1
00:00:11,840 --> 00:00:13,960
Hello and welcome to the 
Decipher Podcast. 

2
00:00:13,960 --> 00:00:16,320
I'm Dennis Fisher. 
Joining me today is Todd 

3
00:00:16,320 --> 00:00:19,320
Beardsley from Run 0. 
Todd, how are you, man? 

4
00:00:19,360 --> 00:00:22,400
Good to see you, Ahoy. 
Ahoy, Dennis, I'm great. 

5
00:00:22,400 --> 00:00:24,080
How are you? 
I'm doing great. 

6
00:00:24,480 --> 00:00:28,720
It's really good to see you. 
We were just just chatting about

7
00:00:28,720 --> 00:00:33,200
like how long we were going to 
this episode might be And before

8
00:00:33,200 --> 00:00:35,720
we dive into the reason that 
you're here this this cool 

9
00:00:36,520 --> 00:00:41,240
chemology report that you put 
out you you mentioned that you 

10
00:00:41,240 --> 00:00:46,040
have a podcast in the episodes 
average 6 seconds, correct. 

11
00:00:46,520 --> 00:00:50,080
OK, so I need to know pretty 
much everything about this 

12
00:00:50,080 --> 00:00:51,040
podcast. 
Let me let. 

13
00:00:51,040 --> 00:00:53,400
Me have it. 
Well, I'm going to hit you with 

14
00:00:53,400 --> 00:00:56,560
a name. 
It's called War in Pieces and it

15
00:00:56,560 --> 00:01:00,000
is a sentence by sentence 
reading of War and Peace. 

16
00:01:00,960 --> 00:01:05,040
This is a project I kicked off 
just this year on January 1st of

17
00:01:05,080 --> 00:01:11,640
2026 and it is expected to take 
about 60 years to complete from 

18
00:01:12,120 --> 00:01:14,680
from now. 
So we're targeting May 10th, I 

19
00:01:14,680 --> 00:01:16,880
think 2085. 
Excellent. 

20
00:01:19,360 --> 00:01:23,920
To be done and it is what it 
says it's actually. 

21
00:01:23,920 --> 00:01:28,680
So it was a ridiculous idea that
struck me. 

22
00:01:28,680 --> 00:01:31,360
I have other podcasts I have 
like a horror podcast called 

23
00:01:31,360 --> 00:01:33,000
Podsoth, but don't worry about 
that. 

24
00:01:33,000 --> 00:01:38,360
Warren Pieces is the new hotness
and what I'm doing with it is 

25
00:01:38,360 --> 00:01:42,520
really I want to find out like 
how much can I automate the the 

26
00:01:42,560 --> 00:01:46,320
active podcasting, like end to 
end and I'm like reaching for 

27
00:01:46,320 --> 00:01:49,080
like fresh technologies to learn
and all that other stuff. 

28
00:01:49,400 --> 00:01:54,120
So I'm doing experiments with 
like OCR ING a an original text 

29
00:01:54,360 --> 00:01:59,000
to count sentences and I get 
errors when the LLM goes in 

30
00:01:59,000 --> 00:02:02,200
there. 
This is interesting, like 

31
00:02:02,640 --> 00:02:05,480
because I'm using something of 
an antique translation. 

32
00:02:05,840 --> 00:02:07,960
It's a Constance Garnett 
translation from 1930. 

33
00:02:08,320 --> 00:02:12,000
OK, it is all right. 
The way says it's the best 

34
00:02:12,000 --> 00:02:15,000
translation, so. 
I stand with Hemingway. 

35
00:02:15,000 --> 00:02:18,400
Let's go. 
But yeah, it is a ridiculous 

36
00:02:18,400 --> 00:02:21,680
experiment. 
You can subscribe today at war 

37
00:02:21,680 --> 00:02:25,640
in peak dot ES. 
So just war in pieces but a dot 

38
00:02:25,640 --> 00:02:27,600
before the ESI? 
Love it. 

39
00:02:28,640 --> 00:02:31,880
This is completely insane and I 
I love everything about it. 

40
00:02:32,360 --> 00:02:34,840
Yeah. 
Automation Git. 

41
00:02:35,160 --> 00:02:38,160
I'm like, I'm backing up 
everything I'm get I'm 

42
00:02:38,160 --> 00:02:42,000
publishing through my normal 
podcast host, but I want to get 

43
00:02:42,000 --> 00:02:45,440
to a point where I can like go 
up to someone in a bar and say, 

44
00:02:45,440 --> 00:02:47,200
please read this sentence out 
loud. 

45
00:02:47,200 --> 00:02:54,080
Go and then one click, record, 
snip clip, post to the podcast, 

46
00:02:54,080 --> 00:02:56,040
publish. 
Like that's that's my goal. 

47
00:02:56,120 --> 00:03:00,240
I don't know how to do it yet, 
but I've gotten a lot faster. 

48
00:03:01,040 --> 00:03:05,480
This is so great. 
There's I think like 98% of the 

49
00:03:05,480 --> 00:03:08,080
population. 
I started War and Peace, never 

50
00:03:08,080 --> 00:03:09,680
finished it. 
Nobody, you know. 

51
00:03:09,960 --> 00:03:12,600
No, lots of people finished. 
That it's, yeah, I'm sure 

52
00:03:12,600 --> 00:03:14,720
somebody. 
Greatest books in literature 

53
00:03:14,800 --> 00:03:19,320
like on Earth so. 
I know I've read a lot of books.

54
00:03:19,320 --> 00:03:22,160
With it, Dennis, you've never 
been reading it now. 

55
00:03:23,960 --> 00:03:29,440
It's even better. 
Oh my God this reminds me of 

56
00:03:29,440 --> 00:03:34,400
like there's this podcast called
One Heat Minute where these two 

57
00:03:34,400 --> 00:03:39,320
Australian guys do an episode on
one minute of the movie Heat 

58
00:03:39,560 --> 00:03:40,920
every. 
Which? 

59
00:03:40,920 --> 00:03:45,280
Is like a two hour and 30 minute
movie, 2 hour and 40 minute 

60
00:03:45,280 --> 00:03:48,360
movie. 
It it started like years ago, 

61
00:03:48,360 --> 00:03:51,280
like I'm pretty sure they 
finished, but they at some point

62
00:03:51,280 --> 00:03:53,640
got Michael Mann on there to 
talk about it. 

63
00:03:53,640 --> 00:03:56,280
And it was just these two dudes 
that were like, we love this 

64
00:03:56,280 --> 00:03:58,320
movie. 
Let's see how this works. 

65
00:03:58,560 --> 00:04:02,280
This was a fun genre. 
Like at the very start of like 

66
00:04:02,280 --> 00:04:05,440
the 20 tens, I want to say, 
Yeah, I want to say the first, 

67
00:04:05,680 --> 00:04:09,080
certainly in my opinion, the 
best in the genre is Star Wars 

68
00:04:09,080 --> 00:04:12,160
Minute, 2 minutes, 5 minute 
recap of Star Wars. 

69
00:04:12,200 --> 00:04:14,960
And it's really, and they do, 
they end up getting like people 

70
00:04:14,960 --> 00:04:18,120
who work on Star Wars, like tech
FX people and all that, just 

71
00:04:18,120 --> 00:04:20,480
like guesting in. 
And so those episodes tend to be

72
00:04:20,480 --> 00:04:25,040
like 20 or 30 minutes long. 
That's what these two guys did 

73
00:04:25,040 --> 00:04:26,000
too. 
Like their episodes? 

74
00:04:26,240 --> 00:04:32,160
Are like and. 
It's, I mean, I'd love somebody 

75
00:04:32,160 --> 00:04:34,080
that's that. 
Mine is more ridiculous. 

76
00:04:35,200 --> 00:04:36,640
I think yours is more 
ridiculous. 

77
00:04:36,640 --> 00:04:39,160
Yeah, I'm going to, I'm going to
go with you on that. 

78
00:04:40,320 --> 00:04:44,680
Like I, I am all for people that
are like fully obsessed with 

79
00:04:44,680 --> 00:04:48,640
something to that degree where 
they're just like, I love this 

80
00:04:48,640 --> 00:04:50,800
so much. 
I'm going to see if there's 

81
00:04:50,800 --> 00:04:55,600
other psychos out there like me 
that love it this much and see 

82
00:04:55,600 --> 00:04:58,280
if I can get them to subscribe. 
It's incredible. 

83
00:05:00,120 --> 00:05:00,840
I'd love it. 
What a. 

84
00:05:00,920 --> 00:05:01,520
What a. 
Journey. 

85
00:05:01,560 --> 00:05:05,920
This is on Pieces. 
We have a companion Patreon 

86
00:05:05,920 --> 00:05:09,320
podcast called Warren Pages. 
It's a page by page recap of 

87
00:05:09,320 --> 00:05:12,440
Warren Pieces. 
Wait, is this real? 

88
00:05:12,520 --> 00:05:13,080
Is that? 
Real. 

89
00:05:13,120 --> 00:05:19,720
It's real. 
This is the best. 

90
00:05:19,800 --> 00:05:22,520
I love it. 
Absolutely amazing. 

91
00:05:22,520 --> 00:05:26,080
We're we're already like 100 
times longer than your average. 

92
00:05:26,080 --> 00:05:29,760
Episode right now so I'm I'm 
shocked if I get any listeners 

93
00:05:29,760 --> 00:05:31,480
for more in pieces to stick 
around this long. 

94
00:05:34,200 --> 00:05:36,680
Amazing. 
Oh. 

95
00:05:37,040 --> 00:05:39,000
Let's talk about what we're here
for. 

96
00:05:39,280 --> 00:05:43,800
I listen, man, I'll talk about 
this forever, you know, But 

97
00:05:43,800 --> 00:05:49,080
yeah, we should talk about this 
report you did, which came out I

98
00:05:49,080 --> 00:05:52,560
think last week as we're 
recording this on. 

99
00:05:52,880 --> 00:05:58,560
It's basically like, I don't 
know how you like think about it

100
00:05:58,560 --> 00:06:01,480
or, or like describe it, but I 
sort of looked at it. 

101
00:06:01,480 --> 00:06:05,600
It's called Kevology and it's 
kind of like a look at Sis's 

102
00:06:05,600 --> 00:06:10,280
known exploited vulnerabilities 
catalog, but not just like, hey,

103
00:06:10,280 --> 00:06:12,720
let's break it down all these 
bones and put them in the 

104
00:06:12,720 --> 00:06:15,120
categories. 
It's like looks at it from all 

105
00:06:15,120 --> 00:06:21,200
these different perspectives and
you know, where you know, when 

106
00:06:21,200 --> 00:06:26,040
exploits come in, the just kind 
of this holistic picture of it. 

