Everything You Should Know Before Mythos Arrives | Nebulock, Damien Lewke

EO14:53Added Aug 31, 2026

A cyberattack used to take an elite team and a decade of hard-won instinct. Now it takes two people and a GPU.Damien Lewke spent his career on defense - at t...

Watch on YouTube →
Contributed by 刘嘉琪

Transcript

Transcript format
  1. Intro

  2. 00:00Mythos changes the balance of power in
  3. 00:02cyber. [music] Two people in a GPU who
  4. 00:04with enough conviction can target a
  5. 00:06company. And I think that that [music]
  6. 00:07will happen. But I also think like
  7. 00:10mythos to me is not like existentially
  8. 00:12scary. Mythos is what [music] we in
  9. 00:15security have been saying for years.
  10. 00:17Really the question we should be asking
  11. 00:18is okay after mythos what's coming
  12. 00:21after? What are we ready for? We have a
  13. 00:24very unique window of time right now
  14. 00:26where we understand what is coming and
  15. 00:29we have the ability to adopt technology.
  16. 00:32The question is can defenders adjust as
  17. 00:36quickly as the attackers can. I'm Damian
  18. 00:38Luki. I'm the founder and CEO of
  19. 00:40Nebulock. Nebulock is a contextual
  20. 00:42[music] security platform. Really what
  21. 00:44we do is look at all the existing
  22. 00:46security tools that you have and we find
  23. 00:50potential [music] threats hidden between
  24. 00:51the layers. We raised the $25 million
  25. 00:53series A led by First Mark with
  26. 00:55participation from all of our existing
  27. 00:57investors. So, Bane Capital Ventures,
  28. 00:59Decible, Zeta Venture Partners, and Step
  29. 01:01Function.
  30. Love the Problem, Not the Solution

  31. 01:14I'm very fortunate. I discovered my
  32. 01:16passion my first day on the job as an
  33. 01:18intern at a company called North of
  34. 01:19Grumman. [music] So I started my career
  35. 01:21in the DoD building out cyber ops and
  36. 01:24threat hunting teams before [music]
  37. 01:26being a relatively early employee at
  38. 01:29Crowdstrike, joining after the series C,
  39. 01:31being there through and after the IPO.
  40. 01:33My first job when I was in the DoD, I
  41. 01:35actually worked full-time and went to
  42. 01:36grad school at night to get a masters in
  43. 01:38aerospace [music] systems engineering.
  44. 01:40What that taught me was not to be a hero
  45. 01:43every single day. But what was most
  46. 01:44important was that you showed up and did
  47. 01:46your best as best you could day in day
  48. 01:49out. That's really expanded as I've gone
  49. 01:52throughout my career. So on the personal
  50. 01:53side, I have a challenge where I run
  51. 01:561,000 miles a year. It's the same kind
  52. 01:58of idea, which is like at 10:30 in the
  53. 02:00morning on a Tuesday in [music]
  54. 02:02February, can you show up and do your
  55. 02:04best the same way that you would on a
  56. 02:07Friday morning when everything is going
  57. 02:09great? I then had a chance to experience
  58. 02:12network security at Palo Alto Networks
  59. 02:14and and [music] managed detection and
  60. 02:16response running the AI detection
  61. 02:18security research product teams at
  62. 02:20Arctic Wolf and I I took a stint [music]
  63. 02:22at MIT writing a graduate dissertation
  64. 02:24out of the computer science and AI lab
  65. 02:26there. What led me to start Nebulock
  66. 02:28really was a [music] two-sided problem.
  67. 02:31So the first is beginning as an
  68. 02:33operator. I saw the real problem that
  69. 02:36all of our existing customers [music]
  70. 02:39had at Arctic Wolf and also what our
  71. 02:411200 person security operations center
  72. 02:43had. The dissonance was everybody had
  73. 02:46already invested in these [music] best
  74. 02:48of breed tools and despite owning the
  75. 02:52Audi or Ferrari of security, everybody
  76. 02:55was still getting compromised and it was
  77. 02:57because different [music] point
  78. 02:59solutions to specific problems were not
  79. 03:02the way to solve how to get breached. It
  80. 03:04was rethinking everything from first
  81. 03:06principles. Two years ago, my thesis was
  82. 03:10adversaries, so bad actors are going to
  83. 03:12use AI to automate tailored access
  84. 03:14operations. They're going to be able to
  85. 03:16automate the entire life cycle of
  86. 03:19targeting an enterprise, compromising
  87. 03:21it, achieving their objective, and
  88. 03:23slipping out undetected. [music] And it
  89. 03:25was those two problems that led me to
  90. 03:28build Nebulock. The idea being we can
  91. How the Security Talent Gap Collapsed into a Subscription

