Episode 15: Special Guest Vladlen Rotshteyn

September 15, 2026 | 34 mins

Subscribe:

In this episode of Know Your Adversary, Jared Atkinson and Justin Kohler are joined by Vlad Rotshteyn to discuss what effective attack surface and exposure management looks like inside a large enterprise.

Vlad shares his path from enterprise IT into cybersecurity and how that experience shaped his approach to security. The conversation explores why visibility across assets, identities, vulnerabilities, and security tooling is critical to understanding where an organization is actually exposed.

The group also digs into moving beyond vulnerability severity to prioritize risk with context, how Attack Path Management and BloodHound can provide a clearer picture of exposure, and why better visibility can sometimes make security metrics look worse before they get better. They close with Vlad’s perspective on AI, the importance of asking the right questions, and why new technology can’t replace strong security fundamentals.

00;00;01;02 - 00;00;14;11
Jared Atkinson
Yeah. It's my fourth year. Yeah. That's good. I'm trying to think of, like, a analogy. I have a jersey for something, but it wasn't that I've ever been there.

00;00;14;13 - 00;00;19;22
Jared Atkinson
Do you do you come for training to know? Okay. Let's say that would be a long time.

00;00;19;27 - 00;00;24;07
Vlad Rotshteyn
Yeah. No. Yeah. We got in on Tuesday, and then we're leaving Monday morning.

00;00;24;10 - 00;00;41;01
Jared Atkinson
Is anybody on our team doing the whole thing? Like training through Defcon? I'm sure somebody is. I can't I can't do it at all. Too exhausted when you live here. Yeah. No, I just can't get away for another weekend either. Oh, yeah. Yeah. You live here? Yeah.

00;00;41;02 - 00;00;42;25
Vlad Rotshteyn
How do you deal with the heat?

00;00;42;26 - 00;01;02;18
Jared Atkinson
Yeah. Yeah. You just stay inside. Do you guys live here? Are you Las Vegas? He's local. Okay. Yeah. Yeah, yeah. AC. Dude, I had to replace both my AC this year. That sucks. Yeah, it's it's rough. It's a rough number. All right, guys, well, we're good to go. Whenever you ready? Okay. Are you starting or am I starting or what?

00;01;02;20 - 00;01;04;12
Jared Atkinson
I like how to pronounce your last name.

00;01;04;19 - 00;01;05;07
Vlad Rotshteyn
Rotshteyn

00;01;05;08 - 00;01;05;22
Jared Atkinson
Rotshteyn

00;01;05;25 - 00;01;06;11
Vlad Rotshteyn
Rotshteyn

00;01;06;12 - 00;01;28;29
Jared Atkinson
And you go by Vlad, right? Yes. Okay, cool. I think you do. You're better at pronunciation, rush. Okay. All right, here we go. Welcome back to the Know Your Adversary podcast. I'm Jared Atkinson, I'm Justin Kohler, and today we're joined by Vlad Rotshteyn. Vlad you want to introduce yourself. Maybe tell us a little bit about your background and how you got into cybersecurity.

00;01;29;01 - 00;02;03;20
Vlad Rotshteyn
Yeah, sure. So I'm Vlad, I've been doing essentially enterprise. It works since like early 2007. So got into the industry kind of in a roundabout way. So started college computer science, then kind of dropped that, but always maintained the interest in it and stuff. So eventually, you know, I ended up with a degree in chemistry, but I was like, all right, well, what am I supposed to do with chemistry?

00;02;03;20 - 00;02;31;15
Vlad Rotshteyn
But also how to do computer stuff? So ended up, you know, getting really lucky, getting a job in the farmer space, doing it support. So for about 15 years I was doing enterprise it supports, I was supporting business functions. I had full, basically full IT responsibilities without actually having, you know, reporting into it. So I would.

00;02;31;16 - 00;02;32;27
Justin Kohler
Wait, you didn't report into it?

00;02;32;28 - 00;02;48;26
Vlad Rotshteyn
No no, no. So it was a business. It was kind of like a dotted line. Oh okay. Yeah. So it was basically, you know, full it responsibilities. But not reporting. So. Interesting. Yeah. Because it's a big, big company. So you're the federated. So like some of the business units kind of have their own in-house like IT teams.

00;02;48;26 - 00;03;16;27
Vlad Rotshteyn
And you know that's essentially how I started up. So then around Covid I decided that I needed to make a career change. And, you know, should have it should really start doing what I should have been doing, you know, 15 years ago and really pivoting into the cybersecurity space. So I took it upon myself to really push to get into the field where I should be connected with the cybersecurity team at the company.

00;03;16;27 - 00;03;37;22
Vlad Rotshteyn
And essentially it was like, hey, I would like to come work for the cyber security team. I've, you know, worked, you know, in the IT department. So, like, I know all this stuff and I know kind of like where, you know, I just say some of the skeletons are buried and, you know, hey, you know, I have so much trouble knowledge come like, let me help you.