107
00:06:26,520 --> 00:06:30,440
I know you, you worked at CISA, 
you were, you know, in charge of

108
00:06:30,440 --> 00:06:34,920
this essentially. 
What motivated you to to sort of

109
00:06:35,040 --> 00:06:37,800
dive deep into it? 
Maybe now I know since you'd 

110
00:06:37,800 --> 00:06:41,160
like to dive deep into shit, but
I do what what? 

111
00:06:41,520 --> 00:06:44,280
What motivated you to like, 
really dig into this? 

112
00:06:44,760 --> 00:06:48,640
So I would say the inciting 
event of of kevology colon and 

113
00:06:48,640 --> 00:06:53,600
analysis of exploit scores and 
timelines on this is a Kev was 

114
00:06:53,720 --> 00:06:56,000
we had, I want to say it was 
like a customer. 

115
00:06:56,000 --> 00:06:57,320
It wasn't even a customer 
request. 

116
00:06:57,320 --> 00:07:01,360
It was a customer wish of I work
at run zero. 

117
00:07:01,640 --> 00:07:04,680
We do exposure management, asset
management, vulnerability stuff,

118
00:07:04,840 --> 00:07:08,000
you know, all that. 
And they had this wish and the 

119
00:07:08,000 --> 00:07:12,200
wish was, boy, it'd be cool if I
could just like deal with all 

120
00:07:12,200 --> 00:07:15,960
the outstanding Kevs, you know, 
just with with your product. 

121
00:07:15,960 --> 00:07:17,480
And we said, yes, that would be 
cool. 

122
00:07:18,200 --> 00:07:21,080
And I used to work on the Kev. 
I kind of know what goes into 

123
00:07:21,080 --> 00:07:25,120
the Kev. 
I was a section chief and like 

124
00:07:25,120 --> 00:07:26,520
you say, essentially in charge 
of the Kev. 

125
00:07:26,600 --> 00:07:29,240
It takes like a billion people 
to make this thing, but sure. 

126
00:07:30,240 --> 00:07:33,080
Yeah. 
But I was, I was on point for 

127
00:07:33,080 --> 00:07:33,640
it. 
So. 

128
00:07:34,840 --> 00:07:37,360
And I'm like, OK. 
And I'm like, this is going to 

129
00:07:37,360 --> 00:07:38,640
be trickier than you expect, 
though. 

130
00:07:39,320 --> 00:07:44,880
And then I wrote a 20,000 word 
paper on why, why this is a hard

131
00:07:44,880 --> 00:07:49,080
ask. 
Getting 100% Kev coverage today 

132
00:07:49,080 --> 00:07:52,800
is I, I would pause. 
It is impossible with certainly 

133
00:07:52,800 --> 00:07:56,960
with one, one solution. 
Like if you buy one piece of 

134
00:07:56,960 --> 00:08:01,320
security software, right? 
If if it is sold to you as like,

135
00:08:01,320 --> 00:08:03,880
oh, push this button and you can
find all your Kev exposures, 

136
00:08:04,040 --> 00:08:08,560
they're lying to you because 
that does not seem to fit nicely

137
00:08:08,560 --> 00:08:10,280
into one SKU. 
You know what I mean? 

138
00:08:11,160 --> 00:08:15,200
Have covers traditional IT 
vulnerabilities, operational 

139
00:08:15,200 --> 00:08:18,800
technology vulnerabilities, 
cloud stuff that is probably 

140
00:08:18,800 --> 00:08:21,560
already fixed by the time you 
get around to it, but still 

141
00:08:21,560 --> 00:08:26,400
useful for log analysis and all 
that mobile stuff, which is you 

142
00:08:26,400 --> 00:08:30,400
know the the boogeyman of every 
IT operator everywhere because 

143
00:08:30,400 --> 00:08:33,039
almost all mobile is bring your 
own device you don't actually 

144
00:08:33,039 --> 00:08:37,760
have control over it all of that
right and so so that's like 5 

145
00:08:37,760 --> 00:08:41,120
categories of software right 
there right yeah and then you 

146
00:08:41,120 --> 00:08:43,600
have locals and remotes and 
privilege escalation and all 

147
00:08:43,600 --> 00:08:45,400
this other stuff going on in the
cab. 

148
00:08:46,160 --> 00:08:49,720
One of the misconceptions, I'd 
say, of the CAB is like it is a 

149
00:08:49,800 --> 00:08:54,360
list of, of the worst, of the 
worst vulnerabilities that have 

150
00:08:54,360 --> 00:08:57,880
affected federal government 
systems that are used for 

151
00:08:57,880 --> 00:09:00,760
initial access, right? 
Like, this is, this is often how

152
00:09:00,760 --> 00:09:03,520
people think of the cat, right? 
And that's wrong in like 4 

153
00:09:03,520 --> 00:09:04,720
different ways. 
Yeah. 

154
00:09:05,640 --> 00:09:06,800
So very much so. 
Yeah. 

155
00:09:08,440 --> 00:09:10,360
So, yeah, so that was like the 
inciting event. 

156
00:09:10,560 --> 00:09:13,280
This is basically an elaborate 
excuse to my boss of why we 

157
00:09:13,280 --> 00:09:16,320
can't do this, but also no one 
can. 

158
00:09:16,800 --> 00:09:19,840
And so, but we want, but we 
still want to like address the 

159
00:09:19,840 --> 00:09:24,600
problem right, of like, well, if
you if, if it's impossible or 

160
00:09:24,600 --> 00:09:29,920
just like way too expensive to 
to say like, yes, we have 100% 

161
00:09:29,920 --> 00:09:32,160
Kev coverage. 
Like what can we take from the 

162
00:09:32,160 --> 00:09:36,080
Kev that is like a useful 
vulnerability signal? 

163
00:09:36,080 --> 00:09:38,160
What can we use it as an 
intelligence source? 

164
00:09:38,400 --> 00:09:41,160
Can we pick out the things that 
are on the Kev that are actually

165
00:09:41,160 --> 00:09:43,320
relevant to me in my network, 
right. 

166
00:09:44,160 --> 00:09:48,920
And so Chemology posits a number
of ways, right, that you could 

167
00:09:48,920 --> 00:09:51,680
do something like that. 
Like if you really like CBSS 

168
00:09:51,680 --> 00:09:55,880
scores, we talk about like, oh, 
well, maybe you want just like 

169
00:09:55,880 --> 00:09:58,600
the criticality of CBSS, but 
that's a little bit of a lie. 

170
00:09:59,320 --> 00:10:03,600
Maybe you want just like these 
particular CBSS attributes. 

171
00:10:03,960 --> 00:10:06,520
And so select through for that 
and then you get a nice little 

172
00:10:06,520 --> 00:10:10,560
list of like all my remotes, non
authenticated, no user 

173
00:10:10,560 --> 00:10:13,400
interaction, full shell access 
bugs, right? 

174
00:10:13,400 --> 00:10:17,200
Like that's like the straight 
shot RCE, which is usually what 

175
00:10:17,200 --> 00:10:19,240
people are thinking of when 
they're thinking of software 

176
00:10:19,240 --> 00:10:20,640
vulnerabilities. 
Almost always. 

177
00:10:21,440 --> 00:10:25,480
And so like we can, if we can 
like 0 in on just those as a 

178
00:10:25,480 --> 00:10:27,480
priority mechanism, right? 
Like everything on the CAB 

179
00:10:27,480 --> 00:10:30,880
should be patched for sure. 
And if you're a federal civilian

180
00:10:30,880 --> 00:10:34,080
executive branch agency, you 
have to patch all of them. 

181
00:10:34,080 --> 00:10:37,560
Sorry, that is impossible, but 
but you still must do it. 

182
00:10:37,600 --> 00:10:39,920
And so they don't really have a 
lot of choice, but they can have

183
00:10:39,920 --> 00:10:42,120
choices on prioritization 
sometimes, right. 

184
00:10:42,400 --> 00:10:45,680
So you want to like be able to 
sort it and like maybe build 

185
00:10:45,680 --> 00:10:48,280
other lists out of the cab 
because it's really big. 

186
00:10:48,920 --> 00:10:52,320
I say really big, but it's like 
1500 and change. 

187
00:10:52,760 --> 00:10:58,160
I think it's 1528 today 
vulnerabilities, but that's out 

188
00:10:58,160 --> 00:11:02,240
of a universe of like over 
hundreds of thousands, right? 

189
00:11:02,240 --> 00:11:03,800
An. 
Unknowable number, yes. 

190
00:11:04,120 --> 00:11:07,760
CDs have been published. 
Almost all of them will never 

191
00:11:07,760 --> 00:11:11,480
see exploitation action, right. 
And but these ones definitely 

192
00:11:11,480 --> 00:11:13,760
did. 
And so like, that makes them 

193
00:11:13,760 --> 00:11:16,120
interesting. 
And so of this very interesting 

194
00:11:16,120 --> 00:11:19,320
set, what's even more 
interesting, right, that that's 

195
00:11:19,320 --> 00:11:22,200
kind of what you know, the 
kevology approach, right? 

196
00:11:22,920 --> 00:11:25,440
I I joke that the next paper I 
read on this is going to be 

197
00:11:25,440 --> 00:11:30,920
kevonomy as we evolve the 
theology into a proper onomy. 

198
00:11:31,520 --> 00:11:33,480
Yeah, like astrology to 
astronomy, but. 

199
00:11:36,160 --> 00:11:38,120
Maybe you could do a podcast 
where you're just reading the 

200
00:11:38,120 --> 00:11:40,280
description of each 
vulnerability like. 

201
00:11:40,640 --> 00:11:44,440
For this is not a terrible idea.
I don't know man. 

202
00:11:45,240 --> 00:11:46,760
No, wait, that is a terrible 
idea. 

203
00:11:46,760 --> 00:11:49,480
I mean, I stick to world 
literature. 

204
00:11:50,080 --> 00:11:54,640
That's not dare you. 
Impenetrable giants of world 

205
00:11:54,640 --> 00:11:58,400
literature. 
Yeah, you mentioned that this 

206
00:11:58,400 --> 00:12:02,040
this basically came about as 
like a customer request and 

207
00:12:02,480 --> 00:12:06,480
seeing if this would work. 
And, and sometimes it does seem 

208
00:12:06,480 --> 00:12:09,080
like there's there's just as 
much value in proving that you 

209
00:12:09,080 --> 00:12:11,400
can't do something as there is 
in. 