  92. 03:30democratize the most high lever activity
  93. 03:33in security to all organizations
  94. 03:35regardless of size, skill set or budget
  95. 03:38in a way that's flexible and integrates
  96. 03:39with the existing systems that they
  97. 03:41have. I'd say the power distribution has
  98. 03:43already happened. Much like how AI has
  99. 03:46enabled productivity for developers,
  100. 03:49it's also allowed both attackers and
  101. 03:52defenders to uplevel themselves. elite
  102. 03:55AI engineering or elite security
  103. 03:57judgment. Certainly elite security
  104. 03:59judgment that gut instinct takes a
  105. 04:02decade or more to build and that it's a
  106. 04:04very small subset of people. But a
  107. 04:07mythos allow a script kitty so a
  108. 04:10non-sophisticated thread actor to be
  109. 04:12able to do things that used to be
  110. 04:14reserved to a very elite group of
  111. 04:16people. What the actual power
  112. 04:18convergence means is not hey can I do
  113. 04:21things faster but rather the talent gap
  114. 04:24has collapsed to a subscription model.
  115. 04:28It impacts it in a cascading series of
  116. 04:29events. So it starts with the individual
  117. 04:32and then onto companies because an
  118. 04:34individual can quickly adopt AI. A
  119. 04:36company can adopt AI relatively quickly
  120. 04:39but ultimately this will go towards
  121. 04:41nation states. We see that nation states
  122. 04:43already US cyber command is using AI as
  123. 04:46a part of its components that is really
  124. 04:49really concerning but I also think like
  125. 04:52the broader more existential question is
  126. 04:54what happens when the citizen hacker
  127. 04:56when one person gets access to a mythos
  128. 04:58level model because they aren't governed
  129. 05:00by geopolitics and rules of engagement
  130. 05:03they can do what they want and I think
  131. 05:05that that will happen the number of
  132. 05:07potential threat actors is dramatically
  133. 05:09increasing you know you've gone from a
  134. 05:12you score highly sophisticated groups to
  135. 05:16honestly two people in a GPU who with
  136. 05:18enough conviction can target a company.
  137. 05:20[music] You see earlier stage companies
  138. 05:23being targeted. We've seen this in the
  139. 05:25headlines recently where growth stage
  140. 05:27companies like Verscell have had
  141. Quitting with No salary: The $0 Test

  142. 05:30breaches. [music]
  143. 05:30That's no fault of anyone's but just
  144. 05:33when more people can do these [music]
  145. 05:35things, you're going to see a greater
  146. 05:37indication and a and a greater veracity
  147. 05:39of threats. I got to a point in early
  148. 05:432024 where I decided to quit my job
  149. 05:46outright and focus on this problem.
  150. 05:49There was a core moment where I
  151. 05:50genuinely asked myself, could I try and
  152. 05:52solve this problem and make zero dollars
  153. 05:54doing it? And the answer was a
  154. 05:56resounding yes. And it was at that point
  155. 05:58that I knew I was ready. Thankfully,
  156. 06:00we've been able to grow and scale as a
  157. 06:02business. I'm joined by some amazing
  158. 06:05folks. We get to partner with
  159. 06:07organizations from the Fortune 500 to
  160. 06:09growth stage security companies like
  161. 06:12Cribble as customers. Why was I okay
  162. 06:14making zero dollars and going after
  163. 06:16this? As a founder, I think what you
  164. 06:18really need to be obsessed with is the
  165. 06:19problem, not the solution. Ultimately,
  166. 06:22you build a team to help you design the
  167. 06:25solution and you validate your idea with
  168. 06:27the market to design the solution, but
  169. 06:29like you have to fall in love with the
  170. 06:30problem. [music] And to me, the problem
  171. 06:32was just so pervasive. I realized like I
  172. 06:35had to do my absolute best and you just
  173. 06:38got to show up day in day out and see
  174. 06:39like, hey, wait a minute. Is this
  175. 06:41something you can really go after? And I
  176. 06:42was fortunate that I did early market
  177. 06:44discovery that validated the thesis and
  178. 06:47ultimately allowed us to build what
  179. 06:48we've built today. No matter how right
  180. 06:50or wrong the world tells you that you
  181. 06:53are about the idea you're pursuing, as
  182. 06:55an entrepreneur, the key is that you
  183. 06:57have conviction and that you continue to
  184. 06:59back yourself up with that. I think
  185. 07:00that's really important as a founder.
  186. How One Person Actually Hacks with AI

