Cisco Systems, Inc. (CSCO) Earnings Call Transcript & Summary
January 24, 2024
Earnings Call Speaker Segments
Mark Watts
executiveHello everyone and welcome to the Art of Defending: How to Build a Comprehensive Threat Response Strategy webinar on what's your Webex producer. In a moment I will turn the session over to Gio Tan, but first I have a few housekeeping notes to cover. Please note, your microphone is being automatically muted, so feel free to ask your questions in the Q&A panel throughout the session. To view the Q&A panel, click the 3 dots on the lower right corner of your Webex window. And at the end of the session, a survey will automatically pop-up in your browser, please click continue to complete the survey, we really appreciate your feedback. With that we are ready, so let's get started. Gio, in a few seconds, it's all yours.
Gio Tan
executiveThanks, Mark. So hi everyone and welcome to this webinar today. So today you will be hearing from Carlos Diaz, who is a Principal Engineer at Cisco, as well as Rob Gresham, who is the Principal Technical Marketing Engineer at Cisco. So the webinar has been recorded ahead of time to ensure a good webinar playback experience for all. But if you have any questions while the playback is happening, please put it in the Q&A. We will be able to get through them through the webinar, or if not, post the webinar itself. With that, Mark, back to you to playback the recording. Thank you.
Emma Carpenter
executiveToday's session will involve a scenario in which 2 SOC leaders are given a task by their CIO. Let's get started. Hi, Carlos and Rob. I'm thrilled to have enlisted your expertise in our Happy Puppies Company. As you know, we need to deliver a comprehensive threat response strategy to the Board of Directors where I can get their approval for the next part of our security budget you'll be leading with your teams. I'll leave you to it.
Carlos Diaz
executiveThank you, Emma. Well, greetings, Robert, nice to meet you. I joined here before a month ago. I'm a detection engineer and lead, leading part of the SOC. And I'm looking forward to you joining the company so that we can get this important task done.
Rob Gresham
executiveThanks, Carlos, for bringing me on. It seems like she brought me on to basically lead and build the response plans and help with the automation of some of our tasks and kind of get as much efficiency out of our products that we have available. So I look forward to working tightly with you to help the SOC actually manage the processes that they need to manage.
Carlos Diaz
executiveLikewise, brother. Welcome aboard at Happy Puppies. So what I wanted to do is I wanted to bring you up to speed in your ramp up and tell you what I've learned in my first month here. And I also wanted to share with you what I believe the task is at it and for, right? Basically, we are going to defend Happy Puppies, and I personally think it's an art of defending against complex attacks. So I want to tell you a little bit about my philosophy, which will be a little bit of theory. I want to get into some practical scenarios of the most immediate trends I've learned in the last month. And then when I can pretty much discuss execution strategy moving forward. What are your thoughts?
Rob Gresham
executiveI think that really dovetails well with what we're trying to accomplish, right? We have detection and engineering, and then we have response engineering or response and helping the SOC. So being able to understand your theory and then tying that to -- I'll go do a likewise demo on the same capability on what we're trying to do with the security collection we have available.
Carlos Diaz
executiveGreat. Let's get right into it. So Rob, look, my philosophy about defending is that I think driving security programs has a unique persona at the center, and that is a cyber defender. What I find unique about cyber defender from other knowledge working professions is that you're essentially like the 911 operators, and they require key decision-making points in order to do the right things to defend. What I've learned in my career as a defender is that it's comprised of 3 strategies: prevention strategies that I put in place to try to be anticipative or enjoy a proactive stance, detecting circumstances or concerns that are relevant to my business, so basically, I need to identify credible concerns, and most importantly, in the event that my mechanism have been bypassing prevention, having enough time to respond and confront the harmful risk that we may be faced with. I firmly believe that it's very hard to scale a SOC in humans, so we have to be very particular and selective about the controls we apply for the worst vulnerabilities so we can defeat the most significant threats that harm the business. That's at the hard what I believe. What are your thoughts about this?
Rob Gresham
executiveWell, looking at what you're presenting here, it kind of takes me to how we play with our tools, right? How do we make these tools work for us? When we're looking at prevention and anticipating, that means we have to have a good threat assessment and understanding of what our attack surface looks like, also what threats are targeting us. That allows you to create and identify good detections that help us do a better job of defending. Then you're just not taking stock in every miter TTP or tactic. You're basically pulling the ones that are important for us. And then I'm building response capabilities to confront that, whether they're with you proactively in a prevention scenario or reactively in a response scenario of being able to go, okay, I got to investigate this, I got to find it. But we also do threat hunting across the way. I think all of these things are defending in the grand scheme of things. So I agree with you 100%.
Carlos Diaz
executiveSo listen, before we move on to the next point, I just wanted to ask you, the role of CTI in this entire philosophy of defending, right? I believe that defending and the usage of CTI has to allow us to take effective actions in the sequence of events or the sequence of an attack as it progresses. So if I design an effective defense status, it relies on visibility, correlated detection so that you can have the best confirmed decision-making power to apply those actions to degrade the impact. Do you have experience with that particular site of response?
Rob Gresham
executiveYes. A lot of times we use like, I don't know, call out a friend, right, David Bianco, who uses Pyramid of Pain. We want to move up the top end of that stack. We want to be able to take like cyber threat intelligence and actually hone in on those TTPs and tactics and techniques and not necessarily the IP addresses and hashes and domains that maybe advisers are using because they're pivoting fairly quickly on that. I totally agree.
