WEBVTT

00:00:06.770 --> 00:00:09.230
Welcome to the Azure Security Podcast, where

00:00:09.230 --> 00:00:11.750
we discuss topics relating to security, privacy,

00:00:12.029 --> 00:00:14.449
reliability, and compliance on the Microsoft

00:00:14.449 --> 00:00:19.030
Cloud Platform. Hey, everybody. Welcome to Episode

00:00:19.030 --> 00:00:22.730
127. This week is myself, Michael, with Sarah

00:00:22.730 --> 00:00:25.250
and Mark, and our guest this week is Shara DiGrippo,

00:00:25.469 --> 00:00:27.690
who is actually on the podcast. Man, it must

00:00:27.690 --> 00:00:28.929
have been two years ago. I need to look that

00:00:28.929 --> 00:00:31.969
up. But before we get to our guest, we've got

00:00:31.969 --> 00:00:33.710
a couple of little news items. Actually, I'm

00:00:33.710 --> 00:00:35.250
the only one who actually has news this week,

00:00:35.270 --> 00:00:37.539
which is... Kind of interesting. So a good friend

00:00:37.539 --> 00:00:39.659
of mine, an ex -colleague of mine, Peter Vanhover,

00:00:39.759 --> 00:00:43.200
who works in the Azure data team, more accurately,

00:00:43.219 --> 00:00:46.320
the Azure data security team, has published an

00:00:46.320 --> 00:00:49.299
Azure database security newsletter for April

00:00:49.299 --> 00:00:51.939
2026. I would definitely go and take a look at

00:00:51.939 --> 00:00:55.259
that. Some of the things that really sort of

00:00:55.259 --> 00:00:57.740
stood out for me, one of the big ones is customer

00:00:57.740 --> 00:01:01.549
managed keys for Fabric SQL database. as well

00:01:01.549 --> 00:01:04.189
as versionless keys for transparent data encryption

00:01:04.189 --> 00:01:06.569
in Azure SQL Database. And there's a whole bunch

00:01:06.569 --> 00:01:08.650
of best practices in there as well. It's really

00:01:08.650 --> 00:01:12.609
cool seeing Peter put this out because I'm just

00:01:12.609 --> 00:01:16.510
a big fan of just small... highly pointed, hey,

00:01:16.750 --> 00:01:18.870
you're aware of this and don't forget about this

00:01:18.870 --> 00:01:20.670
and there's this new feature here. I think that

00:01:20.670 --> 00:01:23.310
really is useful stuff. It really helps people

00:01:23.310 --> 00:01:25.689
understand how they can improve their security

00:01:25.689 --> 00:01:28.150
posture as well as taking advantage of newer

00:01:28.150 --> 00:01:30.829
security features in the product. And I'm always

00:01:30.829 --> 00:01:34.450
a big fan of customer managed keys. So now they've

00:01:34.450 --> 00:01:36.810
got the news out the way, or one item of it,

00:01:36.829 --> 00:01:39.250
let's turn our attention to our guest. As I mentioned,

00:01:39.349 --> 00:01:42.310
our guest this week is Sherrod. Sherrod, so why

00:01:42.310 --> 00:01:44.370
don't you take a little moment and reintroduce

00:01:44.370 --> 00:01:47.129
yourself to our listeners? Thanks, Michael. Hi,

00:01:47.290 --> 00:01:51.010
it's me, Sherrod Grippo. My official title is

00:01:51.010 --> 00:01:53.689
Partner GM for Global Threat Intelligence at

00:01:53.689 --> 00:01:56.909
Microsoft. But my unofficial title is Vibe Merchant,

00:01:56.909 --> 00:02:00.530
and I've got the vibes, and I'm here to provide

00:02:00.530 --> 00:02:04.530
them. What I focus on for the past 22 years or

00:02:04.530 --> 00:02:08.669
so is watching what threat actors do. and talking

00:02:08.669 --> 00:02:11.710
about it and disrupting them and imposing cost

00:02:11.710 --> 00:02:14.550
on them and doing detection engineering to stop

00:02:14.550 --> 00:02:17.430
them. And that's what I do here at Microsoft.

00:02:17.810 --> 00:02:20.610
Hey, Sherry. So, well, I saw you a couple of

00:02:20.610 --> 00:02:22.870
weeks ago talking about threat intel and what's

00:02:22.870 --> 00:02:26.770
going on in the world back up in San Francisco.

00:02:26.810 --> 00:02:30.849
So tell us, tell everybody else here, like what's

00:02:30.849 --> 00:02:36.710
occurring in threat intel land. Yeah. So, Sarah's

00:02:36.710 --> 00:02:39.469
talking about how we had a lovely time in San

00:02:39.469 --> 00:02:42.449
Francisco at the RSA conference. Probably the

00:02:42.449 --> 00:02:45.669
biggest, I think, show for information security,

00:02:46.189 --> 00:02:48.110
everyone talking about threat intelligence and

00:02:48.110 --> 00:02:51.289
obviously AI. If you've heard of that, it's this

00:02:51.289 --> 00:02:55.150
new thing that everyone is interested in. AI

00:02:55.150 --> 00:02:58.030
is big on the landscape right now because obviously

00:02:58.030 --> 00:03:01.229
everyone is talking about it, everyone is using

00:03:01.229 --> 00:03:04.229
it, and that includes threat actors. So what

00:03:04.229 --> 00:03:09.759
we're seeing is So groups of people with malicious

00:03:09.759 --> 00:03:14.180
intent, either in order to have a financial gain

00:03:14.180 --> 00:03:16.860
or to perform espionage or disruption for their

00:03:16.860 --> 00:03:21.719
respective government employer, is using AI across

00:03:21.719 --> 00:03:25.360
the entire attack chain. We're not seeing anything

00:03:25.360 --> 00:03:28.400
right now that's fully autonomous, like fully

00:03:28.400 --> 00:03:32.159
automated campaigns. Every step of that life

00:03:32.159 --> 00:03:35.479
cycle now has some sort of AI component. We're

00:03:35.479 --> 00:03:38.400
seeing threat actors do things like create fake

00:03:38.400 --> 00:03:41.240
resumes to get jobs. They're doing things like

00:03:41.240 --> 00:03:44.000
obviously creating social engineering. They're

00:03:44.000 --> 00:03:46.740
scaling out fake identities so that they can

00:03:46.740 --> 00:03:50.120
generate paperwork and get licensing and documents.

00:03:50.539 --> 00:03:53.250
They're using it for communication. Of course,

00:03:53.270 --> 00:03:55.610
they're creating malicious code like malware,

00:03:55.849 --> 00:03:59.250
malicious scripts. We have even seen threat actors

00:03:59.250 --> 00:04:04.090
go all the way to the step of automating ransomware

00:04:04.090 --> 00:04:06.810
negotiations so that the victim who is under

00:04:06.810 --> 00:04:10.449
ransom is talking to an AI agent. I'm going to

00:04:10.449 --> 00:04:14.810
just have to say wow on that last point. Is your

00:04:14.810 --> 00:04:18.730
ransomware negotiator is a chat bot? That's right.

00:04:19.959 --> 00:04:23.459
While that does seem a bit of a dystopian future,

00:04:23.740 --> 00:04:25.819
it makes sense from an automation perspective.

