Risky Business - Snake Oilers: watchTowr, XBOW and CoreView
Episode Date: September 11, 2026In this edition of the Snake Oilers podcast three vendors stop by to pitch the audience on their products: watchTowr: We’re all familiar with watchTowr’s researc...h, but what do they actually do? XBOW: The AI pentesting company pitches its approach CoreView: Your M365 tenant is probably a security disaster. Tame it with CoreView! This episode is also available on YouTube. Show notes
Transcript
Discussion (0)
Hey everyone and welcome to this snake oilers edition of the risky business podcast. My name's Patrick Gray.
For those of you who don't know what a snake oilers podcast is, that's when we get a bunch of vendors to come along and pitch you all their products.
They pay to be here. This is a wholly sponsored podcast. But yeah, we've got three vendors you're going to hear from today.
And they are pitching very interesting products, in my opinion. First up, we're going to hear from Ben Harris, who is the founder of Watchtower.
and a lot of you out there would know Watchtower because they publish really great security research,
often with very funny blogs and whatnot.
They clearly know what they're doing.
But as much as I know their name and I've read their blogs,
I didn't actually know what Watchtower did until we recorded this segment.
So, well, until they approached us about recording a segment.
So, yeah, if you too want to know what Watchtower does, you're going to find out in just a minute.
Then we're going to be hearing from Federe Kershberm, who is the head of the security labs
at Expo. And Expo, of course, is that AI pen testing agent that first became really well known
because it was climbing the rankings on like Hacker 1 and all the bug bounty programs and
whatnot, which, you know, for an AI agent to do that at the time, obviously created a big buzz.
So FedE, we'll be along shortly to explain to us exactly what Expo does. And, you know,
at least at the moment, they're focusing very heavily on web application security testing.
So that is an interesting chat.
FedE also was the original co-founder of Echo Party, the Latin American conference.
I actually met him.
We realized that we met a very long time ago in Vegas.
So there you go, just one of those things that happens, I guess, when you've been floating
around the industry long enough.
And then finally, today we're going to hear from Andrew McAllister, who works for Coreview
here in Australia.
Corview makes a platform that does M365 security.
Of course, M365 is a very complicated platform.
It's got a lot of bells, whistles, knobs and dials.
And, you know, the odds of your M365 tenant being appropriately and properly secured and, you know, put together without you having gone through some sort of exercise.
I'm going to just go ahead and guess that's pretty low.
So Corview, they make a platform that really helps with that.
So Andrew comes along in the third slot this week to pitch Corview.
And big thanks, too, to Corvue's Australia team for booking this.
They do have a substantial team here in Australia.
So yeah, it's good to have an Australian voice.
In this snake oilers edition.
But yes, first up, let's chat with Ben Harris, who is the founder of Watchtower.
Watchtower published just terrific research blog posts about vulnerabilities that they've found
or tear downs on other stuff that they've come across.
Really good stuff.
But I didn't actually know what it is that they do.
And it turns out that really what they do these days is they help their customers
to be able to apply detections and preventions for bugs,
I guess, before those customers can patch them, right?
So they can do really rapid mitigation of certain vulnerabilities at the border
for their clients by helping them spin up detections and preventions.
It's going to make more sense when Ben explains it.
So I'll drop you in here now where Ben Harris explains what it is that Watchtower actually does.
Enjoy.
We build tech that helps organizations and the services.
understand how they're exposed to emerging threats.
Effectively, we have three core pillars in the business.
We have an Intel team, our pre-empt capabilities.
That team is hyper-focused on using our global Honeypot network
to understand what attacks are doing right now,
would it be emerging threats,
end-day, zero-day exploitation,
post-exploitation behaviors because we build root kits
to jailbreak lovely appliances,
all the way through to building algorithms
to allow us to kind of predict
what's likely to receive in one exploitation yet.
We then use that capability to then inform
client exposure. So we have recon engines,
what does organization A look like on the internet.
We have red teaming automations
and hours to basically work out how we break in.
And then we wrap that around and of course what we call
our rapid reaction process. So our ability to go
from disclosure or
hint of an emerging threat to telling
an organization if they're exposed and validate
that exposure within hours.