Carlos Diaz
executiveGot you. Okay. So I think in that sense, effective defenders are those that understand how to put their actions to defend in the right sequences before it gets to too late. Let me illustrate this concept for you in the next slide. See, I think that before we invest in implementing those controls and spending time writing detections, I think we need to understand is how to design an effective security architecture or system. So I read this book by Winn Schwartau called Time Based Security. And what I found in that book is that an effective formula he describes is P greater than D plus R. And that's basically his way of demonstrating a rigorous aspect of saying an effective security system is the one that allows you to have enough time to respond, very similar to like fire rating doors and buildings that can resist heat temperatures or fires, et cetera. I found that to be riveting because I want to show you what I found here in the first month of Happy Puppies, right, with Systems C and B. My initial assessment in the last 30 days has been that Happy Puppies has similar investments to detect and prevent, but the way that they have been operationalized is very little prevention, sort of small balance detection in some areas, but there's constant reactivity. So then the immediate improvement I made was moving them from System C to System B, which is I want to get more confidence detection, but we're still finding ourselves where we are responding significantly. So I'm concerned that the amount of humans that it takes to keep up with the threat paradigm has to really account for what Winn Schwartau describes as buying yourself enough time by first applying prevention.
Rob Gresham
executiveI totally agree with your use of using Winn's work. I learned it in SANS at a course that I did on Defense Architecture. So I'm totally enthused that we're using technologies or thought processes and methodologies that are just not pulled out of thin air and experience but actually things that have been used and stand the test of time, right? Because we're principle-based in the grand scheme of things. So totally aligned with you on this. I've seen this before, so I totally agree where response actually creates the environment that you're not moving enough stuff to prevention, right? You're responding so much that you're not creating enough detection or enough prevention. You're not doing yourself a service, right? And then when you have too much detection, you're filtering what you can respond to, but you're still not making that piece. We've got to have that way where if we solved for what does prevention equal, it's detection and response outcomes equals prevention. So if you understand that your detection and response gives you a certain capability to react to that object, how do you move that into a prevention? But the question is, Carlos, I've always had a hard time. Maybe you can explain it to me. How do we move that? How do we move that bar?
Carlos Diaz
executiveOkay. So given that you just joined Happy Puppies, I think that there's a contract between you and I, right? You're the R guy. I'm the visibility and detection and prevention guy. So I think the first thing is to understand what is the R composed of. And I basically think response is all about the actions you take on the technologies we have at hand. But to give you enough time to effectively design that, I think we don't need to understand the amount of actions like you can block, you can restrict, you can apply privileged password reset, and like those are the actions. I think that that's an infinite deep rabbit hole. Then what's most important me to understand is when do we use a particular type of actions. Like for example, if I block an IP address during the attack, I think we're back in System C. We're reacting, right? Versus if I know that I can block an IP consuming CTI or some other types of TTPs, but I block before the attack occurs, then I think we're getting to Winn Schwartau towards prevention giving you enough time because proactively we're stopping the threat from progressing. So I think that's the key first, the attack life cycle progression, before, during and after. If we can understand when those actions would put them in that life cycle, then we're able to predict the third column there of the degrading effect we have against the threat. Let me illustrate that for you with a more concrete example on the next slide, right? So because I have an endpoint background, Rob, I'm very strong on endpoint. I'm depicting you here how I leave my endpoint team here at Happy Puppies. In the center, we have the 13 rounds of capability that a computer offers to an adversary. Basically, you've seen from the bottom up the numbers increment. And so if the adversary can basically walk that entire ladder all the way up to #13, they're clearly in a position to cause harm on that particular system, right? But on the left-hand side is these actions that I was just talking about. And I think you need to complement me here, but it's like when do I block? When do I restrict? When do I observe? I offer you a mini cuts example that steals memory credentials. So when I can map out the way that particular mimic has threat, behaves in the operating system with those 13 dimensions, I can then carefully select the actions that will dismantle that particular malware's capability. Does that make sense?
Rob Gresham
executiveAbsolutely. Tell me more.
Carlos Diaz
executiveOkay. So like I was saying, you have defensive actions N plus 1 based on the products you buy. You don't have a problem with the absence of capabilities of products. The problem is the prioritization and when to use those particular actions purposely aligned to before, during or after. So if you can just animate that slide, here's where it boils down to. I'm depicting there for you with the arrows map to the scenario of Mimikatz, you've got to 2 actions. You're either going to apply a restriction or you're either going to provide a detection, right? And just with those 2 actions out of the 6, notice the difference in the column of when back to the attack's life cycle. By applying the restriction against the privilege of users, meaning admin accounts where Mimikatz can successfully read the memory, I apply it before, I'm now backing Winn Schwartau's Time Based Security. We're in the green. We're buying selves enough time. But if I fail to realize that, and I'm just setting privileges doing the incident, this is where the problem of scaling with humans lies, right? And the same will be true for detection. Now what's most important here is that I don't think we want to have Happy Puppies learning through failures. And that's what the introspective side of the degrading effect is. Naturally, we will learn some, but the goal will be is not to make it the main way that we learned, right? So introspective prevention isn't necessarily advancing Happy Puppies towards a more proactive, a more resilient posture. So in essence, this is where a lot of my skill set is going to stop because I'm not a response expert like you, but that's what I'm thinking I need to understand when I give you correlated detections, I want to give you high context visibility, so you can actually tell us what are the response mechanisms we need to use.
