This week on Dark Rhiino Security’s Security Confidential podcast, host Manoj Tandon talks to Marius Poskus. Marius has over 10 years of experience in cybersecurity, spanning various domains such as cloud security, DevSecOps, AppSec, threat hunting, penetration testing, red/purple teaming, and more. Marius is also a public speaker, mentor, and non-executive director for many cybersecurity businesses. He was the former Cloud Security Architect and Analyst at Domino’s Pizza UK & Ireland, Analyst at Burberry, and many more.
Chapter Titles:
00:00 Introduction
00:18 Our Guest: Marius Poskus
01:03 Physical Security to Cybersecurity
04:14 Tech talk overwhelms the nontechnical
11:00 How do you go about assessing risk?
17:20 A message to the executives
21:56 Cyber basics: How do you connect the dots?
26:39 Understanding the techniques from the 3 letter agencies
42:47 The Role of Offense
48:58 What can we do to implement processes to look out for configurations?
53:55 Connecting with Marius
Audio:
Important Links:
Transcript
Manoj Tandon (00:00.845)
Hello everyone, this is your host, Manoj Tandon. Welcome to another episode of Dark Rhino Security, Security Confidential. And today we are honored to have Marius Poskus join us. Those of you who don’t know him, absolutely check him out on the web. He is a cybersecurity professional with 10 years of experience. And he’s done quite a bit of work in the area, arranging everything from penetration testing to cloud security. He’s been a public speaker in the field.
He is a architect. He has attained some of the highest credentials that are available in our industry and comes packed loaded with a bunch of practical advice, which we’re gonna try and extract out of him here today in this show. So we’re honored to have you here, Marius. Thank you so much for coming on the show.
Marius Poskus (00:52.898)
Brilliant, thank you for having me.
Manoj Tandon (00:55.917)
So, you know, one thing that was interesting, I understand there was a time when you were in physical security, right? So is that true? How did you make that jump from physical to cyber?
Marius Poskus (01:03.466)
Yes, yes it was. Yep, yep, it’s good.
Marius Poskus (01:12.714)
It was obviously, it’s a big learning curve, but I was always into tech. So obviously, I spent a lot of time post sort of university and during university, during physical security, because that was an easy way to get part-time work and then it was natural progression into full-time work. But as I was sort of developing and I saw limitations in terms of progression and growth, and I was always keen individual to learn and.
study. So it’s kind of a natural curve. I spent a lot of time doing sort of self-development, started, you know, on certifications, starting kind of embedding myself in a community. I think one place where I really sort of transcended where I was going to was the community itself, because there were so many people who were eager to help and guide me through my journey. And, you know, I’m always I’m doing the same now I’m doing a lot of mentoring.
running sort of a there’s a capstone program that we do here for career changers people so I run a mentoring classes there so always say to people you know there’s so many people helped me in the journey and I’m always I’m helping a lot of people now into their journey but all that all I’m asking from them is just to pay it forward and then help the next generation to break into cyber security
Manoj Tandon (02:25.979)
Well, that’s very kind and noble of you to do. And I know our industry could use a lot more people. And one of the strengths in our industry is the diversity of background that people come with into the cybersecurity place. It lends itself to many different thoughts that might not be available if everybody just came from a computer science background, if you will. Right. So,
Marius Poskus (02:52.275)
Yeah, yeah, indeed.
Manoj Tandon (02:54.329)
So appreciative that you’re helping people come in. Was it an easy jump for you or was there a bit of a struggle in the career change?
Marius Poskus (03:04.59)
Um, it was, it was kind of two ways. It was, it’s difficult and easy in some way because security and concepts and thinking from physical security transients into cyber security. Obviously it’s, it’s a lot more technical. So, you know, I think as most of the people we, I was struggling with, you know, imposter syndrome and, you know, taking that leap because it, when you start looking at first, cyber security seems like a
And it’s a massive field because there is, as we discussed, there is blue team in penetration testing, cloud security. And it feels like you have to know everything to be successful, but it doesn’t. You start somewhere and especially, I think the journey in is very hard, but once you get in, everything becomes more clear. And once you start understanding the concepts and how we operate as individuals. And as I say, wherever I’ve worked, there’s always been a supporting sort of
cast around you or people that always are happy to share their knowledge and their experience and communicate and learn from them and grow.
Manoj Tandon (04:11.991)
Yeah, so Marius, you know, one of, you know, we have a lot of very technical people that come on to this as our audience. And we also have not technical people who listen and just hearing what you just said. There is a an issue often that.
The tech talk overwhelms the non-techie in cybersecurity and they don’t understand the big picture. And it’s very hard for them to, if you will, connect the dots and build the picture, if you will.
So it would be great, you know, given what you just said to, you know, help, let’s connect those dots and let’s start with some foundations and then we can dive into details here. But foundationally, why, you know, you cannot pick up a paper or go online and not find some material breach that has occurred every day. It’s an everyday occurrence, something has happened.
Why do these things continue to happen? Are we getting something wrong? And if so, what is it that we’re getting wrong?
Marius Poskus (05:28.91)
I think there’s a, from my experience, I’m talking for various individuals, there’s a few tendencies that continue to keep seeing and they keep happening is most of the time organizations that has low level of maturity, they get buy in into, shall we say, then the jargon and they’re trying to buy a new shiny blinker 30,000 that’s going to solve all their breaches.
Manoj Tandon (05:38.283)
Okay.
Manoj Tandon (05:55.926)
Yep.
