked so you know is it has it been exploited in the Wild by active malware is there proof of concept code available on GitHub you know are they talking about it on the dark web those type of information so that you can Implement our scoring plus CVSs scoring in in my opinion the best way to do this is in servicenow with their risk calculators right you can now take record a future and use that data as a data point to really make a decision on how you should prioritize vulnerabilities for patching you know we'd all love to patch every possible vulnerability but I mean at the rate that uh our software developers in the world create vulnerabilities I don't think it'll ever be possible right so if we can help um you know if we can help you you prioritize and really make a good decision in terms of which vulnerabilities to patch we think we can save you a tremendous amount of time and make you a more secure Enterprise and then the last one is vendor risk management so I've talked about this right like you know you need to be aware of the Cyber risk of your third parties right and so we track because we're doing a lot of those use cases and brand in terms of typos what domain detection and breach monitoring and brand mentioning on the dark web and credential leakage and all of those things we can kind of track what's going on with vendors right so are you working with vendors that are introducing risk to your to your uh business right and so let's go into a little bit more detail at how this works so for security incident response the first thing that happens is like as an incident gets created you all know that like indicators get pulled into that incident so that incident might be coming from a SIM like curator or Splunk might be coming in from uh EDR tool like setting a one and so once that alert or that incident is created and those uh indicators are are uh parsed out we immediately look up those indicators within recorded future and provide all of that information in that context right within servicenow the other piece of it is is it constantly re-looks up those indicators for a short period of time to make sure that hey like you know the first time you know that incident was created maybe recorded future didn't quite know about it yet but you know 10 15 minutes or maybe an hour maybe five hours later recording future have got some evidence to show that hey that hash is actually malicious or hey that IP address is part of some C2 infrastructure right and so we kind of maintain this like up-to-date level of hey this is what this indicator is all about and here's what you need to do right and we push that right into the incident versus the incident response ticket so that you can make a decision right away of what's going on CE we've done that we also push that data into the threat intelligence framework of of servicenow so that you'll have it there in if you you know the next time you see that indicator you'll have that data and that information that from that previous incident the next thing we have is is our alerts right so we're bringing in the alerts into a servicenow so whether that be dark web threats or typo squat domains I think I'm going to show you a typo Squad domain detection for example um but we're bringing in those alerts into Securities from response we're allowing you to kind of manage those alerts close them work on them do whatever you need to do within servicenow and all of that gets pushed back to reported future as well so you don't have a bunch of alerts just sitting there um and the last thing is you know we do load some of these large data sets into um like Define feeds and so those feeds are available to you in whatever workflow capacity you want to use them so for uh and this is just a little bit more talking about that so for servicenow VR same thing right you have a vulnerability that vulnerability came from a scanning tool it has a cve recorded feature will look up that TV and tell you what we know from the external context that information gets pushed into the vulnerability itself so that you can read it and make a decision but also it's scoring the the risk score and I'll talk about the risk score a little bit the risk score is is added to risk calculators so that it helps prioritize the scoring so that if you go into your servicenow vulnerability response and you sort by risk for recorded future can impact that score right and so that way it helps you make sure that you are you know properly prioritizing those vulnerabilities for patches uh and then obviously you know you can use the vulnerability response platform to either push uh incident or an itsm ticket to go get that thing patched so that's the servicenow side of the world and the last thing is is vendor risk management right so I create my list of vendors that I am working with within service now and we constantly update that uh in that vendor with whatever Risk rules and I'll talk about Risk rules a bit uh with whatever Risk rules and evidence we have around that vendor so you can make a decision like huh you know we've been working with company a but they've had some serious breaches or credential leakages or they're talking about uh they're being talked about on the dark web or uh maybe they have you know bad infrastructure built into their company environment um maybe I'll go with company b instead because they seem to have less risk associated to them right or from a security response team or a security operations team you know what vendors should I be aware of and what you know what tooling what products Services should I be most concerned about Aaron have any questions come in I know I'm I'm talking about my usual uh no this has been really smooth I I don't see anywhere to comment I think um one question was will we have these slides up and available after the uh the webinar today and the answer is yes um both the recording which will be also available in YouTube and the