This week on Dark Rhiino Security’s Security Confidential podcast, Host Manoj Tandon welcomes Brian Stoner. Brian has a long history with cybersecurity OEMs and has extensive experience in MSSP, Channel, Strategic Alliances, and OEM for high-growth security solution providers. Brian Stoner has worked at McAfee, Fireeye, Cylance, Stellar Cyber, and is now the Vice President of Worldwide Channels and Alliances at DTEX System.
Chapter Titles:
00:00 Introduction
01:18 Technology trends
02:30 Is the industry overcrowded?
05:49 DTEX: who are they and what do they do?
08:45 Compromised Machines 9:26 Endpoint detection
13:48 Where is DTEX Classified?
15:32 Managing Vulnerabilities on the endpoint
18:19 Working with Sectors
20:39 Customer Profile: How small is too small?
24:05 DTEX Cloud
25:23 Trends with Investors
28:00 Remote work: Can you trust your employees?
30:00 Remote work: Fake Linkedin Profiles
33:53 More about Brian
Audio:
Important Links:
Transcript
Manoj Tandon: This is your host, Manoj Tandon, and welcome to another episode of Dark Rhino Security Confidential. Today, we are honored to welcome back an old friend of the show and my friend, Brian Stoner. Brian and I go back a long way, back to the days of Computer Associates, but Brian’s got an illustrious history in cybersecurity. For those of you who don’t remember him from the past episode, he’s worked at some of the greatest cybersecurity companies out there, companies like CA, Cylance, BlackBerry, FireEye, McAfee, Stellar Cyber, and now Dtex. So Brian’s got a long, long resume, and it’s a very cool one. He keeps his ear to the ground and is very knowledgeable. We’re glad to have him. Welcome to the show, Brian. Thanks for coming back.
Brian Stoner: Yeah, thanks for having me back, Manoj. It’s always fun to catch up.
Manoj Tandon: Absolutely. So I guess one place to start off with since we last talked—you’ve obviously changed roles—but do you see technology trends or things happening here that were the root cause behind this? Is there something exciting happening in the world of cyber?
Brian Stoner: Yeah, and actually it goes back to some of the other places that I’ve worked because a really good friend of mine, Dede Dayton—who I don’t know if you know personally or not, but she’s another big cybersecurity executive—she’s the one who brought me into FireEye, she’s the one who brought me into Cylance, and she’s also the one who kind of recommended me to Dtex when they needed a Channel Chief. I was happy to take on the role and really help Dtex make it to the next level in the cyber industry.
Manoj Tandon: That’s fantastic. I don’t know Dede personally; I only know her from the couple of interactions we had at Cylance back when she was running, I think, Global VP of Channels.
Brian Stoner: She was, yep.
Manoj Tandon: Yeah, at one point in time. But that’s great to hear. When you’re looking at the channel—I guess before I ask this question, let me just kind of set the context. When I look at the cybersecurity software landscape today, it reminds me a lot of what the automotive landscape was in the early 1900s in North America. There used to be a time when we had 400 automotive manufacturers in North America, and now we’re left with Ford, GM, and Chrysler.
So, is this an industry that is overcrowded? Is it ripe for consolidation? What are your thoughts on that?
Brian Stoner: Yeah, I think you’re seeing the consolidation right now, especially with the economy and the VC money starting to dry up a little bit. You’re going to start to see a lot more acquisitions. People are building out platforms and adding functionality that are complementary to their core product offerings. I think you’re seeing a lot of that right now.
Manoj Tandon: So then you come along and you take on a Herculean challenge of taking a small company like Dtex and really expanding its channel programs. How does a company like that differentiate itself? I mean, it seems like a really crowded market space.
Brian Stoner: Well, I think at Dtex, we’re really fortunate that we have founders who started the company 20 years ago, and they’ve been evolving the platform for many years. So it’s not a two-year-old startup where we’re selling our beta product and fixing it for our customers as we go.
Manoj Tandon: Right, I think nobody ever does that.
Brian Stoner: We’ve never been there before. I think customers are starting to mature to the point, especially larger customers, where they’re building insider risk programs. And I think a lot of the breaches that we’ve seen in the last several years—everybody thought that the SIEM was going to help them detect it and DLP was going to stop it. Unfortunately, what we’re finding out is that DLP has become the bike lock of our industry.