Marius Poskus (05:57.306)
which everybody knows that’s not the way. Secondly, some organizations might view cybersecurity as not important enough or a cost center, or they view themselves as an organization that they don’t have data that’s important enough to be protected because they think, oh, it never gonna happen to us. And that’s again, that’s another probably learning curve where organizations need to invest and think about. Secondly, I still keep coming across
people and security professionals to truly understand risk and how to quantify the risk, how to properly get qualitative analysis and quantitative analysis of understanding risk. But the key point is here as well. It’s not only understanding the risk because normally people sometimes security professionals forget we don’t never own the risk. We are a consultative function for the business of
We raise the risks, we highlight the risks, and then business has ultimately decision of whether we’re gonna mitigate the risk or not. But how to create a compelling enough narrative to highlight serious and material risks. That’s another skill that sometimes when you climb the leadership ladder, you need to cultivate and learn, be able to create that narrative, create stories that creates an impact to the board members or whether it’s C-suite.
Sometimes I think people forget that you need to invest time. When you go into a new position, I think as a CISO or any security leader, you need to understand the personas on the board and how do they like consuming the information. That’s the key point. How do they like consuming information and how are you going to relay that information to them? Also, I think sometimes we often see it’s broken reporting models. If a CISO or security leader reports to the CIO, there’s always a
Manoj Tandon (07:54.302)
Uh.
Marius Poskus (07:55.682)
Their priority is platform uptime, your priority is security. So sometimes it does never go past CIO. If you report to the CTO, same thing, development always wins. So security always gets left behind. So you need to build a culture. You need to speak to enough people that you get heard and you get understood where you’re coming from. And I’ve always been sort of a proponent. I’m no longer talking, you know, scamming and retracting, so highlighting the material breaches.
It’s about creating a narrative that people understand. Where you’re coming from, security is an orphan viewed at cost center. So how we can tell the leadership and the board that all of my risk mitigations is not necessarily a cost center. It’s how do we save money for the business? How do we keep the business out of the headlines? How do we potentially reduce the reputational damage and regulatory environment to save them from fines?
So that’s the key points I see where organizations are still failing.
Manoj Tandon (08:59.705)
Yeah, well, you have said quite a bit there quite saliently in the last several minutes. And you’re spot on with all of it. There is a huge amount of focus on technology and what you just described was IT as a business or cybersecurity as a business problem, not necessarily as a technology problem. And the
description of risk to the stakeholders. You know, often I think some of us in the cybersecurity business are guilty of it where we’re speaking a language that they’re not gonna understand. And so inherently they tune out of the conversation. And then having that culture of cybersecurity and understanding it not as a cost center, but it can also potentially be a revenue center. I mean, if you look at some of the ways in which
Let’s just pick on IAM, the way you can implement it and manage identities, especially if you’re doing it on a customer-facing side, can lend itself to a lot of analytics and buying patterns that might not otherwise be readily decipherable. So, it’s not just a cost center. Right?
Marius Poskus (10:15.702)
Yeah, indeed. And I’ve always been a big proponent, for example. So if you are in a business that’s potentially selling their services, their products, I’ve always been in sort of embedding myself in the business development side of work. And I always provide, for example, for the current business, I provide cybersecurity slides and what we do to the business developers. So when they talk into our potential clients, we highlight.
how security is important to us, so their customer data is safe with us, how we differentiate amongst our competitors to make sure that we have a potentially higher chance of winning that business because they’ve got to be safe with us.
Manoj Tandon (10:58.937)
So when you’re going into an organization, Marius, and looking at their cybersecurity program and really beefing it up to a high performance program, what are the elements? What needs to be done? You mentioned risk as a foundational issue, the assessment of it. Is there any practical guidance on how to go about it?
And I’ll tell you why I asked the question. So we know there’s quantitative methods out there like FAIR that allow you to quantify it, but for a lot of companies, it may not be an affordable mechanism by which to go down. FAIR consulting is expensive, those are big projects. Whereas if you’re a 30 person or a 50 person organization, you might be like, ah, I can’t afford that. So how do I go about assessing, let’s start there with risk and then…
Take us through the rest of the elements here.
Marius Poskus (11:56.558)
I think first and foremost, you have to sort of assess and engage sort of within an organization. What’s the risk appetite? What do we work in with? Because it depends where you end up. If you end up in speedy tech house, there are normally going to be more acceptance of risk. So find the balance. Where is the limit? I’m a big proponent of you first starting to sort of do qualitative risk analysis. So you do, for example, matrix five by five.
and you quality all your risks, so based on quality. The top risks, then you can do a quantitative analysis of analyzing how much will it cost to mitigate them and whether that cost exceeds the potential damage that risk might have to your organization. So you start sort of there, you’re building the picture. Because the thing is sometimes people forget, cybersecurity is not one department within business and it’s looking only at IT problems, as we just discussed, it’s a business problem.
So normally I would go in an organization and have a, have essentially have a meeting with every key stakeholder, get their opinion of potential risks that their department is facing with, coupled that with, you know, IT, whether it’s finance, HR, they all have systems that they’re gonna be working with that has potential risks. So what do they are afraid of? What makes them keep them up at night essentially?
and put that all in the risk register. And then you essentially, you create structures within it. So normally, for example, in my organization, I always start with, you have a cybersecurity risk register, and then you embed that to enterprise risk management, where all the risks come together. And then we have a sort of risk co-committee, where we discuss the next steps based on the most prominent risks, what needs to go in the program, what we can live with for now.
The key point I want to point out sometimes, and I’ll point this, I’ve just been to, at about a month ago, there was a cybersecurity conference called InfoSec in London. And one of the vendors, they had their big slogan was, end cyber risk. And I was like, you can never end cyber risk. You can never wash your hands and walk off. And that’s why I always say to some people, you can close the risk, but you can never stop monitoring the risk. Because…
Manoj Tandon (14:02.329)
Okay.
Marius Poskus (14:19.97)
The closing of risk or risk assessment is the point in time of the risk that’s currently here. With changing threat landscape, changing what you’re doing in your environment, that risk can go up and down, so it needs to be monitored all the time throughout its lifecycle.