Rob Gresham
executiveAbsolutely. So this is where you start talking about countermeasures -- active and passive countermeasures, where we do things ahead of time because we know them -- we, as a team, have to understand what countermeasures are in play actively as the attack is going. So what objects are being blocked, for example, like your previous example of, hey, I'm going to block this IP address. And you're blocking, say, a known C2 IP address. Well, that just tells me that there's malware on that box, that I still have a problem that I have to resolve. I still have an investigation that's required in order to clear the adversary out of the area, I've got to push them all the way out. So there's some more processes like what am I going to do moving into that. Am I just going to start restricting user access? Are they moving sideways? There's different techniques or tactics on the defender side to actually degrade the analysts or degrade the adversary's movement inside our environment. Sometimes when it's a rapidly moving adversary, you want to take out the credentials first before doing quarantining the system. It's an assessment at that point. And I think you've got good idea of where we need to go between restriction and detection. But tell me more how this works with our tools that we have currently?
Carlos Diaz
executiveYes. Let me actually tell you, I think that what's important is we needed to assess that technology to put this into motion. It has to give us flexible and granular access so that we can take those actions in different mix/match combinations to create defensive playbooks. But at the heart of it, it's got to be the context of the visibility. So let me walk you through the scenario now in how to put the current investments we have. I think here the key is back to CTIs and threat intelligence, is that can't be the main way that we pursue detecting things because I think what you said about Mr. Bianco, I just looked him up, brilliant paper on that Pyramid of Pain. IOCs are just telling us isolated symptoms. But if we're going to get into giving you these response actions pretty much in an expedited way, we have to know how to make sense of those IOCs, how they're interrelated and how they will play out. And that's why in context, we got to understand the scenario. Now one way that I'm going to do that for you is I'm going to take those logs and I contextualize them for you. I'm going to put these things called minor tactics that basically help us get a human rational level of where the key stage would attack R, but I'm also going to be using very specific ways to correlate the objects, the IOCs that you see in there into how they're relating, et cetera. My attempt is to give you a way to understand key sequences that unearth strike paths of what the detectors are telling us because if I can do that for you, then you should start deriving a level of understanding of the threat intelligence that we're consuming. So naturally, if you have understanding, you should be in a position to start evaluating the defensive mechanisms that you can take an action against that threat, right? And so here's the same attack. However, these are the 5 products that we have currently invested with Emma or CIO. We have EPP for prevention, application change control on the endpoint, that's me now, your colleague. We have James over there on the proxy. We have Leandro, who is also working on the EDR. But essentially, we want to know is how to put these products to work against this threat with the right sequence of actions to respond. Like the example there where we're going to need your help is, well, how do I use the application change control to apply meaningful restrictions, hopefully to dismantle the attack early enough. Or are there situations, Rob -- this one is critical for you. Are there situations where we just can't prevent things because we risk outages, but it's meaningful enough to observe and detect with confidence and then hopefully, we can prioritize the review of those alerts and take a response because we have reasonable suspicion. So in essence, these are the tools that were bought in Happy Puppies, and we have deployed them officially today. They're working but where you're going to be very valuable for our team is helping us figure out in that sequence we outlined is the correct one for a credible concern at hand.
Rob Gresham
executiveIn theory, these all works in a perfect world, right? We all know that the data is missing sometimes, and we're missing certain visibilities. When we don't have the right architecture and right capability, what's your recommendation for kind of bridging the gap in those pieces?
Carlos Diaz
executiveWhen we don't have the right architecture -- sorry, I have [ to restrict the walk ].
Rob Gresham
executiveYes.
Carlos Diaz
executiveWell, I think that bridging the gap there is going to be highly reactive when you don't have the architecture until you get it to where you want it to be. But I think in essence, it comes down to applying controls in key areas until you start segmenting other bigger parts of your architecture. Like for example, segmenting appropriately with network, switches, routers, that's a much higher effort until you get to the desired end state. So I tend to take a very data-oriented approach to start preventing heavily on the endpoint, minimizing the opportunity to react, right? Because if I don't protect the endpoint with the high-risk aspect, like viruses, Trojans, worms, then I may not have the desired network segmentation. But if I don't protect the endpoint, these types of threats will run rapid in my flat architecture.
Rob Gresham
executiveAbsolutely. So what you're telling me is that really effective detection can unearth these harmful attack sequences, right? But I need to know more about this whole contextual correlated thing. I have an idea. I could share it with you. Are you willing to listen and kind of give me a thing? Because I'm not trying to tell you how to do your job. But I've learned something in this process of being on the receiving end of content. And the better content -- context you give me is an awesome way for us to progress forward, right? Because if I get the right content, I can react lot faster and stop a harmful attack that's coming because I'll understand exactly what's coming on. And I don't have to hunt through amounts of raw data to go put the pieces back together.
Carlos Diaz
executiveYes, Rob, let me be extra care with you, brother, as we welcome you here to Happy Puppies. I know how to do the correlation activities in the systems attributes. Where I struggle is knowing what are those things that I need to correlate? So as long as you can guide me there, we're an open book for your wisdom.
Rob Gresham
executiveAwesome. Well, let me talk to you about like what we think about correlation, aggregation and enrichment, right? Enrichment is one of those powerful things that we can use upfront, but when we're talking about correlation, we're talking about matching those observables together, right? When we do this matching process, it gives us the context that if it's a duck and it quacks like a duck, has legs, has wings, sits in the water, it's generally a duck or some foul thing in my environment for lack of a better fun that I can come up with. But the reality is it will demonstrate something is happening wrong. And then at that point, I need to be able to correlate that with things that are already occurring in my environment. What is the life cycle of those threats? Is it early in their life cycle? Is it later in their life cycle? Are there already alerts already set forward? I need that kind of aggregation through time and status because you may have sent me a high priority alert that's getting low fidelity alerts coming in. And I need to be able to see those additional alerts coming in because that will tell me if I'm effectively doing containment or I'm really horrible at it, which can happen sometimes depending on how well your processes and tools like. You see a polymorphic malware and you don't do good malware analysis on the actual executable. You could end up blocking something that just isn't really helping you contain that incident. And then lastly, we -- I love you, and I really want to appreciate your work and efforts, but I also need to trust and verify. So while you're using whatever enrichment tools that Emma has bought, I want to be able to third-party expert take in other additional context and be able to analyze on top of it to validate those key enrichment capabilities. It's not because our threat intelligence isn't the best in the world, it's more of I need confidence that I'm -- that intelligence is not only awesome, but I can add more value. And then especially when you don't know something, maybe these other tools might give me a little bit of a kick in the right direction, so I can react to the investigation as needed when we don't have all the information that we're looking at.