  187. 07:06So, do I think that cyber attackers are
  188. 07:09not just targeting governments or the
  189. 07:11Fortune 100, but normal people?
  190. 07:14Absolutely. They're able to remotely
  191. 07:17access your Google Workspace account.
  192. 07:20Once they have access to your Google
  193. 07:21Workspace account, they're able to
  194. 07:23access elements of your Google Drive and
  195. 07:25eventually are able to find a way to
  196. 07:27work their way onto your endpoint
  197. 07:30system. Once they're in your endpoint
  198. 07:32system, they can basically go wherever
  199. 07:33they want. They can move laterally and
  200. 07:36access critical cloud resources because
  201. 07:38again, they look completely normal.
  202. 07:40Those are the hardest to spot because
  203. 07:42those are the ones who in isolation have
  204. 07:45green flag activity, but it's only when
  205. 07:48you take a step back, [music] you look
  206. 07:50at the sequence of events and the
  207. 07:52context of their actions that you can
  208. 07:54actually spot a glaring red flag.
  209. 07:56Whereas about 10 years ago, cyber
  210. 07:59attackers [music] behaved in bad ways. I
  211. 08:03think that's what's changed a lot,
  212. 08:04especially since I started in security,
  213. 08:06[music] right? Attackers are going to
  214. 08:07try and blend in. They're going to log
  215. 08:09in at normal hours. They're going to
  216. 08:12[music] steal your username and password
  217. 08:14so it doesn't look suspicious or
  218. 08:16malicious. Can I distinguish what Damian
  219. 08:20as Damian versus [music] Damian whose
  220. 08:22account has been compromised? like what
  221. 08:24that actually sequence what that actual
  222. 08:26sequence of behavior looks like and
  223. 08:28based on that sequence [music] can I say
  224. 6 Steps of Cyber Attack

  225. 08:30oh that's Damian it's totally cool or
  226. 08:33hey wait a minute Damian's doing [music]
  227. 08:35something he shouldn't be he's been
  228. 08:36compromised the real concern here is
  229. 08:40everything I described is being done by
  230. 08:42one person so you don't need a team to
  231. 08:45do all of these things anymore you can
  232. 08:47do it as one very patient person so if I
  233. 08:50could draw an axis across the cyber kill
  234. 08:54chain, reconnaissance, targeting,
  235. 08:56exploitation, persistence, lateral
  236. 08:59movement, and then action on objectives.
  237. 09:01AI is already automated kind of the
  238. 09:03first three core components, and humans
  239. 09:06are being orchestrated on the last part.
  240. 09:09And then if I had like a cost on my
  241. 09:11y-axis, like the cost would be very low
  242. 09:13and then it would get very high. So
  243. 09:14you'd kind of have like killchain on
  244. 09:16your x-axis, cost on your y-axis. If I
  245. 09:19were a thread actor right now,
  246. 09:20reconnaissance basically 0. [music]
  247. 09:23Writing a fishing email also very cheap.
  248. 09:26Vulnerability exploitation is getting
  249. 09:28significantly cheaper. Establishing
  250. 09:30persistence is also relatively cheap.
  251. 09:33Right now, lateral movement and
  252. 09:35ultimately like achieving your objective
  253. 09:37still requires a human. It's a bit more
  254. 09:40expensive. A human plus an agent [music]
  255. 09:42can get there together, but you still
  256. 09:44need a human. But the first four
  257. 09:46components of that is basically
  258. 09:47automated. As attackers go to machine
  259. 09:49speed, do we think that defenders are
  260. 09:51going to machine speed as well? I think
  261. 09:54we have the opportunity to do that now.
  262. Assume You're Already Hacked

  263. 10:00The core thread that I saw was that as
  264. 10:02defenders, we're always one step behind
  265. 10:04the attackers. In the DoD, we had to
  266. 10:06operate with the information that we had
  267. 10:08access to without knowing everything the
  268. 10:10adversary could. At Crowdstrike, we
  269. 10:12scaled that effectively on the endpoint,
  270. 10:13but the endpoint was only part of the
  271. 10:15enterprise puzzle. The same at PaloAlto
  272. 10:18Networks, right? We had the network, but
  273. 10:19that was only part of the puzzle. And
  274. 10:22then finally, from the managed detection
  275. 10:23and response side of Arctic Wolf, you
  276. 10:25had best of breed solutions, but you
  277. 10:27could only solve problems as best as the
  278. 10:30existing tools that you had, and you
  279. 10:33were responding to everything
  280. 10:34reactively. So the common thread was
  281. 10:36attackers were always one step ahead
  282. 10:37[music] of defenders. And that's because
  283. 10:39we were always reacting to alerts as
  284. 10:42opposed to proactively leaning into how
  285. 10:45threat actors might be getting around
  286. 10:46our systems. And it was that gap that
  287. 10:49prompted me to start Nebulock. That's
  288. 10:52really where threat hunting comes in.
  289. 10:54Threat hunting is analogous to cyber
  290. 10:57security operations, much like the
  291. 10:59difference between a fire marshal and
  292. 11:01[music] a smoke detector. So in cyber
  293. 11:04security, when you have an alert system,
  294. 11:06[music] that's your smoke detector.
  295. 11:08there's a fire going off and I'm
  296. 11:09alerting you that something [music] bad
  297. 11:11has happened. Whereas a threat hunter is
  298. 11:13like a fire marshal. They go into a
  299. 11:15building before the fire and they point
  300. 11:17out the risks or risk areas that might
  301. 11:20[music] be impacted should there be a
  302. 11:22fire. Threat hunting exists under the
  303. 11:24opice that you should assume a breach.
  304. 11:27You should assume that an attacker is
  305. 11:28within your environment. So does this
  306. The Three Signs an Attacker is Already Inside Your Environment