Manoj Tandon (14:35.221)
Yeah, and when you’re talking risks, I think there’s also an element of there of execution from the bad actors. I mean, how much of the risks are exploitable in the organization, right? Because there might be valid risks, but if they’re not exploitable, that’s fantastic. Although I can’t say that I’ve run across that too often, but it’s a factor there. But you do need to look at that.
threat landscape and then assess the priority of the risk. Do you think, is that a good approach to doing it?
Marius Poskus (15:15.806)
Yeah, because obviously, you know, there are a few ways that you look at it. You look from asset perspective. So you have obviously critical assets because risk is not the same risk. If you have a risk that is on your crown jewels or on someone or say on receptionist laptop. It’s a very big difference because the receptionist laptop risk is not going to interfere potentially with your business operations. If you have obviously, you know, layered defense, but there is obviously…
Manoj Tandon (15:32.621)
Okay, yep, absolutely.
Marius Poskus (15:44.918)
the assets, the data as well, data classification and the data importance to your organization. But I think it all goes down to that crown jewels and what is the main risk that will stop your business operations. I think the one thing that I’m seeing, there’s a slightly changing emphasis now within the businesses. So we stop going to thinking about 100% security protection because we will never achieve that. There’s a lot of emphasis.
Manoj Tandon (16:11.861)
Yeah, that’s impossible.
Marius Poskus (16:14.038)
Yeah, that’s impossible. And now we’re going towards securing enough that the threat actor goes to the next one. And also, should the disruption happen, there’s a lot of emphasis now on business resilience. So should something bad happen, can we restore operations within five, 10 minutes to limit the disruption? Because inevitably, something will gonna happen at some point.
Manoj Tandon (16:37.517)
Those, that’s a fundamental principle from defense in depth, which unfortunately is not talked about enough in the literature. When we read the literature, a lot of it is around the tech and the shiny new toy that’s out there and what it’s capable of doing. But not necessarily how that toy needs to be integrated into a defensive framework to actually create a viable.
Marius Poskus (16:52.667)
Yeah, exactly.
Manoj Tandon (17:04.017)
safety net, if you will, to do exactly what you’re stating, slow the progress down and do some kind of a containment process and have that resilience. So, when you, what do you say to, there’s a couple things that come to mind and I’d just love to get your feedback on them. To the executive who says, look, fundamentally, we can’t get to 100% cybersecurity. So, you know
Why don’t I just minimize my spend and I’m going to overload myself on cyber liability coverage should something bad happen and make sure that there’s a financial backstop to the losses. Also, you know, I might, we’re moving to the cloud and everything’s in the cloud so that’s, you know,
this now becomes Amazon’s problem or it becomes Oracle’s problem or it becomes Microsoft’s problem. So why should I increase my budget or even make an attempt at going to a higher performance level of cybersecurity when we’ve admitted that it’s not possible to secure the environment to 100%.
Marius Poskus (18:24.31)
Yeah, it’s not possible, but it goes back to it goes down to a narrative as this. Again, it goes, it depends on the business, but every, every business needs to make profits and normally you are serving your customers. So your, your business keep kept that is being breached over and over again through their lack of defenses. You know, liability will not cover you against regulatory requirements.
and compliance sometimes, especially it depends on what frameworks you work with. So for example, UK, if you are financial services, you have FCA requirements. If you process card data, PCI, you can’t get away from that. Secondly, obviously we’re talking about some things like reputational damage is very hard to quantify, but what you can quantify is the potential risk of onboarding new clients, losing potential current clients and losing the
Manoj Tandon (18:56.473)
Okay.
Marius Poskus (19:21.41)
the support and trust within your clients, that the risk that you are walking into, and potentially losing business, you can definitely quantify that on the potential under investment in cybersecurity, as well as, I just mentioned, talking about business development and how we stand out in front of, amongst our competitors as being the most secure one, that they should go with us and protecting their customer data.
there’s big fines happening for that as well. So you can’t just cover yourself with liability up to your neck and think everything’s gonna be fine.
Manoj Tandon (19:59.833)
I love it. You said it, not I. Maybe people believe you, Marius, because there’s a lot of that going around. There’s a lot of, especially when it comes to cloud security, there’s a lot of decision makers who are under the misguidance that is Amazon’s problem or Microsoft’s problem or Microsoft’s problem. It’s not our problem once we move to the cloud.
Marius Poskus (20:06.45)
I hope they do.
Marius Poskus (20:27.146)
Well, yeah, that’s another question. I think we’re in security, we’re getting better. There’s probably some senior leadership, like CIOs or board, still don’t understand the shared responsibility model. And that’s again, potentially a learning curve to your understanding them. It depends where you go, whether your investment is, whether it’s infrastructure as a service, platform as a service, and software as a service, and where your responsibility is like, but you can’t just say, oh, we’re gonna migrate from on-premise to the cloud.
Manoj Tandon (20:29.676)
Anyhow.
Marius Poskus (20:55.958)
and Microsoft will cover all our problems.
Manoj Tandon (20:59.865)
that well, you’re absolutely right. But believe it or not, there is a lot of that going around.
Marius Poskus (21:08.114)
Oh, I’m sure it is. I, you know, I’ve heard it myself in different conferences where people, you know, get shocked where you actually talk about, you know, who’s responsible for what, you know, and yeah, they think, oh, we go into the cloud because so much, they’re going to do all of it for us, but no, it doesn’t.
Manoj Tandon (21:25.337)
Well, you just look at the amount of data that’s been stolen out of Amazon S3 buckets. I mean, just look at all that, right? How did that happen if Amazon’s responsible for it? Amazon’s responsible for the platform, the infrastructure. They’re not responsible for your data and how you’ve configured access to it. So maybe read the fine print, people. That’s all I can, that’s what I can say to that. But let’s get into continuing building a program
Marius Poskus (21:48.366)
So yeah.