210
00:12:11,440 --> 00:12:14,640
Showing and like, and I don't 
like to take a can't laying 

211
00:12:14,640 --> 00:12:17,920
down, you know, like and and 
here's the thing, like what I 

212
00:12:17,920 --> 00:12:20,880
want to do is arm people like 
one of the goals of this paper 

213
00:12:21,200 --> 00:12:27,560
is to arm the the beleaguered IT
security operator, the analyst. 

214
00:12:27,840 --> 00:12:32,200
And I want them to be able to 
tell their boss of like, why I 

215
00:12:32,200 --> 00:12:36,080
can't tell you one way or 
another about this Apple iOS 

216
00:12:36,080 --> 00:12:40,040
bug, right? 
Because it's BYOD, it's probably

217
00:12:40,040 --> 00:12:43,800
fixed, right? 
Because like iOS tends, it tends

218
00:12:43,800 --> 00:12:47,320
to be hard to avoid an iOS fix. 
It does, yeah. 

219
00:12:47,640 --> 00:12:52,200
After a while and we see that 
like looking with all this like 

220
00:12:52,200 --> 00:12:55,720
sorting stuff that we do on it 
now, and this is all released by

221
00:12:55,720 --> 00:12:56,800
the way, we can talk about it in
a second. 

222
00:12:57,760 --> 00:13:00,640
But with all the sorting stuff 
we do, we can see that like 

223
00:13:01,200 --> 00:13:06,960
Apple iOS bugs in particular 
tend to skew way to the left 

224
00:13:06,960 --> 00:13:10,560
side of an EPS graph. 
So like EPS is exploit 

225
00:13:10,680 --> 00:13:13,200
prediction scoring system. 
It's a percentage. 

226
00:13:14,200 --> 00:13:17,280
It's a percentage chance of if 
this vulnerability is going to 

227
00:13:17,280 --> 00:13:19,360
be exploited in the next 30 
days. 

228
00:13:19,920 --> 00:13:23,840
And Apple iOS bugs tend to score
real low on that because the 

229
00:13:23,840 --> 00:13:27,800
exploitation that happens in iOS
tends to be extremely targeted 

230
00:13:28,000 --> 00:13:31,160
usually to a journalist, usually
in a part of the world that's 

231
00:13:31,520 --> 00:13:33,280
not very cool to be a journalist
in. 

232
00:13:34,120 --> 00:13:36,320
And that's it. 
And then it gets burnt and then 

233
00:13:36,320 --> 00:13:40,920
like Apple notices it, you know,
a citizen lab notices it and 

234
00:13:40,920 --> 00:13:43,880
then it gets fixed, right? 
And so the chance of that 

235
00:13:43,880 --> 00:13:47,240
getting exploited again 
understandably very low. 

236
00:13:48,480 --> 00:13:49,960
And so you can take that to your
boss. 

237
00:13:49,960 --> 00:13:52,440
You can say, like, look like I 
understand this is a big deal 

238
00:13:52,440 --> 00:13:53,960
bug. 
It's like straight shot RCE 

239
00:13:54,160 --> 00:13:55,600
through like a text message or 
something. 

240
00:13:56,360 --> 00:13:59,960
But don't worry about it. 
It was, you know, two months 

241
00:13:59,960 --> 00:14:02,680
ago. 
It was used in in in a campaign 

242
00:14:02,680 --> 00:14:05,520
probably. 
And EPSS is telling me like this

243
00:14:05,520 --> 00:14:10,480
is not going to pop up for us. 
Right, Yeah, the the Apple 

244
00:14:10,480 --> 00:14:12,040
example I think is a really good
one. 

245
00:14:12,080 --> 00:14:14,320
I was talking to somebody else 
about this the other day. 

246
00:14:14,800 --> 00:14:17,560
I think when the the latest 
Apple release came out about. 

247
00:14:17,920 --> 00:14:21,440
OK, yes, there was a thing in 
there that was exploited, you 

248
00:14:21,440 --> 00:14:24,440
know, in iOS. 
We don't know exactly when, but 

249
00:14:24,440 --> 00:14:28,360
we know that Google tag was the 
one that, you know, noticed it. 

250
00:14:28,480 --> 00:14:31,480
So that tells you that's exactly
what you just described. 

251
00:14:31,800 --> 00:14:34,080
It's probably. 
Certainly espionage or 

252
00:14:34,120 --> 00:14:36,960
government. 
Back against like 4 people or 

253
00:14:37,120 --> 00:14:40,520
something like that. 
Some very small subset of 

254
00:14:40,800 --> 00:14:41,600
journalists are no. 
Of. 

255
00:14:41,600 --> 00:14:47,360
Course. 
As a journalist, yeah, not in 

256
00:14:47,360 --> 00:14:50,360
favor of that shit, but you 
know. 

257
00:14:50,800 --> 00:14:52,920
Like, you should know about it 
and be aware of it, and then 

258
00:14:52,920 --> 00:14:55,160
every once in a while you're 
going to see some Apple thing 

259
00:14:55,560 --> 00:14:58,160
that isn't quite yet patched, 
right? 

260
00:14:58,160 --> 00:15:02,240
But like almost always when you 
see a CVE for an Apple bug, 

261
00:15:02,240 --> 00:15:05,120
which is an important 
distinction actually, CVE for an

262
00:15:05,120 --> 00:15:08,080
Apple bug almost always means 
that the fix has already been 

263
00:15:08,080 --> 00:15:10,880
rolled out and in most cases 
already applied. 

264
00:15:11,480 --> 00:15:14,760
OK, Yeah, this is another thing 
I wanted to ask you about. 

265
00:15:15,160 --> 00:15:20,120
There's a section in the report 
where you talk about the time 

266
00:15:20,120 --> 00:15:24,880
delta between when CV ES are 
issued and when they enter the 

267
00:15:24,880 --> 00:15:28,480
Kev. 
And like entering the Kev is 

268
00:15:28,480 --> 00:15:30,240
here. 
Sometimes the CVE is before it, 

269
00:15:30,240 --> 00:15:32,560
sometimes it's after it. 
Which is a weird thing to think 

270
00:15:32,560 --> 00:15:34,840
about really. 
Rarely is it after, but it does 

271
00:15:34,840 --> 00:15:36,680
happen. 
It happens which like. 

272
00:15:36,680 --> 00:15:39,880
Can you explain how and why that
happens? 

273
00:15:39,880 --> 00:15:41,680
I can think about why it happens
with Apple. 

274
00:15:41,680 --> 00:15:46,040
But this was a point of 
contention when I was in SZA at 

275
00:15:46,040 --> 00:15:47,480
the federal U.S. 
Federal government. 

276
00:15:48,440 --> 00:15:53,360
So one of the barriers to entry 
to Kev is that for a 

277
00:15:53,360 --> 00:15:58,720
vulnerability to be listed on 
the scissor Kev, it must have a 

278
00:15:58,720 --> 00:16:02,640
CVE ID associated with it. 
Must have, there must be a CVE 

279
00:16:02,640 --> 00:16:07,360
ID assigned to it, which is a 
little bit of a tricky word 

280
00:16:08,480 --> 00:16:14,240
because vendors like Microsoft, 
Google to Apple, pretty much 

281
00:16:14,240 --> 00:16:17,360
every like major soft software 
vendor today, right? 

282
00:16:17,480 --> 00:16:21,120
Technology vendor today is their
own CBE numbering authority. 

283
00:16:21,120 --> 00:16:23,760
So they can reserve CB ES all 
day long, right? 

284
00:16:24,680 --> 00:16:31,280
And So what we will typically 
see is most cases the CBE was 

285
00:16:31,280 --> 00:16:34,560
reserved and published like 
weeks to months ago, right? 

286
00:16:34,560 --> 00:16:38,440
And then eventually Kev catches 
up with the evidence and all 

287
00:16:38,440 --> 00:16:41,320
that, right? 
Yeah, but every once in a while,

288
00:16:42,240 --> 00:16:45,880
Sizzle will get a communication 
from the vendor of the software 

289
00:16:45,880 --> 00:16:47,880
saying like, hey, we're gonna 
publish this thing. 

290
00:16:47,880 --> 00:16:49,640
There's active exploitation 
right now. 

291
00:16:49,960 --> 00:16:51,640
You should probably put this on 
the Kev. 

292
00:16:51,640 --> 00:16:53,600
And then we would say, like, 
that sounds bad. 

293
00:16:53,600 --> 00:16:55,720
Do you have evidence of it? 
And they'll say, yes, we do. 

294
00:16:55,720 --> 00:16:57,560
And then they send it over and 
we look at it and we're like, 

295
00:16:57,920 --> 00:17:01,480
looks like an exploit to me. 
Yeah, we'll list it on the Kev. 

296
00:17:01,680 --> 00:17:04,520
I'll say we they now list it on 
the Kev. 

297
00:17:05,800 --> 00:17:10,599
You some, we try to get that CDE
published, like we'll push them 

298
00:17:10,599 --> 00:17:13,800
to get the CDE published and all
that, but if they don't, we'll 

299
00:17:13,800 --> 00:17:15,800
still list it on the Kev because
we don't want to slow down 

300
00:17:15,800 --> 00:17:19,079
patching. 
But then the CDE itself might 

301
00:17:19,079 --> 00:17:22,480
get published 2 days later, 
three days later or something 

302
00:17:23,760 --> 00:17:26,079
like that. 
And so you sometimes will be in 

303
00:17:26,079 --> 00:17:29,360
a zone where like I have a 
CDEIDA description of the bug on

304
00:17:29,360 --> 00:17:31,160
the Kev. 
Kev's always have descriptions, 

305
00:17:31,560 --> 00:17:36,320
so even without the CDE you'll 
get like a little bit of warning

306
00:17:36,320 --> 00:17:37,480
on that. 
Those are rare though. 

307
00:17:37,480 --> 00:17:41,560
Most of the time it is something
that's already something that's 

308
00:17:41,560 --> 00:17:44,760
already identified, something 
that already has patch, right 

309
00:17:45,760 --> 00:17:48,440
you you always have to have a 
patch or reasonable mitigation 

310
00:17:48,440 --> 00:17:50,880
to get on the Kev. 
Otherwise it's just a list of 

311
00:17:50,880 --> 00:17:53,280
bugs to look at, there's nothing
to do. 

312
00:17:55,400 --> 00:17:57,720
We've got lots of those lists we
don't need, yeah. 

313
00:17:58,520 --> 00:18:02,000
Don't need another one Has a 
CVID, has a reasonable 

314
00:18:02,000 --> 00:18:07,600
mitigation, has exploitation 
evidence and that's like non 

315
00:18:07,600 --> 00:18:12,000
consensual exploitation. 
So like, yeah, so like, red 

316
00:18:12,000 --> 00:18:14,600
teaming is consensual, like 
ultimately. 

