Risky Business - Soap Box: HD Moore talks OT security, frontier fearmongering and more

Episode Date: September 29, 2026

In this sponsored Soap Box edition of the Risky Business podcast Patrick Gray chats with industry legend HD Moore about how his company runZero wound up being used heavi...ly to discover OT devices in enterprise networks. They also talk about the vulnpocalypse and how frontier lab fearmongering is reminiscent of the collective freakout when HD released the Metasploit exploit framework back in 2003. This episode is also available on YouTube. Show notes

Transcript
Discussion (0)
Starting point is 00:00:04 Hi everyone and welcome to this special soapbox edition of the Risky Business podcast. My name's Patrick Gray. For those of you who are unfamiliar, these soapbox editions of the show are wholly sponsored and that means everyone you hear in one of these soapbox editions. They paid to be here. But that's okay because we still get to talk to very, very interesting people despite this being, ooh, sponsored content. Because today we're chatting with H.D. Moore, who's a bit of an industry legend. He, of course, is behind. Metasploit, he released Metasploit back in 2003. We actually talk about that a little in this interview actually, but he's probably best known today for being the co-founder and chief executive of Run Zero. Now, for those of you who are not familiar with it, Run Zero is like an asset and systems like Discovery Platform, which can go out there and really find all of the devices that
Starting point is 00:00:57 are connected to your network, servers, desktops, IOT, whatever it is, and really paint an accurate picture of what it is that you actually own, which is, you know, obviously very useful to a security program. And run zero is actually just recently been acquired. Like the, uh, the transaction closed very recently. I should disclose to that I am an advisor. Well, I was an advisor to run zero, which meant that I received a payment after this, um, uh, this transaction closed. Uh, but yeah, they got bought by Accenture alongside a company called Netrise and also Dragos, which does OT slash IoT security stuff, right? So that begs the question, why did a sort of, you know, enterprise IT discovery platform wind up being gobbled up and sort of placed together with these, you know, with a very large
Starting point is 00:01:54 OT security company? So as part of this interview, we'll be chatting about, you know, why Run Zero and How Run Zero gradually became a product that does a lot of stuff relating to OT. We talk a bit about what the vision is for the sort of combined entity that is being created, but we also have a really fun conversation about some other stuff. We talk about the Volpocalypse, and we also talk about, I guess, you know, how this AI Doom stuff, we've been there before, right? So 23 years ago, when HD released MetaSploit, people were calling him a cyber terrorist and saying he was giving machine guns to toddlers and stuff like that, right?
Starting point is 00:02:34 So we've been around for the hype cycle, him and I both once before, so we have a bit of a chat about that. But look, I'll drop you in here where HD sort of explains where Run Zero came from and, you know, how it got to where it got to, like why it wound up being something that was so highly relevant to OT and IOT network. So here is HD Moore. kind of going back to basics, the reason Run Zero started was we're all sitting around the pool in Vegas, what, eight years ago, chatting about this stuff. And the idea was like, you know, hey, folks have kind of abandoned network discovery.
Starting point is 00:03:08 They've kind of assumed that you can, everything on the network is managed, everything unmanaged doesn't exist. And the problem was that unmanaged stuff that unknown stuff kept getting hit again and again. That kept being the kind of Achilles heel of networks. There's the stuff that the security team had no idea that existed, that they didn't have an agent on. So, you know, going forward, that became more and more of Run Zero scope became OT, because that stuff is mostly unmanaged. It's PLCs, it's random industrial routers, things like that,
Starting point is 00:03:33 things that don't run your crowd strike agents that don't have any other kinds of visibility to that outside of maybe passive discovery. Even then, you don't really know it's on the network. You're only kind of seeing where you happen to get a span tap or capture. So from that sense, like Brunswick got really kind of deep in the OT space in terms of helping folks who had no idea how those networks even configured, figure out there, how they're wired up, where the increase points are. And that stuff really kind of hit the fan in the last year or so.