Manoj Tandon (21:55.489)
You know, there is a reference to the pyramid of pain. Let’s start there and then let’s move into the MITRE ATT&CK framework. And let’s kind of do this as like cybersecurity for dummies. So assume that people need to understand the basics. Marius, I know your level of understanding is very deep, but how do they connect these dots from the pyramid of pain to the MITRE ATT&CK framework, to threat intel, to building or…
buying an effective sock. So maybe they can’t build one internally, but if they’re gonna go outside to an MSSP and buy sock as a service, they still have to ask a lot of intelligent questions and do a lot of assessing as to how all this fits together. What…
Marius Poskus (22:39.354)
Yeah, yeah, that ties in well. Now, I’m just going to say that ties in well to the paper. I’m currently writing a paper about how to build effective sock, essentially using MITRE ATT&CK. So firstly, pyramid of pain is it’s a concept been sort of developed over the last few years. But I think the key point to mention is if we look at sort of legacy systems like firewalls and AVs, all the viruses, we used to detect them based on their.
hash values or something like if you take a virus, there was a program or something like you can just spit out a hash, something like Nd5, people might have heard of it or SHA-1, but it essentially detects a fingerprint of that virus. So in the older days, you know, firewalls or even antivirus sort of software, they used to create the fingerprints for those viruses, how you can block them and detect them.
Manoj Tandon (23:19.212)
Yeah.
Manoj Tandon (23:36.789)
and that would be a signature based approach, correct?
Marius Poskus (23:40.37)
But as the times move on, obviously, you have to understand how these hash values work. Because if you ever go into any program and you put in a Shakespeare text, if I change one comma, the whole hash value changes. And it’s always variable input, same length output. But it’s completely different just with one exclamation mark, one space.
Therefore, obviously threat actors became very savvy. So you can change one character in your virus and that virus is no longer detected in your antivirus until it’s obviously been detected by the company who creates the signatures and obviously, and so on and so forth. So we moving up the pyramid. So started with the hash values, then we used to track IP addresses, domain names, where they do their command and control communication networks for botnets and things like that. But as we…
Manoj Tandon (24:22.369)
Right.
Marius Poskus (24:37.25)
They are called sort of trivial values who are very easy to change for reactors. You can buy viruses now on the black marketplaces. You can create new IP addresses with a click of a button. It’s very easy. So these are very hard to detect. So we move it up the pyramid of pain to the top where we start tracking for actor behaviors. Cause behaviors and the procedures and techniques that they use, it’s very much harder to change. Cause we built up
sort of historical map for MITRE ATT&CK of what threat actor groups use as their tactics, techniques, and that’s all plotted onto MITRE essentially graph that I think it has, it’s sort of replaced if people remember cyber kill chain used to be sort of a military step program how somebody would do their cyber or military operations. So now it moved into MITRE ATT&CK, which is similar. And I think it went from instead of like…
Manoj Tandon (25:25.879)
Right.
Marius Poskus (25:35.69)
nine steps now, I think it’s like 12 steps where it talks about whether they do prior to engagement, during engagement and post engagement sort of the activities. So we can track now through actors based on the profile, for example, something like a quantity group. There is so much evidence and through intelligence to say that what normally techniques do they use and normally through what I will say always do to people, if you want to leverage MITRE
threat intelligence and do the initial research. Because normally you can gather enough information about threat actor groups that I always say, depends on the organization, but say you pick up an organization that works in UK in financial services, you can find enough information that which threat actor groups historically have often attacked financial services within the UK. And you can map these threat actors on the matrix. And then you discover what tactics, techniques they use.
Manoj Tandon (26:18.861)
Okay.
Marius Poskus (26:32.738)
and then you can build a layer of your defenses from that essentially.
Manoj Tandon (26:38.413)
Why is it so MITRE ATT&CK has captured the tactics and techniques bad actors use? Why is it then on when you many people watch the news and they see a three-letter agency describe an attack or whatnot but they always say well we’re not going to reveal the tactic techniques and procedures? What’s the
Marius Poskus (27:06.402)
I don’t think it’s a big secret. I think it’s just, if we’re talking on sort of news level, normally people will not understand the techniques. And secondly, I think the probably the bigger picture is nowadays is it becomes so much intertwined between actors and their groups that it’s very hard to do any sort of level with confidence, any attribution.
Manoj Tandon (27:06.543)
Some of these.
Marius Poskus (27:31.47)
Because the new threat actor groups keep coming and rising and there’s loads of them in Russia, China, North Korea. So, and they always try to mimic each other. So sometimes to throw you off your scent, they will put in some Cyrillic into their viruses to think that it’s Russians where there’s actually Chinese and things like that. So there are people who actually do that for their work, they’re forensic experts.
researchers who actually sift through lines of code and try and understand those behaviors. And that’s where we get normally those reports, where we get the behaviors that they’re doing, the tools that they’re using. There’s a bunch of things that we can do, not only from behavior wise, but from tooling mapping to our data mapping of what data we need to have in our security, but incident and event management platform. And then how to create effective analytics to detect that. And Miter Attack, I think is so
So useful and so, you know, there’s so many things that you can do, because it’s not only from defensive side, you can build your defenses using minor attack, but you can do retteaming emulation exercises to test those defenses and evaluate, you can also then layer deception technologies where you create a dwell time for threat actors to actually gather the techniques and tactics and the steps that they use in your environment, you know, to potentially delay them and drop them off the ascent, you know, where, where your crown jewels are. So.
Manoj Tandon (28:35.097)
Okay.
Marius Poskus (28:59.246)
There’s a lot of potential scenarios. And I saw even there’s a few papers published that people use MITRE ATT&CK for malicious file detection. There’s potential mappings into risk frameworks, how to solve risk with MITRE ATT&CK. And yeah, it’s very, very good.