Of course, one thing we've launched recently
is our mitigation capability. Given how
quickly in the wild exploitation now happens, we're
talking single digit hours. Because
we've become, I think, well,
well, used to kind of reproducing vulnerabilities that scale very quickly,
especially now with the advent of AI, we can flip reproduction, so POCs,
into Waf rules, IDS, IPS, IPS rules, and ultimately then push those automatically once we actually
find a vulnerable VPN or mail server or similar.
So ultimately, our job...
Pushing a rapid detection is going to be less...
Look, it's not always going to be reliable, but it's always going to be less risky than
pushing an emergency patch, right?
I'm guessing that's the appeal for a lot of people there, right?
Exactly.
And I think that the reality is that as much as we want to go faster,
patching is not a big red button that we just kind of hit very quickly.
It's a process, especially for regulated organizations or large organizations,
they can't just yellow patch, right?
So our aim is to basically sandbag.
If we can make it harder to exploit a particular system in that first exploitation wave,
we buy those teams times they can go and do remediation properly
in their own kind of terms on their own kind of timelines.
it would probably make sense at this point to describe what sort of technologies you're doing this for
like you know obviously people are giving you money to mitigate vulnerabilities in classes of products
what products are they that they are most concerned about that they're they're giving you budget
to help mitigate so i think if you know if we talked about it kind of 12 months ago i think we'd have
the kind of big hits of dpn remote access solutions all the way to kind of like management
solutions of environments through to mail service effectively all the things that we tell
people don't expose to the internet, but for some reason they just keep doing. And of course,
I think given kind of what's changed in the last six months, that's now rapidly expanded.
The reality is that now everything's being exploited, whether it's kind of easy or hard because
LMs are lowering the bar for, I think, for sophistication needed. So where I think historically we'd
see in the big concern around, you know, those typical legacy enterprise solutions that we pay lots
of money for, that has broadened quite significantly, I'd suggest at this point. So right, so it was like
the 40 net Palo Alto VPN Concentrator problem was what you were solving. And now you're trying
to solve like the everything problem because everything's getting owned because now all it takes is for
someone to use an LLM to say, oh, well, I've just found this thing on the edge of a network that looks
pretty crusty that I've never heard of. Can you please develop an exploit for it? And some open
weights model says, yeah, okay, here you go. Exactly. I mean, literally that. And of course,
I think we've all seen the kind of drama in the last kind of couple of months. It's not going to
get better. Right. And the reality is that teams have struggled to reduce what they
exposed to the internet for the last 10 years. They're not going to suddenly figure out.
now. So if we can use existing security controls to kind of, again, just kind of stem the bleeding,
like a bit of a phrase, like then they get the times carry on their process while we kind of
adapt to this new reality. Now, you just touched on something very briefly at the intro there,
which I thought was actually very interesting, right? So I want to pick you up on it.
Because, you know, you're just, it's like when someone mentioned, oh yeah, and we do this little
thing, which I know is really hard, you know, really hard and a lot of work. And I'm like, okay,
that was a weird thing to gloss over. But you said that you actually, um, like,
reverse engineer some of these appliances and I'm guessing that is the 40s and the and the
and the and whatever and you can actually get access to the firmware which means that you can see
what attackers are doing on them you know in these in these honey pots is that is that about right
like you act is that actually how you're able to get some insight into TTPs once attackers are
actually like popping shell on those devices it's a great question and I think it this is really
interesting so let me can we give some backgrounds I think backgrounds kind of kind of explains a lot of why we went on
this path. A big part of us reproducing vulnerabilities, right, is getting access different versions
of appliance A, right, and being able to diff them, work out what's changed between patch and
unpatched. Now, of course, that means we have to jail break, crack open some of these appliances,
because they don't want you to kind of go through them. As I said, you glossed over that part,
and I know that that's not that easy. Like, it's doable, but it's work, right? So I'm like, okay,
well, you're doing it for a reason. Correct, correct. And so we were going through this process
every time. And basically it added time to the amount of time we need to rapidly react
to emerging threat, because sometimes we play cat and mouse with certain vendors who would try and, you
know, break ways to jailbreak their appliances. And we kind of came to conclusion at one point and kind of
went, okay, this is actually really annoying now and taking too much time. And one of our
very uniquely skilled researchers, Alice, decided to build what we call Stab. So Stab is effectively
our in-memory kernel back door. We can inject via a hypervisor into a VM that gives us a
shell on most appliances at this point, even when, fortunate, do very strange things with
their kernels, but ultimately means that we can skip that entire reverse engineering process,
that jailbreak process at scale. Now, we then, one day woke up and went, vendors aren't giving
telemetry from these devices or these appliances, but people are getting popped constantly.