00:04:26.860 --> 00:04:30.540
I'm not arguing the logic at all. It hadn't even

00:04:30.540 --> 00:04:34.540
occurred to me. Threat actors are always trying

00:04:34.540 --> 00:04:37.980
to be more efficient, do more with less. And

00:04:37.980 --> 00:04:41.660
I think they've found that if they can get lots

00:04:41.660 --> 00:04:43.980
of organizations under ransom, they have to negotiate

00:04:43.980 --> 00:04:46.680
with all of them. So why not put an AI agent

00:04:46.680 --> 00:04:49.740
in front of them? Yeah. I mean, I like to say

00:04:49.740 --> 00:04:52.160
that they're the fastest adopters of every technology

00:04:52.160 --> 00:04:54.180
because they have no legal, moral, or ethical

00:04:54.180 --> 00:04:59.199
constraints to worry about. Yeah, exactly. And

00:04:59.199 --> 00:05:00.939
they want to go faster. They want to scale. They

00:05:00.939 --> 00:05:04.800
want to do more. Threat actors tend to be ambitious.

00:05:05.060 --> 00:05:09.800
So when accelerating tools come online, they

00:05:09.800 --> 00:05:11.319
take advantage of them. And we've seen that.

00:05:11.840 --> 00:05:14.959
perennially for decades. Threat actors use what's

00:05:14.959 --> 00:05:18.120
available to them and AI is no different. One

00:05:18.120 --> 00:05:21.339
thing I saw recently was threat actors actually

00:05:21.339 --> 00:05:27.060
creating highly personalized phishing lures using

00:05:27.060 --> 00:05:30.240
AI, which was really fascinating to see. So the

00:05:30.240 --> 00:05:32.019
AI would do all the background research that

00:05:32.019 --> 00:05:34.459
it had to do and then craft something that was

00:05:34.459 --> 00:05:38.060
highly, highly personal. We've seen that and

00:05:38.060 --> 00:05:40.840
we've seen that for a while and I think When

00:05:40.840 --> 00:05:44.079
I look at it, I use AI to sort of refine the

00:05:44.079 --> 00:05:46.240
emails that I'm sending or to help my messages

00:05:46.240 --> 00:05:49.240
come across with a different tone or more clearly.

00:05:49.639 --> 00:05:52.040
If you think about, as well, the language barrier,

00:05:52.120 --> 00:05:54.220
a lot of these threat actors don't speak the

00:05:54.220 --> 00:05:56.899
native language of their targets. It gives them

00:05:56.899 --> 00:06:00.920
this advantage where they can have a casual conversational

00:06:00.920 --> 00:06:04.379
tone that maybe just a basic translation app

00:06:04.379 --> 00:06:08.589
wouldn't be able to provide for them. They can

00:06:08.589 --> 00:06:12.709
do this at scale. So they can feed an LLM a list

00:06:12.709 --> 00:06:15.209
of targets and say, go research them, figure

00:06:15.209 --> 00:06:17.610
out the way that they communicate, figure out

00:06:17.610 --> 00:06:20.310
their style, and let's create some social engineering

00:06:20.310 --> 00:06:23.689
that really speaks to each of these target individuals.

00:06:24.089 --> 00:06:28.649
So I'm curious, is this like a few leading edge

00:06:28.649 --> 00:06:32.110
groups? Is this everybody experimenting? Is this...

00:06:32.560 --> 00:06:36.160
Everybody's already put it into their normal

00:06:36.160 --> 00:06:40.420
standard operating procedures. I'm curious the

00:06:40.420 --> 00:06:43.040
prevalence of this and the breadth and depth

00:06:43.040 --> 00:06:50.519
of it. In 2023, we released a report about how

00:06:50.519 --> 00:06:53.040
we're seeing a variety of nation -sponsored actors

00:06:53.040 --> 00:06:56.339
use AI. The report that came out about a month

00:06:56.339 --> 00:06:59.399
ago really focuses on some of the North Korea

00:06:59.399 --> 00:07:01.480
-based actors. So the actors that we refer to

00:07:01.480 --> 00:07:04.319
as sleet, so citrine sleet, sapphire sleet, coral

00:07:04.319 --> 00:07:08.420
sleet, those actors. And it goes into some case

00:07:08.420 --> 00:07:11.779
studies of what we see, for example, coral sleet

00:07:11.779 --> 00:07:15.839
doing. They're doing AI on development platforms

00:07:15.839 --> 00:07:19.279
so that they can manage web infrastructure at

00:07:19.279 --> 00:07:22.300
scale, for example. So they are able to put together

00:07:22.300 --> 00:07:25.930
staging infrastructure, test it. operate their

00:07:25.930 --> 00:07:28.730
command and control for their botnets, and they

00:07:28.730 --> 00:07:31.889
use AI and AI agents to do all of that. So I

00:07:31.889 --> 00:07:34.529
would say that there are leading edge use cases

00:07:34.529 --> 00:07:38.449
and there are leading edge novelty from some

00:07:38.449 --> 00:07:40.370
of the threat actors, but all of the threat actors

00:07:40.370 --> 00:07:43.410
across the board, including crime for China,

00:07:43.410 --> 00:07:45.509
Russia, North Korea, and Iran, we see leveraging

00:07:45.509 --> 00:07:48.889
AI in some way. Gotcha. So it's early adoption,

00:07:49.050 --> 00:07:52.189
but it's widespread and everybody's kind of trying

00:07:52.189 --> 00:07:54.670
their own ideas. That's where we are right now.

00:07:55.199 --> 00:07:57.839
There's a lot of experimentation, but we're absolutely

00:07:57.839 --> 00:08:01.240
seeing workflows being created the same way you

00:08:01.240 --> 00:08:03.660
or I would. I know Michael was talking about

00:08:03.660 --> 00:08:05.540
all the agents that he's been deploying for his

00:08:05.540 --> 00:08:08.100
work every day, and threat actors do the same

00:08:08.100 --> 00:08:11.680
thing. Let's be honest. The barrier for entry

00:08:11.680 --> 00:08:15.939
is really low. It's low. I don't mean it in a

00:08:15.939 --> 00:08:17.720
negative way. It's good that it's low because

00:08:17.720 --> 00:08:21.120
it can be used for good. I made a joke the other

00:08:21.120 --> 00:08:22.860
day, but I was actually dead serious. I was talking

00:08:22.860 --> 00:08:25.889
to a bunch of... kids who are graduating school.

00:08:26.589 --> 00:08:28.750
And jokingly, I said to them, what's the hottest

00:08:28.750 --> 00:08:30.550
programming language right now? And they threw

00:08:30.550 --> 00:08:35.029
out Python, Rust, not JavaScript, TypeScript,

00:08:35.129 --> 00:08:36.429
and a bunch of others. And I said, no, you're

00:08:36.429 --> 00:08:38.909
all wrong. I said, the programming language right

00:08:38.909 --> 00:08:41.590
now that's really hot is the written word. It's

00:08:41.590 --> 00:08:47.070
the ability to write unambiguous prompts. is

00:08:47.070 --> 00:08:49.009
the programming language right now. That's the

00:08:49.009 --> 00:08:51.289
hot programming language. And I mean that sincerely.

00:08:51.649 --> 00:08:54.149
And to your point, I mean, even things like AI

00:08:54.149 --> 00:08:56.330
agents, at their heart, I mean, it's the LLM

00:08:56.330 --> 00:08:59.350
itself, but also the ability to craft a very

00:08:59.350 --> 00:09:02.230
efficient prompt is really, really important.