Starting point is 00:03:55 And where that kind of dovetails with, you know, corporate enterprise that every enterprise out there has some kind of equipment like that, even if they don't realize they do. It tends to be building management systems, your HVAC controls, everything's like your building access systems. The things that you don't think of as IT products, but nobody else thinks of this theirs. That's where you tend to see the biggest problems. So places where you typically have your real estate firm managing IT are where a lot of corporates get hacked because it's like, okay, well, I don't manage that. The building people manage that device, that controller, even though it's on your network. Yeah, that HVAC. I mean, the target got, that's how Target got owned, like a decade ago or whatever.
Starting point is 00:04:28 It was actually the HVAC controller, right? Like that had just admin password or whatever. And that was, but I mean, like, you know, back then I didn't understand why that wasn't on its own VLAN, right? And look, I got to stop being surprised and disappointed, you know, because I've been at this for 25 years. And yeah, I've got to stop being surprised and disappointed by that. Because when given a choice between convenience or a secure, sensible architecture, that's not really that much more work, people just tend to do the easy thing. It's gotten really bizarre.
Starting point is 00:04:56 So one thing we did a couple months ago at Run Zero was you put together protocol gateway discovery. So you can find devices behind other devices, even if they don't speak IP. So backnet controllers are a really good example. That's most of your HVAC. You connect to a thermostat. And that thermostat lets you talk to everything else in the backnet bus, which can include like your fire, your safety, sprinklers, all that kind of horrible stuff you really don't want attackers to get to. So we did an internet scan.
Starting point is 00:05:17 We found about 5,000 devices directly in the internet. But behind them, we found over 110,000 devices that you can control. So the stuff of the internet was pretty boring. It's like a thermostat. But the stuff behind them was actually really important, like door locks, relays, you know, sprinkler systems, all the safety systems, the early warning for shooters, active shooter drills. So it's pretty wild, like how much of that stuff is out there. And, you know, nobody had looked for it effectively. Evan says, okay, there's a thermostat in the network, I don't care. Now I realize that one layer behind the thermostat was everything else he do really care about. Well, it's interesting there that you said that that's not even IP, right? Because some of the earlier work that you did that was very interesting with Run Zero. is you could discover devices that were UP and Pying their way onto the internet, for example, right? So you had a lot of people doing discovery who would say, give us an IP range, we'll scan, it will find all of the IP cameras. Now, of course, at a time of war, etc., like this has become quite an important thing that a lot of countries care about. They want to find insecure IP cameras that the adversaries might use to, like, do, you know, airstrike battle damage assessments or whatever, right?
Starting point is 00:06:19 So it's important stuff. So a lot of these discovery places would just look for like HickVision, right? And, okay, we found him. What your stuff would do, though, and it was really interesting when you looked at the scan results, you'd see like HickVision running on Cisco. And it was because it had like UP and P'd its way out. So you've always been really good at doing that like that extra hop. But that was with IP-based stuff, right?
Starting point is 00:06:41 So could you tell me more about how you were able to go from a thermostat through some sort of question mark protocol and then enumerate stuff and connect to stuff behind it? Like what protocols do they use? Yeah, the two that are most common for HVACs are in the States, at least, it'll be Backnet. And it's basically almost like a cyro-boss. Like, once you connect to the first gateway, you can just enumerate devices by ID number and just kind of go through that. And if you find another device in the network, you could then keep routing through that and change all you want to. On most European networks, it's called K&X, and it's a little bit different.