EDR can't be deployed at this point because they have locked them down. How about we take these
appliances, load stab onto them, load our own EDR. So they look like real appliances, they are real
appliances to as a honey pot for intensive purposes, but we then get pre-post exploitation artifacts.
And exactly to your point, we get all the telemetry then for ODA exploitation.
That's pretty useful, really, isn't it? I mean, you know, you're collecting all of those
TTPs. I imagine you're collecting things like, you know, C2 as an IOC and whatever. And like,
you know, that's just going to be, that's just going to be pretty handy. And then, what,
you got some thread intel people who pull some threads there? Yes. So, so, I mean,
the big theme, and we've been told us now for like maybe 18 months, we know attacks are getting
it faster and faster to exploit vulnerabilities. They've been becoming a little bit more sophisticated
around this, but the TLDR is they pop appliances very, very quickly, they backdoor them,
sysadmin rushes in, patches them as fast as they can, machine is now patched, backdoor, of course,
persists, they're still popped. And so our challenge was we can identify exposure and like
vulnerability, but we can't actually then work out for someone that you came in. So by putting
telemetry and artifacts off those honey pots, like you mentioned, we can then effectively work out
where the web shells are being dropped.
Can we see if they're patched but actually still backdoored?
And that's been an incredibly useful.
So you can build a remote detection, right?
So if you've actually seen what they're dropping on it,
you can then go and probe your customers and see which ones.
Okay, that makes sense.
I can absolutely see why someone would pay money for that.
100%.
The other side of this, though, is that there's, you know,
you mentioned that there's like this WAF component to it, right?
Is this a watchtower developed WAF that goes in front of an organization's applications,
or are you just providing rules for existing WAFs?
Like, how does that work?
So the big thing for us with mitigation at this point is that the challenge around remediation
and kind of moving these things in is stability, availability, change controls, right?
We don't want to start implementing new technology and new products into things because that
kind of defeats the point.
So we integrate directly into enterprise-grade WAFSI, your CLAREFRAs, your ACMI, your CLAREFERS,
etc.
The value of what we do, though, is the speed to generate those WAFORs, right?
If we can generate them within 30 minutes of availability becoming, you know, known before
exploitation begins. If someone else can produce that same rule two days later, it's fairly used
at that point from the exploitation perspective. So again, it's our speed and our ability to deploy that
that becomes, we think, very, very powerful. So this stuff, I imagine, is a product and sort of thread
intel feed for the top end of town, the sort of organizations that actually have the,
you know, have wafts and stuff in the first place, right? Which is going to be your bigger orgs.
Correct, correct. So we see ourselves as that always on Red Team, trying to constantly break in and
then mitigate what we find. So yeah, your series typically within government environments, Fortune 10,
50, 100, BFSI, crystal infrastructure, that's where we're typically kind of called in, because the
reality is we are designed to help with a threat that's very aggressive, very persistent. It's just
those kind of those kind of same characteristics are now flowing into every man, dog within L&M and
more. Now, you mentioned too a couple times that's come up that you do research, you find your own
O'Day, right? And then you can mitigate O'Day, why, you know, then you go off and patch it to the vendor.
you're not the only company that does this.
You know, I mean, look, people have been doing this forever, right?
I've always questioned the utility of it.
When there's people actually out there using exploits in the wild that you have to mitigate,
you do that, right?
So there's obviously a great deal of value there.
And I can see that the research that you do is awesome marketing.
I mean, we're always talking about it on the news podcast,
mostly because you guys write really funny blog posts and it's great research.
But like, how much is that pushing the ball forward, right?
Really, apart from like being a good time and getting your name,
into like the media. Like how useful is it to have you guys finding bugs that might otherwise be
undiscovered, you know, and then mitigating them? Like, how does that work? So, so I think the
world has changed quite significantly. So my view used to be that it's our job to understand what
client exposure looks like, client attacks have just looked like, see what's going to be
targeted by attackers or has historically been targeted. And it actually helped them preempt for what's
going to be very clearly coming next. And that, honestly, we believe, really made a material difference.
And I think, again, we went on a bit of a rampage with regards to what we think the challenge
looks like in the industry at this point and how we think at least things should hopefully
improve.