00;03;37;22 - 00;03;57;18
Vlad Rotshteyn
So, you know, I took it upon myself. I, you know, studying for the test. I got my certification. And, you know, essentially, after a year and a half of shadowing, the cyber security team position opened up and I was invited to join the team. And, you know, I've been there for four and a half years now. So nice.

00;03;57;25 - 00;04;17;03
Vlad Rotshteyn
Yeah. It's just really, you know, extension of, you know what I do? I'm really good at acquiring software, deploying software, running software, seeing it's, you know, the end to end spectrum of, you know, not even just, you know, security, but just, you know, enterprise how to run enterprise IT tooling is, you know, is a skill in itself.

00;04;17;05 - 00;04;33;29
Jared Atkinson
Yeah. Yeah. I think it's when you said that you went from computer science to chemistry, usually when people changed their major, they changed to an easier major. So I was like, I started with mechanical engineering and then I went to history. Right? And it was like, okay, that, you know, my all my electives are like chemistry and physics.

00;04;33;29 - 00;04;51;23
Jared Atkinson
And so I have terrible elective GPA and great regular, you know, coursework, GPA. But yeah, it's kind of funny. Go ahead. No. You go. What what brought you into cybersecurity? Like, what was the thing you're like, I want to make it like. Like what? What made you choose cybersecurity from IT.

00;04;51;24 - 00;05;18;23
Vlad Rotshteyn
More so like, I needed to have a way to progress my career. Okay. So being in my in the previous role, like I was, you know, I was kind of pigeonholed into what I was. So like, if I ever needed to, let's say, leave or, you know, change, you know, companies or something, I would be kind of limited to, you know, doing the same niche work.

00;05;18;29 - 00;05;50;29
Vlad Rotshteyn
Totally. And the opportunity to be very limited. But, you know, making reaching a branching out into enterprise it, you know, leaves enterprise security just, you know, opens a whole, you know, new opportunity because not only it's no longer just, you know, a form of application specific work. Now it's enterprise security specific work that you know, anybody needs. So like what I what I'm doing now is applicable to pretty much anyone, any, any enterprise that runs computers or, you know, runs any tech.

00;05;51;01 - 00;05;59;25
Vlad Rotshteyn
You know, I do that. And that's really what I've been working on is, you know, doing the whole and, you know, attack surface management program.

00;05;59;28 - 00;06;24;00
Justin Kohler
And before we go before we go into that, I think it's it's really common for most like I've heard it many times like that. The best cybersecurity people are either the ones came from a computer science background or network admin or helpdesk. Right. Like they come up from like understanding what people help people break systems. Right. And then I think, I think a valuable component of cybersecurity is actually understanding how everything works.

00;06;24;01 - 00;06;47;23
Jared Atkinson
Right? So when you're a programmer, you have to understand how the API works. You have to understand how software works. You have to understand how like the systems are built up from their component parts. And I think that helps you to kind of decompose the cybersecurity problems a little bit better. And so that's a useful background. And like, you know, I'm like I love the analogies to different fields, but I imagine chemistry I wasn't very good at it, but I imagine it's kind of a similar idea.

00;06;47;24 - 00;06;59;24
Jared Atkinson
Right. So you have the elements and then you have compounds and you kind of like are building things up. And so that idea of decomposition and how you can make more complex things out of simpler things is a useful kind of mental model.

00;06;59;27 - 00;07;23;19
Vlad Rotshteyn
Yeah, certainly. That's one aspect of chemistry. But, you know, I look at the chemistry like it was just kind of a mean to end. Like I just needed to graduate at that point. Yeah. Look, for me, chemistry kind of like hit the line of I was taking quantum chemistry and like one of the like the first weeks of the courses, they were like, okay, teleportation is actually on.

00;07;23;21 - 00;07;31;12
Vlad Rotshteyn
Like, you know, the quantum level, like teleportation is real. I'm like, okay, I'm done. Magic. Yeah, yeah. Okay. This is magic. Done. So that that that was.

00;07;31;16 - 00;07;32;29
Jared Atkinson
Just hold on to survive, baby.

00;07;33;00 - 00;07;33;18
Vlad Rotshteyn
Yeah. Yeah.

00;07;33;18 - 00;07;54;00
Justin Kohler
So well in terms of like, it's actually a good segue back to where you're going with the attack surface management. And like, you can't really talk about exacts, right. But like, can you give us a sense of what what what you manage. Right. So like yeah you mentioned attack surface I think of like components like building up to something greater.

00;07;54;01 - 00;08;00;05
Justin Kohler
Yeah. That's kind of what we were talking about in the lead up to this is there's like a bunch of different components that make up that problem.

00;08;00;06 - 00;08;23;09
Vlad Rotshteyn
So and yeah, right. So it's the components. But also you know, it's understanding as you it's the data. You know, you really have to know what it is you are trying to protect. And you know, know your environment. And you know, like as I like to say, I, I'm a data nerd and like, I like to have data to tell my story and like, I like to have that available at my fingertips to do that.