00:09:02.570 --> 00:09:04.809
But yeah, as long as you can do that, I mean,

00:09:04.809 --> 00:09:08.470
you can get a lot done. I think so, that's right.

00:09:08.690 --> 00:09:12.269
And something I think about too is from a computer

00:09:12.269 --> 00:09:16.860
evolution timeline, most of us, you know started

00:09:16.860 --> 00:09:19.139
with a command line interface where you had to

00:09:19.139 --> 00:09:22.360
actually type commands not you know prompts you

00:09:22.360 --> 00:09:25.399
had to type the actual command to move around

00:09:25.399 --> 00:09:28.960
within your data and then you know the next step

00:09:28.960 --> 00:09:30.960
that we got was the gui which i think most people

00:09:30.960 --> 00:09:32.940
are familiar with which is a graphical user interface

00:09:32.940 --> 00:09:35.700
where you can point and click and you know you

00:09:35.700 --> 00:09:39.360
see icons and now we are at an interface with

00:09:39.360 --> 00:09:42.039
our computers and our technology we interface

00:09:42.039 --> 00:09:44.480
with our data now with natural language if we

00:09:44.480 --> 00:09:47.860
want to. I can ask questions about my data. I

00:09:47.860 --> 00:09:51.480
can talk to my data. And I think that that's

00:09:51.480 --> 00:09:56.419
a huge democratization of the ability to compute,

00:09:56.539 --> 00:09:59.539
of the ability to use technology. But it also

00:09:59.539 --> 00:10:01.399
means that people have access to tools that they

00:10:01.399 --> 00:10:03.659
don't understand or have skill in using. And

00:10:03.659 --> 00:10:06.679
so that can be dangerous in a variety of ways.

00:10:07.200 --> 00:10:09.279
It can be good though as well. And I'll give

00:10:09.279 --> 00:10:12.549
an example. So I basically live, in GitHub Copilot.

00:10:13.230 --> 00:10:16.950
And I had this horrible, horrible merge conflict

00:10:16.950 --> 00:10:21.289
on GitHub. And I was trying to work it out. And

00:10:21.289 --> 00:10:24.590
I'm not going to pretend that I know Git upside

00:10:24.590 --> 00:10:26.850
down, inside out, the wrong way around. I don't.

00:10:26.850 --> 00:10:29.830
I know it well. But some of the corner cases

00:10:29.830 --> 00:10:32.169
I'm just not good at. Just told GitHub Copilot

00:10:32.169 --> 00:10:35.029
precisely what was going on and it did it for

00:10:35.029 --> 00:10:38.029
me. And it did it correctly. Would have taken

00:10:38.029 --> 00:10:40.090
me quite some time to probably get it wrong.

00:10:40.879 --> 00:10:44.179
Whereas GitHub Copilot got it right quickly and

00:10:44.179 --> 00:10:48.000
correctly with just a human prompt. So I agree

00:10:48.000 --> 00:10:50.179
100 % that people are using tools they don't

00:10:50.179 --> 00:10:52.460
necessarily understand. I mean, let's look at

00:10:52.460 --> 00:10:59.159
OpenCore, right? But when it's used well, it

00:10:59.159 --> 00:11:01.139
can be a real time saver. By the way, I didn't

00:11:01.139 --> 00:11:02.759
realize this. By the way, for everyone who's

00:11:02.759 --> 00:11:06.779
listening, we have zero agenda. We literally

00:11:06.779 --> 00:11:10.309
had share a join. And I said, I guess we're talking

00:11:10.309 --> 00:11:12.330
threat intel, just because I know Sherrod so

00:11:12.330 --> 00:11:14.370
well. That's the only thing I know about. That's

00:11:14.370 --> 00:11:18.269
right. And AI. And AI. But the point is that,

00:11:18.289 --> 00:11:19.830
you know, I think it's good that we can take

00:11:19.830 --> 00:11:21.669
it in relative, you know, different directions

00:11:21.669 --> 00:11:25.370
as needed. So, Michael, I actually have an...

00:11:25.789 --> 00:11:31.649
identical experience. So I was updating a website

00:11:31.649 --> 00:11:36.049
and I can code, but I'm pretty rusty. And I couldn't

00:11:36.049 --> 00:11:38.669
believe how quickly, even compared with a year

00:11:38.669 --> 00:11:42.830
ago when I was updating the same code, how much

00:11:42.830 --> 00:11:46.710
the LLMs have improved because there was a year

00:11:46.710 --> 00:11:50.190
ago it could not fix. It was a really annoying

00:11:50.190 --> 00:11:53.009
justification thing on the website. And this

00:11:53.009 --> 00:11:56.149
time it fixed it in one prompt. So Yeah, it's

00:11:56.149 --> 00:11:59.950
incredible what you can do with the AI and the

00:11:59.950 --> 00:12:03.429
LLM. So I'm not surprised that actors are taking

00:12:03.429 --> 00:12:08.330
advantage because I sure am. I am too. And the

00:12:08.330 --> 00:12:10.309
workflows that are available and the resources

00:12:10.309 --> 00:12:14.629
that are there, it's incredible. I really do

00:12:14.629 --> 00:12:16.809
think that we are at an evolutionary moment in

00:12:16.809 --> 00:12:19.169
computing and in technology. And maybe, I'll

00:12:19.169 --> 00:12:21.629
say it, maybe in the human race where we are

00:12:21.629 --> 00:12:24.549
at a real inflection point. Yeah, it's kind of

00:12:24.549 --> 00:12:27.129
interesting because, of course, security people

00:12:27.129 --> 00:12:29.029
are all critical thinkers, right? And we always

00:12:29.029 --> 00:12:32.190
look at, hey, what could go wrong, right? Yes.

00:12:32.750 --> 00:12:36.889
And you triggered me a little bit because I created

00:12:36.889 --> 00:12:39.720
a slide that talked about... And for several

00:12:39.720 --> 00:12:42.440
of my workshops, it talks about how AI basically

00:12:42.440 --> 00:12:45.580
brings to life the old dream that, you know,

00:12:45.600 --> 00:12:47.740
I have this vision in my head of like a dude

00:12:47.740 --> 00:12:50.940
wearing a cardboard box spray painted silver,

00:12:51.080 --> 00:12:53.179
right, in a black and white TV show. And like,

00:12:53.179 --> 00:12:54.779
we've dreamed that these computers would talk

00:12:54.779 --> 00:12:57.059
our language. And now they do. And we're like,

00:12:57.179 --> 00:13:01.899
oh, crap. Yeah. Yeah. And I do think that, you

00:13:01.899 --> 00:13:05.899
know, I love. Marvel, I love the MCU. And those

00:13:05.899 --> 00:13:10.460
early films of Iron Man with Jarvis, I feel like

00:13:10.460 --> 00:13:13.179
it's here. I feel like Jarvis is here. I don't

00:13:13.179 --> 00:13:15.539
think he's fully here, but we're not that far

00:13:15.539 --> 00:13:18.019
away. We're a significant percentage of the way

00:13:18.019 --> 00:13:21.379
there. It's really close. Hey, how about I bring

00:13:21.379 --> 00:13:25.220
us back down to Threat Intel? What a concept.