Manoj Tandon (29:17.95)
So, it sounds, for someone to navigate the MITRE ATT&CK framework, what is the best way to do it? From what you described, there are tremendous uses, a lot of information up there. It might be overwhelming. Are there tools that allow you to navigate it with a degree of simplicity and
Marius Poskus (29:39.53)
Yeah, yeah, I would say this. You obviously you have to start somewhere. So I, I’m a, I’m a big proponent because I use a lot of my tech and sort of defensive side. So I developed sort of my, the paper that I’m writing is based on a sort of continuous cycle of framework. So you start with, and as I say, you don’t have to use some fancy tooling. You can do a lot of research for Google. So define three actors that are important for you to track for your organization based on the industry.
based on your location, geographical, and the business that your company is doing. So you can detect, start with say five to 10 reactors. Then you can use Mitre Navigator tool that’s free on the website, and you can map all of these reactors based on their techniques and tactics. Then what I would normally do, because in Navigator, you can create layers. So each reactor.
Manoj Tandon (30:34.254)
Okay.
Marius Poskus (30:35.466)
you create one layer from each tractor. So say you have seven tractors, you create seven layers and then the eighth layer, you can create a layer from layers. So each layer, each technique, you attribute a score of one. So the last layer, you combine the score and you put A plus B plus C from all the layers. And then you have essentially a heat map, which shows which techniques has the most matches between those seven tractor groups. So that’s your prioritized technique map.
Manoj Tandon (30:53.192)
Yep.
Manoj Tandon (31:05.241)
Okay.
Marius Poskus (31:05.314)
Then you map those techniques to the data sources and data components that you need to ingest in your security incident and event management platform to be able to detect.
Manoj Tandon (31:16.185)
That’s the guide on what logs to, because I’ll tell you, there’s a lot of, in the SIM world, there’s a lot of usage. We want to ingest all your logs or send us everything. And what you’re describing is a much more refined and practical approach. You don’t need everything. You need the critical things to start with.
Marius Poskus (31:16.406)
then each technique.
Marius Poskus (31:38.55)
Yeah, and especially because there’s a two mapping system. So you map first to data sources and then data components within the sources. So you have data source, say it’s active directory. Well, for that technique, you might only need sign-ins and logouts or specifics. So you can pinpoint a specific data component of that source. Because we know nowadays most of the SIEM’s gone into the cloud, and they’re obviously based on congestion costs. So you can.
Manoj Tandon (32:07.871)
Yep.
Marius Poskus (32:08.31)
get a prioritized ingestion based model. So once you map that, each normally within MITRE ATT&CK, each technique has a section of how to build your analytic rules to detect that technique as well. So based on whatever you’re using, whether it’s Splunk, there was normally an example of query language of how to structure query language, whether you use Azure Sentinel, it’s custom query language, how to detect those techniques. So once you build the detection,
Manoj Tandon (32:34.208)
Yep.
Marius Poskus (32:37.238)
The last point normally I put in my framework is, depending obviously on the company and their budget spent, but nowadays you can get quite cheap, relatively cheap some of the deception technologies. So we can put something like, for example, even if you’re using stuff like Defender for endpoint, nowadays you can put fake admin credentials and you can create alarms on it. So whenever that credential is being touched, you obviously, you know you are compromised.
because that credential is fake and it’s not being used by any machine or any person. So you can create sort of fake loop house, fake VPN login points, even a fake virtual machine sometimes. Virtual machine to stand up is not that expensive. Yeah, it’s trivial. So you can create a mimicking sort of crumb jewels virtual machine and then again create a lot of bells and whistles around it. So that sort of creates a cycle. So use first do Threat Intelligence.
Manoj Tandon (33:20.793)
Trivial. Yeah.
Marius Poskus (33:36.726)
You map it to factors, to techniques, data sources, analytics. And then you kind of, I always have a kind of a true, sort of two pronged spit out. So you either detect and create analytics for specific actors, but some of the ones that really, really important, you push them to your security program. So you don’t always want just to detect, but the really, really risky and important ones, you put them in a program and you build mitigations.
So some of them will be detected, some of them will be mitigated, and then it goes deception technologies, because deception technologies again feed into your threat intelligence cycle, and then you keep doing research and you can repeat that cycle, rinse and repeat, whether you discover new techniques and tactics and you can go round and round, because you always want to have a timely visual of your defenses, because obviously threat actors will change. The importance change, you might expand to different geographies where you might need to add new threat actors.
and things like that.
Manoj Tandon (34:40.241)
So you have to stay on top of all the threats that are coming in.
that necessitates very good access to threat intel of some kind. Without that, so now is there, are there systems out there that are not so expensive or open source threat intel that companies can leverage that maybe, that the enterprise tools might be out
Too expensive. Let’s just leave it at that for a lot of organizations to up form.
Marius Poskus (35:22.046)
Yeah, as I say, normally, as I say to people, start easy. Start with Google. There are enough reports about threat actors, something like Verizon prepares every year. There’s specific cybersecurity organizations that put their reports out on threat actors. And there’s things like you can start… There are organizations that share a lot of information. Even MITRE has a lot of information about threat actors and sort of their roadmaps of what they’re doing.
And then you start obviously building as it matures, you can start onboarding potential tools, you can even start something simple like, I have built before, some things like sticks or taxi servers where you can onboard some of the threat intelligence. Obviously some of these as well, you can’t ingest everything, it still needs a manual overview to make sure that it aligns to your organization needs. But then you start escalating it, there are specific organizations that…
do specific threat intelligence. There are specific threat intelligence centers like ISACs. So for example, there are ISACs that are dedicated for specific industries. So there is ISAC for financial services, for automotive. Some of them might be costly, but then again, I think they price their costings based on the company size. So if you’re a relatively small organization, the cost will be quite lower than if you’re a large organization.