317
00:18:15,000 --> 00:18:18,320
Right. 
And so bizarre hits are a little

318
00:18:18,320 --> 00:18:24,200
bit of a Gray area, but like, 
generally speaking, the attack 

319
00:18:24,200 --> 00:18:28,000
should have been successful. 
But that's always like a weird 

320
00:18:28,000 --> 00:18:30,320
case that takes a lot of work to
actually verify. 

321
00:18:30,680 --> 00:18:33,760
Yeah. 
And then 4th is has to be 

322
00:18:33,760 --> 00:18:35,680
relevant to federal interests, 
right? 

323
00:18:35,680 --> 00:18:38,160
Which doesn't just mean the 
computers that, like federal 

324
00:18:38,160 --> 00:18:41,360
government runs. 
Sure, it could be State, local, 

325
00:18:41,360 --> 00:18:43,000
tribal territorial governments 
are a big. 

326
00:18:43,000 --> 00:18:45,080
Source. 
Or the defense industrial base 

327
00:18:45,120 --> 00:18:47,320
or something like that. 
Defense is a big deal. 

328
00:18:49,160 --> 00:18:50,640
Critical infrastructure is a big
deal. 

329
00:18:50,640 --> 00:18:53,440
So like, water and Power 
Distribution are like the big 

330
00:18:53,440 --> 00:18:58,520
ones for us, for SZA and 
international allies is a big 

331
00:18:58,520 --> 00:19:00,200
deal. 
So like, OK, if someone's 

332
00:19:00,200 --> 00:19:02,240
burning through Canada, like, we
want to know about it. 

333
00:19:03,480 --> 00:19:05,600
Yeah. 
Because maybe we're next, you 

334
00:19:05,600 --> 00:19:08,520
know? 
So that's why. 

335
00:19:08,560 --> 00:19:10,760
Right? 
And so. 

336
00:19:10,880 --> 00:19:12,960
So, yeah. 
So like every once in a while 

337
00:19:12,960 --> 00:19:17,400
you'll see Cdes published, 
they're always reserved before 

338
00:19:17,400 --> 00:19:20,640
they go on the cab and in the 
worst case is like, oh, there's 

339
00:19:20,640 --> 00:19:23,400
this crazy O day. 
It's with a vendor that isn't 

340
00:19:23,400 --> 00:19:26,280
its own CVE authority. 
No problem. 

341
00:19:26,560 --> 00:19:29,600
SZA is also a CVE numbering 
authority, so they can pop one 

342
00:19:29,600 --> 00:19:34,840
out real fast in those cases. 
You mentioned in that they. 

343
00:19:34,920 --> 00:19:36,600
Get real nerdy about this. 
So I'm gonna no. 

344
00:19:36,920 --> 00:19:40,120
Listen, I love this shit for 
whatever reason. 

345
00:19:40,120 --> 00:19:42,200
I enjoy it too and I will talk 
about it all day. 

346
00:19:44,240 --> 00:19:46,960
I've had long conversations with
other people about like the CBE 

347
00:19:46,960 --> 00:19:48,880
system for no real reason, like 
just. 

348
00:19:49,120 --> 00:19:52,280
I don't even know why but. 
Should join one of our working 

349
00:19:52,280 --> 00:19:56,400
groups. 
Steve Christie tried to get me 

350
00:19:56,400 --> 00:19:59,880
to do that at some point. 
I don't know man. 

351
00:20:03,520 --> 00:20:07,560
Steve, you mentioned that one of
the things that CISA or, you 

352
00:20:07,560 --> 00:20:10,800
know, even other people like, 
like you guys might ask for is 

353
00:20:10,800 --> 00:20:14,720
the evidence of exploitation. 
Like sometimes that that's easy.

354
00:20:14,720 --> 00:20:18,240
Like you could have victims 
publicly saying we were 

355
00:20:18,240 --> 00:20:19,600
exploited or something like 
that. 

356
00:20:20,000 --> 00:20:24,000
But in the case of, you know, 
let's pick like an an O day that

357
00:20:24,000 --> 00:20:27,400
is not publicly known yet and 
somebody is saying we've seen 

358
00:20:27,400 --> 00:20:30,800
this be exploitable. 
Like what qualifies as evidence?

359
00:20:30,800 --> 00:20:33,880
Like what are you looking for 
so. 

360
00:20:34,800 --> 00:20:39,040
So for starters, if you have 
evidence of exploitation of a 

361
00:20:39,040 --> 00:20:43,120
CVE and it hits all those things
I talked about, please get in 

362
00:20:43,120 --> 00:20:44,920
touch with the people who write 
the Kev and that is 

363
00:20:44,920 --> 00:20:53,200
kev@mail.sizza.dhs.gov. 
It's a lot of machines is. 

364
00:20:53,280 --> 00:20:55,640
Someone actually monitoring that
anymore, Todd? 

365
00:20:56,440 --> 00:20:58,520
Yeah, no, no, Yeah, humans read 
that. 

366
00:20:58,920 --> 00:21:00,000
OK, good. 
I know. 

367
00:21:00,000 --> 00:21:01,640
Personally read that. 
Excellent. 

368
00:21:01,880 --> 00:21:04,880
That's good to know. 
Yes, and they they will pay 

369
00:21:04,880 --> 00:21:06,520
attention to that. 
So if you have evidence like 

370
00:21:06,520 --> 00:21:09,520
start a communication there like
or just like drop AP cap on them

371
00:21:09,520 --> 00:21:10,600
and say nothing, it would be 
funny. 

372
00:21:12,600 --> 00:21:15,920
But so things like P caps are 
really good, like for things 

373
00:21:15,920 --> 00:21:19,000
that are in the clear that 
aren't encrypted, things like 

374
00:21:19,000 --> 00:21:22,760
system logs showing, you know, 
especially for things like 

375
00:21:22,760 --> 00:21:26,720
privilege escalation, you know, 
EDR logs are really good for 

376
00:21:26,720 --> 00:21:30,400
that kind of thing. 
OK, You know, firewall, you 

377
00:21:30,400 --> 00:21:32,680
know, smart firewall, IPS kind 
of stuff. 

378
00:21:32,680 --> 00:21:35,160
Intrusion prevention, system 
logs. 

379
00:21:36,040 --> 00:21:40,600
A lot of times when I was doing 
the evidence work, it would be 

380
00:21:40,600 --> 00:21:43,240
we'd get a collection, right? 
We'd have like, oh, we have this

381
00:21:43,240 --> 00:21:47,360
like anomaly detection thing 
that logged a thing over on this

382
00:21:47,360 --> 00:21:50,040
network device. 
And then we can see by the time 

383
00:21:50,040 --> 00:21:52,640
stamps, because good for you, 
you're using NTP. 

384
00:21:53,000 --> 00:21:55,840
Amazing. 
We can see by the time stamps 

385
00:21:55,840 --> 00:21:59,360
that then this machine started 
acting real funny and has a 

386
00:21:59,360 --> 00:22:01,680
bunch of logs about it, right. 
And so like, that's the kind and

387
00:22:01,680 --> 00:22:05,640
that's the fun part, right? 
Is like being the Poirot of, of 

388
00:22:05,640 --> 00:22:06,320
exploiting. 
Yeah. 

389
00:22:06,400 --> 00:22:10,080
You know, mystery solving is 
super fun. 

390
00:22:10,120 --> 00:22:14,240
Like it's a very fun job. 
And then you can kind of like 

391
00:22:14,240 --> 00:22:17,040
try and correlate that with 
maybe other. 

392
00:22:17,040 --> 00:22:18,840
Things you make a case, right, 
right. 

393
00:22:18,920 --> 00:22:21,920
And a lot of times you're making
a case of it's this CVE and not 

394
00:22:21,920 --> 00:22:28,040
that CVE cuz that is important. 
There might be a patch set is 

395
00:22:28,040 --> 00:22:31,280
released from somebody that 
addresses 5 CVS. 

396
00:22:31,400 --> 00:22:36,160
Solarwind's web helpdesk, just 
as we're recording this, just 

397
00:22:36,160 --> 00:22:39,040
did one four or five days ago. 
Yeah, very recently. 

398
00:22:39,240 --> 00:22:41,080
And there were five CV ES in 
there. 

399
00:22:41,080 --> 00:22:45,040
But you will notice only one of 
them is listed on the cab 

400
00:22:45,040 --> 00:22:48,080
because it's just that one that 
that had the exploitation 

401
00:22:48,080 --> 00:22:51,840
evidence. 
So that's, that is often 

402
00:22:51,840 --> 00:22:54,320
important, especially when 
people are trying to prioritize 

403
00:22:54,320 --> 00:22:57,600
things because CV ES are lists 
of vulnerabilities, not lists of

404
00:22:57,600 --> 00:23:01,600
patches. 
And so even if like, and if that

405
00:23:01,600 --> 00:23:05,840
patch is like no good, you know,
like or there's an evasion for 

406
00:23:05,840 --> 00:23:07,920
it or something like that, you 
have to know like, well, which 

407
00:23:07,920 --> 00:23:09,640
one am I evade? 
Which one am I now patching 

408
00:23:09,640 --> 00:23:11,760
again and all that, all that 
kind of stuff. 

409
00:23:12,360 --> 00:23:16,720
The patches that we list that 
they list, God Dang it that just

410
00:23:16,720 --> 00:23:21,760
that sizzle lists have gone 
through some like assurances 

411
00:23:21,760 --> 00:23:23,640
that like, yes, this actually 
patches the thing. 

412
00:23:23,960 --> 00:23:27,680
If a patch smells funny when 
whoever's investigating it, like

413
00:23:27,960 --> 00:23:30,200
they'll, they'll talk to the 
vendor, They'll say like, I 

414
00:23:30,240 --> 00:23:31,680
don't think you're actually 
patching the thing. 

415
00:23:31,680 --> 00:23:33,240
You're patching just like 1 
vector. 

416
00:23:33,240 --> 00:23:35,760
And sometimes that'll get like a
new patch in there. 

417
00:23:36,560 --> 00:23:40,720
But I'm, I'm very confident that
every patch listed on, on the 

418
00:23:40,720 --> 00:23:44,680
scissor cab is, is good, right? 
Because otherwise we're sending,

419
00:23:44,800 --> 00:23:48,280
they're sending, you know, 
hundreds and hundreds of like 

420
00:23:48,280 --> 00:23:51,280
federal IT workers out to do a 
thing on a timeline. 

421
00:23:51,440 --> 00:23:53,280
It's not going to work. 
Then they got to do it again. 