00;08;23;09 - 00;08;43;05
Vlad Rotshteyn
And the, the tooling that I'm running and like, you know, all the stuff that I've just been working on has, like, really enabled me. So, you know, when I think of attack surface management, I think of what really the whole end to and from all the way from your external public presence down to the perimeter level and then also the internal level.

00;08;43;05 - 00;09;05;16
Vlad Rotshteyn
So, you know, you can't protect what you can't see, obviously. And then you also need to know how you are even validating what you are seeing. So you know a lot of things you need centralized way to do that, especially in a large enterprise, because, you know, a large enterprise, you have you have federated teams, you know, doing different, running different security tools.

00;09;05;16 - 00;09;26;15
Vlad Rotshteyn
How do you bring that all together? How do you do centralized visibility? You know, that's all, you know, new things that we are, I guess, working towards. The industry term. The new term is CTM, a continuous threat exposure management. And that is essentially, you know, my approach and my philosophy that I'm, you know, carrying forward in the work that I'm doing.

00;09;26;16 - 00;09;37;25
Justin Kohler
And so that's like like, like it goes from everything from like assets to identities to the, to the misconfigurations on those particular things, whether they be bonds or, or just a permissions issue.

00;09;37;27 - 00;10;02;23
Vlad Rotshteyn
Exactly. Yeah. All of that and all that, you know, is part of the larger question of like, where what are we supposed to where are we exposed? Because it really moves away from the legacy, you know, vulnerability management or management by headlines or even just managing by, you know, CV severities. Yeah. Okay. So you have a CV that's, you know, 9.8 ten whatever it back in the day, you'd be like, drop everything, patch it.

00;10;02;23 - 00;10;28;13
Vlad Rotshteyn
But now it's like, well do we need to like it's all about context. Like, you know, no longer is just the CV in a vacuum. It's really understanding. So about the asset that it's running on. So if it's a, you know, CBE that is only exploitable via network. But you know the asset doesn't have network connection. Well there's really that much of a problem right.

00;10;28;14 - 00;10;31;01
Justin Kohler
Yeah. I mean yes eventually. But like is that our biggest problem.

00;10;31;02 - 00;10;48;29
Vlad Rotshteyn
And prioritize. So you need to understand like the same CV. It might be different on internet exposed asset versus an internal asset. But that's another thing you have to know and identify which of your assets are actually exposed. But you know, that's the whole you know, it's all about the visibility.

00;10;49;00 - 00;11;08;18
Jared Atkinson
Or on a user like a user workstation versus a server workload. Right. Something that like if I, you know, actually accidentally take down a individual users computer, not that big of a deal. If I take down a massive server that's working with customers and that becomes a bigger deal, right? So the I was on a podcast with somebody who works at a vulnerability management company, and they were I think it was false.

00;11;08;20 - 00;11;30;12
Jared Atkinson
But I think he was talking about this idea of, you're trying to drive the time to patching to zero, but you kind of have to rack and stack the different categories to, to your point of, of systems. Right. So it's like basically the time to patch on a user workstation should essentially be zero, because the like ramifications of that going wrong is, you know, not a substantial right.

00;11;30;13 - 00;11;49;25
Justin Kohler
But then you have other categories to where maybe you need to be a little bit more process oriented or just like, very simply like resetting a user's password could be really, really easy. But like, you know, the service account is a little bit like harder, you know, or especially like, like any type of non-human identity, like, gets into what is this thing used for, what is it supposed to do?

00;11;49;26 - 00;11;52;29
Justin Kohler
And then, like, how old is it? And who knows the answer to that question.

00;11;53;01 - 00;12;15;19
Vlad Rotshteyn
And. Right, exactly. And you know, and like going back to, you know, like in the data, like I'm now with, you know, the data that I have with like, you know, the tooling that I've done and the, you know, integrations and the programs that I'm running to give me, again, like the visibility from literally top down across all aspects of the attack surface, you know, it really does help me to tell the data story that I want.

00;12;15;20 - 00;12;27;10
Vlad Rotshteyn
Because again, like traditionally, it's like, you know, a like RB. And before we could even ask answer, are we want to something we need to understand whether we have any visibility to see.

00;12;27;11 - 00;12;28;19
Justin Kohler
If you are vulnerable or not.

00;12;28;21 - 00;12;51;21
Vlad Rotshteyn
Yeah. And you know, back to the quality question is going to be okay. Yeah. Like, you know, identify patches. But again like how are we assuring that koalas is actually covering everything that it's supposed to like, how do we know that there's no gaps in, you know, the covers like what is called essentially, you know. Yeah. Yeah. What is koalas scanning against.

00;12;51;28 - 00;13;14;02
Vlad Rotshteyn
And and how do we verify that it's not missing anything. Or what do we do if it does miss something. Like how do we plug in those gaps. So it's a gap coverage I think gap coverage is actually far more important than you know. Again traditional because because it's it's a data you want. It's a story you want, you want to tell with your data.

