Everything You Should Know Before Mythos Arrives | Nebulock, Damien Lewke
A cyberattack used to take an elite team and a decade of hard-won instinct. Now it takes two people and a GPU.Damien Lewke spent his career on defense - at t...
Watch on YouTube →Transcript
Intro
- 00:00Mythos changes the balance of power in
- 00:02cyber. [music] Two people in a GPU who
- 00:04with enough conviction can target a
- 00:06company. And I think that that [music]
- 00:07will happen. But I also think like
- 00:10mythos to me is not like existentially
- 00:12scary. Mythos is what [music] we in
- 00:15security have been saying for years.
- 00:17Really the question we should be asking
- 00:18is okay after mythos what's coming
- 00:21after? What are we ready for? We have a
- 00:24very unique window of time right now
- 00:26where we understand what is coming and
- 00:29we have the ability to adopt technology.
- 00:32The question is can defenders adjust as
- 00:36quickly as the attackers can. I'm Damian
- 00:38Luki. I'm the founder and CEO of
- 00:40Nebulock. Nebulock is a contextual
- 00:42[music] security platform. Really what
- 00:44we do is look at all the existing
- 00:46security tools that you have and we find
- 00:50potential [music] threats hidden between
- 00:51the layers. We raised the $25 million
- 00:53series A led by First Mark with
- 00:55participation from all of our existing
- 00:57investors. So, Bane Capital Ventures,
- 00:59Decible, Zeta Venture Partners, and Step
- 01:01Function.
Love the Problem, Not the Solution
- 01:14I'm very fortunate. I discovered my
- 01:16passion my first day on the job as an
- 01:18intern at a company called North of
- 01:19Grumman. [music] So I started my career
- 01:21in the DoD building out cyber ops and
- 01:24threat hunting teams before [music]
- 01:26being a relatively early employee at
- 01:29Crowdstrike, joining after the series C,
- 01:31being there through and after the IPO.
- 01:33My first job when I was in the DoD, I
- 01:35actually worked full-time and went to
- 01:36grad school at night to get a masters in
- 01:38aerospace [music] systems engineering.
- 01:40What that taught me was not to be a hero
- 01:43every single day. But what was most
- 01:44important was that you showed up and did
- 01:46your best as best you could day in day
- 01:49out. That's really expanded as I've gone
- 01:52throughout my career. So on the personal
- 01:53side, I have a challenge where I run
- 01:561,000 miles a year. It's the same kind
- 01:58of idea, which is like at 10:30 in the
- 02:00morning on a Tuesday in [music]
- 02:02February, can you show up and do your
- 02:04best the same way that you would on a
- 02:07Friday morning when everything is going
- 02:09great? I then had a chance to experience
- 02:12network security at Palo Alto Networks
- 02:14and and [music] managed detection and
- 02:16response running the AI detection
- 02:18security research product teams at
- 02:20Arctic Wolf and I I took a stint [music]
- 02:22at MIT writing a graduate dissertation
- 02:24out of the computer science and AI lab
- 02:26there. What led me to start Nebulock
- 02:28really was a [music] two-sided problem.
- 02:31So the first is beginning as an
- 02:33operator. I saw the real problem that
- 02:36all of our existing customers [music]
- 02:39had at Arctic Wolf and also what our
- 02:411200 person security operations center
- 02:43had. The dissonance was everybody had
- 02:46already invested in these [music] best
- 02:48of breed tools and despite owning the
- 02:52Audi or Ferrari of security, everybody
- 02:55was still getting compromised and it was
- 02:57because different [music] point
- 02:59solutions to specific problems were not
- 03:02the way to solve how to get breached. It
- 03:04was rethinking everything from first
- 03:06principles. Two years ago, my thesis was
- 03:10adversaries, so bad actors are going to
- 03:12use AI to automate tailored access
- 03:14operations. They're going to be able to
- 03:16automate the entire life cycle of
- 03:19targeting an enterprise, compromising
- 03:21it, achieving their objective, and
- 03:23slipping out undetected. [music] And it
- 03:25was those two problems that led me to
- 03:28build Nebulock. The idea being we can
How the Security Talent Gap Collapsed into a Subscription
- 03:30democratize the most high lever activity
- 03:33in security to all organizations
- 03:35regardless of size, skill set or budget
- 03:38in a way that's flexible and integrates
- 03:39with the existing systems that they
- 03:41have. I'd say the power distribution has
- 03:43already happened. Much like how AI has
- 03:46enabled productivity for developers,
- 03:49it's also allowed both attackers and
- 03:52defenders to uplevel themselves. elite
- 03:55AI engineering or elite security
- 03:57judgment. Certainly elite security
- 03:59judgment that gut instinct takes a
- 04:02decade or more to build and that it's a
- 04:04very small subset of people. But a
- 04:07mythos allow a script kitty so a
- 04:10non-sophisticated thread actor to be
- 04:12able to do things that used to be
- 04:14reserved to a very elite group of
- 04:16people. What the actual power
- 04:18convergence means is not hey can I do
- 04:21things faster but rather the talent gap
- 04:24has collapsed to a subscription model.