Carlos Diaz
executiveI think what I just learned through you is that it's more important for me to know how to correctly describe the things that I'm going to correlate and then also how to characterize the things that I have collected so that I can put it in your hands with the right level of confidence, the right level of criterion and the right level of basically understanding. Did I get you correctly?
Rob Gresham
executiveYou get me so perfect. And naturally, you picked me up on my next slide, is basically I needed to kind of talk about this whole behavior characteristics thing. We started with this idea of ABCs of objects, right? A, objects have attributes. They do things. They have a behavior. And then they have characteristics, what kind of object is it. And a lot of times raw data doesn't provide -- it provides a lot of attributes. And maybe it provides some behaviors, but characteristics are lacking, or we need to drive characteristics or context between attaching known behaviors or known characteristics or even attributes together. Like for example, the duration of an attack is the start time and the end time of something, that's a derived behavior. And we -- that gives us context about what's happening. Does any of this make sense to you? Or is this way odd?
Carlos Diaz
executiveWell, let me see if I understand now. Now I got the e-mail you sent me a couple of weeks ago when you were talking about this ABCs concept. So I think I want to understand is that characteristics is the way that we humans in the SOC tend to speak. Like for example, this program is malware or this program is elevated, meaning that RAM would increase privileges. That's important to describe the alert to a human that's an expert in cybersecurity. But what I love the most based on designing systems for prevention and detection is this part you're talking about behaviors because now you're telling me that there's a way to create like a taxonomy or dictionary, you use the process here. But you tell me that a process can create a registry key and that allows me to pretty much see the things I need to prevent for. So it's kind of like I'm having a guided way to understand the requirements as an engineer. Did I understand what you're doing here right?
Rob Gresham
executiveYou hit the nail on the head again. I mean, dude, we're going to have a great time defending Happy Puppies because I think that we're going to just be kicking people out, or kicking adversaries out as much as we possibly can when we see them. So -- but I have a question for you. If this is a really solid methodology and a capability, what is it that you see here when I show you this? And this is a friend's tool that they brought up, and they kind of showed me. And I was like, this is awesome. This gives me the kind of thing that I need to work with. But how do you see it? What do you see?
Carlos Diaz
executiveWell, to be honest with you, I see it's obviously based on the color, I see a very clear emphasis on perhaps what's important in the picture. But the thing that strikes me the most, and not for anything, I start to relate that to your ABCs, like for example, the executed. It's the fact that behaviors are being described there or actions are being described, right? And I think I can just clearly see that this is some form of cyber activity because I recognize Outlook, Winword, and essentially the rest of the chain. What am I looking at here?
Rob Gresham
executiveWell, if you're an adversary looking for a place to go steel credentials, you would pick up really quickly that Rubius is a kerberoasting tool, right? And that we're losing credentials right here. This changes the game on how I respond with a credential theft against a domain controller or some object. Now I have to start looking at identity. I can't really look at the host anymore. I can't trust the identities that are in the environment that are in this attack path. So it's all the identities that are related to that piece, but it's also did -- was the Kerberoast execution successful? Did they get a golden ticket? If they did, then I got to respond fast and different and very different than what I would in a normal malware-infected environment, if that makes sense.
Carlos Diaz
executiveSo having heard you speak in the previous slides, I think what you're showing me here and as a detection engineer lead, this represents the world class outcome that I need to engineer for. Now I understand what you're talking about correlated context. For example, in my world, we have the skill to do that is, I need to track process payers like Outlook to Winword. We have -- we consume today Windows event ID 4688. We noticed that you typically get a process pair. So this tells me that I need to basically correlate process payers to build this path that you're showing. And most importantly, I think just show me the relevance that user identities are crucial in the context of identity, so you know how to take that response action for credentials be installed. That's what I think I now got clearly from what you were telling me earlier.
Rob Gresham
executiveAnd again, Carlos, you and I are seeking up on spot every time -- at this point where we're starting to move through this. This doesn't happen in every org, so it makes kind of awesome that I get to find a peer where I'm working together that we're actually seeing the fruits of our labor from visibility driving to detection, detection driving to understanding. So I can react accordingly. But when we look at this, sometimes we've got to look at what this correlated context needs, right? It needs multiple sources. And we need to be able to tie these attack sequences together in each component as we drive along this problem. So whether it's e-mail, DNS records, EDR, NDR tools, this new tool that Cisco gave us called Network Visibility Module or even net flow data, right? And then everybody is like, oh, PCAP [ entered ], it didn't happen. Maybe not. I mean if we can create that context from the data, maybe I don't need to keep every PCAP that goes on. Maybe I just need to see all the pieces together, that correlation that we talked about and pulling those pieces together. So if we say like spear phishing happens, you get an e-mail, maybe it's a good/bad, maybe it's tagged, maybe it's intent from that e-mail vendor. And then we turn around and we see the redirect from our -- maybe it's secure access or even Zscaler or another tool coming into place, and we see that capability. And then it doesn't matter what EDR vendor we choose. Most of them give us process injection, some kind of domain account information. And then we're watching and collecting all the network visibility capabilities that we have in that detection response tool to get system network connections from the NDR vendor, but also that NBM tool gave us that lateral tool transfer, seeing that lateral left to right movement happening on those hosts. And that was powerful because it also gave us the processes that, that lateral movement was using in that 2 pair tool you were talking about, but also it gives us user accounts of the system at the time and what was the process user that was actually using that, whether it's admin credentials or elevated credentials in that space. So if we can take all of this data content, drive into that particular solution, we'd have something powerful. Would you agree?