00;13;14;02 - 00;13;34;00
Vlad Rotshteyn
And you know, I think, you know, the the chills we have now. And, you know, I think also enterprises don't even realize right now that they need something like this. You know, they they think they have coverage, but they don't realize that, you know, they are missing stuff because, yeah, again, they're relying on, you know, disparate tools to do all their scanning.

00;13;34;00 - 00;13;41;29
Vlad Rotshteyn
But then again, with large enterprise, you can't do this where you need like a central plane of visibility.

00;13;42;01 - 00;13;56;12
Justin Kohler
And you mentioned you said attack surface management. And usually when I hear attack surface management, I think of like the scanners that hit the outside of a company. But like, just to be very clear, when you take when you're using the word tech service manager, you're talking about everything internal external identities, assets, everything.

00;13;56;13 - 00;14;19;15
Vlad Rotshteyn
So when I talk about what you were saying, you know, I had the you know, this explicitly the e to the end of an external attack surface map, which is, you know, that's that's, you know, anything that your company hosts on the internet via its, you know, preferred registrar. Yeah. Again, like, you know, if you have a physical site, you likely have Cidr blocks assigned to your network gear, your physical locations, your stuff like that.

00;14;19;15 - 00;14;42;16
Vlad Rotshteyn
So, you know, obviously, you know, you want to monitor that as well. So, you know, the way I look at it. So like domains that are essentially are hosted on behalf of your corporations that don't have direct connections into your actual infrastructure. So those are more so like you still want to monitor them, but, you know, those are more presented representational.

00;14;42;22 - 00;15;09;13
Vlad Rotshteyn
So let's say, you know, I have a situation of like a snail, a domain that somebody forgot about. And then, you know, it creates a situation where you have a dangling DNS, you know, somebody else forgets about it, and then, hey, I never gets released. And then somebody takes a somebody new takes over there, and hey, you know, one of your domains that you forgot about that you registered ten years ago is now, you know, redirecting you to some, you know, site or content that you don't want to see.

00;15;09;15 - 00;15;45;04
Vlad Rotshteyn
So that's a reputation then obviously you don't want to monitor your, your perimeter because you know, those those I might actually be your entry point because those are, you know, you could be where you are. You know, your your VPN appliances said your, you know, other entry points into the environment said. So you want to protect that. And then obviously, you know what's sitting on the internet where you want to protect as well, because that's, you know, you want to have make sure you have your security tool coverage, you know, your whatever your security stack is required should be running at a not or identifying where it's not running that you know, you need to

00;15;45;04 - 00;16;15;01
Vlad Rotshteyn
remediate it. Because also, you know, it's a lot of a lot of the, you know, tools. Also just these days they've consolidated information. So you know what used to be, you know, vulnerability scanning again by koalas is a lot of times a lot of these vendors have just incorporated into the product. So like now all these new or basically all the vendors that you know, have EDR functionalities by product of having EDR functionality is that they produce the same exact moment.

00;16;15;04 - 00;16;16;22
Justin Kohler
They have all the access to that.

00;16;16;27 - 00;16;33;23
Vlad Rotshteyn
Yeah, exactly. Because they vulnerable information. All it is, is just fingerprinting what you have essentially installed in your software. And that's, you know, you just get a software, you know, installed apps and match your CPUs and that's it. So it's not that hard to do anymore. And you know, if you ever need the rage, it's already enumerating your entire environment.

00;16;33;23 - 00;16;54;13
Vlad Rotshteyn
Then you're generating that thing. So it's, you know, again, as long as you're covered, as long as, you know, as long as you have the assurance that you're covered, then, you know, you could actually be able to then answer the question, are we vulnerable? And what are we going to do about it? Because then you have the context of, you know, whether it's internet exposed or not and actually help you play ties.

00;16;54;16 - 00;17;15;20
Justin Kohler
Do you? Maybe a very unfair question, but so similar to are we vulnerable? How do you answer the question of are we better today than we were yesterday or the month prior, or the quarter prior or the year prior? Like, like everything is always bad all at once. Like, how do you say that we are making progress, making progress versus not making progress.

00;17;15;22 - 00;17;43;16
Vlad Rotshteyn
Yeah. So that's where you're you got established baseline of what what good good looks like. Well and you know I always like to take the approach of before we even set the baseline about good. Good. Looks like let's clean up all our technical debt and let's clean up everything that we are seeing. That's bad now so that, you know, because it's a lot harder to detect anything not net new if you have stuff that's already existing.

00;17;43;21 - 00;17;56;24
Vlad Rotshteyn
Yeah. Basically, you know, in a perfect world, yeah. In a perfect world, you, you clean up all your tech that you get a clean baseline. And then going forward, anything net new is very easy to pick up because, hey, it's going to fall out and you'll get picked up really quickly.

00;17;56;24 - 00;18;22;16
Jared Atkinson
So on the on the attack path management side, we we often have customers that they have a concept. Let's say you have Active Directory coverage with with a BloodHound type tool. And you see kind of like what are the number of attack paths that we have to our critical infrastructure. One of the problems is, is that when you when you then add a new technology like Azure or GitHub or AWS, that number goes up, but it's not actually representative of a worse situation.