00:13:26.590 --> 00:13:28.549
That rabbit hole we just went down was all my

00:13:28.549 --> 00:13:31.470
mistake, my fault, because I said the barrier

00:13:31.470 --> 00:13:34.730
for entry is so low and it is. And threat actors

00:13:34.730 --> 00:13:37.029
are taking full advantage of that. That leads

00:13:37.029 --> 00:13:38.809
to the next question, if the attackers are using

00:13:38.809 --> 00:13:41.750
AI to help them be more efficient, so what's

00:13:41.750 --> 00:13:43.429
happening on the defensive side of the house?

00:13:43.830 --> 00:13:47.570
I think defenders are so well placed right now

00:13:47.570 --> 00:13:50.950
to be able to scale and accelerate their capability.

00:13:51.710 --> 00:13:54.570
The thing I've been saying a lot lately is A

00:13:54.570 --> 00:13:58.029
and AI. almost stands for accelerate more than

00:13:58.029 --> 00:14:01.330
artificial. You can go so much faster as a defender.

00:14:01.549 --> 00:14:04.250
You can get resources so much more quickly. And

00:14:04.250 --> 00:14:08.210
we really are seeing incredibly innovative and

00:14:08.210 --> 00:14:11.769
talented people put AI automation into detection

00:14:11.769 --> 00:14:16.009
engineering, into the SOC, into hunting, into

00:14:16.009 --> 00:14:20.730
looking through huge pieces of data. One of the

00:14:20.730 --> 00:14:25.149
favorite use cases that I really love is doing

00:14:25.629 --> 00:14:28.870
code audit to look for hard -coded credentials.

00:14:29.529 --> 00:14:31.370
Michael, something you and I have talked about

00:14:31.370 --> 00:14:35.210
quite a bit, don't do that. But AI is able to

00:14:35.210 --> 00:14:39.009
go through code bases and find those things that,

00:14:39.110 --> 00:14:42.629
hey, this is clearly a problem, you need to change

00:14:42.629 --> 00:14:44.750
it. And it finds it really quickly and you can

00:14:44.750 --> 00:14:46.750
take care of it very fast so that you're releasing

00:14:46.750 --> 00:14:49.970
code that isn't vulnerable to begin with. Yeah,

00:14:49.990 --> 00:14:51.889
it's more than that. It's not just hunting for

00:14:51.889 --> 00:14:53.889
credentials, right? I mean, again, you and I

00:14:53.889 --> 00:14:55.940
have spoken about this at length. You know, you

00:14:55.940 --> 00:14:59.159
can use LLMs to do huge code audits. I mean,

00:14:59.179 --> 00:15:02.740
we see that now with the new anthropic mythos

00:15:02.740 --> 00:15:06.299
models. You know, they're basically right now

00:15:06.299 --> 00:15:10.120
being restricted as to who can access them because,

00:15:10.220 --> 00:15:14.019
you know, they're good at what they do. And so,

00:15:14.100 --> 00:15:16.100
you know, I don't know what the policy is long

00:15:16.100 --> 00:15:18.220
term, but for the short term, they're going to

00:15:18.220 --> 00:15:20.419
be restricted to a small number of commercial

00:15:20.419 --> 00:15:24.980
entities. I think... Again, I use LLMs every

00:15:24.980 --> 00:15:28.419
day for doing code audit, but we also have a

00:15:28.419 --> 00:15:31.100
whole bunch of agents that do the majority of

00:15:31.100 --> 00:15:33.500
the work. I don't actually write the prompts.

00:15:34.059 --> 00:15:36.460
I may nudge the prompts, but I don't actually

00:15:36.460 --> 00:15:38.059
write the prompts and do the actual review. Some

00:15:38.059 --> 00:15:40.980
of those prompts are huge. I was one of the agents

00:15:40.980 --> 00:15:42.379
that I've been working on. I'm not going to go

00:15:42.379 --> 00:15:43.720
into all the details. It takes a whole bunch

00:15:43.720 --> 00:15:46.149
of very sensitive documents. and produces a whole

00:15:46.149 --> 00:15:48.110
bunch of sensitive output that's used by a completely

00:15:48.110 --> 00:15:50.529
different team at Microsoft to help them drive

00:15:50.529 --> 00:15:54.570
what they do. And the prompt for that is seven

00:15:54.570 --> 00:15:59.389
pages long. And it produces very high quality

00:15:59.389 --> 00:16:02.029
output. You know, that would take me, if I was

00:16:02.029 --> 00:16:03.889
to review these documents by hand, it would take

00:16:03.889 --> 00:16:06.610
me weeks to be able to review the documents versus

00:16:06.610 --> 00:16:11.090
15 minutes, you know, for my agent to actually

00:16:11.090 --> 00:16:15.129
do the work. But again, the secret sauce there

00:16:15.129 --> 00:16:19.309
is really the prompt itself. And that prompt

00:16:19.309 --> 00:16:21.509
that I use, as I mentioned, is at least seven

00:16:21.509 --> 00:16:24.409
pages long. And that's kind of the thing we're

00:16:24.409 --> 00:16:28.230
learning, right, is that for defenders, you have

00:16:28.230 --> 00:16:31.409
a new tool that can do a lot for you. And you

00:16:31.409 --> 00:16:35.730
need to really understand how to skillfully use

00:16:35.730 --> 00:16:38.690
this tool now. And I think a lot of defenders

00:16:38.690 --> 00:16:42.399
are starting to realize. power, like you said,

00:16:42.480 --> 00:16:46.240
of really good prompting, whether that has some

00:16:46.240 --> 00:16:51.279
metric around length or specificity or constant

00:16:51.279 --> 00:16:54.279
refinement or whatever it may be. I think it's

00:16:54.279 --> 00:16:55.940
really interesting seeing defenders learn how

00:16:55.940 --> 00:16:57.899
to communicate differently. And essentially,

00:16:58.159 --> 00:17:00.440
a lot of us have social engineering backgrounds

00:17:00.440 --> 00:17:04.720
or social engineering expertise. You need to

00:17:04.720 --> 00:17:07.039
be able to social engineer the LLM that you're

00:17:07.039 --> 00:17:11.470
talking to. And so get really good at talking

00:17:11.470 --> 00:17:15.950
with urgency, talking with emotion, giving constraints,

00:17:16.369 --> 00:17:20.269
giving consequences. What will happen? How is

00:17:20.269 --> 00:17:24.049
this going to work? Being really specific and

00:17:24.049 --> 00:17:27.130
innovative with the way that you use these tools

00:17:27.130 --> 00:17:31.170
is going to get better results. Like AI persuasion.

00:17:31.450 --> 00:17:40.119
Absolutely. I really like about the AI technology

00:17:40.119 --> 00:17:42.400
because I know there's a lot of, hey, it's going

00:17:42.400 --> 00:17:45.099
to take my job and all those kind of fears. At

00:17:45.099 --> 00:17:47.460
the end of the day, it's task automation. It

00:17:47.460 --> 00:17:50.000
doesn't change the critical thinking or the objective

00:17:50.000 --> 00:17:52.359
of what jobs have to get done. It just makes

00:17:52.359 --> 00:17:55.740
them happen more automatically. But the thing

00:17:55.740 --> 00:17:58.240
that I think a lot of people overlook is there's

00:17:58.240 --> 00:18:00.359
a bunch of stuff that people don't like to do.