But then there are also tools developing. So obviously we know Israelis are always great at building a new tooling. So I think it’s called Iron Dome. There is an organization that I think is bridging the gap. Because the one problem I always discovered is that post breaches, we hear about the breaches, but normally either because of regulatory requirements or because of, you know, potential fines or costs involved, we never hear the details about the breaches. Sometimes we hear about.
Manoj Tandon (36:54.635)
Yeah.
Marius Poskus (37:15.81)
five, six years down the line when it’s already long time ago. But we rarely, rarely hear, you know, the actual tactics that they’ve been used, breach say that happened last week. But there are organizations like, I think it’s called Iron Dome. So they have a platform where they connect all their clients and clients can share with all of their customers, breach details. So you get specific breach details. You just have anonymized company. So all you have is the sector.
and the region, and then you have details about what they used, what tactics, what tools they used, and it’s shared within the customer network.
Manoj Tandon (37:58.085)
That’s brilliant, actually, to have that. And that’s a very practical approach to building a great sock in a defensive posture. And I would assume that you’re also including in those special threats where you’re building a program, that’s where SOAR’s coming into play, where you’re having automated mitigation approaches for really critical.
Marius Poskus (38:22.85)
Yeah, yeah, indeed. You know, it’s always based on a use cases because the thing is every sock will have different business context. You know, we, everyone’s bad, for example, you know, Oh, impossible traveler lads, you know, does anybody get to the bottom of root cause of why it’s happening? So, you know, it’s specific. For example, we have to say developers that work in, in Belarus. Yeah. But if they, if, if they had a login from Belarus, I have conditional access policies that you can’t log in from Belarus.
So they normally have to use VPN, let’s say VPN from France. So sometimes you will get a login from Belarus and within two minutes there’s a login from France because they forgot to turn on the VPN. But unless you know the business context, you think that something might be dangerous. But built on the business context, you can provide automation rules that say, this is okay, but if there’s any other scenario, ring alarm bells. So it’s about, you know,
And I always say to people as well, you can start your program even in small organizations. Like if you leverage some of the like tooling, that’s why I quite like, you know, if you talk about clouds as well, I think Microsoft is doing great in terms of cloud security. GCP is great because of their networking capabilities and out of the box, you know, whole world networking and AWS is very good with their machines and stuff. But I like Microsoft. So, for example, you can build stuff like, you know,
Manoj Tandon (39:30.314)
Yep.
Marius Poskus (39:47.83)
For example, you started with one analyst and the analyst only works nine to five. What happens if an incident happens at six? So in Defender, you can pre-build automation that says, if that laptop has been detected with a virus at 6 p.m., isolate the machine from network, create an investigation package with all the logs and alerts, and leave it there. Analyst comes in the next day at 9 a.m., he can do his investigation.
Manoj Tandon (39:52.589)
Thanks.
Marius Poskus (40:16.414)
and then based on outcome, put the machine back into the network or not. But you contained with automation without potentially spreading to the environment.
Manoj Tandon (40:27.629)
Do you see with AI and the scenario that you just described, it seems like it would be ripe for machine learning, or a lot of these scenarios would be ripe for machine learning, a place where we get to a humanless sock?
Marius Poskus (40:44.97)
I don’t think we’ll ever get to the human-less SOC, but if you look at the traditional SOC, I think AI has a potential, has a chance to get rid of level ones, maybe some of the level twos. But when we go to level three, I think SOC will always struggle to understand the real business context and all the things that’s happening within the business. And that’s why normally it goes through the chain and up the escalation to level threes when something serious happens.
and need to make sometimes even need to make business case determinations where, you know, can you plug off the, your crown jewels and turn them off when something serious happens, you know, and somebody needs to make a decision whether, you know, what’s the risk versus, you know, the potential losses of the costs, you know, and AI would never be able to do that because you still need to get a signed up from someone. So, but yeah, I think it’s definitely has a potential to replace the low level that
sort of the first layer of stuff that happens within your sock and reduce the noise because you know sometimes and we just discussed socks people tend to you know until they build enough knowledge and maturity they turn on all of the logs all of the alerts and then it just goes 150 alerts during the day try and investigate all of them obviously creates a lot of noise creates a lot of pressure because sometimes as well and i’ve seen that before
due to an experience sometimes, for example, security professionals sometimes they report to the boards, oh, how many incidents we solved and how many closed. That creates unnecessary pressure for analysts to keep closing loads of incidents. But that metric is useless, in my opinion, because the more incidents you have, does not mean anything good. You should have less incidents, because that’s how you create maturity in your organization, instead of how many you solve and what’s your time to respond and things like that.
Manoj Tandon (42:37.293)
Brilliant. I hope people take that away from this discussion as well. I couldn’t agree with you more on that. What about offense? Is there what’s the role of offense or is there a role of offense in?
Marius Poskus (42:54.018)
Yeah, I think there’s always a role for offense. I’ve always been a big proponent of sort of bridging automated offense with offense, with manual offense. So, I just kind of mentioned as well, when you start building your SOC, there are ways where you can test your detections. Because obviously you just created a loads of analytic rules, but how do you know that they gonna detect that threat until the threat is here? So you can create a hypothetical rent emulation test scenarios where you can actually try and trip those,
alarms and see what’s going to happen. And that’s how you test the effectiveness of the soul. Obviously, there are, again, based on organization maturity, you have organizations that have red teams and have individuals that continuously create hypotheses and test your defensive environment. And then you go into purple teaming where red and blue work hand in hand to test and enhance your defenses. But then you have tools that are bridging that gap. You have tools like
MITRE itself built an attack IQ tool. You have, I’ve used before, simulate tooling. That the tooling is called breach and attack simulation. So again, they have a great MITRE attack mappings where you can test specific techniques within your MITRE attack framework. They have threat intelligence feeds that come into your platform. And they are quite good because for example, you have a threat intelligence feed that says something is being exploited in the wild.