422
00:23:53,280 --> 00:23:55,400
I mean, like, that is a bad use 
of taxpayer money. 

423
00:23:56,080 --> 00:23:58,120
It sure is, yeah, We've got 
enough of those. 

424
00:23:58,120 --> 00:24:01,400
We don't need another one. 
Which is ultimately why Kev is 

425
00:24:01,400 --> 00:24:04,160
so selective, right? 
Like Kev will get some knocks 

426
00:24:04,160 --> 00:24:08,400
from other people in 
cybersecurity and saying like, 

427
00:24:08,600 --> 00:24:12,000
Kev is so slow and like we knew 
about this thing, you know, days

428
00:24:12,000 --> 00:24:14,800
and days and days before it 
says, why are you so pokey on 

429
00:24:14,800 --> 00:24:16,400
the on this? 
And it's like, and the reason 

430
00:24:16,400 --> 00:24:23,680
for it is that Kev prioritizes 
accuracy more than speed in 

431
00:24:23,680 --> 00:24:25,320
those cases. 
Totally fair. 

432
00:24:25,680 --> 00:24:28,000
And it's and it's fair. 
And if it's like a really hot 

433
00:24:28,000 --> 00:24:30,600
vulnerability that everybody, 
everybody knows about because 

434
00:24:30,600 --> 00:24:33,400
everybody reads the cipher or 
bleeping computer or something, 

435
00:24:33,600 --> 00:24:36,040
yeah, they're going to be on it 
anyway. 

436
00:24:36,240 --> 00:24:39,040
They don't really need to wait 
for the Kev to tell them to do 

437
00:24:39,040 --> 00:24:43,800
the thing, hopefully, right? 
Kev is the Kev is definitely not

438
00:24:43,800 --> 00:24:46,720
your first line of defense. 
It is much closer to your life. 

439
00:24:47,560 --> 00:24:50,520
I would hope so, yeah. 
I mean, that reminds me a little

440
00:24:50,520 --> 00:24:53,320
bit of the thing that you always
hear from Microsoft and other 

441
00:24:53,320 --> 00:24:56,760
large vendors of like, why 
aren't you getting this patch 

442
00:24:56,760 --> 00:25:00,600
out faster? 
And you know, the common answer 

443
00:25:00,600 --> 00:25:05,200
is we have 10,000 versions of 
this in 400 languages and we 

444
00:25:05,200 --> 00:25:07,440
have to test all of those so it 
doesn't break stuff on your 

445
00:25:07,440 --> 00:25:09,120
network. 
And Microsoft's really good 

446
00:25:09,120 --> 00:25:12,880
about that too, because they 
really, they legitimately do 

447
00:25:12,880 --> 00:25:16,400
like no one thinks about, you 
know, the Microsoft point of 

448
00:25:16,400 --> 00:25:19,480
sale system that also runs, you 
know, Windows. 

449
00:25:19,560 --> 00:25:21,840
Me or whatever it is, Windows me
literally. 

450
00:25:21,840 --> 00:25:25,800
Yes, yeah, like when that thing,
but like when they're doing an 

451
00:25:25,800 --> 00:25:29,120
ME patch, which I guess they 
probably wouldn't anymore until 

452
00:25:29,120 --> 00:25:33,880
unless they need to. 
So like, OK, so like Windows 10 

453
00:25:33,880 --> 00:25:36,800
IoT build for example, right. 
That is a thing that's in the 

454
00:25:36,800 --> 00:25:39,600
world and it's actually arguably
a better desktop operating 

455
00:25:39,600 --> 00:25:42,400
system in my opinion. 
But the IoT build is a very 

456
00:25:42,400 --> 00:25:43,960
stripped down version of 
Windows. 

457
00:25:44,600 --> 00:25:46,200
But because of this, they have 
to test, right? 

458
00:25:46,200 --> 00:25:49,520
Like you always have to test and
so and there's every version of 

459
00:25:49,520 --> 00:25:53,080
Windows has like 20 or 30 
flavours and then you have all 

460
00:25:53,080 --> 00:25:56,000
the language stuff too. 
That sometimes matters, 

461
00:25:56,840 --> 00:25:58,600
especially for things like font 
rendering bugs. 

462
00:26:00,040 --> 00:26:04,240
Which there are plenty of. 
Yeah, Yeah, exactly. 

463
00:26:04,360 --> 00:26:08,200
And those are the, you know, 
those are the things that the 

464
00:26:08,200 --> 00:26:11,960
mitigating factors where you're 
like, we really need this patch.

465
00:26:11,960 --> 00:26:13,200
It's being exploited in the 
wild. 

466
00:26:13,200 --> 00:26:17,160
But you know, the the people on 
the that are building the patch 

467
00:26:17,160 --> 00:26:20,680
are like, OK, we know that, but 
we don't wanna break a bunch of 

468
00:26:20,680 --> 00:26:23,120
other shit. 
When we give you this patch, 

469
00:26:23,640 --> 00:26:24,840
then you're gonna yell at us for
that. 

470
00:26:24,840 --> 00:26:27,920
Cuz then you'll have a bad time 
and you might not patch again. 

471
00:26:28,240 --> 00:26:31,640
I remember you and I are 
gentlemen of a certain vintage. 

472
00:26:31,800 --> 00:26:35,880
Of a certain age. 
I remember when Microsoft was 

473
00:26:35,880 --> 00:26:40,640
issuing hotfixes and the 
hotfixes opened with like, don't

474
00:26:41,240 --> 00:26:43,720
you'll apply this unless you're 
actually experiencing this 

475
00:26:43,720 --> 00:26:44,920
problem. 
Absolutely. 

476
00:26:44,920 --> 00:26:46,920
Security fixes. 
It was hilarious because it's 

477
00:26:46,920 --> 00:26:49,360
like, oh, don't apply this until
you've already been owned. 

478
00:26:49,360 --> 00:26:50,640
It was like. 
Well, I'm. 

479
00:26:51,400 --> 00:26:53,400
Going to go ahead and just apply
it now. 

480
00:26:53,560 --> 00:26:55,320
Right. 
Or I'm going to throw this 

481
00:26:55,320 --> 00:26:58,560
server in the ocean because, you
know, it's probably. 

482
00:26:58,720 --> 00:27:02,120
That is no longer the case. 
We, we've at least I, you know, 

483
00:27:02,120 --> 00:27:05,360
we often talk about like nothing
ever changes and everybody has 

484
00:27:05,360 --> 00:27:06,800
bad habits and they've had these
bad habits. 

485
00:27:07,240 --> 00:27:13,000
I think we have made a, I think 
we have pivoted very slowly over

486
00:27:13,000 --> 00:27:18,840
the last 30 years from like 
let's be extremely careful with 

487
00:27:18,840 --> 00:27:22,720
the vendor supplied patches to 
like let's trust the vendor 

488
00:27:22,720 --> 00:27:26,720
supply patches unless I get 
other other information, right. 

489
00:27:26,720 --> 00:27:29,160
Yeah. 
And Chrome really was the one 

490
00:27:29,160 --> 00:27:31,360
that did it. 
Google Chrome with with the auto

491
00:27:31,360 --> 00:27:35,280
patching of the browser was 
insanity at the time. 

492
00:27:35,400 --> 00:27:38,360
Oh my God, People could. 
You lost their minds. 

493
00:27:38,520 --> 00:27:42,360
Yeah. 
Oh how dare you patch my browser

494
00:27:42,560 --> 00:27:44,320
And meanwhile IE 6 is chugging 
along. 

495
00:27:44,320 --> 00:27:45,800
It's like I don't need any 
patches, I'm good. 

496
00:27:45,840 --> 00:27:49,000
Like oh did you want a patch? 
Here have a 12 step process. 

497
00:27:49,200 --> 00:27:51,280
Yeah, you can't watch, but I 
wouldn't recommend it. 

498
00:27:51,280 --> 00:27:55,560
Yeah, that's so true the the 
Chrome scenes now. 

499
00:27:55,560 --> 00:28:01,720
Where like it is newsworthy when
a patch, a security fix actually

500
00:28:01,720 --> 00:28:04,520
breaks something on like a major
piece of software, right? 

501
00:28:04,520 --> 00:28:07,240
Like that is, that is its own 
story. 

502
00:28:07,560 --> 00:28:09,640
It used to be a regular 
occurrence like it used to. 

503
00:28:09,720 --> 00:28:13,200
To be constant. 
Yes, honest to God. 

504
00:28:13,280 --> 00:28:16,520
And everyone got burned like 20 
times on that particular stove. 

505
00:28:17,360 --> 00:28:19,640
But I think we've gotten to a 
point where we're like, OK, I'm 

506
00:28:19,680 --> 00:28:21,280
pretty sure the stove is cooled 
off now. 

507
00:28:23,800 --> 00:28:27,160
The Chrome like auto patching 
was a huge, huge deal. 

508
00:28:27,160 --> 00:28:29,760
It's hard to remember now, like,
and especially for folks that 

509
00:28:29,760 --> 00:28:34,800
weren't around at the time, it 
was a massive uproar in, I mean,

510
00:28:34,800 --> 00:28:38,120
I guess it was before that, but 
Microsoft saying, hey, we're 

511
00:28:38,120 --> 00:28:41,160
going to push patches to you 
instead of you having to come 

512
00:28:41,160 --> 00:28:44,600
and get them from us. 
People lost their damn minds or 

513
00:28:44,680 --> 00:28:48,520
how dare you. 
Like I have those things for 

514
00:28:48,520 --> 00:28:51,320
breaking. 
It is a delicate House of Cards.

515
00:28:53,480 --> 00:28:56,640
This is barely hanging on by a 
thread and you're going to just 

516
00:28:56,640 --> 00:28:58,440
shove software at it? 
Come on. 

517
00:28:58,840 --> 00:29:02,880
Let's not do that. 
Yeah, but now we're just like, 

518
00:29:03,040 --> 00:29:06,880
why isn't my TV or my dishwasher
patched like every two days? 

519
00:29:06,880 --> 00:29:10,160
Like, right, let's go. 
Like I I know there's a tax. 

520
00:29:10,160 --> 00:29:14,240
House like home, like Soho, you 
know, small office Home Office 

521
00:29:14,240 --> 00:29:19,800
routers are now more or less 
auto patching, I would say. 

522
00:29:20,840 --> 00:29:24,080
But it's like, I don't know, 
it's like 7030 I think between 

523
00:29:24,080 --> 00:29:28,560
the vendors and are you one of 
the lucky ones like that? 

524
00:29:28,800 --> 00:29:33,120
Just you might have to. 
And those are devices that you 

525
00:29:33,120 --> 00:29:36,640
literally were were unable to 
patch for a very long time. 