What I mean by that is it keeps the honest people honest, but if somebody’s really going to steal your bike, they’re going to steal your bike. And over the last several years, every major breach that we’ve seen—they’ve all had DLP, but guess what got stolen? All their customer data. So I think Dtex is at a point where the industry is maturing to where they know now that they need something that gives them more insight into the happenings on their endpoints than what they’re getting from the current siloed solutions. They need to be able to look at human behavior as a combined risk versus chasing alerts like we’ve been doing for the last 20 years.
Manoj Tandon: So get into that a little bit more. Exactly what does Dtex do, then?
Brian Stoner: So, a couple of interesting things that Dtex has built into their platform. The first really unique thing is that we collect our own telemetry from the endpoint. We’ve built a really lightweight log forwarder that takes only the security-relevant data from every endpoint at the kernel level. So we’re not relying on Sysmon or other agents that are doing things on the endpoint. We’re really just collecting the relevant security data. And it’s only three to five megs per day, significantly less than if you’re pulling Sysmon today.
What we do is we pull that into our platform, we enrich it, and we use all sorts of different detection methods. Obviously machine learning is part of it, but there’s a whole series of rules and other things that we’ve built to recognize over 10,000 different behaviors.
Manoj Tandon: Just let me stop you real quick. So you’re not looking for processes; you’re looking for patterns?
Brian Stoner: Yes, absolutely. And all of those patterns we combine into a risk score for each individual or each device. So now instead of looking at your device and saying, “Oh, Manoj is trying to send a spreadsheet somewhere that has data on it,” a truly malicious insider is going to do some level of reconnaissance. They’re going to pull down some data from different sources at a higher volume than they normally would. They might combine it into a zip file. They might rename some things to try to obfuscate what they’re doing. And then they might send a few test files out through Dropbox, or they might send something to their Gmail that looks fairly innocuous. And then they might even start looking on the web at “how do I get around my DLP solution?” But there are other things that people do where they just didn’t know they shouldn’t be doing it. Maybe they’re sending things to Dropbox and they’re doing it to do their job because email won’t let them send files over a certain size and their customers need to get it.
So there are negligent behaviors that you can’t confuse with a truly malicious insider. We look at the combined group of actions that they’re doing in real time and build a risk score based on the user, not on the individual alerts.
Manoj Tandon: But now this is the use case of a rogue insider, right? What about the case where we see the vast majority of entries for ransomware are phishing attacks and compromised machines?
Brian Stoner: It’s the same thing. Compromise is not a malicious insider per se, but when you understand the normal behaviors of that user and it starts doing things that are outside of their normal patterns, that’s anomalous.
Either they’ve been compromised or an attacker has gotten into their machine and is doing things that they don’t normally do. We can detect both.
Manoj Tandon: Okay, got it. So as far as polymorphism goes—of these malware pieces where they’re changing small incremental bits designed to make it different enough that it’s not going to get picked up by a SIEM, or by an EDR agent, or by an endpoint agent—have you guys done testing that in those instances then you guys will in fact pick it up because it’s looking for a pattern of behavior?
Brian Stoner: Yeah, we capture everything that happens on the endpoint every 60 seconds. So if that file loads, we’re hashing it, we’re watching what it does. If it tries to build outbound communication, or tries to scan the network, or tries to do other things, we recognize those things right away. We have five different detection areas within the risk score that we build. One is those user behaviors, UEBA-type detections. We have what we call zero-trust DLP, where we’re hashing every file. We hash every action every user in the organization takes against those files.
We can assign risk based on who created the file—if it’s an engineering file, those types of things—and then we track everything the user does with it. That’s what’s missing today: we just try to detect that event when somebody tries to take something out. We don’t see everything they do leading up to that, nor do we see everything they do after that. Once an attacker sends that file out encrypted so DLP doesn’t see it, they also have to go back and clean up after themselves. Those are other things that we capture that you normally don’t capture with other solutions.
Manoj Tandon: Is Dtex then going to work in conjunction with the SIEM again, where if it’s picking up these alerts, you are going to put them into your SIEM and write rules for alerts?