00;18;22;16 - 00;18;41;04
Jared Atkinson
It's representative to your point of better visibility. Right? Because now you actually are seeing that closer to the truth of what the actual actual situation is. And so there's kind of like this, this way that we try to measure to where it's like, what were the what were the attack paths that you had last quarter or maybe at the beginning of the quarter?

00;18;41;06 - 00;19;05;23
Jared Atkinson
And how did you how did you deal with just that subset of attack paths versus, you know, what attack paths did you discover as a result of better coverage over time? Right. So we're trying to like kind of measure we're trying to hold a static number of what we started with and how we're trying to attack that. But then we also are recognizing that the number might go up literally, but it's going up because of visibility, not because you're not making progress on reducing that that count.

00;19;05;24 - 00;19;24;09
Justin Kohler
Yeah. I've always had this like analogy of a bank account where it's like, if I started with $500 last month and now in my bank account, there's $100, right? You could see that, like I've only spent $400. But in the middle of that, I could have gotten a paycheck. And I, you know, I spent actually $2,000, but you didn't see that because that was like the visibility gap.

00;19;24;09 - 00;19;45;17
Justin Kohler
So like, that's what he's talking about. Like, you only want to see like, how did you spend that original $500? Not in in terms of increase visibility. I'm curious if you guys track like because like especially in like this AI age. Right. And I'm sure you're seeing like a spike probably initially of just like findings. I think that's generally like the industry at large is seeing that.

00;19;45;19 - 00;20;12;23
Justin Kohler
What do you then focus on if, if like previously if our run rate of issues was, let's say 100 and now all of a sudden it's 1000, then what do you focus on now? Do you focus on like a cycle time like like if for a critical issues that we confirm like to us are critical for reasons that are beyond just a CBE, do you just like, hey, our cycle time is really good still like we're looking at like five days or two days or whatever the the end.

00;20;12;26 - 00;20;21;26
Justin Kohler
Does that make sense to you? The cycle time. Like we have an issue and then we close it and like yeah, like I'm trying to say like in when everything's getting worse, what are you focus on.

00;20;21;29 - 00;20;47;26
Vlad Rotshteyn
Well yeah. So it's a team effort. So I like to say that I'm, you know, essentially just the messenger. So I run the tool. So I don't have entitlement to actually fix anything because also I, you know, my head would just exploded if I had to do even more work kind of thing. But yeah, like, I, you know, I'm the messenger and, you know, we we run the tools to surface the findings.

00;20;47;28 - 00;20;54;25
Vlad Rotshteyn
And, you know, we have a good partnership with our, you know, good teams that are actually responsible for it.

00;20;54;27 - 00;20;56;07
Justin Kohler
Yeah. For the different platform teams.

00;20;56;07 - 00;21;16;04
Vlad Rotshteyn
Right. So yeah, you know we meet regularly and you know they if anything they get notified. So yeah we you know we are we actively you know look at and manage and triage stuff. So yeah it's it's active observation. Yeah. We you know we don't let you know big stuffs like yeah.

00;21;16;05 - 00;21;35;05
Justin Kohler
Do you do you. So you mentioned like and I think most organizations are set up like this where it's like the the people doing exposure management like understanding like to your point like it's a full time job just to understand is everything covered. Forget about CV or issues or whatever. Do we have coverage over the things that we own?

00;21;35;09 - 00;21;52;23
Justin Kohler
And then once we find issues, how are we like prioritizing is right. But then there's usually like you're not unique in that. Usually the people who are doing that work do not have the power to push the button. Do you think that that's going to change like, oh, really?

00;21;52;25 - 00;22;08;25
Vlad Rotshteyn
Yeah. Okay. Because it really should be like, you know, like, you know, separation of duties because, yeah, it's I guess, you know, the larger because the larger the enterprise, the larger corporation you work for, and the more you have to know.

00;22;08;27 - 00;22;10;22
Justin Kohler
There's nuance to this.

00;22;10;25 - 00;22;31;18
Vlad Rotshteyn
To know about, like the business impact of like stuff. Yeah. Because look, I if I had the power to patch up, sure I'll patch everything. But then like if something breaks, I don't want to be the one responsible. Yeah. So like, yeah, again it's I'm, I'm already getting enough grief for, you know, surfacing problems. You know, like, I don't want him to cause any more by fixing the problems that I surface myself.

00;22;31;19 - 00;22;54;01
Jared Atkinson
You you talked about that federated model, right? So it's almost like the, the person that's doing that's making the change should be the person that's closest to the actual system that's being impacted. Right? Because then they they're the ones that most likely have the understanding of what like what the impact might be. Right. So like they can they can estimate what is the worst case scenario if this thing completely breaks.

00;22;54;02 - 00;23;07;19
Jared Atkinson
Right. What how would that cause an impact to the business? Like you, you're not going to know the details about every single system out there. But at the same time, they also can estimate probably the probability that it would cause, you know, something to go go wrong.