526
00:29:36,640 --> 00:29:40,200
Like not only was it technically
hard, but a lot of times the 

527
00:29:40,200 --> 00:29:42,640
vendors wouldn't even issue 
patches or. 

528
00:29:42,960 --> 00:29:47,160
No, they would just like they 
wouldn't like you bus button and

529
00:29:47,160 --> 00:29:49,880
you're like well if you want 
this fixed, buy the next one. 

530
00:29:49,880 --> 00:29:52,960
It's £200. 
Yeah, the planned obsolescence. 

531
00:29:52,960 --> 00:29:56,200
Yeah, it's a beautiful thing. 
Welcome to IoT. 

532
00:29:59,840 --> 00:30:02,840
No, Dennis, IoT never dies. 
No, no, it does. 

533
00:30:02,840 --> 00:30:04,520
Here's. 
The thing there's hardly any 

534
00:30:04,520 --> 00:30:08,120
moving parts in most IoT, so 
like they will last for. 

535
00:30:08,320 --> 00:30:11,720
Decades. 
And do they do? 

536
00:30:11,720 --> 00:30:15,480
We're seeing it now just like, 
yeah, light bulbs and like, 

537
00:30:15,480 --> 00:30:18,560
little devices everywhere that 
like you wish would die but 

538
00:30:18,560 --> 00:30:22,200
aren't. 
Yeah, you got your low energy 

539
00:30:22,200 --> 00:30:24,680
LEDs. 
Those those suckers are going to

540
00:30:24,680 --> 00:30:26,440
burn for 20 years. 
They'll be fine. 

541
00:30:26,920 --> 00:30:29,040
Yeah. 
Oh God, I'm. 

542
00:30:30,960 --> 00:30:35,280
Sorry for depressing. 
Giving me Jesus. 

543
00:30:35,520 --> 00:30:38,960
This is one of the conceits I 
think of like classic cyberpunk 

544
00:30:38,960 --> 00:30:41,880
literature of like, oh cool, I'm
going to get a cool cyber arm 

545
00:30:42,800 --> 00:30:44,640
and I'll have like super 
strength in that arm and I can 

546
00:30:44,880 --> 00:30:48,040
change my fingers. 
How are you dealing with 

547
00:30:48,040 --> 00:30:51,480
hardware upgrades? 
Go back into surgery like. 

548
00:30:53,680 --> 00:30:56,160
Yeah, exactly how are they going
to replace that for you like 

549
00:30:56,160 --> 00:30:58,920
when the new model comes out? 
How do you update the firmware? 

550
00:30:59,040 --> 00:31:02,840
Can someone else update the 
firmware in the midst of combat?

551
00:31:04,440 --> 00:31:07,480
Yeah, there's probably a good 
movie there somewhere. 

552
00:31:07,480 --> 00:31:10,680
It's probably, or a bad movie 
more likely. 

553
00:31:12,400 --> 00:31:15,920
Was there anything that like, as
you dug into this, really like 

554
00:31:15,920 --> 00:31:19,800
surprised you, honestly. 
Obviously you're like you're dug

555
00:31:19,800 --> 00:31:22,400
into this to begin with, but as 
you were writing this, was there

556
00:31:22,400 --> 00:31:26,320
any anything that like like ha, 
I didn't, I kind of thought it 

557
00:31:26,320 --> 00:31:29,440
would be the other way or I 
wasn't expecting that kind of 

558
00:31:29,440 --> 00:31:33,400
result. 
I would say it was so it was 

559
00:31:33,400 --> 00:31:38,120
surprising to me. 
It's just like all the ways you 

560
00:31:38,120 --> 00:31:42,640
could play around with time with
all this stuff that was like the

561
00:31:43,200 --> 00:31:45,600
you already brought it up like 
my favorite graph in this whole 

562
00:31:45,600 --> 00:31:47,640
thing. 
It's entitled CDE and exploit 

563
00:31:47,640 --> 00:31:49,640
publish dates versus Kev 
additions. 

564
00:31:49,760 --> 00:31:52,920
Yeah, there's also like two 
other things in there and it's a

565
00:31:52,920 --> 00:31:55,200
super fun graph. 
I'm gonna try to describe it. 

566
00:31:55,920 --> 00:31:59,560
So I won't try to describe it, 
but like it creates this really 

567
00:31:59,560 --> 00:32:03,960
like pleasing pattern, right? 
Of I have AI have a solid line 

568
00:32:03,960 --> 00:32:08,640
of Kevs, like I get Kev updates,
you know, 2 to 6 * a week every 

569
00:32:08,640 --> 00:32:11,640
week since, you know, Kev 
started in 2021. 

570
00:32:12,160 --> 00:32:14,760
And that's like the baseline, 
right? 

571
00:32:14,760 --> 00:32:16,800
This is how this whole graph is,
is built out. 

572
00:32:17,360 --> 00:32:20,360
And then you can see like these 
like little waterfalls of like 

573
00:32:20,360 --> 00:32:23,400
metasplate modules that were 
written, you know, 10 years ago,

574
00:32:23,840 --> 00:32:27,760
all kind of tracking along. 
And then and then it gets added 

575
00:32:27,760 --> 00:32:31,480
to the Kev several years later. 
But then as time goes on, you'll

576
00:32:31,480 --> 00:32:35,080
see like Metasploit modules tend
to cluster up a little bit 

577
00:32:35,080 --> 00:32:40,440
closer to the line. 
The nuclei templates used to be 

578
00:32:40,600 --> 00:32:43,560
published well after the Kev was
published, but now those are 

579
00:32:43,560 --> 00:32:46,240
falling down to like being 
published same day of. 

580
00:32:46,560 --> 00:32:51,520
And the reason for that is the 
project discovery people run run

581
00:32:51,520 --> 00:32:56,400
a little bug bounty for for 
exploits against certain kinds 

582
00:32:56,400 --> 00:32:59,120
of vulnerabilities and Kev 
listed as a kind of 

583
00:32:59,120 --> 00:33:03,920
vulnerability and so. 
And money is a good motivator. 

584
00:33:04,120 --> 00:33:05,960
So there we. 
Go they are now. 

585
00:33:06,160 --> 00:33:10,040
Sure, I have my own thoughts 
about how bug bunnies work and 

586
00:33:10,240 --> 00:33:14,280
in the age of AI slop, but 
generally speaking, the nuclei 

587
00:33:14,280 --> 00:33:15,720
stuff does tend to be pretty 
good. 

588
00:33:16,520 --> 00:33:19,680
There's a good community there 
writing like good good templates

589
00:33:19,680 --> 00:33:22,520
and not relying on just like 
automatic Yolo. 

590
00:33:25,440 --> 00:33:27,400
But those lot but like it's 
really funny. 

591
00:33:27,400 --> 00:33:32,560
It's fun to see like as Kev 
moves along and and expands out 

592
00:33:32,560 --> 00:33:36,520
to more technologies, how the 
the public exploit development 

593
00:33:36,520 --> 00:33:41,320
starts to coalesce around it, 
How CV ES are all over the place

594
00:33:41,680 --> 00:33:43,320
for a cab, which is another 
funny thing. 

595
00:33:43,320 --> 00:33:44,960
Like you'll see things listen on
Kev. 

596
00:33:45,120 --> 00:33:49,600
Like, it would not surprise me 
tomorrow to see like a new 2008 

597
00:33:49,600 --> 00:33:51,800
vulnerability. 
Like, listen on, Kev, because 

598
00:33:51,840 --> 00:33:55,720
old exploits work. 
Yeah, you will find you will 

599
00:33:55,720 --> 00:33:59,240
find it in the wild. 
And so then when SZA learns 

600
00:33:59,240 --> 00:34:01,800
about the exploitation, gets a 
chance to inspect the evidence, 

601
00:34:01,800 --> 00:34:03,240
see that the patch actually 
works. 

602
00:34:03,280 --> 00:34:04,600
Like, it will get out to the 
cab. 

603
00:34:04,600 --> 00:34:06,840
And that's just, and that's just
kind of like they don't really 

604
00:34:06,840 --> 00:34:09,800
care. 
It doesn't matter if it if it 

605
00:34:09,800 --> 00:34:12,480
was patched 10 years ago or this
week. 

606
00:34:13,360 --> 00:34:16,040
No it doesn't. 
And you see those like fairly 

607
00:34:16,040 --> 00:34:20,320
regularly if you pay attention 
to the Kev addition like RSS 

608
00:34:20,320 --> 00:34:23,440
features around. 
Yeah, pretty routinely. 

609
00:34:23,679 --> 00:34:25,719
Yeah, 08 is actually a good 
example. 

610
00:34:25,719 --> 00:34:30,280
Like you could probably find 
several Microsoft like 2008 bugs

611
00:34:30,280 --> 00:34:34,280
that have been added to the Kev 
in the last six months per year 

612
00:34:35,639 --> 00:34:37,560
every time. 
I see one surprising, I would 

613
00:34:37,560 --> 00:34:41,719
say like the other thing that 
really that jumped out at me. 

614
00:34:41,719 --> 00:34:45,600
It was a surprise when you 
bucket all the Kev 

615
00:34:45,600 --> 00:34:50,040
vulnerabilities into just like a
series on EPSS scores. 

616
00:34:50,040 --> 00:34:53,320
So EPSS is exploit prediction 
scoring system chance that 

617
00:34:53,320 --> 00:34:55,480
you're gonna get exploited in 
the next 30 days. 

618
00:34:56,080 --> 00:34:58,760
It describes a really fun 
inverse bell curve. 

619
00:34:59,000 --> 00:35:03,440
So like 90 to 100% over well 
over represented, right? 

620
00:35:03,440 --> 00:35:05,880
Probably gonna get popped again 
with this somewhere in the 

621
00:35:05,880 --> 00:35:09,120
world, right? 
But then and then it falls off 

622
00:35:09,120 --> 00:35:11,160
pretty sharply towards the 
middle and then it shoots up 

623
00:35:11,160 --> 00:35:14,720
again at the end where it's like
the zero to 10% chance. 

624
00:35:15,840 --> 00:35:20,880
Also pretty, pretty common to 
add those to the Kev and that's 

625
00:35:20,880 --> 00:35:23,800
fun. 
Like I, I and so like it tells 

626
00:35:23,800 --> 00:35:27,680
me that Kev actually does have 
pretty good visibility into very

627
00:35:27,680 --> 00:35:31,560
targeted attacks because and 
that's the only way you could do

628
00:35:31,560 --> 00:35:33,040
this, right? 
That's the only that's the only 

629
00:35:33,040 --> 00:35:35,640
explanation I can come up with. 
That's the only one I can think 

630
00:35:35,640 --> 00:35:38,640
of too, and. 
Oh, so you're getting 

631
00:35:38,640 --> 00:35:45,280
intelligence on exploitation 
that nobody sees other than you?