  307. 11:30specific person with these specific
  308. 11:33permissions have access to the kind of
  309. 11:35data they're touching? For example,
  310. 11:38there are really three key things that
  311. 11:40an attacker will do that show
  312. 11:42compromise. The first is [music]
  313. 11:45there will be a slow but consistent
  314. 11:49exfiltration of data that looks much
  315. 11:51like backup behavior. All desktop files
  316. 11:54being uploaded to a personal Google
  317. 11:56Drive. The second piece will be
  318. 12:00performing outside the scope of their
  319. 12:02initial role. So the marketing intern
  320. 12:05accessing financial [music]
  321. 12:06information and then the third is at
  322. 12:09some point you will see some sort of
  323. 12:12persistence mechanism [music]
  324. 12:14that could be a remote management tool
  325. 12:17being installed so that they can access
  326. 12:19a system from any time or that might be
  327. 12:21the multiplication of accounts that they
  328. 12:25have access to. So opening up service
  329. 12:27accounts when they're a human user for
  330. 12:29example. Those are the the three things
  331. 12:31that's exactly why we exist, right? Like
  332. 12:33Nebulon is a contextual security
  333. 12:35platform. Really what we do is look at
  334. 12:38all the existing security tools that you
  335. 12:40have and we find potential threats
  336. 12:43hidden between the layers. Cyber
  337. 12:45security very quickly is becoming like
  338. 12:46an existential question which is not hey
  339. 12:49will something bad happen but when
  340. 12:51something bad happens what do we do
  341. 12:53about it? The key that we all have to
  342. 12:55accept is at some point a threat actor
  343. 12:57will target us. That's not to fear
  344. 12:59monger. It's just the reality of a world
  345. Don't Fear AI, Fear Inaction

  346. 13:01where the democratization of cyber
  347. 13:04attacks is a reality. I would not fear
  348. 13:09that AI is going to catastrophically
  349. 13:12destroy everything when it comes to
  350. 13:15security, but rather that AI is here
  351. 13:17both to [music] create and solve the
  352. 13:20challenge for network defenders. So the
  353. 13:23sky is not falling. What I would tell
  354. 13:25them to fear or be concerned about is
  355. 13:28inaction that we don't see these warning
  356. 13:31signs and instead do nothing. So I think
  357. 13:34we have again like a very rare window to
  358. 13:36act and that whole thesis [music] that
  359. 13:39whole idea is exactly why Nebulock
  360. 13:41exists to democratize the highest
  361. 13:43leverage thing which is all about
  362. 13:46finding bad activity before it becomes
  363. 13:48like a persistent breach [music] and
  364. 13:50giving that back to the people. Yeah, I
  365. What You Need as a Founder

  366. 13:53think one thing that as a founder most
  367. 13:55people don't think about is there's you
  368. 13:58the business person and then there's you
  369. 14:00the person. [music]
  370. 14:00Having a personal support network is
  371. 14:04really really important. I think what
  372. 14:06makes my dad so great as a mentor to me
  373. 14:10is he understands me deeply. He's my
  374. 14:13dad. I'm very fortunate in that regard
  375. 14:15to have access to someone who I have a a
  376. 14:18long-standing [music] and deep and
  377. 14:19meaningful relationship with. And he
  378. 14:21also reminds me to show up as like my
  379. 14:23truest self as opposed to hyper
  380. 14:25optimizing to be like just Damian the
  381. 14:27CEO, but rather like Damian the person,
  382. 14:30Damian the founder, Damian who wants to
  383. 14:34build an environment where people can
  384. 14:36thrive and grow and do their best work.
  385. 14:38[music] So I was not anticipating that
  386. 14:40question. It got me a little emotional.
  387. 14:42[snorts]