What I think has massively changed now as a reality that we can't wait for disclosure vulnerabilities,
we can't wait for information to leak because you've got people with LLMs who won't
go through the disclosure process for vulnerabilities.
And so what we've effectively now done is orchestrated and kind of scaled that research
process.
So instead of lots of researchers, we now are using researchers that are fueling our internal
kind of harnesses.
we reproduce vulnerabilities at scale based on the tech.
So the tech that we see our clients using,
it means that we can effectively again
keep getting further and further ahead of what attacks are likely to do.
No, no, this makes, look, this makes a lot of sense
because what you want to do is every time a new model drops,
you want to throw your harness at it
because that's what everyone else is doing as well,
including malicious types.
They're going to go figure it out.
I mean, what you're doing is you're finding the bugs
that are going to come out of that new model
with a one shot, which is what everybody's doing
and then you want to get those mitigation.
That makes a lot of sense.
That's a smart idea.
So the big thing for us right now as well is that being able to find ways into organizations,
we feel is just not enough anymore, right?
It's one thing to say, look at me, I've got this end day or oh day, et cetera.
It doesn't feel like it's actually helping when teams have got just more holes in the shit
than they've ever had before, right?
If we can now help mitigate as well, it goes from being, to your point, you know,
sometimes a little bit performative through to actually making a difference to actually help
organizations defend themselves.
And again, in a world where things are moving so quickly, we feel that we have an impact,
if that makes sense.
It sure does. All right, Ben Harris. Thank you so much for joining us for explaining to it and explaining to us what Watchtower actually does. As I say, it's a company that we've spoken about thanks to your research so many times on the regular show. So jumped at the chance. I jumped at the chance to bring someone along to actually explain it. A real pleasure to chat to you. Thank you. Thank you. Thank you for your time. Appreciate it.
That was Ben Harris there from Watchtower. Big thanks to him for that. And yeah, I'm glad I'm
I finally know what it is that they actually do. So now we're going to hear from Federer Kershbaum,
who is the head of the security lab over at Expo. And Expo made a big splash early on
through the whole AI revolution because they had put together a pen testing agent that was
really doing well on the bug bounty rankings, right? So it was like actually,
leading the rankings, I believe, at like Hacker 1 for a while, which really, you know, caused
quite a stir. So, you know, I thought it would be good to get these guys on the show and find
out exactly what it is that they're selling, you know, how it all works. And yeah, that's what
Federer joined us to talk about. So here he is explaining to you all what Expo is and what it does.
Enjoy. Expo, it's, you're right. It's an autonomous AI pentester. We are focusing
mainly on application security vulnerabilities.
We are trying to make findings and discovery
something that can be made autonomously
and produce exploits rather than vulnerabilities.
We care about outcomes, not just a long list of problems.
So, yeah, Expo, if you have to think about it,
It is an AI take on finding and exploiting vulnerabilities.
That's interesting, right?
Because we've seen other off-sec, like, you know, Clankar Offsec startups, right?
They're going after things like, you know, how to get domain admin or how to, you know,
get into a corporate environment, whereas what you're saying is like this is very much
application security focus, very much like web application security focused.
Currently, we are trying to focus on what most companies are developing and
exposing. I think infrastructure is super interesting. There are a number of companies that are trying to
tackle that. But I think what Expo is special, it is trying to audit custom apps. And it's not only
trying to find what's unique from your app, but it's also trying to actually exploit them.
And in a way, there are not many playbooks for that. It is how you can build that instinct, that
adversarial mindset and understand based on different rules and strategies.
Hey, is this interesting?
Can I mix it with other findings?
Oh, I can change stuff?
So for us, it is how we can synthesize the same questions we would do to build the tools
that would find the bone and then exploit it.
So, yeah, I think we're mainly focuses in how we would do not only pet testing, but
vulnerability research in general.
Yeah, I mean, I think one thing that I've discovered about these LLMs, having just studied them a lot, I guess, is that they're really good at reading the manual, which is, if you know hackers, right?
You've been around hackers long enough.
This is their superpower a lot of the time is they read the manual, they read a lot about how to do stuff.
And that's one thing the machines are very good at doing, is just reading a lot and sort of knowing where to go.
So, you know, what we used to think of as like some sort of, you know, superpower ability just to see things that other people don't.
I mean, really, it comes down to the fact that you know a lot more about how computers work because you've read the manual and the machines are good at that, right?