Starting point is 00:07:11 It's not quite as active and routed. In both cases, you're stabbing yourself as a remote foreign router to the network and then routing your own traffic into it over these bizarre protocols. On the OT side of things, it's mostly Ethernet IP slash SIP. And that protocol is really neat because not only can you do serial chaining, but you can do serial to IP to serial to SIRL to IP, and keep working a way around a network through a combination of Ethernet ports and serial ports and just relay as long as you want to. You get to the point where you're making like 20 second connections,
Starting point is 00:07:37 balancing through five devices. And in fact, you can turn a lot of Ethernet SIP device into like remote port scanners for subments you can't directly route into. And it's a lot of fun. It's really funny because I can guarantee you right now that you are blowing up. Well, not blowing up, but you are being indiscreet about someone's tradecraft right now, right? Like I reckon if there was some sort of leak out of NSA la Snowden again, this is the sort of stuff you would see. I mean, would you think? Would you think so?
Starting point is 00:08:00 Yeah, it's not like it's hidden. It's just that people haven't implemented tools for it. Like, you don't see any commercial vendors implementing anything beyond the first step of these enumerations. Or if you do, you see them being very structured tools by the HVAC company to then monitor your equipment. But there's no one really putting those two together. So if you look at like a lot of team management. doing it publicly, I guess is my point. I'm guessing that like, you know, and no one's sort of snapping this sort of stuff in a in a forensics context. But I'm guessing people are using this in the wilder is what I'm getting
Starting point is 00:08:26 out. Yeah. I'm kind of going to your earlier point about finding unexpected things like UP and P and P.D.D. Fries is cutting a hole in the firewall by default. It was a huge thing. It's still a problem today. A lot of your Hick Vision, the other cameras will automatically cut a hole in the firewall and UP and P. Ford by default, whether you do anything or not. So one thing else we're finding more recently with a lot of the OT attacks, the devices are being hit through cellular router connections that no one knows the IP of because they're on a public APN through a telco. So you never know what IP they're going to pop out of in the first place. So how do you even find him, right?
Starting point is 00:08:54 So I think we've been spending a lot of time on it run zero is being able to scan the inside of the network, fingerprint everything uniquely, then scan the entire internet and matches you up, say, hey, this device inside is the device outside. Even if we don't know what range is yours, we know it's yours because we can match us two signatures. Yeah, I mean, this is something you've done a lot of, right? Like even doing stuff like matching, you know, key fingerprints inside and outside, right? by scanning the whole internet and then doing that targeted scanning of like, yeah,
Starting point is 00:09:18 internally. Yeah, and we can be pretty lazy about it. We can pull a lot of data from existing third-party data sets. So, for example, Shodan has about nine of the ten fingerprints we need already in the Shodan dataset. So we just pull them out to start with. Another fun thing about Shodan's data set is that there's holes in it, and the holes are really conspicuous.
Starting point is 00:09:35 Like, you'll try to figure out, well, why doesn't Starlink exist in the Shodan dataset? It's a really good example. And then what does Starlink have exposed? That is not a new public dataset because of it. been excluded from all the public ones. So an example of like, interesting, I'll punch get to the punchline. 4,000 fortinets is what's there. But very interesting that like, yeah, so the Starlink IP space is almost all fortnight gateways and it's not in showden at all, which is just kind of a weird confluence of things. But stuff like that you went into and you start doing a dissection and
Starting point is 00:10:02 say, okay, here's what we expect to see. Here's what's actually in these different third parties. Let's go scan the difference and figure out where they went. Now, look, I just want to switch gears here for a for a second and talk about vulnerability scanning because, you know, you did a big sort of pivot into, well, not a pivot into vulnerability scanning, but you added a lot of features to run zero that made it quite a useful vulnerability scanner. You did this great talk at a decibel event. I was there in San Francisco next to RSA, where you pointed out like the incumbent VOLN scanners basically haven't changed the way they do anything for, you know, 20 years.
Starting point is 00:10:36 And they don't really give you much useful information. They just dump a bunch of, you know, CVEs on you. And that's why, you know, one of the reasons vulnerability management is such a mess. So the idea with Run Zero is you could scan, you could find stuff that attackers can actually reach. You can get a better sense of the impact. But it feels like now, even that is just like untenable. Vulnerability management has just got completely untenable because of this AI-driven volumpocholapse. And you and I have talked about this.