00;23;07;20 - 00;23;19;22
Vlad Rotshteyn
Yeah. And I have, you know, full sympathy for that because I was on that side of it before coming. You know, I was on the, you know, the receiving end of, you know, getting notifications. You know, that systems my, my assistant.

00;23;19;25 - 00;23;23;27
Justin Kohler
Security people that are like just fix it and you're like, wait, you don't understand the implication of that?

00;23;23;27 - 00;23;44;14
Vlad Rotshteyn
Yeah. So like I have, you know, your work a couple of times, you know, where like, hey, like, no, like you can't push a patch right now because, you know, this system has to be up because it's running a critical project or something. So, yeah, you know, you have to understand both sides. So that's why, you know, the larger the organization, I think the harder it is to, you know, be responsible for everything.

00;23;44;14 - 00;24;10;17
Vlad Rotshteyn
But also it just it's logistically impossible. So, you know, for the smaller, you know, shops, obviously, you know, you have one person wearing a million hats. Totally. I mean, I still feel like I wear a million hats, but it's all just security, like tooling and security output related. Not necessarily, you know, remitting the output. Like if I, if I see something critical of actually needs to be remediated, like I have my escalation paths to the business, but not necessarily something that I have the entitlement to.

00;24;10;18 - 00;24;11;07
Vlad Rotshteyn
I don't know.

00;24;11;07 - 00;24;30;27
Jared Atkinson
If it's an an interesting thing that you alluded to, and I don't know if you're doing anything like this, but the cool thing about having the the integrated attack surface management or exposure management kind of capability with something like BloodHound with attack path management, is that when we think about BloodHound, we think about how do we produce findings just from this picture of the attack pass.

00;24;30;28 - 00;24;49;08
Jared Atkinson
Right. But there's this really cool integration to where you could start to use that as a prioritization tool. Like I think about I'm a detection engineering type guy. So I think about it as when I have alerts, how do I use the graph context to then help me to prioritize alerts. But for when you talk about vulnerabilities, kind of the other side of that coin to where it's like, I have a bunch of vulnerability.

00;24;49;08 - 00;25;05;27
Jared Atkinson
You talked about this idea that there was you could have the same vulnerability in two different places, but it's the context that actually matters, right? So it's an example would be I have a CV on two systems, the same CV. And so from like a pure kind of in a vacuum perspective, as you mentioned, they appear to be the same priority.

00;25;05;27 - 00;25;20;28
Jared Atkinson
But then you say this one, if it's exploited there's an attack path to tier zero. But in this other one there's no attack paths that even leave that machine. Then obviously you have a different perspective or you have a better, more holistic picture of how you should be prioritized. And that seems seems useful.

00;25;20;29 - 00;25;43;00
Vlad Rotshteyn
Yeah. No, certainly a chaining. Obviously chaining is what it's all about. Like, you know, here to here to here and then you're in. Yeah. And you know of course, you know BloodHound just in addition to the stuff that BloodHound generates I mean, BloodHound collects all this other information that is not, you know, that's not generated for the attack paths.

00;25;43;00 - 00;26;09;22
Vlad Rotshteyn
That is just really useful. So I think your privilege collection is just, I think, underrated in what it is able to surface. So, you know, the ability to quickly see who's a local admin to what machine, I think is very underappreciated. And I appreciate it a lot. Yeah.

00;26;09;23 - 00;26;31;26
Jared Atkinson
We we kind of call that the connective tissue because it is a it is a huge pain in the butt for people to like get that collection going because you have to you have to grant access to individual systems, for instance. Right. And so unprivileged collection is gives you the big picture. It gives you like the skeleton. But then you once you get the the privilege collection, you have sessions, you have local admins, you have local groups.

00;26;31;26 - 00;26;45;03
Jared Atkinson
And you start to be able to see how these things are connected in a different way. And it's like a, you know, it could look bad with just the unprivileged. But once you get the once you get the privilege collection, now you have a much better picture of what's actually happening in the environment. It's like it becomes alive.

00;26;45;05 - 00;27;06;01
Vlad Rotshteyn
Yeah, it's it's goes back to the data, you know, feed me that and let me tell the story with my data. But the more that I have, the clearer picture I'm able to tell. Yeah, yeah. You know, I'm working with my, you know, partners to also, you know, enhance the information that I get from BloodHound to help me run my, you know, program as well to really give me the insights.

00;27;06;04 - 00;27;19;04
Vlad Rotshteyn
You know, again, not only from the findings that it's generated, but from, you know, this extra, this privilege collection as well, that I'm able to layer on top of stuff that I need to prioritize as well. So really useful information.

00;27;19;10 - 00;27;37;01
Justin Kohler
That was bananas when I first for first heard about the fact that I had to have somebody explain this to me like four different times because I did not believe it, I was like, hold on. The domain controller does not have that information, but everything's on the domain. It just like it doesn't compute. It doesn't seem like it should function that way.