00:18:00.720 --> 00:18:03.319
No developer likes to... document their code.

00:18:03.460 --> 00:18:05.440
No analyst wants to stop in the middle of an

00:18:05.440 --> 00:18:08.420
investigation to write up a report, to give to

00:18:08.420 --> 00:18:10.880
their manager, to give an update and up the chain.

00:18:11.279 --> 00:18:14.180
Like it's really good at the crap that we hate

00:18:14.180 --> 00:18:17.420
doing as people. And so that's, that's one of

00:18:17.420 --> 00:18:19.099
the things I think a lot of people overlook when

00:18:19.099 --> 00:18:21.099
they're sort of looking at this and they, they,

00:18:21.180 --> 00:18:23.220
they keep looking at it like it's like classic

00:18:23.220 --> 00:18:25.279
automation or classic machine learning and data

00:18:25.279 --> 00:18:27.880
analysis, but it's like, this actually does something

00:18:27.880 --> 00:18:31.859
different. And I love that in the SOC or for

00:18:31.859 --> 00:18:35.259
Defenders overall, we've always felt like we

00:18:35.259 --> 00:18:36.920
don't have enough people. We don't have enough

00:18:36.920 --> 00:18:40.319
resources. I wish we had headcount, all these

00:18:40.319 --> 00:18:43.200
things. And I think that if you're smart about

00:18:43.200 --> 00:18:46.279
the way that you leverage these new tools, you

00:18:46.279 --> 00:18:48.279
can get rid of some of those complaints and constraints

00:18:48.279 --> 00:18:50.859
and frustrations and actually have a much more

00:18:50.859 --> 00:18:54.200
seamless operation. Yeah, you wanted to get to

00:18:54.200 --> 00:18:56.019
threat hunting, but you couldn't because you

00:18:56.019 --> 00:18:58.519
were doing all the investigation stuff. Well,

00:18:58.539 --> 00:19:02.019
now it takes 80 % less effort to do that, and

00:19:02.019 --> 00:19:04.599
you have time to get to the other alerts, to

00:19:04.599 --> 00:19:06.500
do more threat hunting, to do more threat intel

00:19:06.500 --> 00:19:09.019
research. All the things that you've wanted to

00:19:09.019 --> 00:19:11.559
do, because there's always a list, that you couldn't

00:19:11.559 --> 00:19:14.259
do. Yeah, I think that's great. That's one of

00:19:14.259 --> 00:19:17.359
the things that brings me a lot of hope and excitement.

00:19:17.460 --> 00:19:20.839
I consider myself an AI optimist, so this is

00:19:20.839 --> 00:19:23.059
one of the points that I like. Yeah, I'm definitely

00:19:23.059 --> 00:19:25.859
an AI optimist. I really am. I see the huge opportunity.

00:19:26.259 --> 00:19:28.220
I mean, don't get me wrong. I mean, from an attacking

00:19:28.220 --> 00:19:30.740
perspective, I mean, obviously there's some big

00:19:30.740 --> 00:19:33.019
risks there. But it's like anything, right? I

00:19:33.019 --> 00:19:35.619
mean, books in the library can be used for good

00:19:35.619 --> 00:19:37.500
and for bad. I mean, it's just the way things

00:19:37.500 --> 00:19:41.730
are. So we talk very generally about... threat

00:19:41.730 --> 00:19:44.869
intel and sort of ai and ai in general where

00:19:44.869 --> 00:19:47.029
where are we at with microsoft in terms of threat

00:19:47.029 --> 00:19:48.930
intel like what is what is front and center with

00:19:48.930 --> 00:19:50.750
uh with what's going on at microsoft around threat

00:19:50.750 --> 00:19:54.170
intel and potentially even ai well so microsoft

00:19:54.170 --> 00:19:57.470
has a really as you're aware has a really big

00:19:57.470 --> 00:20:00.890
and robust um machine around threat intelligence

00:20:00.890 --> 00:20:05.230
we have a variety of teams that do um hunting

00:20:05.230 --> 00:20:07.589
they're specialized malware reverse engineers

00:20:07.589 --> 00:20:12.559
there are language experts We look at 100 trillion

00:20:12.559 --> 00:20:16.440
security signals a day coming from 1 .5 billion

00:20:16.440 --> 00:20:19.500
endpoints. So Microsoft has a broad and deep

00:20:19.500 --> 00:20:25.480
visibility with which to make inferences and

00:20:25.480 --> 00:20:27.799
have insights into what's happening in the landscape.

00:20:28.099 --> 00:20:32.039
And that's sort of what the reality is like for

00:20:32.039 --> 00:20:35.099
us. Microsoft looks at those signals and then

00:20:35.099 --> 00:20:37.519
determines where we can best use the information.

00:20:38.509 --> 00:20:40.289
that we have coming in. And a lot of times that's

00:20:40.289 --> 00:20:43.049
used to protect, obviously, Microsoft itself,

00:20:43.250 --> 00:20:46.309
but also, of course, we put those detections

00:20:46.309 --> 00:20:50.569
into products or we work with our partners for

00:20:50.569 --> 00:20:54.569
doing things that are disruptive, for blocking

00:20:54.569 --> 00:20:59.630
botnets, or working in a variety of ways with

00:20:59.630 --> 00:21:01.769
various public and private partners to make sure

00:21:01.769 --> 00:21:04.150
that the threat intelligence that we have is

00:21:04.150 --> 00:21:07.849
being used to increase the security posture of

00:21:08.250 --> 00:21:11.349
Ourself, our customers, the world. I have a really

00:21:11.349 --> 00:21:14.569
silly question. I have a silly answer. Fantastic.

00:21:14.890 --> 00:21:16.130
Actually, I hope your answer is better than my

00:21:16.130 --> 00:21:19.029
question. So I hear the term, look, this is really

00:21:19.029 --> 00:21:22.230
naive. I hear the term, you know, N trillion

00:21:22.230 --> 00:21:26.769
signals. Give me three examples of signals. A

00:21:26.769 --> 00:21:30.369
signal would be malicious email is blocked in

00:21:30.369 --> 00:21:33.829
MDO. A signal would be... A piece of code attempts

00:21:33.829 --> 00:21:36.750
to execute on an endpoint and Defender detects

00:21:36.750 --> 00:21:40.250
and blocks that. A piece of signal would be a

00:21:40.250 --> 00:21:44.710
URL that is hosting a malicious payload and getting

00:21:44.710 --> 00:21:46.509
people to click on it and download that malicious

00:21:46.509 --> 00:21:50.930
payload. Give me another one. A security signal

00:21:50.930 --> 00:21:54.259
that comes in is... Atomic indicators, hashes,

00:21:54.259 --> 00:21:57.420
IP addresses, domain names that have some association

00:21:57.420 --> 00:21:59.980
with serving malicious traffic of some kind or

00:21:59.980 --> 00:22:03.839
being used to communicate malicious. Like a reputation

00:22:03.839 --> 00:22:06.759
or a URL? Like reputation, yeah. Like a list

00:22:06.759 --> 00:22:09.420
of IP addresses that are part of a botnet, for

00:22:09.420 --> 00:22:11.920
example. Okay, got it. Cool. Okay, so it's actually

00:22:11.920 --> 00:22:15.359
known relevant to security or attacks, not just

00:22:15.359 --> 00:22:19.500
raw data. Correct. Wow. The scale of that is

00:22:19.500 --> 00:22:22.119
stunning. It's crazy. But you have to remember

00:22:22.119 --> 00:22:26.819
too, we're talking about IoT devices. We're talking

00:22:26.819 --> 00:22:29.680
about multi -cloud, right? So Microsoft has cloud

00:22:29.680 --> 00:22:31.940
protections, not just for Azure, but also for

00:22:31.940 --> 00:22:36.400
Google Cloud, for AWS. We're talking about IoT.