Carlos Diaz
executiveI would agree, but then I just want to validate here because I'm getting excited about the correlated context as there are many products. So going back to your attribute behavior and characteristics, you only showed us a process application applied to that. Are you saying that your methodology has all the objects for the e-mail domain, the DNS domain, the NDR domain, et cetera, it can scale up to that? Because if the answer is yes, then I feel confident I can take the telemetry, contextualize it with those behaviors, those characteristics, and I can build this particular slide.
Rob Gresham
executiveI think that we have the context and the smarts and the capability to build this. But I was getting a demo the other day from Emma, which she brought me in on a technical review of a particular product. And I want to show it to you because they gave me like a little click-through thing that I can walk through and kind of show it to you. So I want to show you and see if this really kind of lines up to what we were talking here. So as you can see here, this is an investigation view of this particular incident that we're looking at. And right now, we don't see a lot of context in this piece. And I can move through the object and kind of give you an overview. But when I was playing with it and looking at it, it's an example of a wizard spider attack. And if you're familiar with them, might or ingenuity used them in Round 4 as an evaluation of EDR, so we can see how good EDRs are working and whatnot. And with this particular Cisco XDR product, they kind of showed us this piece here. And I just honed in on this particular one because when I found it, it was a familiar process that we know well, right? It's on d.exe, it was like holy cow, that's a valid process. I would miss that in most detection. So what makes this suspicious to us, and it already identified that it came from users public. So then I'm like, oh, wow, what else has this been used on this system? And the best part of this is that we got the whole attack. Even if I drift down -- I'm sorry, moving up -- if I drift down to the bottom here, I can see the whole entire attack time line from end to end over the period of what has happened. And I was like, okay, this is pretty awesome. Now the question is that can we feed our data into this product, get it into the right way so that they can actually ingest it and produce these outcomes. But I needed you to do a technical assessment on it and make sure it's actually delivering the results that we see. Does this fit in the same methodology that you have that I have?
Carlos Diaz
executiveYes, this definitely fits in. And I think what I'm appreciating is all of that dense detail seems to be that correlated context that you were emphasizing for effective response. Does this allow you to take any response actions immediately from the screen? Because naturally going to pick a response action.
Rob Gresham
executiveYes. Absolutely. I could take a response action. If I just needed to immediately go, I would just go here, pick an attribute of that object. If it was the Cisco Unified connector or the idea of the AMP good and then I can move into an AMP process and I could actually start stopping any traffic or run an automation workflow, moving it to a triage group, automatically hereby using integrated orchestration. But the key here for me is really identifying the investigation. We're going to talk more about my response capabilities and where this comes in because this was really a powerful point of view of just validating the data and the tooling that you're bringing to me, not that we're not building our SIM logging capabilities. But if we could use this to augment, you could focus really deeply on those custom use cases that this tool doesn't cover. And then feed it the right data so that when we need to do an incident or do an investigation, we have the right data in the right context to actually go right into an investigation, go into a containment mechanism and go right into getting the business back up and running again, if need be. What does that sound like?
Carlos Diaz
executiveYes. That's pretty impressive. I like that entire correlated context. So I told you what I'm capable of. I'll tell you what I'm not capable of. But you're already impressing me on how to move forward. So bring me forward into what are your requirements that I can design the best effective system aligned to time-based security.
Rob Gresham
executiveSo when we start to get to response, response is best when we understand the who, the what and the how, in order for us to apply effective counteractions at the time that we need it. Like that Rubius thing that we just talked about as a lead-in, most incident responders would lead to containment first. Why are they going to containment first? Because the endpoint is responding to containment. But Rubius is a bigger problem. You have to be able to be an experienced incident responder and have dealt with that to know that this is an attack against your active directory environment, and you need to respond quickly. And meaning quickly is meaning you can't let that attacker keep that golden -- holding Kerberoast key for long because that golden ticket is going to cause us a lot of problems, even to -- maybe to the point that we have to rebuild the entire environment. So if you could roll the active directory environment fairly quickly, you could probably keep the attacker out for a few minutes and maybe an inconvenience to your environment, but it would be keeping a lot of expensive pieces here. But again, I'm going to take that friend's demo here and show me that different piece. We expanded a little bit more. We gave it a little bit different perspective this time. This time I just highlighted all the executable capabilities and what objects are connected. And if you can see the telemetry pieces that pull the richness, that pull all of this together, gives me a much bigger picture, not only just from the strike path perspective of where Rubius was in and how this whole process went end-to-end. But seeing all these other objects, even if you took Rubius out of the equation, I get to see the attack. I can see the progression of it. Does that make sense?
Carlos Diaz
executiveThat makes sense. And I'm already thinking countermeasure mode is to use my [ hospice ] firewall against non-signed Microsoft processes or nonessential processes or products I bought and block LDAP connections inbound to the domain controllers.