Starting point is 00:11:08 Like, it's got to the point now where people are just getting known by stuff that doesn't even have a CVE. So, you know, how is vulnerability scanning supposed to save you, right? So it's, you know, we've swung back to discoverability and control. But walk us through the, you know, walk us through the current state of exploitation out there, if you would. I mean, the dirty secret of CVE hasn't mattered in a long time. Most of the bugs people are exploiting don't have CVEs when they're being exploited. So the, you know, Von Popolipsy will accelerating that. So you may see, what is it, like 65,000, 70 CVE so far this year.
Starting point is 00:11:40 That's not including the 200,000, the wings right now, they don't even get a CVE. yet. If look at the stuff the Anthropic presented, for example, they said they found about 20,000 at one points, but long story short, about 83 have got a fixed patched, about 130 something have not been fixed yet, but have been disclosed and accepted by the vendor. And there's a giant pile of ones that the vendors have not accepted in the first place. So I can tell you, we did a disclosure process for Open BMC, which is kind of the underpinnings of all modern BMC implementations these days. You know, Dell, IDRAF 10, Supermico, and newest boards, you know, Huawei, Huawei 3Com, or sorry, Huawei is open UBMC, but Huawei 3rd.
Starting point is 00:12:12 Recom is using or Hs. She is using OPMC. For long as we're short, we found an off-bypass directly to pre-visclation. So you go from zero to root on every device that's running this BMC stack that is now the most popular stack in the world for managing every surfer out there, including the hyperscalers. And we, you know, we announced it, or we told the vendors about it 60-7 days ago. They did not patch it. We disclosed it a couple days ago. No one even noticed.
Starting point is 00:12:34 We've been reporting vulnerabilities and run zero for this thing for almost since 60 days ago. Like, we've been telling customers about it, hey, this is something you need to turn off really quickly. there's an exploit coming out for it ASAP, no one cares. And more surprisingly, the vendors who are downstream of Open BMC, the commercial vendors that rely at Open BMC for their own stacks, they don't care until it's a patchable. So we've got CVs for it, but again, even the case of a CVE that we've been telling customers about
Starting point is 00:12:57 for almost two and a half, three months now, is not really on humans' radar. So in a lot of ways, and this is just one of 40 bugs that we're trying to get fixed right now. These are the only two that have been published of the set of 40. So it's a nightmare out there. I've been looking at working with other folks, in the kind of phone discovery space. And everyone's sitting on hundreds of thousands of bugs. Most people will never get a CB.
Starting point is 00:13:16 Most will never get patched. So the question is like, okay, if CB is not longer matter and exploitation is only an example of what happens when something is exploited enough that someone else notices, like put it this way, most of the volumes going forward will be exploited exactly once and only in your infrastructure and that's it. Like, no one's going to go burn their good bug
Starting point is 00:13:32 by setting it across the world. They're going to take your... Well, you don't need to either. You just got to find some enterprise crapware, right? And then throw tokens at it until you get a bug because it hasn't been QA'd that well. So like, you know, I was talking recently about how I think where we're going to land is say you're an airline, your ticket booking website, that's going to have a lot of tokens burned on it to look for bugs, to make it secure,
Starting point is 00:13:53 to refactor it, to make it as good as it possibly can be. And everything else that was touching the internet from your org, you're going to try to get that off the internet. You're going to go back to like zero trust network access principles. You're going to, you know what I mean? Like, it's all about like a attack surface reduction at the moment. But what you're saying, seem to be saying right now is that there's not much that can be done, right? Like even if you've got the run zero volume scanning and everything, like people aren't just, they're just drowning. Yeah, I mean, the important part isn't that you've patched everything on the CV side
Starting point is 00:14:23 because that doesn't really matter anymore. The important part is you know what you have in the first place. Where is it connected? How can you get to it? What is it connected to? What's it connected to? What's a blast radius of a bug? What vendors are in place? Like, you need to understand, like, okay, if you knew something comes out,
Starting point is 00:14:34 where is it, what can it impact? And then if someone gets into that, where can they go? and that's true no matter what CB it is, no matter, you know, what level of patchability the issue has. So really is back to basics. Like you go back to, you know, mid-1990s, and everybody who was a hacker at the time could walk their way into any system they wanted to.