Brian Stoner: Absolutely. One of the things that we do that’s really unique is we can create different policies based on the risk score of the user.
If somebody’s just doing some negligent behaviors, we can send an email to that individual to say, “You know what? That’s not a sanctioned application. You shouldn’t be sending company data through there. Stop doing that.”
But as that user gets riskier, we can start taking things away. We can take away their access to certain applications, we can take away access to different processes, we can kick them off the network, we can kick them off of Active Directory. As they get riskier, we’ll build a dossier on that user and we can send that to HR. HR can say to the manager, “We’ve got to go have a conversation with this guy before he starts trying to exfiltrate data,” because he’s showing all these behaviors that are leading up to that. So we’re trying to get left of boom on this one versus trying to block the attack-type activities. So it’ll go into the SOAR, the alert can go into the SIEM, but the actions that we take can also be taken through a SOAR.
What we’re seeing a lot of—and we have a strategic relationship right now with Splunk—so we have a Splunk app and a Splunk forwarder. They can either just take in the alerts, or they can take in all of our data.
The other big partnership we have is with CrowdStrike. When all of your users went out beyond the corporate firewall, where all of your network detections reside, you lose that visibility. They’re not down the hall anymore; you can’t go see what they’re doing. So what we do is we provide all that context. If CrowdStrike fires off an alert that there’s some malware that’s been downloaded to a browser, we can show everything the user has been doing that led up to that and everything that happened afterwards. Those are all things that CrowdStrike doesn’t even capture. So it helps give that visibility back to the SOC that they lost when all the users went remote.
Manoj Tandon: Where do you guys fit in that world of EDR, endpoint protection, and DLP? Where is Dtex classified?
Brian Stoner: Yeah, so we actually cover five different areas. The first one would be user behavior and UEBA. We also have what we call zero-trust DLP, where we track everything that happens to files and can intercede and interject ourselves wherever necessary. We also have the full MITRE ATT&CK framework built into the tool. And here’s another interesting side note: we finished an eight-month bake-off with MITRE against all of our major competitors, and they chose to partner with us. Because the MITRE ATT&CK framework is primarily an external attacker framework, we are jointly developing an insider framework with MITRE that’ll be released later this year.
Manoj Tandon: Oh, very cool.
Brian Stoner: Yeah. So we’ve got that, and then we also have a whole forensics module and a risk and compliance module built into the product. As I mentioned before, we can provide all the context around what’s happening with remote users beyond what your EDR is telling you about vulnerabilities on that. That’s kind of where we fit. So like I mentioned before, we can replace several different traditional agents that would be on an endpoint and give the customer some performance back on their endpoints.
Manoj Tandon: One thing that really caught my attention was you said that you have seen your clients replace Tanium with you. When I look at Tanium, Tanium has a lot of pieces built into it, but it’s a lot about—if I oversimplified it—managing vulnerabilities on the endpoint, where you’re getting an asset inventory, you can patch remotely, and you can find hidden assets. There’s a lot of things going on there. Do you guys have those component technology pieces, or has it just become redundant?
Brian Stoner: No, we rely on whatever RMM tool that the customer is using for deployment and all that. So we don’t have that functionality built in, but a nice way to think about it is the SOC is managing vulnerabilities. The insider risk team that’s being developed right now is focused on users and enforcing policy within the company. So we typically deal with somebody outside of the traditional SOC—either HR or this insider risk group—that in a lot of cases is kind of part of that governance, risk, and compliance group in a larger company.
Manoj Tandon: Okay, so that’s your main audience. So it’s not the CISO’s office in particular?
Brian Stoner: A lot of times, if there is an insider risk kind of pet project for the CISO, he brings it in, and two years later, it’s time for the renewal and he’s gone. Then it’s a little more difficult to sell the renewal. But if it’s really integrated into a program—which, right now, we’re working with Deloitte and PwC. They both have very mature practices. The way they used to have identity and access management practices, they now have insider risk practices that focus on “how do you build policy at HR to deal with individuals that are doing things that are outside of your policy?”
It’s one thing for us to send an alert, but if they’re trying to figure out how to handle this—do we tell the manager? Do we sit down with the manager and the employee? What do we do? That’s what our bigger partners are helping our customers with, and then we’re providing them the data. Because you can’t manage what you can’t measure. We can help measure a lot of things that traditional tools don’t measure because they’re so focused on alerts, whereas we’re focused on users.