- 04:28It impacts it in a cascading series of
- 04:29events. So it starts with the individual
- 04:32and then onto companies because an
- 04:34individual can quickly adopt AI. A
- 04:36company can adopt AI relatively quickly
- 04:39but ultimately this will go towards
- 04:41nation states. We see that nation states
- 04:43already US cyber command is using AI as
- 04:46a part of its components that is really
- 04:49really concerning but I also think like
- 04:52the broader more existential question is
- 04:54what happens when the citizen hacker
- 04:56when one person gets access to a mythos
- 04:58level model because they aren't governed
- 05:00by geopolitics and rules of engagement
- 05:03they can do what they want and I think
- 05:05that that will happen the number of
- 05:07potential threat actors is dramatically
- 05:09increasing you know you've gone from a
- 05:12you score highly sophisticated groups to
- 05:16honestly two people in a GPU who with
- 05:18enough conviction can target a company.
- 05:20[music] You see earlier stage companies
- 05:23being targeted. We've seen this in the
- 05:25headlines recently where growth stage
- 05:27companies like Verscell have had
Quitting with No salary: The $0 Test
- 05:30breaches. [music]
- 05:30That's no fault of anyone's but just
- 05:33when more people can do these [music]
- 05:35things, you're going to see a greater
- 05:37indication and a and a greater veracity
- 05:39of threats. I got to a point in early
- 05:432024 where I decided to quit my job
- 05:46outright and focus on this problem.
- 05:49There was a core moment where I
- 05:50genuinely asked myself, could I try and
- 05:52solve this problem and make zero dollars
- 05:54doing it? And the answer was a
- 05:56resounding yes. And it was at that point
- 05:58that I knew I was ready. Thankfully,
- 06:00we've been able to grow and scale as a
- 06:02business. I'm joined by some amazing
- 06:05folks. We get to partner with
- 06:07organizations from the Fortune 500 to
- 06:09growth stage security companies like
- 06:12Cribble as customers. Why was I okay
- 06:14making zero dollars and going after
- 06:16this? As a founder, I think what you
- 06:18really need to be obsessed with is the
- 06:19problem, not the solution. Ultimately,
- 06:22you build a team to help you design the
- 06:25solution and you validate your idea with
- 06:27the market to design the solution, but
- 06:29like you have to fall in love with the
- 06:30problem. [music] And to me, the problem
- 06:32was just so pervasive. I realized like I
- 06:35had to do my absolute best and you just
- 06:38got to show up day in day out and see
- 06:39like, hey, wait a minute. Is this
- 06:41something you can really go after? And I
- 06:42was fortunate that I did early market
- 06:44discovery that validated the thesis and
- 06:47ultimately allowed us to build what
- 06:48we've built today. No matter how right
- 06:50or wrong the world tells you that you
- 06:53are about the idea you're pursuing, as
- 06:55an entrepreneur, the key is that you
- 06:57have conviction and that you continue to
- 06:59back yourself up with that. I think
- 07:00that's really important as a founder.
How One Person Actually Hacks with AI
- 07:06So, do I think that cyber attackers are
- 07:09not just targeting governments or the
- 07:11Fortune 100, but normal people?