So it sort of eroded that superpower in the humans a little bit, hasn't it?
I think what I was trying to share in hacking in general, it is, you know, it's people that spend a bit more of time trying to, you know,
troubleshoot and then they know the limits and they know how they work and I don't
know how many people actually knows a WS documentation in a full but I know an LLM does
yeah I mean this is this is the point I'm getting at right is they read the
manual you know I jokingly like to say to some and this is like pre-LLMs I
had a kind of a way of telling pentesters about penetration pasting you know
when all these cheat sheets came out and people
just copy and paste comments out and see what was happening on the other end.
And for some, that was fantastic.
And in fact, they were half true.
But I think the challenge is when you were off script and what made some companies or some individuals find unique stuff
and not just run-of-the-mill findings.
So I find pen testing that has been commoditized for sure.
and I think everyone who has been in the pen test industry has a same love and hate.
But I think we're in this unique time that you said it.
You know, basic bones that are on the animal can be detected and can be removed,
but also a bit more complicated that require breeding the mantle to exploit.
It is a great moment for doing that right now.
Well, I mean, I think we should celebrate.
You know, people talk about the commoditization.
of pen testing like it's a bad thing. I mean, it's a terrific thing when you think about it,
because it makes it available to more people. Once it becomes commodity, once it's not a highly
paid specialist discipline, I mean, look, you're always going to need human pen testers to go that
extra mile or even to scope things with the LLMs, like, you know, my colleague James Wilson is
doing a lot of vulnerability research at the moment using LLMs. And, you know, he has to whip these
things around to get them to do what he says, because they'll come back to him and say,
oh there's no way to go further with this
and he's like yes there is keep going
it'll you know convincing these things to keep going
because of his knowledge right
so there's always going to be people who need to do
you know human beings are always going to be needed here
but I guess what this means is the
baseline for what we can automate has gone up
substantially and it looks like
you know in the case of Exbo
you're really trying to apply that to web application testing
and I imagine it really is the case
where you give it you know some guidance on how to
poke, you know, through your harness on how to poke at an application, and it's got the
flexibility, because it's an LLM, to know that when I get this sort of response, hey, there might
be something interesting down there.
I mean, that's pretty much what the product is, right?
I'm guessing Expo is basically just the harness.
I'm guessing the models are you probably using multiple, but why don't you tell me?
Like, what is the actual, you know, architecture of the product?
Don't get wrong.
I love seeing, you know, that reverse engineering on how it should be.
And you're right. So Expo, it is a harness. You're right. We call it like a mix between the brain and the body. Body being the harness. So, hey, how can you use tools? How can you interpret output? And the brain, it is a mix of models. And we normally try sharing which models are we using and which models are, you know, useful for. Each model has its own personality. Some are a bit more aggressive.
Some are more cautious.
Some are great at source code, but are really bad interacting with a life site.
So I'll start with the beginning, which was actually when it started, most people thought LMs were not good for cyber, right?
And it seems like a long time ago, but it wasn't.
It was like a year and a half.
And that's when we got number one on Hacker Well.
competing with real humans.
But in order to understand the process, it is,
hey, how can you find a vulnerability and how you can confirm it?
And I think that's the thesis of Expo,
trying to identify a problem,
seeing in the context of the application if it has any use,
and trying to understand its impact.
Like, if you have a SQL injection,
it's not just about getting a sleep timer,
timer, but rather, hey, can I read something? Can this be used to extract the token and then
log myself in or craft a cookie? So when we think about Expo, it's which questions are best
answer with which brain and what are our body? So it's a harness and a router, right? That's cool.
You know, it's really interesting. And like, do you have an LLM, do you have a model which is driving
the router as well? Or how does that work?
So we have what we call a coordinator, and that coordinator tries to manage our solvers.
Our solvers are agents that have hyper-focused, and they have one task and one task only.
One of our distinguished engineers, Brendan, gave a talk a few days ago about how we prompt these solvers to get the problems, you know, get them as much as they can.
and just trying to force them into finding something that we don't know if they are there.