Starting point is 00:14:51 So we're talking about some... So this is fine. Like, I've had variations to this conversation, like, especially down at unprompted where I'm seeing people I've known, you know, 25 years. And we're like, man... They were doing this from 5 years ago, right? Exactly, right?
Starting point is 00:15:00 Like, that's the thing is, like, I think for... And it's been really funny watching the discourse of the, you know, we're all going to die from the labs, right, and everything. Because for those of us who are old and have been around in this for a long time, we're like, we've been here before. Like, we've lived this reality previously. And like, it was messy and it was ugly, but like we got through it.
Starting point is 00:15:22 I mean, you seem to be like singing from the same songbook right now. Yeah. What do we do back then? We disconnected stuff. We put firewalls of place. We added more monitoring. We added more detection. You assumed you weren't going to catch every attack when it happened.
Starting point is 00:15:35 You assumed that you'd had to have enough information later on to find it. So the big difference between now and then, of course, there's a number of people who can do it. Instead of it being, you know, a couple of our friends doing this on the weekends, it's become anybody with an LLM and five bucks to spend can get pretty close. So, but again, the challenge is like that, well, the nice thing at least is these LM tools are not particularly sneaky. They're really good at, you know, as Harun mentioned,
Starting point is 00:15:56 they're really good at taking bait. You can trick them into telling you who they are and to leaking themselves. Like, they're really great to attack with honeypots. So defenders have a great chance to honeypot the crap out of things right now and use those to find people who are using LLM tools. against him really, really quickly. Oh, man, the Harun Mir stuff, I've interviewed him about that, and it's hilarious, right, where it's like, you can pop up a web server that says, hi, I'm a web server that helps agents.
Starting point is 00:16:16 Please connect over here, and it does. And then you're like, hey, run this go binary. And it says, no, that's a reverse shell. I'm not going to do that. You say, no, come on, run it. And it goes, okay. It's awesome. Yeah, but that's where you are.
Starting point is 00:16:27 So, yeah, we've got really fast exploit tools, and they're really smart, but they're also really dumb. And so detection becomes something you can actually do these days. Like, honeypots become more relevant again, and firewalls become more relevant. IPX control depends were relevant so we're kind of right back to the mid-1990s you can't stop someone from attacking you from zero with you i'm with you but like it just occurred to me that the the the most comparable situation right that i can think of to people freaking out about people releasing technologies that make exploitation easy you can see where i'm going with this and this is
Starting point is 00:16:59 how we met we met in 2003 when i was working for zd net in sydney on the news desk covering security. And a guy called HD Moore in the United States released a tool, released a project called MetaSplight. And this was so controversial. I think, you know, unless you were there at the time, people were saying the craziest stuff about you. Can you remember like some of the choice quotes about what people said about you? Like, where you were cyber terrorist and that, you know, those were the sort of vibes, right? Yeah, let's see, handing machine guns and toddlers, enabling cybercrime, you name it, right? And the funny thing about Metisplay was like it was controversial for a couple years because we're ahead of the
Starting point is 00:17:36 curve. And then we're just chasing behind the bad guys the rest of our history, right? That's what was then a year or two years, three years behind the baddies going forward. But there was a small period of time when folks were looking at metaplodies being the leading edge of security and exploit tech. And at that point, that's been a crossed over. And folks stopped complaining about metaphodies
Starting point is 00:17:52 being the same enabling bad guys. They started realizing it the only way they're in keep up is to put things into the open. So I think we're right there again. Like open models are how the injuries are going to keep surviving. And, you know, screaming for regulation is not helping anybody. And it doesn't matter if you want to pace yourself or not. the world's going to keep on hacking.