uh and the and the presenter deck will be uploaded to the listing on our community so you will see those and then I think um you know just to add a comment like you know what Chris talks about um how much you're able to impact your prioritization with a pretty future it's not just about the you know refining like the severity of those vulnerabilities but really you know changing the way that you look at severity because you can really reduce the number of high criticals when you look at it with a dynamic threat and and I think we're going to cover that in this uh in this example slide right here yeah sure yeah so here's the thing you know I I the one of the guys I work with that works with servicenow is a big fan of stories Jamie said make sure we include a story in this presentation so um can tell you what the company is because it didn't want to be named but they're in the financial technology Services they're they're a Fortune 500 company and they implemented servicenow um vulnerability risk integration with our vulnerability data and you know the the quote is pretty good right it dramatically improves so uh the the quote exactly was recorded features the preferred threat uh uh vulnerability intelligence provider and within their security operations team like they saw huge results right 76 reduced number of critical items right again like they had like 400 000 critical items right so this ability to kind of reduce that that number was so so valuable you know they got down to the Whole 30 days of to patch which is you know when we first talked to them they didn't think that was ever going to be possible for their environment but you know because they were able to prioritize the things that they really cared about they were able to get there and they said that it's like 15 hours saved by replacing manual monthly reporting with the dashboard um so you know we know that man hours are the or the the the true valuable thing within a security operations team right so any any you know any minute we can save you but certainly talking in hours is is super valuable yeah and if you look at that in terms of risk quantification and you've reduced that you know number of critical items by by that by that percentage then you can do so much more to reduce you know like if you look at quantification of risk can I reduce 50 of my Risk by patching you know like that small number of systems and so they look at risk and from that lens and they're able to really you know get to the important stuff first all the other stuff is going to get you know obviously we're going to get to it eventually but they're able to really reduce the most risk you know getting the most bang for their Buck out of out of this prioritization scheme yep yeah so I'll jump into a demo oh go ahead Aaron oh no let's hit the demo yeah sure yeah okay so let me get out of this slide deck here so like I said there's three different Integrations you can see in my demo system I kind of have them all stacked here um you know first integration I want to go over is Sir right so sir all about you know let's managing let's manage our incidents let's make a decision of what's going on and so there are two kind of different incidents I want to show you there's an incident created either by a Sim or an EDR or whatever you know whatever security tooling that you're feeding into sir and then there's an RF alert so from uh so if I look at this one for example so communication with a trickbot C2 server well what's going on here well uh a a an alert came in there was 4.45 megabytes transfer transferred from this IP on this port to this IP which is suspected trickbot on Port 443 and you can see all of the work that sir has done to make sure that this incident is enriched and ready to go and if you go all the way down to the bottom you can start to see the evidence here right and so there's a few different things we actually found like one you know from the data coming into servicenow we found a hash we found an indicator we found uh uh or and we found two IP addresses and if we dive into that indicator that you know external indicator the 36.91 IP we can see all of the evidence that reported future provides right and so you know we have some related entities so we've Associated this to banking Trojans to Trojan to trickbot we've you know we don't have any uh related entities but we have some risk evidence right so this IP address as per recorded feature so what these are are what we call Risk rules and Risk rules are how reported future quantifies risk for different indicator types so each indicator type whether that be an IP a hash a domain a URL a company a country whatever thing that we're trying to quantify risk on we have these set of Risk rules and they are basically the kind of categorizations of risk and they have different criticalities different impacts on that risk score I was talking about so our risk score is from 0 to 99 99 being extremely malicious and so the fact that recorded future knows this to be an actively communicating C2 server is very malicious that would immediately push the risk score to 95. it's also a current C2 server which means that we have Network traffic analysis that we're now analyzing and we still see that that IP address is acting like a C2 server it also has a few historical information so this is a key differentiator for reported future not only are we providing the context of what happened now but we provide the context of what happened in the past and and this changes how how an IP address or a hash or a domain um may be scored right an IP address could be being used by a threat actor um for you know for however long but you know once the threat actor realizes that most people understand that this is a malicious indicator and it's not working as much anymore because you know firewalls or EDR products or whatever uh are blocking it they're going to release that IP address and that IP address