Rob Gresham
executiveAwesome. That's a great way to think about this going forward. So -- but let's talk about -- more about what the SOC problems when we're going into response and actions and capabilities. So when we talk about SOC and response, a lot of times we forget that investigation is part of response. An investigation is mired in the ability to understand the detection to be able to find those attack paths, stitch them together. And a lot of tools that we have in the industry today don't stitch the tooling together to show you the attack sequence. They tell you miter. They throw a bunch of alerts on the screen, and we'll give you an example of it. But they throw alerts on the screen loosely, and then you have to drill in and kind of pull those pieces together. But when you're looking at response and you tie that investigation, the investigation capability is not really easily mapped to MITRE and that's a difficult process to handle, right, when we tie those pieces there. And then as we higher actions, what are the things that we're going to do that custom things for Happy Puppies, the problem we have is that we can't find the bad guy in this particular space so we need to go do a particular thing and stop and remove it and recover systems. What is the procedure? And how do we integrate these 3 things together? And that's where response comes in, right? And I need to be able to action your tools and build into those APIs, build into those workflows and organize this so that people aren't doing the same thing over and over again, right? It's not somebody do an index equal star on our SIM tool or they have these reusable components that they can work that are based on outcomes. What do you think about that? How do you see that integration process?
Carlos Diaz
executiveI see it fairly fluid. And honestly, I just had no idea that the MITRE ATT&CK framework doesn't necessarily have a correlation to PICERL. I think that's how you pronounce it. And it makes complete sense that detection alerts context like attack framework aspect doesn't necessarily relate to the right actions for the techniques of the framework. That's just riveting to me. Thank you.
Rob Gresham
executiveYes. And for some folks, they don't know what PICERL is, maybe you don't understand it. It's probably an acronym and buzzword that we throw out there. It's Preparation, Identification, Containment, Eradication, Recovery and Lessons learned. It is the full cycle of your acronym P greater than D plus R. But it's actually the task and the organizational tasks and process and procedure that put those pieces together. Much like MITRE is the framework for detection, PICERL is the framework for response from investigation all the way through.
Carlos Diaz
executiveThat's clear to me. Got you.
Rob Gresham
executiveAwesome. So let's take a scenario where we take legacy detection capabilities that we talk about in the normal. And normally, we would have 2 PCs. We get 2 beacons or 2 things. And then we'd have to go hunt and find that file or correlate the file from that beacon to that execution process because a lot of times, command and control is a network activity, like the DNS tool that we got. And it's false positive, and we pulled that back. How do we know what process? How do we know what component created that connection? Well, we get -- maybe we tie network flow to that data and then network flow comes in. But not all of these pieces are being created in a correlated detection. And in recent years, right, like you, there's a heavy emphasis on endpoint detection. And then the endpoint detection is basically like a ring maybe, like a ring doorbell at best that see somebody walking out the front door, but it can't tell you when it's being attacked from the left or right. It only tells you what's leaving the environment, not what's coming back into the environment and certainly can't correlate those 2 activities together for you. Now some XDRs are coming out with capabilities to do those, that's absolutely viable. Without this tool from Cisco that we saw was awesome and on point in that sense of being able to tie those multiple techniques and sources together to be able to create a capability. So when I walked you through initially is walking -- is talking about backwards chaining. The key piece to investigation and identification is taking that signal that you sent me. And then backwards, looking at that from the attack sequence that I know and looking for the thing that's missing. So I can fill in the gaps to understand, well, what's the process tree of this execution? How bad is this piece in? And that demo that we gave you that we had all the perfect data, that's great. But maybe I won't have the data. Maybe the EDR didn't detect it because what's the main focus here. The endpoint is trying to have defensive agent go on, right? The attacker, the adversary is trying to get in the environment and move without us seeing them. So as much as I appreciate your efforts in trying to go find them, but sometimes, you're going to miss. And that's okay. Can we ask the right questions to get the data to show me that process tree at that time if we have tools like network visibility module that watch like a rain, watching them leave the door, watching them come back in, and we can control -- we can see what visibility is happening on the endpoint network flow, then we've got a lot better chance of seeing them come in the door. But if they break in a window, we want to see them leave with the goods, right? If they're hanging out, we'll find them eventually. They'll trip over something else. So -- go ahead, sorry.
Carlos Diaz
executiveNo, I just wanted to validate that what you're bringing to bear here is an emphasis, we have to correlate in order to get that content like this doesn't work without correlation because you just missed the blind spots. Got it.
Rob Gresham
executiveSo if you take MITRE and you lay it over a full attack sequence, just like you were talking about earlier, when we start to see the whole pieces of the pie, all of this tied together, this gives us a good understanding of things that we need to move and how we need to see that. So let's take this example as an attack sequence, and we're going to play this out over response capability. So again, I bring you that piece here where my buddy brought this cool tool into play and gave it a life. The key here is that does this allow you to spot the lateral movement in that environment because it has enough information. I would say yes, right? In the lower right-hand corner, you can actually see -- I'm sorry, lower left-hand corner, you see the PC1 and then you see PC2, right? Directly diagonal to the right of it. And then you see the connecting IP address the left -- I'm sorry, to my other direction, the right. Wow, I'm just not knowing my left or right today. But then you see those connected. So what we're showing is what connections do we have and who authenticated. And quickly, we can see that [ Eliz ] has logged into PC2 when she's logged into PC1. That looks like lateral movement, right?
Carlos Diaz
executiveYes, for sure, especially on the DCOM launch or in the MNC process on PC #2. Absolutely. Yes.
Rob Gresham
executiveExactly. That's those when those logs coming into play, I think, right?
Carlos Diaz
executiveYes, absolutely. Yes. Awesome. Great.