00:22:36.519 --> 00:22:41.640
We're talking about multi -platform. So not just

00:22:41.640 --> 00:22:46.480
Windows, but Mac, Android, iOS. The visibility

00:22:46.480 --> 00:22:49.660
is huge and we're talking about malicious signals

00:22:49.660 --> 00:22:52.099
that are in the browser, malicious signals that

00:22:52.099 --> 00:22:55.299
are in search with Bing, malicious ads that are

00:22:55.299 --> 00:22:58.880
serving ad payloads that lead to malware downloads.

00:22:59.259 --> 00:23:02.250
It's broad. Yeah, the analogy I like to use,

00:23:02.450 --> 00:23:05.789
I haven't presented a threat intelligence slide

00:23:05.789 --> 00:23:08.630
in a while, but when I do, it's like you're trying

00:23:08.630 --> 00:23:10.670
to catch a unicorn running through a dark forest,

00:23:10.730 --> 00:23:12.849
and you want as many cameras as you can so that

00:23:12.849 --> 00:23:15.250
you have a better chance of finding it, but you

00:23:15.250 --> 00:23:17.109
can also say, hey, there's a hoof, there's a

00:23:17.109 --> 00:23:20.650
horn, there's a tail. You know, connect the dots.

00:23:21.630 --> 00:23:24.490
I normally don't like analogies, but that's actually

00:23:24.490 --> 00:23:29.220
a pretty good one. So, Sherrod. I'm curious,

00:23:29.359 --> 00:23:31.200
you know, I have sort of my perspective from

00:23:31.200 --> 00:23:34.059
sort of the field of, you know, how our threat

00:23:34.059 --> 00:23:36.000
intelligence evolved and that number keeps going

00:23:36.000 --> 00:23:38.180
up, of course. Can you talk a little bit about

00:23:38.180 --> 00:23:40.740
how like the program and the way we approach

00:23:40.740 --> 00:23:42.980
threat intelligence has evolved over time and

00:23:42.980 --> 00:23:45.140
the kind of things we've learned as we've, you

00:23:45.140 --> 00:23:47.339
know, been managing these, you know, whatever

00:23:47.339 --> 00:23:51.059
it was, 12, 15, 58, 72 to 100 trillion signals.

00:23:51.539 --> 00:23:54.539
Like, are we learning things, doing things differently?

00:23:55.420 --> 00:23:58.549
Curious, curious your perspective on that. Yeah,

00:23:58.549 --> 00:24:00.509
I think, and it's really interesting to me too.

00:24:01.529 --> 00:24:04.569
Microsoft has, I think, in many ways kind of

00:24:04.569 --> 00:24:07.609
followed the evolution that most information

00:24:07.609 --> 00:24:10.150
security vendors and threat intelligence vendors

00:24:10.150 --> 00:24:13.630
have followed, which is over the years, you know,

00:24:13.630 --> 00:24:15.569
the past five or 10 years, the landscape has

00:24:15.569 --> 00:24:18.170
exploded. More and more threat actors have come

00:24:18.170 --> 00:24:21.309
online and Microsoft threat intelligence as a

00:24:21.309 --> 00:24:24.049
group, as a capability, as a function within

00:24:24.049 --> 00:24:26.660
the company. has had to evolve along with the

00:24:26.660 --> 00:24:32.240
landscape. Some of the notable evolutions are

00:24:32.240 --> 00:24:36.200
breaking out our own team to be Microsoft threat

00:24:36.200 --> 00:24:39.759
intelligence or mystic. And then some that some

00:24:39.759 --> 00:24:44.259
of the listeners might remember is when in March

00:24:44.259 --> 00:24:48.180
of 2023, Microsoft moved from threat actor group

00:24:48.180 --> 00:24:51.640
naming aligned to the periodic table of elements

00:24:51.640 --> 00:24:57.299
to weather patterns. And it caused a great consternation

00:24:57.299 --> 00:25:03.279
amongst the threat intelligence cometariat out

00:25:03.279 --> 00:25:05.940
there in the world. But the reason for that was

00:25:05.940 --> 00:25:08.680
we ran out of elements and there were just so

00:25:08.680 --> 00:25:13.140
many threat actors that we ran out of names and

00:25:13.140 --> 00:25:15.240
there was no choice but to move to a new naming

00:25:15.240 --> 00:25:19.059
convention. And just quickly for those who aren't

00:25:19.059 --> 00:25:23.039
aware, Sleet is North Korea, Blizzard is Russia,

00:25:23.380 --> 00:25:26.380
Typhoon is China, and Sandstorm is Iran, with

00:25:26.380 --> 00:25:29.400
Tempest being financially motivated or crime

00:25:29.400 --> 00:25:31.980
-based threat actor groups. So when you hear

00:25:31.980 --> 00:25:33.700
one of those words, you can kind of associate

00:25:33.700 --> 00:25:37.559
what its origin is. We've had to realize that

00:25:37.559 --> 00:25:41.599
there are hundreds up into the thousands of threat

00:25:41.599 --> 00:25:45.279
actor groups, and new ones come and go and disband

00:25:45.279 --> 00:25:50.109
and reform, and we track all of that. And particularly

00:25:50.109 --> 00:25:54.130
in the crime ecosystem, there are threat actor

00:25:54.130 --> 00:25:57.289
groups we track that do just one little thing.

00:25:57.369 --> 00:26:00.690
Maybe they don't deliver ransomware. Maybe they

00:26:00.690 --> 00:26:03.930
just make a toolkit that a lot of threat actors

00:26:03.930 --> 00:26:06.690
then use. Well, we want to track that group and

00:26:06.690 --> 00:26:08.690
see who they're selling that toolkit to, what

00:26:08.690 --> 00:26:10.690
the evolution of the toolkit is. Are they running

00:26:10.690 --> 00:26:14.710
a sale this month, which they do. We want to

00:26:14.710 --> 00:26:16.930
understand the full landscape and all of those

00:26:16.930 --> 00:26:19.089
players. So that means that we have to evolve

00:26:19.089 --> 00:26:20.869
the way that we name them, the way that we track

00:26:20.869 --> 00:26:23.809
them. Sorry, I just have to interrupt you there,

00:26:23.829 --> 00:26:26.750
Sherrod. Did you just say that they have a sale?

00:26:27.490 --> 00:26:31.710
Yes. So there's a variety of threat actor groups

00:26:31.710 --> 00:26:35.970
that have full customer service style help support.

00:26:36.470 --> 00:26:39.089
You can email, you can get chat support for your

00:26:39.089 --> 00:26:44.509
attacker in the middle, MFA bypass. fish kit

00:26:44.509 --> 00:26:48.450
landing pages, for example. They run sales. That

00:26:48.450 --> 00:26:53.569
is wild. Every time I hear stuff about bad actors

00:26:53.569 --> 00:26:56.509
and these groups, obviously, I know some of them

00:26:56.509 --> 00:26:59.049
are very sophisticated. The idea that they have

00:26:59.049 --> 00:27:01.869
a sale, like a real shop, some kind of actual

00:27:01.869 --> 00:27:04.369
commercial thing is always still blows my mind.