Manoj Tandon: Okay, that’s a very good visual demo, if you will. And are there particular sectors, Brian, that are using your technology more than others that have been keen to adopt?
Brian Stoner: The obvious ones are banking, for sure, and healthcare. We do a lot with different governments, especially in Australia and the US. We do a lot with manufacturing. It really just depends on where there’s intellectual property that people really want to protect. And the other thing is a lot of people who build these programs don’t want their end users to feel like they’re being surveilled. I don’t think anybody wants to feel like “Big Brother” is kind of watching over their shoulders. A lot of the competitors that we have that do screen captures and recordings and things like that—it’s very intrusive, and it’s very processor-heavy on their devices.
So we actually spent part of our history headquartered in London when GDPR was coming out, and so we built a whole layer of anonymization in the product so that the SOC or HR can’t be biased. We scramble the names, usernames, and IP addresses for their computers. Unless you have the right credentials, you can’t unscramble it and ascertain who the actual user is. So that prevents IT or the SOC from having a particular focus on certain individuals. It’s all anonymized. So when the threat score reaches a certain threshold, they surface it to HR, and then HR takes the actions that they’ve developed from there. In that way, and because it’s lightweight, users don’t even know it’s there. So I think from a user experience perspective, it really helps the customer there as well. Not only do they not feel like they’re being surveilled, but their machines are faster and have fewer issues.
Manoj Tandon: So what is your customer profile in terms of size? You’ve mentioned a lot of really big companies. How small is too small for you guys?
Brian Stoner: Well, there is no “too small.” I mean, we do have some 10-man trading firms that use our software. So it doesn’t have to be. But I think what we’re starting to see is those Fortune 500s—the people that are building those practices are starting to now kind of filter down into the Fortune 1000s and below that, depending on the amount of IP that the customer is trying to protect. So I think it’s going more and more mainstream. I’ve talked to some service providers that want to start adding insider threat monitoring to their MDR service. It’s starting to filter down a little bit, but we’ve got some work to do to support multi-tenant customers and things like that. We’re working on federation right now. But what we’re noticing is that with the bigger SIs, when they’re working with a bigger customer, that customer wants to keep all their data separate.
So normally what we’re doing is just sending alerts into their current infrastructure. Multi-tenancy is not really necessary because people are using the SIEM and the SOAR as that single pane of glass anyway.
Manoj Tandon: Okay. So you guys are not a strong MSSP model; you’re more of a VAR channel model then? Is that what your go-to-market is?
Brian Stoner: Yeah, so we do have—obviously, and we just did a press release on it—we have a new relationship with GuidePoint, which we just announced. And we also do quite a bit with Optiv. So yeah, a lot of the bigger VARs. But like I mentioned before, we’re doing a lot with the consulting firms and starting to do more with the Global SIs. Because this really supports a whole new practice for them, that means another source of recurring dollars for them.
Manoj Tandon: Does the technology require a heavy amount of consulting or configuration?
Brian Stoner: It doesn’t require a heavy amount of it. I think our enablement is like three days long.
Manoj Tandon: Okay, yeah, this is not a two-week course that you’ve got to take. I’m turning back the clock to our old days of CA, where there were projects for years. We talk about years—“how many years is it going to be?”
Brian Stoner: No, it’s fairly simple. And we also can tune all of our alerts and our risk scores for everything. So, something that happens in a nuclear facility is going to have a different weight on different things than what happens in a bank. So the platform is completely customizable from that perspective, but a lot of it comes out of the box. And the machine learning takes about a week or two to start training. Once it gets trained, it continues to train, but you can still change the weights on different things so it’ll keep the data very relevant for the end user.
Manoj Tandon: And you guys are 100% cloud-based, or is there an on-prem appliance or something that goes in?
Brian Stoner: Yeah, our primary go-to-market is cloud. Most of our customers use the cloud, but we do have banking customers who wanted to host it on virtual images within their data center. We also have customers who want us to deploy on their VPC in a particular cloud, and we can support all those options.
Manoj Tandon: Okay. And you guys have been around for 20 years?