By the way, Expo works at runtime. We work in a black box approach. You can give credentials,
you can provide source code, but our native approach, it's blackbox. So give us a URL and we'll
take the rest. But yeah, we have a coordinator and each of these agents have specific vulnerabilities that are
trying to find and all those findings get into a bigger context and if one of these agents see that
one of the outputs of these agents are useful they can chain that thought together and yeah
exploit it's amazing that this is basically how a pen test team works right where you've got this guy
over here he's really good at stringing together java gadgets right so like there's a deserialization
thing hey fred you know hey sarah come over here i need some help you know and
And it seems like it's the same thing, but you're just using like multiple agents instead,
but they're still specialized like people are.
Yeah.
Our team is quite diverse.
We have people that have spent 30 years in the offensive side of things.
Some people are newcomers, but they went really well on back bounty programs.
So I think the mindset or these sort of agents that we're building have their unique personalities
and their unique traits.
You mentioned, you know, deserialization.
So, Alberto Munoz, which was one of the biggest implementers of, you know, WISO serial, for example, and it leads the offensive capabilities team.
So for me, it's impressive because it's not only about finding the problem and exploited, but also see the reasoning and judgment on how and when it does something.
And there are things that the tradecraft is not really human.
It's not that they're super smart, but they're persistent and they try every single option.
So it's interesting, like watching somebody work over the shoulder.
Which is, in my view, I think pen testing, vulnerability scanning, web application security scanning, you know, black box style.
Is this all collapsing into one thing, is my question.
What do you think?
I think we are going to become the pen testing, what I call pen testing at least, the validation layer, where we can grab information, ask the right questions and go to the right asset and actually.
asked that question. Hey, is this model? Yes, no. And if it is, prove it. So I think we're
becoming that sort of transformation between all the noise and start providing some signal.
All right, well, Fedé Kirchbaum. Thank you so much for joining me to talk all about Expo. I mean,
I remember watching Expo rocket up those charts. And I think initially me like others was like,
they're just automating like a bunch of like not so important things and you know just reporting them at scale
and then I sort of thought well hang on that's what a lot of people are sort of a lot of humans who do bug bounties are doing and then you just saw it consistently rock it up and do very well on the um you know on on the charts and it was it was fascinated to watch and certainly one of the products and projects that got me interested in the application of LLMC in this space a pleasure to chat to you really enjoyed that and
Yeah, we'll stay in touch.
Thank you, Pat.
Keep up with a great show.
That was Federe Kirchbaum there.
The head of the Security Lab at Expo, very interesting stuff.
And, yeah, I mean, it's been fascinating to see what AI has done to offensive security testing
because it's not just Expo.
Like, this stuff is genuinely useful and to a surprising degree, I think.
Anyway, it is time now to hear from Andrew McAllister.
of CoreView here in Australia. Corview, not an Australian company, global company, but they do have a
substantial team here in Australia. They make an M365 security platform, basically, right? So as you're
going to hear, you know, the M365 platform, it's got a lot of knobs and dials. There's a lot of
footguns, like just so many footguns. And Microsoft doesn't really make it that easy for you to know
when you've done something wrong,
when your configuration is drifting into a direction that is dangerous,
so on and so forth.
So that's really what CoreView exists to deal with.
So here is Andrew McAllister explaining in more depth
what it is that Corview actually does.
Enjoy.
CoreView is a SaaS solution that plugs directly into your Microsoft 365 tenant.
And what we do after we've established the connection is
using the Graph API and a bunch of other APIs and scripts
that we've developed scrape the tenant and capture all of the metadata of the usage of all of the Microsoft 365 services inside the tenant.
And we also are able to capture and consume all of the configurations and the settings and the policies of these workloads
and aggregate them into what our platform is.
So Corview at its heart and soul is an amazing visibility tool that aggregates and centralizes all of the information reporting visibility of,
what's going on inside your tenant into one place instead of the 30 different Microsoft
365 admin consoles and then I love a bit of shade well you bet you bang on you bang on right like it's a
it's a it's a nightmare you shouldn't need a third party platform to do this but you know I'm I'm
thankful that there are third party platforms to do this because it needs to be done there are I mean
we would never position ourselves as adversarial against Microsoft we wouldn't exist if Microsoft
didn't exist but the the fact is is that
their platform has evolved so rapidly over the last 10 to 15 years that it's left a lot wanting from both a operational perspective, but also a cyber resilience perspective.
So core views kind of come in behind this amazing ecosystem and filled in some of those gaps.
Yeah, so let's talk for a moment.
I mean, you've described what the product is, right?