Rob Gresham
executiveSo let's take correlated detection and move this on. So now we have got these other objects together, but without correlating these attributes, behaviors and characteristics, the legacy view gives us a different piece. So when we see correlated objects, the urgency increases, right? I can see exactly what needs to be done. I can focus on that one, and then I start working my way back to an individual alert if I have the time. But when we went through this investigation and we went from detection to identification, we used a process taking your correlated alerts, right? And we used a process called forward chaining. In forward chaining, we can actually look forward to see other related objects and start creating a deeper investigation. So in case you miss something, I can see other things that you may -- you didn't get in your correlation or maybe you don't have in your data set. And then I can move forward to confirm that impact. And obviously, as you can see here, I saw execute process. I saw process creation. I picked out the user. I can see that there's possibly a second stage piece of malware they got brought into the environment. And then I can see a send file, execute file that shows that lateral movement to that other incident. Could that other incident be related? But -- sure. But if the lateral movement in the new funnel dropped, it's not going to match the existing file. We needed to see that key network connection happening. Now we are starting to see where the root cause is. We're asking more questions we're seeing which behaviors, what was blocked, what was not blocked and whether there was any lateral movement. Do you have any questions on this piece here?
Carlos Diaz
executiveNo. I think what I derived here is that the quality of the correlated alerts that I need to prepare for you are going to allow you to move forward, meaning pivot forward as the right natural steps where you'll spot the other activity. Did I get you correctly?
Rob Gresham
executiveYou got me perfectly. And so now I'm going to take you one step further. We've done detection and we've done identification. So we've taken your methodology and my methodology and kind of merged them together to a point. We really haven't gotten passed identification. We've validated that this is a problem. We know that where we need to start reacting and where we need to start moving. Our biggest problem at this point is what are we going to respond with. And a lot of times when we do response, and I'm grateful to be joining this team, but Emma is financially fickle sometimes, and I don't mean this in a negative way. But as the market goes down, our ability to buy the best-in-breed product goes down. So then we buy solutions, right -- and we buy solutions that may be financially aren't the best solution on the planet because they gave us a good sale and we got a good price. But then now we got to make up for gaps and that capability or now I have to rip all the capabilities that I put into place. For example, if we traded, I don't know, CrowdStrike for Microsoft Defender, for example. Not saying that Microsoft Defender is any good or worse than either one in the grand scheme of things. But I've built tools and automations and capabilities against CrowdStrike. And now I got to rip all that out, and now I got to build all new automation workflows and everything else into a capability like, for example, Microsoft Defender. Well, my problem with that is that, that makes it really difficult. And in order to think about effective response, we need to be able to start thinking about what are the decisions that need to be made and what are the outcomes that the analyst needs to focus in on. And when you -- what you're seeing in front of you is like a really high-level overview, and I'll dig into it a little bit deeper. But in a high-level overview, we need to understand our tools that we have available in basic sensors, network endpoint and identity and that our data is in the middle of this, and what capabilities do we have from an investigative standpoint. We talked about MITRE giving us an ability to understand that, what investigation thing we need to validate. But then we need to -- what does that give us? What workflows can I put into place that give me answers about the information that I need to know? Like what additional hosts are created? What additional processes are created? Was there a lateral movement? What list of registry keys were created because maybe we didn't have that information. And then I need to build actions on top of it. Maybe it's the endpoint. Maybe it's the network where I'm blocking observables, where I'm blocking and quarantining or isolating the host on that process. What do you think about this piece and how it overlays with your staff?
Carlos Diaz
executiveFor our meeting grid here today, I just got to tell you that I'm thrilled that your expertise is here because these are all the things that I felt I needed a complement on. And so I'm just eager to start getting to work with you and trying to figure out next steps for execution, the #1 thing I see as an engineer, so I want to be able to start automating and essentially emulating adversaries. And soon, we got to go to another executive meeting where your ramp-up will continue. But I think that's in essence where I'm just overly impressed with you joining our company because you are the complement that we need to get a threat response strategy going. Any [ future ] thoughts for me?
Rob Gresham
executiveYes. This thing about generative AI is coming out, right? And we need to think about this because generative AI is going to give us the capability to repeat. It's not intelligence. But it's probability. What is the next action to be there? But if we don't templatize our actions, we can't use generative AI effectively. So we need to automate to the decision point to the analyst, that human machine teaming. I think you mentioned something in our early interview process when you interviewed me, something about human machine maturity model. I actually looked that up, bringing us together with the machine and the human and actually maturing the observation and context and capability so that we can actually isolate things effectively before the human actually gets involved. That's where the super power is. That's where we get really going forward.
Carlos Diaz
executiveExcellent. Yes. Go ahead.
Rob Gresham
executiveSo I want to show you really quickly that tool and then just pivot to that as fast as I can here, is that, in the same investigation and response action capability, we had the incident itself, and we had these response actions here. In here, I can actually go and click on these response actions and actually go and select like, say, if I wanted to contain the URL, I could pick the URLs and run containment and execute. And then I create notes and things for that capability in this process. So I'm actually recording everything that we needed to do and how things were accomplished in this attack. This is powerful, I thought. When I saw this tool and I saw this capability, I'm like this is going to be able to keep my OneNote monster from fighting me and killing me later, trying to build incident reports for Emma on what exactly happened. But the last piece here is I want to cover my takeaways from you.