- 07:14Absolutely. They're able to remotely
- 07:17access your Google Workspace account.
- 07:20Once they have access to your Google
- 07:21Workspace account, they're able to
- 07:23access elements of your Google Drive and
- 07:25eventually are able to find a way to
- 07:27work their way onto your endpoint
- 07:30system. Once they're in your endpoint
- 07:32system, they can basically go wherever
- 07:33they want. They can move laterally and
- 07:36access critical cloud resources because
- 07:38again, they look completely normal.
- 07:40Those are the hardest to spot because
- 07:42those are the ones who in isolation have
- 07:45green flag activity, but it's only when
- 07:48you take a step back, [music] you look
- 07:50at the sequence of events and the
- 07:52context of their actions that you can
- 07:54actually spot a glaring red flag.
- 07:56Whereas about 10 years ago, cyber
- 07:59attackers [music] behaved in bad ways. I
- 08:03think that's what's changed a lot,
- 08:04especially since I started in security,
- 08:06[music] right? Attackers are going to
- 08:07try and blend in. They're going to log
- 08:09in at normal hours. They're going to
- 08:12[music] steal your username and password
- 08:14so it doesn't look suspicious or
- 08:16malicious. Can I distinguish what Damian
- 08:20as Damian versus [music] Damian whose
- 08:22account has been compromised? like what
- 08:24that actually sequence what that actual
- 08:26sequence of behavior looks like and
- 08:28based on that sequence [music] can I say
6 Steps of Cyber Attack
- 08:30oh that's Damian it's totally cool or
- 08:33hey wait a minute Damian's doing [music]
- 08:35something he shouldn't be he's been
- 08:36compromised the real concern here is
- 08:40everything I described is being done by
- 08:42one person so you don't need a team to
- 08:45do all of these things anymore you can
- 08:47do it as one very patient person so if I
- 08:50could draw an axis across the cyber kill
- 08:54chain, reconnaissance, targeting,
- 08:56exploitation, persistence, lateral
- 08:59movement, and then action on objectives.
- 09:01AI is already automated kind of the
- 09:03first three core components, and humans
- 09:06are being orchestrated on the last part.
- 09:09And then if I had like a cost on my
- 09:11y-axis, like the cost would be very low
- 09:13and then it would get very high. So
- 09:14you'd kind of have like killchain on
- 09:16your x-axis, cost on your y-axis. If I
- 09:19were a thread actor right now,
- 09:20reconnaissance basically 0. [music]
- 09:23Writing a fishing email also very cheap.
- 09:26Vulnerability exploitation is getting
- 09:28significantly cheaper. Establishing
- 09:30persistence is also relatively cheap.
- 09:33Right now, lateral movement and
- 09:35ultimately like achieving your objective
- 09:37still requires a human. It's a bit more
- 09:40expensive. A human plus an agent [music]
- 09:42can get there together, but you still
- 09:44need a human. But the first four
- 09:46components of that is basically
- 09:47automated. As attackers go to machine
- 09:49speed, do we think that defenders are
- 09:51going to machine speed as well? I think
- 09:54we have the opportunity to do that now.
Assume You're Already Hacked
- 10:00The core thread that I saw was that as
- 10:02defenders, we're always one step behind
- 10:04the attackers. In the DoD, we had to
- 10:06operate with the information that we had
- 10:08access to without knowing everything the
- 10:10adversary could. At Crowdstrike, we
- 10:12scaled that effectively on the endpoint,
- 10:13but the endpoint was only part of the
- 10:15enterprise puzzle. The same at PaloAlto
- 10:18Networks, right? We had the network, but
- 10:19that was only part of the puzzle. And
- 10:22then finally, from the managed detection
- 10:23and response side of Arctic Wolf, you
- 10:25had best of breed solutions, but you
- 10:27could only solve problems as best as the
- 10:30existing tools that you had, and you
- 10:33were responding to everything
- 10:34reactively. So the common thread was
- 10:36attackers were always one step ahead
- 10:37[music] of defenders. And that's because
- 10:39we were always reacting to alerts as
- 10:42opposed to proactively leaning into how
- 10:45threat actors might be getting around
- 10:46our systems. And it was that gap that
- 10:49prompted me to start Nebulock. That's
- 10:52really where threat hunting comes in.