And I've spoke to other vendors on the show where it's a similar sort of thing, right?
you give them access into the tenant, graph API, pull down a whole bunch of data and then
start to glean some insights. So what are the main problems that you're actually solving here
for customers? Yeah. On the on the cyber side, you can really think about Corvie as being a
beautiful intersection between the operations and the cyber. So I like to kind of go down those two
paths separately. So on the cyber side, what Corvie does that nobody is doing right now is
is taking a backup of all of the configurations and settings inside the tenant.
So it's a daily immutable backup at the configuration layer.
And because of the way that we handle the backup,
we're also providing near real-time drift detection.
So anytime a critical setting or configuration changes inside the tenant,
Corvue will see it and report on it and allow the operators or the security team
to roll that setting back to a known, healthy baseline state.
So, yeah, on the cyber side, think about it,
as a critical part of the BCP or disaster recovery aspect of the tenant.
You can't just back up the water anymore in the glass.
If you think about the water and glass analogy where your tenant is a glass of water,
everybody is backing up the water inside the glass today,
which is all of the data, but nobody's backing up there.
No, no, I get.
I mean, this is like someone flicks the wrong switch or, you know,
some threat actor gains access to the environment and they make a mess, right?
So revert to known good state handy.
Again, I feel like Microsoft should offer this in an easy-to-access form
that doesn't involve a whole bunch of PowerShell scripted
a trench coat, but that is a good idea.
So what else?
Keep it rolling.
Yeah, so the other part of what Coreview can offer is deep visibility
into other potential security risks inside the tenant.
So one of the great examples is all of the third-party entry applications
connected to the tenant.
Corview can take an inventory of all of those.
and provide governance life cycles on those apps.
Those apps are actually now one of the main ways
that adversaries are getting into tenants
is they can scan a Microsoft tenant.
They can find these old intra apps
that have just been left behind with weak permission models
and often those enter apps have significant read-write access
in and out of the tenant.
And so Corvue is able to provide a governance life cycle
on those apps.
Well, hang on, how does the threat actor go
from actually enumerating
apps in the environment to spotting a weak one to then using that app to do things.
Well, I mean, it's very easy to get a, you know, a little scanner that can scan an M365 tenant
and find the app in the first place.
And then it's a matter of not necessarily having to breach the administrative account of
the tenant to get into the tenant.
It's about a breach on that app.
A lot of these apps are commercial off the shelf apps, which usually have good protections in
them, but many, many, many third-party entra apps are little homegrown, home-built apps that
don't have good security controls built into them in the first place. So it's those ones that are
quite easy to compromise. What's going through the app makers infrastructure or what? Get into the
GitHub, like that sort of thing? Yeah, all sorts of different methods on this. You can speak to our
engineers about the more technical routes here. But the point is that third,
third party enter apps is, that's how the Microsoft Midnight Blizzard attack happened in the first place on the Microsoft tenant is a, is a weak third party app there.
So, so yeah, Corview will inventory these. It will show you where you have apps that have readwrite permissions.
It will show you where certificates aren't being updated on these apps and give you some automated remediations to make sure that you never have this drift in these apps that are connected to your tenant.
So, yeah, configurations, app control, and then essentially aggregated security intel,
like just showing you basic things that you should know, but most administrators don't, right?
Like how many of my users are authenticating into my tenant without multifactor as a default?
Yeah, it's amazing how hard that is to figure out often.
And it's not just Microsoft's that's guilty here, but, you know, the number of times you need a third-party tool to be able to tell you that's insane.
Well, it's also insane the number of administrative accounts that have multifactor switched off, right?
And so we will just show you all of these risks, but not only show you, if you can use CoreView, so not only reporting and visibility, but we have a bunch of out-of-the-box remediations built in that you can automate, you can schedule, and so you can build these policies or use our out-of-the-box policies to decide what good looks like on the security side.
baseline it, and then any time Coreview detect something outside of that swim lane,
it can automatically run a remediation. So instead of waiting for the sort of six-monthly
audit to fix up all of these things a couple of times a year, it's constant compliance on that.
So I'm guessing that might be something like some admin somewhere enabled an insecure
protocol for email, you know, for users to be able to retrieve email or something like that.
You know, I mean, that's a classic misconfiguration that you would see in an N365 tenant.
It is, right?
Other obvious examples are where users or admins have set up some sort of automatic forwarding rule on their exchange online mailbox, right?