Brian Stoner: Yeah, I would say we’ve really been coming into our own the last couple of years. We received some money in a round recently from a lot of the investors in FireEye, as a matter of fact. Four of the FireEye original board members are our board members. They see tremendous potential in this technology. Our CEO, Bauman, was the Chief Product Officer at FireEye, and obviously I was at FireEye for a period of time too. It’s kind of like we’re bringing the band back together, so to speak.
Manoj Tandon: Let me ask the question: where do you see the investments going in cybersecurity? You’ve done a couple of companies at this point. What trends are you seeing out there?
Brian Stoner: So, I think the first trend that we’re seeing is the sunsetting of traditional SIEMs, like the rules-based detections. We’re starting to see a lot more of the machine-learning-based detections. I think that’s a function of the fact that pretty much every SIEM was never designed to take in the volume of data that we’re throwing at it, which is why you see companies like Cribl right now having a lot of success—because they can filter out some of that noise to help reduce that amount of data going into the SIEM. That’s another area where we’re kind of helping, too, because we take about a tenth of what Sysmon generates. We can help reduce that at the SIEM as far as endpoint data. From there, what we’re seeing is—even now—we’re seeing attacks on two-factor authentication, which is kind of funny because that was the thing that everybody said the last few years: “If you just do one thing, do two-factor authentication.” But I think that’s where now we’re starting to see SASE start to become a lot more popular. If you can control the access and the device, then it doesn’t matter what kind of controls you have in your cloud and things like that, because they can’t get there anyway.
I’ve seen a lot of service providers start to migrate toward that.
Manoj Tandon: You know, Brian, I’ve heard this statement made by a lot of people lately that “the SIEM is dead,” or “traditional SIEM is dead.” But every time I look at a SOC, everybody’s still staring at a SIEM console all day long. So is the SIEM really dead, or is it evolving?
Brian Stoner: I think it’s evolving. I don’t think it’s dead. I think the challenge is that SIEMs were built in a different era. They were built when we had much smaller volumes of data and when a lot of the detections were rules-based. The problem now is that we’re generating so much telemetry and so much data from cloud workloads, endpoints, containers, SaaS applications, and everything else that the old model of “collect everything and write a rule for it” just doesn’t scale very well anymore. So what you’re seeing is SIEMs becoming more of a data lake or data repository while more intelligent analytics layers are sitting on top of them. And then you’ve got companies like Cribl helping filter and route the data so you don’t bankrupt yourself on storage and ingestion costs. That’s one of the reasons why lightweight telemetry matters so much now.
Manoj Tandon: Yeah, because some of these organizations are spending millions of dollars a year just on ingestion costs alone.
Brian Stoner: Exactly. And the funny thing is, a lot of that data never gets looked at. So organizations are paying enormous amounts of money to store logs they’ll never actually use in an investigation. What they really need is better signal-to-noise ratio. And that’s where a lot of these newer technologies are focusing: “How do we surface the important things faster and with more context?” Because the other problem is staffing. You can’t just keep hiring analysts forever. There aren’t enough people. So now everybody’s trying to figure out how to make analysts more efficient.
Manoj Tandon: Which leads us straight into AI.
Brian Stoner: Exactly. And I think AI is going to have a profound impact on cybersecurity, but maybe not in the way the marketing departments are saying it will. Right now, a lot of people are slapping “AI-powered” on products because it’s the hot thing. But the reality is, AI is really good at pattern recognition, correlation, summarization, and helping analysts prioritize. That’s where it’s delivering value today. Where I think it gets dangerous is when people start talking about fully autonomous response systems making critical decisions without human oversight. Because attackers are going to weaponize AI too.
Manoj Tandon: Well, they already are.
Brian Stoner: Absolutely. We’re seeing phishing emails that are dramatically better written than they were two years ago. We’re seeing deepfakes. We’re seeing AI-generated malware variants. And we’re seeing attackers automate reconnaissance much faster than before. So defenders are going to need AI just to keep pace. But I still think there has to be a human in the loop.
Manoj Tandon: So if we fast forward five years, what does the SOC of the future look like?