may become a benign IP address at some point you do want to have some of the historical context to that IP address but it's super valuable to to but it's it's important that you know eventually the risk score comes down so you don't get false positives and this is why generally the false positive rate for reporting Futures extremely low compared to other threat intelligence sources is because we understand that and we age our indicators over time every second of every day and so in this case we have a few historical things that was linked to an intrusion method it's historically uh a threat research so we have some threat research Associated to the IP address and it was historically reported as defang right and so we also have things like sightings and links and tons and tons of other um types of information that as an analyst you can go in there and read and figure out as much as you want um so that you can make a decision right like you could come in here and say huh well it's an actively communicating C2 server I know this is real I'm gonna go do something about it right away but if you're a level two or level three guy that wants to do a little bit more research you can and of course at any time you can come in here and go look at this at on recorded future right and so this brings you into recorded Futures portal and you get all of the information so interestingly enough that was an incident from 2021 and you can see that the IP address has aged out just like I mentioned you can see here we've just recently released our AI insights so we have a generative AI built on top of our data only our data and so you can get some information but you can see that it was historically absorbed as a source of Spin and it was historically uh Associated to Trojan emotec banking Trojan and trickbot right and so you can see that it's historically linked to those things but we haven't seen evidence since kind of 2021 about that indicator being malicious yeah that's a good point with uh you know any any threat analyst who's working in for a security analysts in service now is they can go and re-query and it will just be additive in the in the in the security instance you'll see you know when when this was more of a risk and when it's not and new incidents that come in we'll get that we'll get the immediate temporal score am I right Chris exactly yeah and and it gets refreshed for I think a week if I'm not mistaken I'd have to double check that but it does get keep getting refreshed just in case we find some new evidence while that incident is open yeah so you can disposition those security incidents as they come in and then I make sure they're assigned accordingly prioritize accordingly Etc so the the composite score affects like what you see there in that risk or column like how severe is the security incident and what you work on first exactly yeah and like and and as you can see this is my demo system so I have stepped back to 2021 2019 Etc um so the other thing I wanted to show you was what it looks like when you have recorded future alerts so here I have a reported future alert within uh servicenow and what it is is typo squat fishing detection right so um in fact what it is is like in My Demo system I have salesforce.com and say um as a domain of my company and so what recorded future is doing is finding typo squat domain um type alerts right so like they're finding typo people trying to type the squat your domain likely for phishing and it will show you like hey like do you own sales force.com no well that's pretty unusual they're probably trying to fish your customers with that email and then recorded future can help you do the takedown requests for that domain if that's something you want to do right and so this is a super important uh this is just one of the use cases in our brand intelligence module there are a lot of other use cases that can generate alerts but it just goes to show that if you know you don't have to interact with alerts within recorded future if you don't want to you can interact with them within servicenow incident response so another thing I wanted to show you was our vulnerability module right and so I talked about the risk calculators so the important thing here is that um you can make a decision on how important you believe the reported future risk score is right and so if you go and look at risk calculators there's lots of them and I think you know there's likely you have even more than what I have in my demo system right you can take into account CVSs scoring be whether that be version two or three you know whether something's in sisa you know all you know how important that asset is to you is it a crown jewel asset is it you know is it a contractor's asset right all of these different things that you can allow you know you can allow to affect the risk scoring of a vulnerability recorded future being one of them and I think that's the power that um servicenow brings you right because we have other we have other Integrations into vulnerability platforms but generally it just sort of shows our score and you can certainly index based on our score but that's sort of it you can't you can't merge you can't you know use your own business rules in your own business risk and your own point of view to risk to make a decision of how all of these things should come together right and that's incredibly valuable um part of servicenow so what does that look like well here I have a bunch of vulnerabilities um and you can see I have them listed by risk score I think I have far too many vulnerabilities I have like 13 000 pages of vulnerabilities in My Demo system um you know I don't patch a lot I just demo um but let's look at one of those vulnerabilities in specific so here's a vulnerability it's vulnerability 4404. um we can see here that you know it has a cve and it has all of the information that servicenow vulnerability response does like remediation steps