And normally, within 24 to 48 hours, they have an in-built test scenario to test in your environment whether that is exploited. Because I wanted to put that into our vulnerability management program because normally, vulnerability management program is very flawed because organizations run into 20, 30, 40, 50,000 vulnerabilities, and you can never, ever patch them all. But having the timely information to know whether that vulnerability…
Manoj Tandon (44:32.685)
Okay.
Marius Poskus (44:49.862)
is on a crown jewel, whether it’s behind any layer defense and whether it’s actually being, can be exploited by threat actors and what’s the level of sophistication needed to exploit that vulnerability gives you a timely sort of action to know whether to patch it or you can accept the risk and go into your normal patching cycle when it’s patched, whether it’s based on SLAs. But sometimes you need to escalate that if something serious like move it happens.
Manoj Tandon (45:16.43)
Right.
Marius Poskus (45:17.518)
with a built move-in scenario, you can test new environment and see it’s exploitable. We raise an emergency patch and do it today and we can sleep well at night.
Manoj Tandon (45:32.485)
What do you think AI is going to do for the bad actor side of the house? Do you think are we going to be able to keep up with what’s going on there? What’s going to happen here? What’s your magical future crystal ball say?
Marius Poskus (45:51.47)
Well, you know, threat actors, obviously, they can leverage AI to create more sophisticated attack methods, attack scripts, viruses, obviously, you know, because every tool has a way to for it to bypass, you know, they can build potentially, you know, attacks that bypasses your EDR or bypasses your firewalls and things like that. But the key point, I think, is here.
and I’ve been having discussions with the people before, we keep talking about layered defense, but people still don’t really understand what it means because we have separate systems that might think, we might think that acts as layers, but they’re not layers, because unless they are working together, they’re not a layered defense. They’re just separate systems that does separate things.
But how do we work? And then that’s where kind of I’ve been working with a few interesting tools where how do you connect, for example, your runtime protection systems with your WAFs, with your firewalls that should something happen in the runtime, how can automatically you spit out a signal to firewall saying block that, block there, block here and create a cohesive system that talks. Like Microsoft is working well to combine the
Manoj Tandon (46:48.034)
Thanks for watching!
Marius Poskus (47:17.122)
Defender for cloud, Defender for endpoint into Azure Sentinel, but there’s obviously more systems you plug in. How do you plug into that? Your static code analysis, dynamic code analysis, software composition analysis, and all of the software development coding. How do you email security protection? How do you all combine between and intertwine layers where one thing fires, it talks to all of them. So it potentially stops it going through any other window or door.
And that’s the real true of, you know, defensive sort of layer where you, they work together because I always say, for example, you know, there’s some companies creating some amazing tools, but I always say to when I, when somebody, you know, pitches their tool, I said, how do you integrate with my scene, with my idea, with all of this, because I don’t want to have another window to look at. And if it’s not cohesively integrated with my defense, it’s just another window to look at where.
Manoj Tandon (47:59.298)
Right.
Marius Poskus (48:16.822)
I’m just going to overwhelm my people. And I don’t want them to look at 10 windows. I want everything to be integrated in my scene so they can do all the work from one plane of glass.
Manoj Tandon (48:30.468)
You’re absolutely right. Now, that being said, there’s a statistic out there that 97% of all breaches are due to misconfiguration.
I don’t know how accurate that is, but I’ve read it in multiple rags, so I’m assuming whether that number is 94, 93, it’s 90 plus percent.
Manoj Tandon (48:57.101)
what can we do to implement processes that really look out for those misconfigurations and get those cleaned up? Because that, again, comes down to a business problem. That’s something that’s on us that we should be able to cue quality check. And…
Marius Poskus (49:15.946)
Yeah, I think there’s a few things come into play into that. The more we go into agile development, obviously, and DevOps and DevSecOps, everything is predetermined towards, you know, we build quick, we do, everything’s quick, but we don’t like doing documentation. And sometimes you need to, you know, when you start it out, you need to have a proper governance in place. You know, if you’re building something in a cloud, you need to have standards.
What images do you use? What images are allowed? How do you, what’s your standard to building a virtual machine? Because the problem is, when you have 10 developers building 10 different virtual machines, their potential security in their head is completely different to someone else. And that’s where misconfigurations happens. So I’m a big proponent of creating something like, you know, I’ve built, I’ve worked in organizations where we create something like cloud adoption model. And we have a prescribed,
Manoj Tandon (49:59.84)
Yep.
Marius Poskus (50:11.946)
prescribed sort of flow of what you happens. How would you build virtual machine? How do you build firewall? How do you build Docker container and what images are allowed in our sort of repository? You create a unified approach. Cause I always say to people policies, procedures, and all of this documentation reduces the potential human error because you have a unified way how you do things in your organization. And then you go into things like, you know,
When people come sort of new into cloud, they do a lot of things through GUI. When you go to enterprise, nobody does cloud building through GUI. Everything happens from infrastructure as code. So if you do a properly infrastructure through code, you can have things like configuration drift detection. So as long as you build in scenarios and alarms where you detect drift configuration changes, because you have your YAML files, so you describe how your infrastructure should look like.
If anything through GUI goes into Amazon and changes one character and something in your virtual machine, the file within YAML that says that this how that machine should look like will give you an alarm because it’s monitoring always saying what from the file, what changed into live environment. And then you obviously, the key point as well is in there.
We just touched as well, IIM, identity access management. It’s people being over-provisioned with too high permissions that are able to do changes without change management. That’s one thing as well. Loads of organizations fail at change management. What’s the process of, where is pre-approved changes and where is the changes that create risk and who’s approved those changes?
Manoj Tandon (51:40.673)
Yep.