632
00:35:46,520 --> 00:35:49,320
This is what I wanted to ask you
about that specifically. 

633
00:35:49,320 --> 00:35:52,960
I'm glad you brought that up. 
Is I think that from the 

634
00:35:52,960 --> 00:35:55,760
outside, the public perception 
might be in that, you know, I'll

635
00:35:55,760 --> 00:36:01,440
just say for myself, you might 
think like, OK, I hope that the 

636
00:36:01,440 --> 00:36:04,880
federal government has some 
insights into this stuff that 

637
00:36:04,880 --> 00:36:08,920
maybe we don't have and have 
intelligence signals that we 

638
00:36:08,920 --> 00:36:12,960
don't have about exploitation 
because they run a massive 

639
00:36:12,960 --> 00:36:17,240
signals intelligence operation 
and a bunch of other things. 

640
00:36:17,320 --> 00:36:20,840
The NSA is part of DoD, not part
of federal civilian executive 

641
00:36:20,840 --> 00:36:21,960
branch, right? 
Right. 

642
00:36:22,760 --> 00:36:25,840
They're friends. 
Yes, they know each other. 

643
00:36:25,960 --> 00:36:29,840
Yeah. 
And you tend the, the federal 

644
00:36:29,840 --> 00:36:33,720
government would tend to get 
information from, you know, 

645
00:36:33,720 --> 00:36:36,880
people that might have been 
victims of targeted attacks or 

646
00:36:36,880 --> 00:36:40,240
they're seeing the same Intel 
signals from, say, Citizen Lab 

647
00:36:40,280 --> 00:36:45,400
or EFF or whoever it happens to.
Be tag or Yeah, yeah. 

648
00:36:45,600 --> 00:36:48,840
Tag. 
So yeah, like those in some, 

649
00:36:49,040 --> 00:36:53,800
it's not every case, but the 
sources of intelligence on this 

650
00:36:53,880 --> 00:36:57,600
just run the gamut, right? 
Classified to unclassified TLP 

651
00:36:57,600 --> 00:37:03,200
rainbow concerned researchers 
that see something weird on the 

652
00:37:03,200 --> 00:37:04,960
Internet, right? 
Yeah, it's everywhere. 

653
00:37:05,840 --> 00:37:09,520
And so this is one of the 
reasons why, by the way, Kev 

654
00:37:09,520 --> 00:37:11,840
doesn't really do a lot on 
attribution. 

655
00:37:12,720 --> 00:37:14,560
Another thing, Kev gets dinged 
at all the time. 

656
00:37:14,560 --> 00:37:17,280
It's like, well, if we 
attributed everything, I see 

657
00:37:17,280 --> 00:37:20,000
where, you know, it's good to 
give credit and it's good to 

658
00:37:20,000 --> 00:37:22,480
like tout your public private 
partnerships and all that. 

659
00:37:23,320 --> 00:37:27,000
If we started attributing 
everything, it'll get real 

660
00:37:27,000 --> 00:37:30,040
obvious real fast of which ones 
come from classified Intel. 

661
00:37:31,160 --> 00:37:32,720
Those ones will not get 
attributed. 

662
00:37:33,120 --> 00:37:36,200
So don't super want to put like 
a big target on that. 

663
00:37:37,360 --> 00:37:39,600
Yeah. 
Because like every once in a 

664
00:37:39,600 --> 00:37:42,720
while, well, I guess it's, I 
don't know, you see it every 

665
00:37:42,720 --> 00:37:44,960
once in a while in the Microsoft
advisories. 

666
00:37:44,960 --> 00:37:49,720
Like they'll thank the NSA like 
explicitly sometimes, you know, 

667
00:37:50,000 --> 00:37:53,000
and NSA puts out, you know, 
public advisories every once in 

668
00:37:53,000 --> 00:37:54,680
a while too. 
And you're like, yeah, OK, 

669
00:37:54,680 --> 00:37:56,240
that's something to pay 
attention to. 

670
00:37:56,280 --> 00:37:59,360
Like if they're being that. 
NSA is making a big deal out of 

671
00:37:59,360 --> 00:38:00,560
it. 
I would say you should pay 

672
00:38:00,560 --> 00:38:03,200
attention to it. 
Yeah, it's a good investment. 

673
00:38:03,240 --> 00:38:06,560
Going out of their way to like, 
talk to Microsoft, then, yes, 

674
00:38:07,480 --> 00:38:10,440
right. 
Yeah, in a publicly attributable

675
00:38:10,440 --> 00:38:13,520
way. 
You know, that is the signal of 

676
00:38:13,520 --> 00:38:16,240
like, we would very much like 
Americans to fix this thing 

677
00:38:16,280 --> 00:38:16,920
right now. 
Thank you. 

678
00:38:16,920 --> 00:38:19,120
Yeah. 
We have a good reason we're not 

679
00:38:19,120 --> 00:38:21,680
selling wolf tickets like we're,
you know, we know what we're 

680
00:38:21,720 --> 00:38:22,680
talking about here. 
Yeah. 

681
00:38:23,720 --> 00:38:27,600
It reminds me a little bit of, 
you know, in a, in a different 

682
00:38:27,600 --> 00:38:29,280
way. 
You worked on Metasploit for a 

683
00:38:29,280 --> 00:38:34,760
long time. 
The the sort of default bar for 

684
00:38:34,760 --> 00:38:39,000
like shit's about to go crazy is
this was just added to 

685
00:38:39,000 --> 00:38:42,080
Metasploit. 
Like, you know, say 15 years 

686
00:38:42,080 --> 00:38:43,400
ago. 
That's the way that we would 

687
00:38:43,400 --> 00:38:45,960
look at things from the outside 
and be like, is there a 

688
00:38:45,960 --> 00:38:49,360
Metasploit module for this? 
Yes, OK. 

689
00:38:49,520 --> 00:38:51,080
It lowers the part of entry 
right? 

690
00:38:51,120 --> 00:38:53,040
Like. 
Exactly that was the argument. 

691
00:38:53,160 --> 00:38:57,480
Right. 
And it creates an incentive, a 

692
00:38:58,320 --> 00:39:01,800
little bit punitively creates an
incentive to please, for real, 

693
00:39:01,800 --> 00:39:04,520
patch this thing because like, 
literally everybody knows how to

694
00:39:04,520 --> 00:39:07,640
exploit it now. 
You know, everything's easy once

695
00:39:07,640 --> 00:39:11,600
you do it once. 
Yes, it's like putting together 

696
00:39:11,600 --> 00:39:13,760
IKEA furniture. 
Like God, I could have done that

697
00:39:13,760 --> 00:39:16,040
in 20 there. 
Are some metisplay modules that 

698
00:39:16,040 --> 00:39:18,440
are a little bit finicky and you
got to fiddle with them a little

699
00:39:18,440 --> 00:39:20,480
bit. 
And like sometimes you've got 

700
00:39:20,480 --> 00:39:23,040
like payload restrictions and 
all this other stuff that goes 

701
00:39:23,040 --> 00:39:25,520
into like sure, advanced 
metisplate usage. 

702
00:39:26,480 --> 00:39:30,600
But like the rule of thumb, this
was a a coinage from your friend

703
00:39:30,600 --> 00:39:33,480
of mine, Josh Korman. 
I am the cavalry. 

704
00:39:34,000 --> 00:39:38,600
This is HD Moore's law of you 
must be this tall and the type 

705
00:39:38,640 --> 00:39:43,000
is number of metasplate modules.
Yeah, to ride the Internet, you 

706
00:39:43,000 --> 00:39:47,640
must be this tall. 
And so I would say metasplate is

707
00:39:47,640 --> 00:39:50,040
a pretty good signal that the 
cat's out of the bag on this 

708
00:39:50,040 --> 00:39:53,560
thing. 
I talk about nuclei a lot. 

709
00:39:53,560 --> 00:39:57,640
We use nuclei templates in 
product at run zero and we 

710
00:39:57,640 --> 00:39:59,680
contribute back. 
We're like not just open source 

711
00:39:59,680 --> 00:40:01,000
leeches. 
We do contribute back. 

712
00:40:03,240 --> 00:40:08,000
But like a nuclei is is arguably
much easier to write in, 

713
00:40:08,000 --> 00:40:11,040
especially for like web app 
stuff, which Medsplate is not 

714
00:40:11,040 --> 00:40:13,240
great at. 
What Medsplate is good at like 

715
00:40:13,520 --> 00:40:15,320
stack based buffer overflows, 
right? 

716
00:40:15,320 --> 00:40:17,040
Like that's Medsplate bread and 
butter. 

717
00:40:18,480 --> 00:40:24,200
Nuclei I'd say is arguably 
better at, well, arguably easier

718
00:40:24,200 --> 00:40:27,160
to write exploits for for like 
web applications, right? 

719
00:40:27,160 --> 00:40:32,280
Because it's very HTTP first. 
Whereas Medsplate was like kind 

720
00:40:32,280 --> 00:40:36,640
of more telnet first. 
Well, it is from like 2003 or 

721
00:40:36,640 --> 00:40:40,400
whatever. 
Yeah, metasploit's still great. 

722
00:40:40,440 --> 00:40:42,160
And they're still doing good, 
good work over there. 

723
00:40:42,160 --> 00:40:45,600
And they've got like usually 2 
to 400 contributors doing the 

724
00:40:45,600 --> 00:40:48,720
thing and metasploit's still 
like a cool thing to list on 

725
00:40:48,720 --> 00:40:51,200
your resume, so. 
Yeah, I would. 

726
00:40:51,200 --> 00:40:55,800
I would say so, yeah. 
It is funny that it's crazy to 

727
00:40:55,800 --> 00:41:00,280
think about that, that that 
framework is well over 20 years 

728
00:41:00,280 --> 00:41:01,960
old at this point. 
And it was like. 

729
00:41:01,960 --> 00:41:03,360
I worked on it when it was 
Pearl. 

730
00:41:05,560 --> 00:41:07,280
You don't have to date yourself 
that hard time. 

731
00:41:09,800 --> 00:41:12,600
I remember when it came out and 
it was like it was 

732
00:41:12,600 --> 00:41:13,960
controversial. 
It was. 

733
00:41:14,080 --> 00:41:16,200
Like there were like 20 exploits
all in one. 