00;27;37;01 - 00;27;49;26
Justin Kohler
And without that kind of visibility, it's like how the how would you do this without it? Like, how would you how how would you ever get a true picture if you can't see the inside of a machine and like the like members of local groups or sessions.

00;27;49;26 - 00;27;49;29
Vlad Rotshteyn
Or.

00;27;49;29 - 00;27;50;10
Justin Kohler
Something like.

00;27;50;10 - 00;27;50;29
Vlad Rotshteyn
That.

00;27;51;02 - 00;27;51;29
Justin Kohler
Completely blind.

00;27;52;01 - 00;28;16;08
Vlad Rotshteyn
And even the full picture, like, no, I'm able to see both the direct, you know, any aid groups or any of the users that are directly assigned to, you know, local admins or, or nested groups or like, or just groups and then people nested within groups that have access as well. So that yeah, that visibility and insight has been really amazing.

00;28;16;10 - 00;28;39;29
Justin Kohler
I mean, we were talking about this yesterday with agent ID, like, so we just released like beta coverage for Azure Agent ID. And the way that Hope was talking about, it's like you got to page through all these different pages in Azure to understand all of this, where we just stitch it together in the graph. And I think it's going to be funny, like looking back on it, the way that we're talking about privilege collection is going to be the way that we think about, like all of these open graph extensions, like, how could you have done this without this kind of visibility?

00;28;40;00 - 00;28;55;19
Justin Kohler
It like, doesn't make sense. Like you're kind of like flying half blind. That's why I think not only are we excited about the opportunity to like, see the inside, but it's like you almost it's it's required. Like you have to have this visibility. Otherwise you're just like, guessing where your biggest problem is.

00;28;55;20 - 00;29;18;22
Vlad Rotshteyn
Yeah. And of course and but with the caveat also that, you know, BloodHound is, you know, could only see as far as it could scan. So, you know, the coverage extends to only things on the network. So and then and then like if you need I guess more coverage for like, you know, your laptop and stuff, then you got to rely on like other tools that might be on there that might surface this information.

00;29;18;27 - 00;29;22;28
Vlad Rotshteyn
But again, but for for the most part, you know, if it's on a network, yeah I'll know.

00;29;23;03 - 00;29;32;26
Justin Kohler
So and that's that's actually what like so you're talking about the privileged collection for like let's say somebody work from home. Right. We're not going to enumerate through VPN like you can.

00;29;32;28 - 00;29;35;15
Vlad Rotshteyn
But like if they come into the office I'll hit them.

00;29;35;16 - 00;29;54;00
Justin Kohler
Or that's also what we're trying to do with like other integrations. So like you mentioned the EDR right. The EDR is already on there. It already has visibility to that stuff. We can just pull it straight from your EDR. So there's like there's integrations that were hopefully very announcing very, very soon for like major EDR providers just getting through the final publishing stage.

00;29;54;00 - 00;30;12;12
Justin Kohler
But it's exactly that. It's just like you don't even need to scan for it anymore. Just rip it from the EDR because you're already hosting that information. A lot of people will store that stuff in Sims as well, right? So like not so much local groups but like logins. Yeah, exactly. So like 4624 is in Splunk or Sentinel or.

00;30;12;14 - 00;30;28;25
Vlad Rotshteyn
Stuff like that. And again you know that's so all of that is great for again you know anything net new like any new detections but all of your legacy debt that you didn't. Again stuff that you didn't know about is not going to be picked up. But now that you have the ability to scan for it, now you'll know about it.

00;30;28;25 - 00;30;45;20
Vlad Rotshteyn
And now you can clean it up and again, you know. And now, like, if you could now set up rules that be like, hey, if it ever pops up again, now you'll be prepared. Because now you could even like target groups, you might want to monitor and stuff like that. So you really just useful insights that, you know, it's data.

00;30;45;20 - 00;30;57;03
Vlad Rotshteyn
That alone might not be super useful. But again, if you layer with other data points, it becomes, you know, really correlated and really actionable and really gives you the full picture of what you should be doing.

00;30;57;10 - 00;31;18;20
Justin Kohler
Well, we've covered a lot, right? Like your entrance from like it to security, kind of like how you think about exposure management and attack service management. What are you kind of looking at next? Like what? Like at especially here at Black Hat. What's the thing that's like, is it just more of the same like especially with like I mean, you can't throw a rock and not hear AI in the vendor hall here, right?

00;31;18;21 - 00;31;27;21
Justin Kohler
But like, what are you like most excited to learn about it? Terrified to work on like, I guess what's what's your focus.

00;31;27;28 - 00;31;59;29
Vlad Rotshteyn
So let's talk about AI. So, my perspective on AI is it's, you know, it's a tool, but you you have to know what you're doing. And again, I'm going to go back to the data. You have to understand what it is you're trying to do. And I feel like people, you know, assume that AI, I guess, holds it almost like almost holds their hand more than it should because, you know, they don't understand.