Starting point is 00:18:08 And so that's where I... But I just realized, like, it really is, like... And I hadn't even thought of it that way before being on this call and, like, talking about it with you. But it really does have the vibes from that time. Has that occurred to you previously? I'm guessing it has. Yeah, especially the more last of last week or two
Starting point is 00:18:24 with anthropics and you need to pace ourselves and so on. Like, come on, man. Like, look back at the history of this. Like, open all those wins and acceleration all is wins. You can't say, no, no, guys, let's slow down. Yeah, yeah, yeah. Technology doesn't slow it. down for anybody, right? But like, I'd also note that like none of the people calling for a slowdown
Starting point is 00:18:41 and everyone who's like inciting panic right now, none of them know anything about cybersecurity, right? Like they are from completely different fields. And I think that's, it's wild, man, because I get asked, you know, I get texts and messages and stuff from like some pretty like influential people and asking me for my opinion on this stuff. And I'm like, man, we all just need to chill. We need to chill. There's going to be, it's going to be bumpy, right? It's definitely going to be bumpy, but, you know, we're not all going to die. Get a grip. I mean, I think that's another parallel with security is that AI has the same kind of like mindless panic the cyber security did.
Starting point is 00:19:17 You know, everything like hackers are called over computers. I keep thinking of the satanic panic from the 80s, right? It feels like that a bit, right? And it's worth it. Like, it's worth that to the commercial firms to incite that panic. We're seeing it because it actually drives sales. Yeah. Anyway.
Starting point is 00:19:31 That's interesting. Sorry. No, it's okay. Like, I love that we've just taken a bit of a bit of a trip down memory. talking about this. But look, while I've got you here, you know, why don't we talk a little bit? Because you've actually shipped a bunch of new stuff. Talking about technology, you haven't paced anything.
Starting point is 00:19:48 You haven't done any pacing. You've released a whole bunch of new stuff, new OT stuff. I should point out too that, like, I think one of the big run zero innovations, underappreciated, mind you, was the fact that you figured out, you did all of the reverse engineering that allowed you to do active scanning of OT environments without knocking stuff over because you reverse engineered all the protocols, understood how they worked. So previously it used to be, oh no, you can't do an active scan of an OT environment. You knock everything over. You know, you figured out how to do that safely.
Starting point is 00:20:20 Still meant you got pushback in a lot of deals where people are like, the graybeards, like, you're not going anywhere near our network with that. But a lot of people did, you know, like you've really sort of changed the culture around that. And now people accept that, well, if you've got a well engineered product, you can do that. But you did all of that pre-AI and now that sort of reverse engineering work that sort of development is a lot easier So you've basically gone turbo mode The last four months why don't you tell us what you've what you've shipped? Sure all times stuff so going back to our four nine release we added all the OT protocols including all the Ote base or
Starting point is 00:20:56 Backplane protocols so speaking non-IP so you find a device network then you can ask that device to find everything else behind it even though it's non-IP So backnet mod bus S7 all kinds of fun stuff. Yeah, that's It's the stuff we're talking about Elia, yeah, yeah. We have a nice, big, fancy, interactive map, a little 3D map you can go pew-pue with and run around and see it all. So showing the connectivity of layer 2, layer 3 and these serial protocols all laid on top of each other is really cool. You can actually see the path from Stroll to IP to another gateway to a multi-home host all the way to where we want to get to. And then we did a huge pile of work around bone remediation, bone tracking, exposure management, just kind of all the meat potatoes, like, you know, dashboard, share-up reports, be able to help you, like, take the fun stuff you see inside the product, get it to somebody else.
Starting point is 00:21:36 else who doesn't know what they're doing. Like, give them a report and sort of them exactly what they want to see and not just a giant inventory, right? So that all worked really well. And then more recently, we did AI and just want to say, like, as always, Patrick is right, we did not want to do AI stuff for the longest time. And then finally we realized we're wrong and just sat down and said, okay, well, how would we do this in a way that customers are actually going to be happy with?