- 10:54Threat hunting is analogous to cyber
- 10:57security operations, much like the
- 10:59difference between a fire marshal and
- 11:01[music] a smoke detector. So in cyber
- 11:04security, when you have an alert system,
- 11:06[music] that's your smoke detector.
- 11:08there's a fire going off and I'm
- 11:09alerting you that something [music] bad
- 11:11has happened. Whereas a threat hunter is
- 11:13like a fire marshal. They go into a
- 11:15building before the fire and they point
- 11:17out the risks or risk areas that might
- 11:20[music] be impacted should there be a
- 11:22fire. Threat hunting exists under the
- 11:24opice that you should assume a breach.
- 11:27You should assume that an attacker is
- 11:28within your environment. So does this
The Three Signs an Attacker is Already Inside Your Environment
- 11:30specific person with these specific
- 11:33permissions have access to the kind of
- 11:35data they're touching? For example,
- 11:38there are really three key things that
- 11:40an attacker will do that show
- 11:42compromise. The first is [music]
- 11:45there will be a slow but consistent
- 11:49exfiltration of data that looks much
- 11:51like backup behavior. All desktop files
- 11:54being uploaded to a personal Google
- 11:56Drive. The second piece will be
- 12:00performing outside the scope of their
- 12:02initial role. So the marketing intern
- 12:05accessing financial [music]
- 12:06information and then the third is at
- 12:09some point you will see some sort of
- 12:12persistence mechanism [music]
- 12:14that could be a remote management tool
- 12:17being installed so that they can access
- 12:19a system from any time or that might be
- 12:21the multiplication of accounts that they
- 12:25have access to. So opening up service
- 12:27accounts when they're a human user for
- 12:29example. Those are the the three things
- 12:31that's exactly why we exist, right? Like
- 12:33Nebulon is a contextual security
- 12:35platform. Really what we do is look at
- 12:38all the existing security tools that you
- 12:40have and we find potential threats
- 12:43hidden between the layers. Cyber
- 12:45security very quickly is becoming like
- 12:46an existential question which is not hey
- 12:49will something bad happen but when
- 12:51something bad happens what do we do
- 12:53about it? The key that we all have to
- 12:55accept is at some point a threat actor
- 12:57will target us. That's not to fear
- 12:59monger. It's just the reality of a world
Don't Fear AI, Fear Inaction
- 13:01where the democratization of cyber
- 13:04attacks is a reality. I would not fear
- 13:09that AI is going to catastrophically
- 13:12destroy everything when it comes to
- 13:15security, but rather that AI is here
- 13:17both to [music] create and solve the
- 13:20challenge for network defenders. So the
- 13:23sky is not falling. What I would tell
- 13:25them to fear or be concerned about is
- 13:28inaction that we don't see these warning
- 13:31signs and instead do nothing. So I think
- 13:34we have again like a very rare window to
- 13:36act and that whole thesis [music] that
- 13:39whole idea is exactly why Nebulock
- 13:41exists to democratize the highest
- 13:43leverage thing which is all about
- 13:46finding bad activity before it becomes
- 13:48like a persistent breach [music] and
- 13:50giving that back to the people. Yeah, I
What You Need as a Founder
- 13:53think one thing that as a founder most
- 13:55people don't think about is there's you
- 13:58the business person and then there's you
- 14:00the person. [music]
- 14:00Having a personal support network is
- 14:04really really important. I think what
- 14:06makes my dad so great as a mentor to me
- 14:10is he understands me deeply. He's my
- 14:13dad. I'm very fortunate in that regard
- 14:15to have access to someone who I have a a
- 14:18long-standing [music] and deep and
- 14:19meaningful relationship with. And he
- 14:21also reminds me to show up as like my
- 14:23truest self as opposed to hyper
- 14:25optimizing to be like just Damian the
- 14:27CEO, but rather like Damian the person,
- 14:30Damian the founder, Damian who wants to
- 14:34build an environment where people can
- 14:36thrive and grow and do their best work.
- 14:38[music] So I was not anticipating that
- 14:40question. It got me a little emotional.
- 14:42[snorts]