Brian Stoner: I think it becomes far more automated and far more contextual. I think the SOC analyst of the future spends less time triaging endless alerts and more time investigating a much smaller number of high-confidence incidents. I think identity becomes central to everything. I think user behavior becomes central to everything. And I think the perimeter continues to disappear. The old model was: “Protect the network.” The new model is: “Protect the identity and the data.” Because users are everywhere now. Your applications are everywhere. Your data is everywhere. So you can’t rely on network-centric controls anymore.
Manoj Tandon: Yeah, the castle-and-moat model is gone.
Brian Stoner: Completely gone. And honestly, COVID accelerated that transformation by probably ten years. Companies were forced to support remote work almost overnight. And once users moved outside the firewall permanently, organizations lost visibility. That’s why endpoint telemetry, identity telemetry, and behavioral analytics became so important. Because the endpoint became the new perimeter.
Manoj Tandon: So let me ask you a philosophical question. Do you think defenders are winning or losing right now?
Brian Stoner: I think defenders are overwhelmed. I don’t know if I’d say they’re losing, but they’re definitely outnumbered. Attackers only have to be right once. Defenders have to be right every single day. And the attack surface keeps expanding. Cloud, SaaS, remote work, APIs, supply chain attacks, AI—everything increases complexity. So I think the organizations that are succeeding are the ones simplifying their environments, consolidating tooling, automating intelligently, and focusing on risk instead of noise. Because you can’t investigate everything anymore. You have to prioritize.
Manoj Tandon: That’s a very important statement. You can’t investigate everything anymore.
Brian Stoner: You can’t. There’s just too much. And that’s one of the reasons why insider risk and behavior analytics are becoming more important. Because instead of trying to investigate every event, you’re investigating the riskiest users, the riskiest behaviors, and the riskiest anomalies. That dramatically narrows the problem space.
Manoj Tandon: So before we wrap up here, Brian, where can people learn more about Dtex?
Brian Stoner: They can go to dtexsystems.com. We’ve got a lot of information there, white papers, case studies, analyst reports, all that kind of stuff. And if people are building insider risk programs or trying to figure out how to get better visibility into remote workforces and endpoint behavior, we’d love to have a conversation.
Manoj Tandon: Fantastic. Brian, always a pleasure, my friend. Great insights as always. Thank you so much for joining us again.
Brian Stoner: Thanks, Manoj. Always great talking with you.
Manoj Tandon: And thank you to all of our listeners for joining us on another episode of Dark Rhino Security Confidential. Please don’t forget to like and subscribe so we can continue bringing you these great conversations.Until next time, stay safe out there.
Brian Stoner: Thanks, everybody.
Learn more about Brian on his Linkedin
Check out the other episodes in Season 8:
Ep. 0 Dark Rhiino Team – Data Loss Prevention
Ep. 1 Boyd Clewis – Cofounder, Author, and Cybersecurity Speaker
Ep. 2 Ken Underhill – CEO, Author, and Cyber Life
Ep. 3 Dr. Gerald Auger- Simply Cyber, Black Hat 2022, and Security Awareness
Ep. 4 Eddie Thomason – Humility, Negativity, and Twitter News
Ep. 5 Zinet Kemal – Author, Diversity, Cloud Security, and CISA
Ep. 6 Derek Scheller – Cyber Warrior, Veteran, and Podcaster
Ep. 7 Ted Harrington – Hackable: How to do Application Security Right
Ep. 8 Kevin Tambascio – Cyber Professional, Cleveland Clinic, and HIMSS
Ep. 9 Greg Tomchick – Pro Athlete turned Cybersecurity CEO
Ep. 10 Brian Stoner – Remote work: Can You Trust Your Employees?
About Brian Stoner

Brian is the Vice President of Worldwide Channels and Alliances at DTEX Systems.
Brians has extensive experience in MSSP, Channel, Strategic Alliances and OEM for high growth security solution providers.
Brian has a long history with cybersecurity OEMs starting with CA where Manoj first met him.
Brian has been with McAfee, Fireeye, Cylance, Stellar Cyber, and is now with DTEX Systems.
About Us:
Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host, Manoj Tandon, talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Google Podcasts, Amazon Music, iHeartRadio, Youtube, LinkedIn, and more.
For inquiries, please email media@darkrhiinosecurity.com