00;32;00;02 - 00;32;21;11
Vlad Rotshteyn
Again, you have to know what you're prompting, what you're trying to get out of it by by your prompt, and also knowing how to validate what it gives you. Because, you know, everyone knows that, hey, AI can make mistakes. It's written everywhere. So and that is really the fundamental part of it. Like I, I find, you know, AI you know Claude code super, super useful.

00;32;21;13 - 00;32;48;28
Vlad Rotshteyn
You know, I made it I had some had Claude write me some scripts to do some targeted extractions from the BloodHound API. But again, like, I know the platform really well. I know. And also, you know, you have to know what to ask because, you know, your API is published, but also the the cipher query, the it's different than like the because it has like some variations.

00;32;48;28 - 00;33;11;01
Vlad Rotshteyn
So basically I was like, hey Claude, here's the BloodHound API. And then, you know, here's I actually went to the cipher queries page. I'm like here, this example of what you need to do to make it work for enterprise and like it worked then had, you know, first like you have to first iterate like, hey, like, you know, let's start building.

00;33;11;01 - 00;33;31;15
Vlad Rotshteyn
But first let me see if I could even establish an API connection. Let me do a successful law. So, you know, that's the first stage of the build that worked. And then we could proceed with iterating. But again you need to understand the you need to understand the product. I need to understand the end to end thing of what you're trying to accomplish, because otherwise, you know, you won't be able to differentiate, you know, garbage in, garbage out.

00;33;31;20 - 00;33;32;00
Justin Kohler
Yeah.

00;33;32;02 - 00;33;32;17
Vlad Rotshteyn
Well.

00;33;32;20 - 00;33;51;07
Justin Kohler
Yeah, it's like writing a it somebody I think you were you explain this to me one time and it like really stuck in my head. It's like you can write a Splunk query that would return data, but are you writing the query that you think you're writing? Yeah, it's a lossy it's a lousy process when you. So you have this idea in your head about the question that you want to ask.

00;33;51;07 - 00;34;07;10
Jared Atkinson
We get use BloodHound as an example. So you have let's say you want to check whether or not there's some certain configuration that's happening. Right. And you you want to say the cool thing about BloodHound is you have this gigantic database and you can say, show me all the instances of this, but you have to convert that from what's in your head to verbal right.

00;34;07;10 - 00;34;16;12
Jared Atkinson
So you have to be able to like, just verbally express what is the thing that I'm trying to do. And then the additional step is you have to convert it from whatever your verbal description is to whatever the query is. And so.

00;34;16;12 - 00;34;17;08
Vlad Rotshteyn
There's the confines of the.

00;34;17;08 - 00;34;35;02
Jared Atkinson
API and there's, there's always going to be some amount of loss or like variation between what's in your head and what you say. And then there's going to be some variation between what you say and what you actually write as the query. And so you don't necessarily know that just because it return true or return results. Those results are actually the thing that you initially were hoping for.

00;34;35;03 - 00;34;51;07
Vlad Rotshteyn
And it's kind of like you could take it back to like, you know, the old age, you know, it joke kind of like, you know, it's about tech support. So, you know, the old joke is like, I know about it is a computer problem. Kind of like I know about the problem as much as you do. I just know how to use Google better.

00;34;51;08 - 00;34;51;26
Jared Atkinson
Yeah, yeah.

00;34;51;29 - 00;35;18;02
Vlad Rotshteyn
So again, it's I think it's a lost art of knowing actually, how to ask for the right information that you're looking for and applying critical thinking to understanding whether what you're returning is correct or not. So I think that is really AI as itself, as a height. Without going back to these fundamentals that I just talked about of like, you know, knowing how to use it, because if you don't know how to use it, it's, you know, useless.

00;35;18;04 - 00;35;20;18
Vlad Rotshteyn
Yeah, it's all hype. Otherwise.

00;35;20;20 - 00;35;26;26
Justin Kohler
Well, anything that we didn't cover, I think we're good. We appreciate you. Do you have anything that you want to kind of give us your final thoughts?

00;35;27;00 - 00;35;47;08
Vlad Rotshteyn
What? I mean, this is great. Look, I'm. I love what you guys are doing. I love, you know, the the security field. You know, everyone's moving fast, and you know, everyone. Look, AI certainly has the ability to break stuff, and it's already breaking stuff. But also, you know what? We we got to stay ahead of it. But, you know, we we need to be able to see what we need to protect.

00;35;47;09 - 00;35;59;07
Vlad Rotshteyn
I mean, that's really the bottom line. And look, AI is not going to solve your basic hygiene issues. And that's something that's still, you know, before you get into AI, you know, get your house in order first kind of thing.

00;35;59;10 - 00;36;09;15
Jared Atkinson
Yeah. Awesome. Thank you for joining us. And we'll see you have a good time at Defcon. Thank you. All right, all right. Thank you. Thanks, guys.

00;36;09;17 - 00;36;11;05
Vlad Rotshteyn
All right. Good job.

00;36;11;08 - 00;36;13;02
Jared Atkinson
Yeah, dude. Yeah. Good job, good job.

00;36;13;08 - 00;36;13;27
Vlad Rotshteyn
I think.