and initial detection and all this kind of information in this case it's uh generate crfm request within Mozilla Firefox before it's Firefox 23 apparently recorded future will will present some information to you right and so the first thing we'll do is give you a score so in in this case you know the score and again you have the ability to go look up this vulnerability within reported future if you want to look at it that you want um we'll give you the threat score and you know again this is going to be that's going to impact that risk score calculator but the key thing here is we provide a ton of evidence right this uh this vulnerability is historically uh exported in the Wild by recently active malware it's you know nist has a very high severity for it it's been linked to historical cyber exploits it's been linked to penetration testing tools right and so you can make a decision like the fact that this vulnerability is being historic like has been historically explored in the wild is a good sign that you know maybe I should patch this one right and so again using our data as a as a data point to make a decision on how to prioritize your vulnerabilities can drastically impact the the quality of that prioritization and again good quick question sure um while we're here does recorded feature provide a risk quantification feature as well you need any um clarification on that yeah so what do you mean exactly by risk quantification so our risk quantification comes down to the cve itself we're very outside in threat intelligence company like we don't have an awareness of like what that asset is to you you know how accessible that asset is you know like this is where like the combination of us plus like I'm breaching attack simulation becomes interesting um I don't know if I answered your question there yeah maybe um you describe like if there's a a ranking by the vulnerability instead of it being like a roll-up or maybe that would help clarify so I think the most important or the most critical score right when you take that into account for the prioritization yeah so I mean that comes back to those risk calculators right and so coming in here and making a determination of how this impacts so like we've sort of cheated it here where we set the risk score based on um uh the the risk score of reported features simply for our demo system but the idea here is that like if the risk score was above a certain point you could add to the risk score and do all of this kind of things right so you have the capability to adjust that risk score within service now to make a decision of what things are more our higher prior uh priority My Demo system like has no understanding of the cmdb My My Demo system has no understanding of what other whatever other factors that you take into account when you're prioritizing all I really have is recorded future so that's what I'm using to do my prioritization but this is the power of servicenow is is being able to take all of those things into account at the same time yeah and I think it doesn't average those scores and I believe it takes the the most critical score as the factor if you're factoring it in with say business criticality and some other internet facing yes or no like rules and things like that so you you can build that out but I believe it pulls the most critical score because obviously that's the one you want to know about yeah yeah and I I think I think it's relatively customizable right you can you can make a decision of how impactful this is I've seen you know I've seen a customer that like just takes our score flat because they're doing their score on 100 as well but they give our score a higher um like uh percentage of the score like like you know we get point six percent you know 60 of the prioritization score is our score and then they just add the different scores together we've got a couple more questions coming in um so while we answer these questions I want to take advantage of the time right now oops is there no poll in here let me create this poll really quick so um we'd like to give you the opportunity to you know you know get get a follow-up afterwards so I'll launch this if you could please indicate whether or not you'd like to be contacted you know maybe you're interested in like getting a demo of the app or you know figuring out if you can install it or get some help um please yeah please indicate that and we'll we'll follow up with you um so one of the questions was in addition to risk scoring can we translate through business value um as a as a risk quantification and I think I think this would be more you know once you've had the VR you know the vulnerable items scored in servicenow that can translate over to if you have this linked uh to our um our risk our irm risk product and saying you know like we have um because like from the vulnerability analyst perspective I'm sure it's it's you know making sure that the service is not vulnerable making sure that you know we're not subject to an intrusion because this is like a critical system that has like Pi or you know is is you know part of our part of our finance accounting or something along those lines whereas you know calculating the business value is more of a function of our risk modules in service now and I think that would be the internal tie-in between the vulnerability and you know things that you have set up in GRC I don't know of course you have anything to add to that one yeah I know absolutely that's that's the power of service now right that's the the kind of context it will never have right but servicenow is kind of like the center of all that information and the power of service now is those interconnections yeah now another question do the rules roll up to a vulnerability type so you can create a trend or something along those lines so in terms of trends like uh again because of the way we pull in data so what I'll show you I'll actually bring up my