That clearly offers a huge security risk.
It's not just email either.
Think about the data lakes within M365, SharePoint OneDrive.
If you've got SharePoint sites that have been sitting there with external shares open for months and months a month because it was needed for a project and then never properly shut.
down. You end up with this sprawl of data, but also permission models across the tenant that just
slowly degradate the overall health of the system. So these are all of the metrics that we are
collecting and aggregating into a governance dashboard. Now, someone in your sort of role,
one of the questions I love to ask, because these are the sort of products that find the
wildest stuff that you can imagine. Have you got a few worries for us about some wild
absolutely bersererer configurations that you've seen.
Like your old-time top five.
Yeah, I mean, we've got the privilege of being, you know,
brought into some, you know, large public sector organizations, I will say,
to run security assessments.
So that's actually something that Corview does before we even attempt to sell our platform
is we will connect to a tenant and offer a low cost or no cost
and no obligation security assessment of that environment.
Well, it's a great way to sell a product, right?
You do the scan, it pops out a show of nonstop show of horrors.
And then, yeah.
Yeah, exactly.
So, yeah, I mean, one of the large public sector tenants that everybody in Australia would be impacted by, I will say,
we discovered that they had something like 33 global administrators in that one tenant, for example.
And clearly that is a challenge and a risk.
And when it came down to it, it was really just because it was more convenient to assign higher privilege to admins than it was to create bespoke admin roles for the...
Well, I mean, that's usually how that happens, right?
Yeah, right.
I mean, I will say this much is that the Microsoft 365 admin permission model inherently breaks traditional least privilege rules of just enough and just in time, right?
So this is something we see quite often, but 33 is egregious.
You know, Microsoft themselves say you should only ever have a maximum of three or four global admins inside any tenant.
And so to find 33 of them was pretty shocking.
We have seen global admin accounts in some significant.
tenants that have a mailbox assigned, right? And when you combine global admin privilege with
mailbox fishing propensity, having a mailbox assigned to any administrator or administrative
account is just a massive no-no. But again, there it is happening in large corporate and
public sector tenants. Conditional access policy switched off that monitor your geolocation of
administrative sign-ons.
And so, you know, this particular customer was concerned about work that seemed to be happening outside of regular business hours.
And lo and behold, you know, there were operators that were now accessing admin accounts from the other side of the world,
unbeknownst to them because they had not had the, you know, the correct conditional access policy on sign-in location configured properly.
we've seen sharepoint sites
we work with the university sector
so share point sites
numbering in the tens of thousands
in some cases so 60 or 70,000 sharepoint sites
that were created for projects and never spun back down again
all of which had some level of external share
still enabled or at a minimum didn't have an administrator
assigned to them anymore
all with PII from the university sitting inside of them
right? Yeah, just a ticking time bomb there. I mean, there's a bunch of examples here,
but if you think about, you know, that inherent risk that you're assuming when you sign up to
the Microsoft ecosystem, the idea of sharing your PII out of this platform externally is really easy.
It's really easy to hit the share button in SharePoint. It's not so easy to unshare that.
Yeah. All righty. Well, Andrew McAllister, thank you very much for joining me to pitch it.
It's always good to hear about solutions like this. I think there's a lot of people out there that
quite realize what a blind spot it is. I mean, Microsoft has certainly come a long way in terms of
allowing people to access certain features, like, you know, figuring out which apps are authorized
into a tenant is actually possible now, and it was very, very difficult in the past. And, you know,
they've tidied up their defaults somewhat, but, you know, M365 is still just a collection of footguns.
So, you know, I'm very supportive of companies using platforms like yours to go
and figure that out.
But yes, a pleasure to chat to you.
Thanks for joining me.
Thanks so much, Patrick.
That was Andrew McAllister there from Corview.
Big thanks to him for that.
And yeah, it's funny, right?
When you think about M365 as just like an office suite in the cloud,
I mean, it is and it isn't.
And like, what is a cloud platform versus a SaaS platform?
And the lines start to get pretty blurry.
So, you know, I think it does make sense
to at least do an eval using tools like this.
to see where you're at, because I am familiar with horror stories.
Let's just put it that way.
But that is it for this edition of the Snake Oilers podcast.
I do hope you enjoyed it.
I'll be back soon with more security news and analysis.
But until then, I've been Patrick Gray.
Thanks for listening.