734
00:41:16,200 --> 00:41:18,920
It was amazing. 
When people lost their shit, 

735
00:41:18,920 --> 00:41:20,920
they were like, what are you 
doing putting this out in the 

736
00:41:20,920 --> 00:41:22,960
world? 
Like, you know, for, I don't 

737
00:41:22,960 --> 00:41:24,960
know, people that don't know the
history, go read the history. 

738
00:41:24,960 --> 00:41:28,040
But like, it was extremely 
controversial. 

739
00:41:28,040 --> 00:41:32,640
Like you know it. 
The the problem Metasploit and 

740
00:41:32,640 --> 00:41:37,680
Nuclei solve is like I would 
like to test the patch or I 

741
00:41:37,680 --> 00:41:41,080
would like to test my detection 
techniques with real with like 

742
00:41:41,080 --> 00:41:45,720
live ammo, right? 
And also I'd like to do that in 

743
00:41:45,720 --> 00:41:50,120
a safe a way that I can and so I
don't need to be pulling, you 

744
00:41:50,120 --> 00:41:53,880
know, rando. 
Please compile this C++ thing 

745
00:41:53,880 --> 00:41:55,560
from pack and Reddit. 
Or right. 

746
00:41:56,400 --> 00:42:00,000
Whereas in those like I'll get a
shell but also this guy will get

747
00:42:00,000 --> 00:42:02,960
a shell. 
That has definitely happened. 

748
00:42:03,200 --> 00:42:05,560
Everybody gets a shell. 
Everybody gets a shell. 

749
00:42:05,560 --> 00:42:08,760
Why not? 
And so like one of the things we

750
00:42:08,760 --> 00:42:13,120
contribute to nuclei here at run
0 pretty routinely is like 

751
00:42:13,120 --> 00:42:18,440
things that maybe, you know, 
they're they sometimes nuclei 

752
00:42:18,440 --> 00:42:21,640
templates don't clean up after 
themselves when they're doing 

753
00:42:21,640 --> 00:42:24,760
exploitation, which can leave 
like stuff like stuff like just 

754
00:42:24,760 --> 00:42:28,040
littered on the target that you 
don't really want stuff that 

755
00:42:28,040 --> 00:42:31,400
will like definitely like an EDR
in two weeks when they finally 

756
00:42:31,400 --> 00:42:32,520
update their signatures. 
Yeah. 

757
00:42:34,920 --> 00:42:40,000
So we'll we we're usually on the
janitorial side of nuclei 

758
00:42:40,040 --> 00:42:44,000
templates. 
I love that description. 

759
00:42:44,000 --> 00:42:48,040
That's great. 
Before I let you go, tell me a 

760
00:42:48,080 --> 00:42:50,040
little bit about the Kev 
Collider. 

761
00:42:50,320 --> 00:42:54,560
Yes, I'm glad you asked. 
So I read this whole paper with 

762
00:42:54,560 --> 00:42:58,120
like four or five different like
ways to slice and dice Kev 

763
00:42:58,640 --> 00:43:01,120
issues. 
And then I thought, well, that's

764
00:43:01,120 --> 00:43:02,720
cool. 
But this paper will get out of 

765
00:43:02,720 --> 00:43:06,320
date real fast. 
So we put together this web app.

766
00:43:07,240 --> 00:43:13,320
That is all it is, is a view of 
the Kev and we keep tracking, 

767
00:43:13,320 --> 00:43:15,280
right? 
Like we add whenever there's new

768
00:43:15,280 --> 00:43:19,520
Kevs, we updated and everything,
and we track the Cavs in a way 

769
00:43:19,520 --> 00:43:22,760
that like exposes all of the 
cavology that you just learned 

770
00:43:22,760 --> 00:43:26,800
about when you read this paper. 
And so now you try and so you 

771
00:43:26,800 --> 00:43:29,360
can and you can pick the things 
that are interesting to you in 

772
00:43:29,360 --> 00:43:31,480
that moment. 
So like, let's say you want to 

773
00:43:31,480 --> 00:43:34,080
just like focus on denial 
service bugs. 

774
00:43:34,240 --> 00:43:36,680
I don't know, you're weird that 
way and you just want to do 

775
00:43:36,680 --> 00:43:38,280
that. 
So you go through and you pick 

776
00:43:38,280 --> 00:43:41,760
the CVSS like, you know, 
availability high, you know, is 

777
00:43:41,760 --> 00:43:46,080
the, is the impact and just pick
that and then deselect the other

778
00:43:46,080 --> 00:43:48,600
two for extra fun, right? 
And so now you're left with a 

779
00:43:48,600 --> 00:43:50,880
list of like, I don't know, 10 
or something that are on the 

780
00:43:50,880 --> 00:43:52,960
cab. 
But now you know it, right? 

781
00:43:53,360 --> 00:43:56,720
And you can just like, and it 
loads in your browser. 

782
00:43:56,720 --> 00:44:00,720
I really like the tech in it cuz
it's all very static. 

783
00:44:01,120 --> 00:44:02,560
It loads everything in your 
browser all at once. 

784
00:44:02,560 --> 00:44:07,520
So like it feels very snappy and
all the filtering is expressed 

785
00:44:07,520 --> 00:44:10,560
as GET parameters. 
And so all you have to do is 

786
00:44:10,560 --> 00:44:13,520
like share this link with your 
friend and they will see exactly

787
00:44:13,520 --> 00:44:16,240
the same view that you see. 
There's no saving, there's no 

788
00:44:16,240 --> 00:44:19,480
session state, there's no like 
login or then certainly no like 

789
00:44:19,480 --> 00:44:21,400
pay wall or anything like that. 
Yeah, it's cool. 

790
00:44:21,400 --> 00:44:24,840
Like a test bench of like, hey, 
I was thinking like, what if I 

791
00:44:24,840 --> 00:44:30,640
took all the EPSS that is like 
in the 90th percentile. 

792
00:44:30,640 --> 00:44:35,240
So like very likely to get 
exploited according to EPSS, but

793
00:44:35,240 --> 00:44:38,200
also don't have a network 
component, right? 

794
00:44:38,200 --> 00:44:41,000
Like show me those. 
Like that's a cool thing to look

795
00:44:41,000 --> 00:44:42,520
at, right? 
Because that would tell you like

796
00:44:42,840 --> 00:44:46,280
your high value privilege 
escalation bugs essentially is 

797
00:44:46,280 --> 00:44:48,280
what that would probably end up 
being. 

798
00:44:49,000 --> 00:44:50,560
And then you can start looking 
for patterns, right? 

799
00:44:50,560 --> 00:44:52,800
And especially if you start 
looking at time, you look at 

800
00:44:52,800 --> 00:44:56,040
like the deadlines that says 
release because like usually 

801
00:44:56,040 --> 00:44:57,960
they release with like a 
three-week deadline. 

802
00:44:58,320 --> 00:45:00,360
Sometimes they release with a 
one day deadline. 

803
00:45:01,280 --> 00:45:03,520
Yeah. 
I want to take a look at those. 

804
00:45:04,040 --> 00:45:05,760
Interesting ones where you're 
like, oh. 

805
00:45:06,200 --> 00:45:10,280
Yeah, you can mix and match like
all of the all of these facets 

806
00:45:10,280 --> 00:45:13,080
and we expose like, I don't 
know, 15 or 20 of them. 

807
00:45:13,880 --> 00:45:16,680
So you can easily like configure
yourself into a place where like

808
00:45:16,680 --> 00:45:19,880
no hits. 
So then do that and then back 

809
00:45:19,880 --> 00:45:21,560
off a little bit, a little bit, 
a little bit. 

810
00:45:21,600 --> 00:45:23,440
Yeah. 
Start finding like the things 

811
00:45:23,440 --> 00:45:26,240
that, you know, pass your filter
for priority. 

812
00:45:26,600 --> 00:45:28,960
Again, you definitely want to 
patch everything that's on the 

813
00:45:28,960 --> 00:45:30,040
cab. 
You want to make sure that you 

814
00:45:30,040 --> 00:45:33,240
have something there, right. 
But for prioritization. 

815
00:45:33,240 --> 00:45:36,000
And it gets you into a place 
where you can start to see like 

816
00:45:36,320 --> 00:45:39,200
when there's a new 
vulnerability, like, oh, let's 

817
00:45:39,200 --> 00:45:42,000
see, like how it shakes up 
against my existing filter that 

818
00:45:42,000 --> 00:45:44,600
I've saved as a bookmark. 
Does it pop there? 

819
00:45:44,800 --> 00:45:46,680
Like, that's cool. 
I like that a lot. 

820
00:45:47,560 --> 00:45:53,240
Yeah, it's very cool. 
I was I I think the I probably 

821
00:45:53,240 --> 00:45:55,720
spent more time playing with the
Collider than I did actually 

822
00:45:55,720 --> 00:45:57,000
reading like the. 
Oh yeah. 

823
00:45:57,360 --> 00:45:59,680
Sorry about that, but no. 
No, no, no, no there. 

824
00:45:59,680 --> 00:46:00,760
I read the paper too. 
The. 

825
00:46:01,920 --> 00:46:04,640
Collider's lots of fun, and it's
called a Collider, so it's. 

826
00:46:04,720 --> 00:46:06,320
Called a Collider we're 
smashing. 

827
00:46:06,640 --> 00:46:08,560
Exactly. 
Vulnerabilities together and see

828
00:46:08,560 --> 00:46:10,520
what falls out. 
Yeah, and it's got like a cool 

829
00:46:10,520 --> 00:46:13,120
robot logo, so go check it out. 
It's got a cool robot. 

830
00:46:13,120 --> 00:46:16,440
It's got a, it's got Doctor Kev,
I think is the character name. 

831
00:46:18,080 --> 00:46:20,680
He's a mad scientist who is a 
part machine, I think. 

832
00:46:22,400 --> 00:46:24,120
I'd love it. 
This is great. 

833
00:46:24,360 --> 00:46:26,520
This is so much fun Todd. 
Thanks so much for your time 

834
00:46:26,520 --> 00:46:29,640
man. 
Go check out Todd's various 

835
00:46:29,640 --> 00:46:31,960
podcasts that last like 6 
seconds. 

836
00:46:32,840 --> 00:46:37,480
If you need if you need a quick 
six second break, one pieces is 

837
00:46:37,480 --> 00:46:40,840
for you. 
But I would be remiss if I did 

838
00:46:40,840 --> 00:46:45,280
not say the words runzero.com. 
Try try Runzero. 

839
00:46:46,000 --> 00:46:48,400
Go, go, go. 
All right. 

840
00:46:48,400 --> 00:46:50,240
Thanks so much, Todd. 
It was great to see you man. 

841
00:46:50,520 --> 00:46:50,840
Thank you.