Marius Poskus (52:05.41)
Sometimes changes happen without approval, and that’s why they create misconfigurations and risk. So that goes into all of the cohesive thing that you need to think. Before I’ve been presenting on the clouds as well, talking about IAM, I always say to people, two of the hardest programs that I’ve ever had to work with and implement is IAM and DLP. So identity access management and data loss prevention is the hardest programs that you will ever work to implement.
Manoj Tandon (52:30.725)
more mention.
Marius Poskus (52:34.382)
because there’s so many variables. For example, if you take simple things like Azure, Azure has about 1,500 permissions. So when you use any out of the box role, normally that role has about 100 or 150 permissions that are too much than they should have. And actually building custom roles to do the least privilege, almost nobody does that because it’s a very big cumbersome work. But once you’ve done it once,
it makes your life so much easier, but loads of people just use pre-built roles that are way over-permissioned. And you know, you have to have a plan, you have to have a vision, how are you going to provision whether, if you start doing, giving roles through subscription, anything that’s within the subscription, you obviously get, you inherit permissions down. So sometimes people, you obviously over, over-permission people to have, you know, access to loads of resources when they shouldn’t have.
Manoj Tandon (53:32.065)
That’s an excellent point. But as you also said, it’s a ton of work to actually affect a major change there and go to the concept of least privilege or implement zero trust type approaches in that environment. It won’t be a simple configuration change.
Marius Poskus (53:51.87)
Nah, I won’t be here.
Manoj Tandon (53:54.381)
So we’re at the last minutes here, Marius. I wanted to make sure you had a platform to let our audience know about anything that you’re working on that’s gonna be coming up, that you want them to engage with you on. What, the floor is yours to let them know of whatever you think.
Marius Poskus (54:11.05)
No, the only thing I just wanted to mention was that, you know, I’m very, you know, been heavily involved with doing my masters and all of the presentations so far, but I just wanted to, you know, I’m close to finishing my master. So if people found intriguing to find out more information about MITRE Tech and how to build effective security operation centers, that my work will be available soon. So I can share with them if anyone wants to read through and get more acquainted with that.
you know, how to build effective sort of tailored, a threat actor tailored defenses in your organizations, then yeah, I can share that information with anyone who wishes.
Manoj Tandon (54:52.447)
That’s fantastic. And how should they reach you? What’s the best mechanism?
Marius Poskus (54:57.046)
The best mechanism is LinkedIn. My name, you can find me on LinkedIn, Vice President of Subsecurity for Global Financial Services.
Manoj Tandon (55:06.797)
Fantastic. Well, you might get some hits there then. So look out for it. People might reach out to you, which would be great. Are you doing any talks or making any appearances? Are you speaking at any of the cyber conferences coming up?
Marius Poskus (55:21.646)
Hopefully soon, you know, I’ve kind of been so involved with so many things now that, you know, I’ve been just writing my dissertation, just done the CISP. So I was doing, I’m doing mentoring classes, so I’ll just try to find space. So my master’s is finishing at the end of this month. So that will free up me some spaces that actually go into. I’m heavily involved with like various sort of leadership community events in here in
in over in the UK. So I’m part of SANS CSO networking events. We do a lot of, and then we have a couple of groups. So we have Cyber Kingdom, where is a lot of cybersecurity CSOs within the UK. There’s a big Israeli community in there. So I think we’ve done recently one event and we had a head of 8200 squadron. I don’t know if you had. So there’s a cybersecurity sort of military group in Israeli.
from them to hear how… So it’s 8200 squadron where… because in Israeli for example they have obviously military services, you can’t choose, 18 you have to go for two years. So obviously that’s why some of the people that end up in 8200 squadron obviously work on cyber intelligence, cyber you know operations for two years. So when they leave at 20
Manoj Tandon (56:18.761)
was not aware of that. Yeah.
Manoj Tandon (56:31.981)
You’re right.
Marius Poskus (56:43.81)
They have this amazing skill set and that’s why there’s so many cyber security startups happening in Israeli because these people come with these extreme skill sets and they’re fostering that environment where startup is supported. So that’s why we have so many unicorns being built there.
Manoj Tandon (57:01.521)
Understood. Well, Marius, it’s been brilliant having you here. Thank you so much for your time. And, you know, don’t be a stranger. If you have something new to talk about, you know, reach out. We’d love to have you back.
Marius Poskus (57:16.726)
Will do. Thank you very much, Manoj.
Manoj Tandon (57:18.797)
Thank you.
Marius’ Linkedin
Check out the other episodes in Season 12:
Ep. 0 Dark Rhino Security – The IT Security Money Pit
Ep. 1 Marius Poskus – Tech talk overwhelms the nontechnical
Ep. 2 Robert Black – Who is responsible for Cybersecurity?
Ep. 3 Eric Allard – Your Guide to SBOMs
Ep. 4 Ryan Leirvik – Understand, Measure, and Manage Cyber Risk
Ep. 5 Dan Wachtler – Building Awareness About Your Startup
Ep. 6 Peter Warmka – A Seniors Survival Guide
Ep. 7 Susan Bennett – More than the Voice of SIRI
Ep. 8 Frank Riccardi – The Human Factor is the Weakest Link
Ep. 9 Dmytro Bielievtsov – What is Vishing?
Ep. 10 Chris and Rory – Bourbon Breakdown
About Marius Poskus

Marius has over 10 years of experience in cyber security, spanning various domains such as cloud security, DevSecOps, AppSec, threat hunting, penetration testing, red/purple teaming, and more.
Marius is also a public speaker, mentor, and non-executive director for many cybersecurity businesses.
He was the former Cloud Security Architect and Analyst at Domino’s Pizza UK & Ireland, Analyst at Burberry, and many more.
About Us:
Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host, Manoj Tandon, talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Google Podcasts, Amazon Music, iHeartRadio, Youtube, LinkedIn, and more.
For inquiries, please email media@darkrhiinosecurity.com