reported future instance here and we'll show you a little bit of some of the trends that we do for vulnerability um so the idea here is that we don't look at vulnerability by type in terms of like you know what type of tools that they impact and so on and so forth we have an understanding of what type of Tool It's associated to through CPE IDs and things like that but what we're doing is looking very much at vulnerabilities as a vulnerability and looking at the trend in terms of mentions of it examples of it being exploited all of that kind of things so we do do Trend analysis on stuff like that and you can see some examples of this here right and so this is uh this is for the watch list let me do the global one um so this is a global look at vulnerabilities in terms of like new vulnerabilities Associated to malware new vulnerabilities you know exploit like being talked about right in the dark web being linked to pen test tools right so you can start to become aware of the kind of improving vulnerabilities or like are not improving the the vulnerabilities that are becoming more and more um risky and we also look at it again from a product perspective but again this is more looking at it in terms of a product as a Target less of like hey it seems like this product is getting more vulnerabilities like we don't do that sort of kind of analysis probably something you could do with this information from recorded future is create those custom reports and service now so record your features group these into categories and you can take a set of CBE he's like your most you know your critical most 50 cbes related to new exploits and you can create a report or if it's something really specific like you know one of those you know makes the headlines type of vulnerabilities that everybody talks about when they come around um you can create reports on the Fly for those and you can get your risk instantaneously you know you've already calculated it with the future integration and then you can report on that grouping of vulnerabilities and get that asset disposition from your you know from your environment using servicenow so that's like the sort of the power of these two tools working together yeah exactly like honestly you'd probably do that way better in service now that you can do it even from our platform so that's that's a great Point yeah I mean again you've got the data right in front of you here from the external view you've got your internal view It's the Best of Both Worlds you know exactly exactly we do have the ability to create Advanced queries right with our threat intelligence module so you can come in here and get very very specific in terms of hey when was this vulnerability Co mentioned alongside you know these type of Industry or these type of threat actors and so on and so forth and this type of you know product right you can get very very specific and start to build um sort of like you know you think like more analyst reports about what's going on so we certainly have the capability to do that um but that's not necessarily integrated like that advanced query Builders and integrated into service now at the moment I got a question around the enrichment I think it's more of an enrichment question is a does recorded future make recommendations or mitigating controls so that you know an analyst can make an informed decision on the vulnerabilities that are listed as critical so they get a recorded feature vulnerability what kind of information do they get that helps them decide how to remediate how to remediate we do not have a ton on that right now for a long time part of the history of our company we've been very much uh hey here's information do with it what you will um but we are working towards having that type of information in terms of like you know opening a vulnerability because you can see with our new and again this is brand new this was launched on Tuesday but if you like open one of these vulnerabilities or any other indicator type within reported future you see this recorded future AI insights and again this AI insights is a generated a generative kind of uh AI built on top of our data and so one of the things that we're going to start feeding that generative AI is information about remediation right and So eventually that is the idea would be that you could open up a vulnerability from recorded future we'll tell you how risky it is and why but we'll also tell you exactly what you should do about it in terms of patching to this version or putting this type of control in place like that is the goal at some point yeah and that'll be additive to the information that you get on solutions from the you know say the vulnerability scanner or even from the nvd correct yeah yeah again because because while we pull in nvd obviously but you know um you know we're we're we're independent so we try to pull data from wherever we can and and make it available you want to comment at all on the insect group um information that comes in with these uh while we're here absolutely uh the the it's a good point so obviously we create a bunch of data that that is both human readable in terms of hey this is exploit in the wild I recently acted malware we've seen activity 28 of the last 28 days 486 all-time sightings and the last thing we've observed was yesterday and here's a hash about it right that's pretty human readable but the fact that this thing is exported in the recent uh in the Wild by recently active malware is very uh machine readable too right and this is what makes it very powerful within service now is you can start to build uh workflows or graphs or whatever you need to make um based on these Risk rules right we also create a bunch of human readable intelligence by our insect group so our insect group is a team of over 80 researchers that spend all day every day researching different uh areas of cyber security and geopolitical security so they're looking at