Starting point is 00:21:58 Because we have some pretty conservative customers as well. We like, do not put AI in the product by default. So we took it to a group. It's so funny. Like this is, I literally had this conversation the other day with the airlock digital guys because I was like, hey, you know, you probably want to do agentic, you know, allow listing and whatever. And they're like, our customers don't want. I'm like, oh, I think they will eventually. And that's, that's what happened, right? Is they were right to resist
Starting point is 00:22:16 it at the time because their customers were like, don't you under any circumstances ship AI features here. And now all of a sudden, those same customers are back and just like, when are you shipping? And it's like, okay, right? Like, that's, it's been a big, it's been a big change in the market, I guess is what. And you had to do both at once, right? We had to be investigating and learning had used the AI tooling on one side while also resisting the demand to put it in the product at the same time. And once those two things cross over and said, okay, we actually know how to do this well enough that it's safe. Let's go ahead and do that. So one of the things that we built is really cool recently was an AI integration generator. So what people always hate is integrations.
Starting point is 00:22:48 Like, no matter which product you use, you may be missing the one integration you need. And everyone's like, okay, we'll build your own or use your API. No one wants to do that. So you can throw AI building APIs, but we found a better way to do it, which is like build a better integration engine into the product directly and then have the AI, you know, tooling spit out integration for you live. So you give it a link to the documentation URL if you have one. If not, it'll figure it out. You go to end point and it'll go just create an integration for it. And you save it off and off you go. So you can build integration to literally anything. Custom, commercial, you name it. We put about 120 publicly online so you can get a sense for how they work.
Starting point is 00:23:18 And we made a really decent API. So things like TLS pinning and all that's going to done for you. You can change stuff. You can set user agents. Like all the normal junk you want to do is kind of pre-baked. You don't have to reinvents a wheel for it. Why don't you just take a step back and define for us what you mean by building an integration when it comes to run zero. Yeah, there's kind of two ways to do it. One is you're trying to pull data into the product. So you're saying, I want to go connect to my network switch. Crowd strike or whatever or call it. Okay, right. So that's what you mean by integration. You can pull data in or you put it back out again or you can just like manage the task.
Starting point is 00:23:46 So we have folks to use integrations for outbound. So push data to Splunk or do a data lake or pull data inbound for full management. We also have folks to use integrations to push and pull data between two runs or instances. So they'll run external scans in one node. with a little push that to an internal node through a jump box. And that whole thing runs as an integration inside the Run Zero kind of tasking, if you will. So it's kind of neat. It's almost just an arbitrary language. You're going to do whatever if you want to with it.
Starting point is 00:24:07 We added S-H-WMI. WMI is over S&B, MSRPC, and HTTP as well. So there's a billion different ways you can talk. So you can build an integration that shells into random boxes if you want to at this point and dumps data and then brings it either to run zero or out of run zero at that point. So it just really kind of took the, you know, the restraints off a little bit and let folks kind of create anything. And I guess there are some restrictions in terms of where it runs
Starting point is 00:24:29 and how you set credentials and encryption, things like that. But we basically made it very easy to build anything you want to in the product just by typing in a sentence saying, go do the thing. I didn't even know WMI was still a thing. Yeah, it's mostly HP these days,
Starting point is 00:24:41 but you still see it over, you know, decom, DCRBC here and there. But it's kind of neat, like, putting all these old protocols and exposing them directly to the scripting engine. So the scripting engine will soon be able to do things like IPMI, Modbus, you name it. So we're looking at how do we take the same engine
Starting point is 00:24:55 and bring it down to like the skin layer as well and let people, you know, really get deep in the weeds of the stuff. You know, the AI integration we did was a little different. It's always B.Y. OK. So you kind of take your, you know, your engine and you plug in the credentials to it and the URL to it. And we use whatever you have. So if you have a management layer that's looking at your API request and steering it through, you know, either managed Oath or an all listing or any kind of filtering or logging system,
Starting point is 00:25:18 you can drop that in and get the observability you want. So a good example would be like open router. You can plug an open router URL and to run zero. And then you get all the observability and OTAL logs out of open. router if you want to or whatever you back and happens to be. That was kind of get up, that way you don't with her about like, you know, data, you know, location. Sorry, you said B. Y. Okay. What's the K there? I'm sorry, bring your own key. So we say take whatever account, whatever you're all you want and we'll run all of the run zero logic through your own endpoint. And including
Starting point is 00:25:43 for report generation, AI kind of, you know, question answering, integracy creation. And then we kind of show you the behind the scenes version of that. So you can go into the AI threads part of the product and say, oh, you know, Joe built an integration. Here's actually the entire thread that you built, here's the output from it. I want to go rebuild, I think, here and there. So it's kind of like letting you can do like arbitrary agentic work within the product using your own AI back in of choice and being able to see the kind of internals of it in the product. Yeah, right. So you've got like a decent, yeah, you've got all of your transcripts and everything in there just from what the product is doing.