00:27:04.589 --> 00:27:08.450
They're fully operationalized. And we see the

00:27:08.450 --> 00:27:10.089
marketing materials that they send out to their

00:27:10.089 --> 00:27:12.849
existing customers saying, you know, if you If

00:27:12.849 --> 00:27:15.049
you're enjoying the product, we're having a sale,

00:27:15.109 --> 00:27:17.329
you can buy a year's license for last year's

00:27:17.329 --> 00:27:20.069
price, for example. I just have this vision in

00:27:20.069 --> 00:27:24.349
my head of those infomercial pitchmen that are

00:27:24.349 --> 00:27:26.910
sitting there saying, yes, but wait, there's

00:27:26.910 --> 00:27:31.529
more. It comes with this. It's true. I have another

00:27:31.529 --> 00:27:34.190
one of my silly questions. You said that there

00:27:34.190 --> 00:27:36.789
are suffixes to denote countries, but also financially

00:27:36.789 --> 00:27:39.920
motivated. So what takes priority if it's like

00:27:39.920 --> 00:27:46.700
a Russian financial operative? So those alignments

00:27:46.700 --> 00:27:51.059
are generally around... the motivation or the

00:27:51.059 --> 00:27:53.740
end goal of the threat actor. Some countries

00:27:53.740 --> 00:27:56.940
do have an interesting relational overlap between

00:27:56.940 --> 00:27:59.759
their military intelligence and espionage capability

00:27:59.759 --> 00:28:03.000
and their criminal groups. We see that some.

00:28:03.380 --> 00:28:05.759
Really what takes precedence is we try to focus

00:28:05.759 --> 00:28:08.059
on how we can best secure Microsoft customers.

00:28:08.279 --> 00:28:11.279
That really is the focus, is where can we use

00:28:11.279 --> 00:28:13.900
this information best? What threat on the landscape

00:28:13.900 --> 00:28:17.619
today is the most concerning? But that changes

00:28:17.619 --> 00:28:20.640
all the time. Threat actor groups are constantly

00:28:20.640 --> 00:28:22.900
evolving, constantly changing. New ones are showing

00:28:22.900 --> 00:28:26.859
up all the time. It's a daily desk reality where

00:28:26.859 --> 00:28:31.400
if I take vacation for a week, it's hard to miss

00:28:31.400 --> 00:28:33.319
out on what's going on. But I come back and I'm

00:28:33.319 --> 00:28:35.339
sort of like, okay, I need to go read all the

00:28:35.339 --> 00:28:37.079
backlog of what all the actor groups did over

00:28:37.079 --> 00:28:38.940
the week so that I'm caught back up on the landscape.

00:28:39.279 --> 00:28:41.980
So one of the thoughts that I had earlier with

00:28:41.980 --> 00:28:44.140
the conversation was so interesting, I kind of

00:28:44.140 --> 00:28:49.769
put it to the side. One of the observations I've

00:28:49.769 --> 00:28:53.309
made about the AI models is triggered by your

00:28:53.309 --> 00:28:55.750
comments on how easy it is to write code and

00:28:55.750 --> 00:28:59.609
applications and get it to do stuff. I've realized

00:28:59.609 --> 00:29:04.630
that AI is overcapable in a way. We used to have

00:29:04.630 --> 00:29:06.569
to build every piece of software brick by brick.

00:29:06.809 --> 00:29:08.829
And then, yes, we learned how to use other bricks

00:29:08.829 --> 00:29:10.789
and reuse components and open source and all

00:29:10.789 --> 00:29:13.230
that kind of stuff. We got efficient at it. But

00:29:13.230 --> 00:29:16.349
if you didn't write the code, it didn't do the

00:29:16.349 --> 00:29:18.490
thing, right? That was the old rule. But with

00:29:18.490 --> 00:29:22.329
the AI models, it comes with hundreds of thousands

00:29:22.329 --> 00:29:25.509
of skills that you probably don't need on any

00:29:25.509 --> 00:29:29.390
given thing. And so it feels like AI is really

00:29:29.390 --> 00:29:31.930
like a constrained by default mode instead of

00:29:31.930 --> 00:29:34.769
build by default. It feels like it inverts the

00:29:34.769 --> 00:29:36.809
thing. And I was just kind of curious on your

00:29:36.809 --> 00:29:38.349
experience of that, because that introduces all

00:29:38.349 --> 00:29:41.210
sorts of interesting security things. But curious

00:29:41.210 --> 00:29:44.059
your thoughts. If you have any reactions to that.

00:29:44.220 --> 00:29:46.859
I certainly do. I mean, you know, LLMs are definitely

00:29:46.859 --> 00:29:50.359
highly capable and we do spend a lot of time

00:29:50.359 --> 00:29:53.259
constraining the models as well. We being the

00:29:53.259 --> 00:29:54.839
industry, I don't mean necessarily Microsoft,

00:29:55.119 --> 00:29:58.180
you know, with all sorts of content safety, which

00:29:58.180 --> 00:30:01.660
the fact that content safety exists means that

00:30:01.660 --> 00:30:03.920
the models are capable of producing something

00:30:03.920 --> 00:30:09.009
that's air quotes. Whatever unsafe means, right,

00:30:09.089 --> 00:30:12.769
in your context. But yeah, 100%. I mean, LLMs

00:30:12.769 --> 00:30:15.869
are incredibly capable and they know a lot. I

00:30:15.869 --> 00:30:20.049
like to try to constrain my models, not... necessarily

00:30:20.049 --> 00:30:23.970
because of any danger, but I think I've mentioned

00:30:23.970 --> 00:30:25.809
this once before. If I'm talking to an LLM about

00:30:25.809 --> 00:30:28.490
rust, I want it to know that I'm talking about

00:30:28.490 --> 00:30:29.789
the programming language and I'm not talking

00:30:29.789 --> 00:30:33.809
about iron oxide. I'm not talking about a movie.

00:30:34.589 --> 00:30:37.150
I'm talking about the programming language. Imagine

00:30:37.150 --> 00:30:39.750
if you're a lawyer and you want to use an LLM

00:30:39.750 --> 00:30:43.809
that knows about legal precedent, not about all

00:30:43.809 --> 00:30:46.009
sorts of other stuff because that will help the

00:30:46.009 --> 00:30:50.210
LLM help the LLM. force the LLM to potentially

00:30:50.210 --> 00:30:52.069
start hallucinating, right? If it's got more

00:30:52.069 --> 00:30:54.150
stuff that has nothing to do with the legal landscape,

00:30:54.390 --> 00:30:56.569
then it can start hallucinating about stuff that

00:30:56.569 --> 00:30:59.230
have nothing to do with the legal landscape.