vulnerabilities at threat actors at malwarefamilies at to Target like companies being targeted at countries and what's going on in conflicts um and you can see the vast amount of information obviously this is one of the most popular vulnerabilities that have ever existed but you can see that we have like 23 different notes between tool profiles validated intelligence event a validated intelligence event is when we see an attacker using a a technique or procedure against a victim and we kind of state what what that that happened but we also have things like snort rules and other threat hunt packages so if you're someone that you know uses Sigma rules within your sim or uses Yara rules within your ADR we generate those as well every day for new types of of threats whether that be threat actors or malware families or vulnerabilities in this case yeah cool any other questions there no nothing right now in the queue okay to the demo yeah so the last thing I wanted to show you was some of our third party risk information right again I know this the this this uh presentation was very much focused on the security operations tools of servicenow in that kind of bubble of servicenow but at recorded future we think your third party risk is as important to the cyber security team um or at least it should be as important and so if you have um servicenow vendor risk management um eventually you get these lists of vendors that you work with and we can implement or we can implement the same scoring that we do for vulnerabilities for your vendors and so in this case I have it ranked kind of top to bottom and you know let's pick on uh Microsoft because it's easy to pick on Microsoft and you can see we have all kinds of information so we have a recently validated Cyber attack we have company website using unsupported technology versions company website with a higher high-risk vulnerability domains are overly permissive SPF I'm sure there's probably you know uh in infections recently reported as you can imagine Microsoft is one of the biggest companies in the world so therefore gets attacked and has a bunch of problems all the time in the world but this is a tremendous amount of information for a cyber team to understand what's going on in the vendors that they work with right and so while micro soft would be an example of a pretty noisy one you could be surprised at the information we can find about even smaller vendors in terms of like hey like they have a on a starting a a very high amount of leaked credentials or hey like this uh you know this small cloud or infrastructure provider has is hosting a lot of malicious infrastructure why is that right and so that type of information can help you a from a procurement perspective kind of make a decision is this a vendor I want to work with or B from a you know cyber risk posture management right is you know should I be concerned with this vendor should I put extra controls in price place while working with this vendor that type of information so again another data source that we can provide within uh servicenow and another data source we think that's uh or another intelligent Source we think is very valuable to um the cyber world and that's sort of everything I wanted to show were there any other questions before I jump back to the to the last slide I don't see anything yet all right so last slide and again this is more of of a call to action or what what do you want to do if you want to learn more I provided a link to the recorded future demo page so click there you know no pressure we can provide you a demo and answer any questions you have so this is both the ability to see a demo of our core platform and all of the modules again our modules are listed here if you wanted to see I you know I definitely talked about more about the ones that we work with within service now but obviously we have a few other modules that may be interesting to you so this recorded feature demo link is is gives you the ability to kind of get a demo of all of those modules and even our Integrations I provided links to our apps within the servicenow App Store feel free to go look at screenshots read the documentation um some really interesting stuff there we have a cve monthly page like if you're if you're part of a vulnerability team and you want to be aware of kind of what's going on in the vulnerability World um you know feel free to go to that page and here's an example of our March 2023 report to click on obviously you can find me on LinkedIn if you have any questions so I'm happy to to uh you know happy to have new connections and love to chat with you um and yeah and I hope you enjoyed this and if you have any questions you know please feel free to reach out yeah definitely so any um you have a distro email or anything that we should provide or just say uh like contact actually you know what we'll keep it simple I'll throw my email on here and so you'll have my email right away you can just reach out to me uh you know happy to answer any questions or get you pointed at the right person well thank you Chris um you know we will be just just so you know if you are traveling to RSA next week this is 2023 for those of you watching this in the future uh we'd love to um you know see in person there is an event a joint event that we're putting on together at RSA as well on Tuesday night uh so you know a chance to you know just follow up you know ask questions in a casual context and uh you know hopefully everybody enjoyed this and I you know want to thank Chris again for coming on and presenting and this this recording will be available for anyone who wants to you know if you if you'd be willing to share it we'd encourage you to do that re-watch learn more um always always happy to do that stuff so uh thank you all for for the extra attention today we'll give you 13 minutes back in your hour uh have a great rest of the week
https://www.youtube.com/watch?v=CvHXhFUzC_I