Carlos Diaz
executiveSure. Like the thing we got -- we had a little bit of this virtual delay. So what I thought as a takeaway from my side in learning about your skill set is that it's important to have the right tools that take these response actions at a great scale easily based on what you were showing about this tool that Emma had you assess called Cisco XDR. And the other thing that I saw is that I can't feed you alerts, just alerts by severity, right? They do nothing for you. I have to correlate them, contextualize them, I can use a very structured approach you call the attributes, behaviors and characteristics. And I saw the value of that, as I was mentioning, an endpoint, where I can provide a correlated context that expedites comprehending attack patterns. Those are the takeaways that I got from you. Is there anything you got from me?
Rob Gresham
executiveNaturally, I knew about time-based security and that piece. But between your ability to detect visibility and detect and my ability to investigate and respond, we create this ability for -- to do defending is effectively degrading the impacts, right? And the model of using time-based security puts our priorities in the right place to be able to enhance what things should be preventative, what things should be detection and response. And we can take those value points up to Emma and say, Emma, these are the things that we think are going to save us more time regardless of what tool it is, whether it's preventative or reactive or detection. And then she can support us in that space, and we have the data and the value to support it.
Carlos Diaz
executiveI firmly agree. So I think next actions is we need to get this execution plan going with the philosophies and on the practical side, probably need to lead from here into some practical workshops emulating the adversary. I'd like to go ask that vendor Cisco XDR, so we could use that product and test it out against the emulations. Any final thoughts?
Rob Gresham
executiveNo, I think that's a good way forward. Let's go ahead and see what we can do to pull them in. Maybe we should ask Emma if there's any questions out there.
Emma Carpenter
executiveSo this has been great, and there are some questions actually. I have one here that says, how are other Cisco products or the whole portfolio helping to degrade the adversarial impacts we see? Do you have any examples from across the portfolio or product lines?
Carlos Diaz
executiveYes, absolutely. So starting with DNS umbrella, I think when it comes to the exfiltration command and control, lateral movement and even reconnaissance basis, that product plays a very strong role at disrupting in those stages of the attack. So depending on where you deploy those products, like if you deploy them on DMC-type servers, you will be enjoying preventative and proactive controls before they impact that. But if you put them on the endpoint areas, you'll be disrupting key areas that the adversary tends to use for the network, that's where it plays. We have another product called Secure Cloud Workload, micro segmentation, Linux, Kubernetes, pods, et cetera, if you're in the cloud world. And the micro segmentation applies explicit host-based firewall segmentation, trust policies, et cetera. Our web proxies, of course, complement umbrella in that area. Cisco secure endpoint is our EPP EDR aspect that tends to disrupt a lot of endpoint-driven things aligned to MITRE. Rob, anything that is -- oh, identity is very important. Cisco ISE integrates with Active Directory, where you can enforce granular policies such as clipping password, assigning groups, enforcement, resetting sessions, et cetera. Rob?
Rob Gresham
executiveWe have lots of recent procurement and technology capabilities. Like one, for example, we produce this identity or we purchase this identity company called Oort. You're going to be seeing that in the Cisco XDR product as a native feature. One that you didn't mention, Carlos, for that phishing thing is our e-mail threat defense actually integrates with Office 365 and pulls the journal so that we can move the message and give you more time in those pieces but also allows you to do retroactive hunts and go and evaluate and recalculate. Maybe this thing was spam that turns into looks more like a phish. You can actually go and react to that and provide that early investigation capability. Naturally, we have Stealthwatch capabilities that formerly known as Stealthwatch -- our secured analytics capabilities on the network side, on the NDR side, being able to pull different visibility, observability capabilities on the network side and create detection and response that will feed our XDR product to add more value. So when you take the whole picture of endpoint network and identity, you have the ability to control your data, which gives you a very solid -- and I'm going to use an industry term here, zero trust capability, which is one of our solution types, be able to do that, right? And XDR is more of a breach tool. I mean after all the controls have worked and bad things have happened, this is where we pull into that last piece.
Carlos Diaz
executiveVery well said. Any other questions?
Emma Carpenter
executiveThat's great. We probably have time for one more quick one. You had mentioned AI, generative AI. So this question is around Cisco's announcement of the AI SOC assistant. Does the AI SOC assistant support all of this automation that we've been talking about today?
Rob Gresham
executiveSo the one that was released is for the firewall, and it's for the cloud automated policy process. So right now we're incrementally releasing 3 different AI capabilities. First one is going to be a visibility and question and answering capability within Cisco. And then the second one is going to be for policy and cloud operations, which is the one you saw recently released. And then there's a last one that we're going to talk about more about these actions is, we have a SOC AI assistant that's going to be released and talked about more in the future. I can't give you that information right now. But the reality is, yes, the answer is yes. Because when we start talking about the future of AI, as you see on this slide, is those actions, those tasks, those workflows that we've built internally for our product, the tool will be able to use them. The tool will be your assistant. The way to guide you, teach you, even if you're not as experienced as me and Carlos in incident response, it will teach you and guide you along the way because we've built specific tasks and capabilities to help you through that process based on the frameworks we talked about here today.
Carlos Diaz
executiveYes. Absolutely.
Mark Watts
executiveWe'd like to thank you all for attending this event. We hope you found it informative. And as a reminder, please take a moment to complete the confidential survey that has been posted in the chat panel. It will also pop up in your browser as you exit. So thank you for joining, and have a great day.
Read the full transcript via the API
You're viewing the first half of this call. Get the complete Cisco Systems, Inc. transcript — plus 248,000+ transcripts from 12,000+ companies, speaker segments, AI summaries and full-text search — through the EarningsCalls.dev API.
Get the API View API docs →This call discussed
For developers and AI pipelines
Programmatic access to Cisco Systems, Inc. earnings transcripts and 248,000+ others is available through the
EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments,
full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.