00:30:59.930 --> 00:31:02.329
So yeah, I think you do want to constrain them

00:31:02.329 --> 00:31:04.890
anyway, but yeah, they are potentially unsafe

00:31:04.890 --> 00:31:08.230
in certain types of contexts. I mean, Sarah,

00:31:08.309 --> 00:31:10.910
you've done some stuff on AI safety, right? I

00:31:10.910 --> 00:31:15.529
have. It's, well, I have worked with the much

00:31:15.529 --> 00:31:18.490
smarter people than me in our AI Red team and

00:31:18.490 --> 00:31:21.630
stuff. Sherrod, so since you came on last time,

00:31:21.670 --> 00:31:24.069
we now have a new fun question that we ask everyone

00:31:24.069 --> 00:31:27.670
who comes on our podcast, which is, what does

00:31:27.670 --> 00:31:31.589
a day in the life of Sherrod look like? Every

00:31:31.589 --> 00:31:34.269
day is definitely different. I love all the different

00:31:34.269 --> 00:31:39.579
things. I definitely think that my role is You

00:31:39.579 --> 00:31:41.400
know, I make the joke that I wear like a helmet

00:31:41.400 --> 00:31:43.539
and a catcher's mitt because people just throw

00:31:43.539 --> 00:31:46.200
things over the wall at me and say, hey, you

00:31:46.200 --> 00:31:48.319
seem like the right person to handle this. And

00:31:48.319 --> 00:31:53.400
I look at it and I think, well, yes, I don't

00:31:53.400 --> 00:31:55.059
know who else this could be. I guess it has to

00:31:55.059 --> 00:31:57.960
be me. So things like, you know, we're partnering

00:31:57.960 --> 00:32:00.299
with another information security vendor and

00:32:00.299 --> 00:32:03.500
we want to release really great disruptive threat

00:32:03.500 --> 00:32:05.980
coverage and we want to do it all at once. And

00:32:05.980 --> 00:32:08.809
so we'll vet. the data that we have against the

00:32:08.809 --> 00:32:11.150
data the partner has, make sure that it all makes

00:32:11.150 --> 00:32:13.950
sense, wrap it up all together and do like a

00:32:13.950 --> 00:32:17.009
co -timed release, even with our public sector

00:32:17.009 --> 00:32:20.430
or law enforcement partners that we've had a

00:32:20.430 --> 00:32:23.990
great success with something. I spend a lot of

00:32:23.990 --> 00:32:26.930
my time, as I said, on the daily desk. I try

00:32:26.930 --> 00:32:30.769
to read and look through everything that's happening

00:32:30.769 --> 00:32:35.210
in our data and in our platforms to see what

00:32:35.210 --> 00:32:36.650
threat actors are doing. That's something that

00:32:36.920 --> 00:32:39.079
I think in this kind of role you really have

00:32:39.079 --> 00:32:42.299
to do. I love reading indictments. I feel like

00:32:42.299 --> 00:32:46.339
they give these incredible insight and picture

00:32:46.339 --> 00:32:49.339
into what threat actors are doing that maybe

00:32:49.339 --> 00:32:52.759
we don't see because of our visibility, you know,

00:32:52.759 --> 00:32:54.519
is only a certain way. They might have a lot

00:32:54.519 --> 00:32:56.559
of information and detail that I can look at.

00:32:57.000 --> 00:33:00.619
And I try to catch up with a coworker or two.

00:33:00.700 --> 00:33:03.809
I try to, you know, put the fun, cool people

00:33:03.809 --> 00:33:08.029
into my day when I can. And Microsoft has an

00:33:08.029 --> 00:33:11.089
interesting culture. I'm only here three years,

00:33:11.190 --> 00:33:13.950
but something I've never experienced before is

00:33:13.950 --> 00:33:17.369
people just call you on Teams. Your phone just

00:33:17.369 --> 00:33:19.410
starts ringing and you click it and there's a

00:33:19.410 --> 00:33:22.309
video of a coworker saying, hey, listen. And

00:33:22.309 --> 00:33:25.299
that is... still something I'm getting used to,

00:33:25.380 --> 00:33:28.579
but it is sort of fun to just get a random phone

00:33:28.579 --> 00:33:30.480
call with somebody on the other line saying,

00:33:30.680 --> 00:33:32.019
hey, I want to talk to you about this thing.

00:33:32.200 --> 00:33:35.660
So it's different every day, but I really love

00:33:35.660 --> 00:33:38.079
the variability in all the different projects.

00:33:38.380 --> 00:33:43.900
And it's all about, for me, understanding what

00:33:43.900 --> 00:33:46.819
threat actors are doing and then taking what

00:33:46.819 --> 00:33:48.759
we know about those threat actors to make the

00:33:48.759 --> 00:33:51.170
world safer. I guess I get to ask the old fun

00:33:51.170 --> 00:33:54.430
question. Final thought, like what would you

00:33:54.430 --> 00:33:56.470
like to leave our listeners with to sort of really

00:33:56.470 --> 00:33:59.490
kind of burn into their brain? And this is the

00:33:59.490 --> 00:34:03.690
most important thing. I think as technology practitioners,

00:34:03.950 --> 00:34:06.390
regardless of what your role is day in, day out,

00:34:06.430 --> 00:34:08.849
you really should be thinking about what threat

00:34:08.849 --> 00:34:13.210
actors are doing and how your work is threat

00:34:13.210 --> 00:34:16.070
informed. how you're making threat -driven choices

00:34:16.070 --> 00:34:18.630
in the code that you're writing, in the systems

00:34:18.630 --> 00:34:21.090
that you're configuring, in the technology that

00:34:21.090 --> 00:34:25.570
you're deploying, making decisions based on what

00:34:25.570 --> 00:34:28.469
a threat actor might do if they were exposed

00:34:28.469 --> 00:34:32.230
to that. And I think it's important for our software

00:34:32.230 --> 00:34:36.869
developers, our new vibe coders, welcome. You

00:34:36.869 --> 00:34:39.849
are terraforming the battlefield that defenders

00:34:39.849 --> 00:34:44.849
have to fight on at some point. And so all we

00:34:44.849 --> 00:34:48.230
ask of you is to give us the higher ground and

00:34:48.230 --> 00:34:50.909
create a battlefield that we can fight on and

00:34:50.909 --> 00:34:53.690
win. And if you're doing that, then you're doing

00:34:53.690 --> 00:34:56.309
the right thing. All right. Well, with that,

00:34:56.329 --> 00:34:57.909
let's bring the episode to an end. Share it as

00:34:57.909 --> 00:34:59.369
usual. Thank you so much for joining us this

00:34:59.369 --> 00:35:01.730
week. And we need to get you on the podcast more

00:35:01.730 --> 00:35:03.550
often. It's always a delight having you on. We

00:35:03.550 --> 00:35:06.070
love having you on. And you always have a whole

00:35:06.070 --> 00:35:09.030
bunch of insights. And to all our listeners out

00:35:09.030 --> 00:35:11.909
there, we hope you found this episode. enjoyable

00:35:11.909 --> 00:35:14.670
and useful and with that stay safe and we'll

00:35:14.670 --> 00:35:16.489
see you next time thanks for listening to the

00:35:16.489 --> 00:35:19.429
azure security podcast you can find show notes

00:35:19.429 --> 00:35:23.369
and other resources at our website azsecuritypodcast

00:35:23.369 --> 00:35:27.349
.net if you have any questions please find us

00:35:27.349 --> 00:35:30.590
on twitter at azure set pod background music

00:35:30.590 --> 00:35:33.969
is from ccmixter .com and licensed under the

00:35:33.969 --> 00:35:35.050
creative commons license