Starting point is 00:26:15 Yeah. And we put, you know, started shipping about a part of the quarter of the product's total content now is like markdown shipped in the binary because we built this whole self-reflective layer where it knows how its own code base works, it knows all its own APIs. Something else we did is we took the MCP layer we had before and MCP layer we had inside the scripting engine and the kind of report engine and made them one. So it doesn't matter how you're calling
Starting point is 00:26:35 the product. You can call it from Cloud directly or you can call it from the integration engine or the in-product U.S. And either way, you can call the same tools. Like, you know, find me the assets that are at least seen, find me an OS with the particular configuration, giving a report and everything running in port 22 that's not a speech. So anything, or, you know, go through your CrowdStrake,
Starting point is 00:26:51 and find me the CrowdStrike machine whose BIOS is at a you can do pretty much anything with that engine. I'm curious, how much use is your MCP server getting? Because I'm kind of working on something. You know, a little bit about it. But like, how much, you know, how much our customers actually connecting to the Run Zero MCP? You know, they're connecting with local agents.
Starting point is 00:27:11 They're connecting with hosted agents. Like, what's at a queries are they doing? Like, you know, is this something that people are actually embracing? Or is it early days? Both. So when we first launched it, no one used it. And we realized they didn't use it because it sucked. we realize that the API calls
Starting point is 00:27:24 yeah we're not great they were slow or you're chewing up half the context window with like you know MCP instructions or whatever that's a funny one or CSV exports or eating your entire coming back out again all the data coming back out is pretty effusive so we come back and say okay let's build a new toolkit where it does like
Starting point is 00:27:38 summarization at the API level instead and of course we had to change our access control we just change our API key management or usage management so after we kind of just redid the whole thing about a month ago it's now getting pretty popular we're seeing folks hitting it all the time we let you do things like
Starting point is 00:27:51 use our natural search translation engine now from the MCP API. So instead of saying, like, I want to find OS colon Cisco or whatever, you can say, find me the Cisco boxes and give me a search query for it. And then it gives you the actual API query that you need to do the rest of if you want. So a little mix of both, you know, arbitrary, you know, MCP. Well, you've taught it, you've taught it how to use the product, right? Like, I mean, I think that's the, that's the return smaller pieces, right? Yeah, yeah.
Starting point is 00:28:16 Definitely where you kill it is either you stuff a million things into your context window or you spew so much data back out again, you can't make any decisions because you blew the whole window on your output. So trying to fix those two things has been fun. But if you make it too short, then, of course, the product doesn't work. You can't answer any complex problems.
Starting point is 00:28:31 So we have things like turn limits. I think our default turn limits about eight or so. We set limits on how many records we search by default. And as long as you have enough context that tells the MSP engine or the agent when to call it with tools and what their limits are, it's pretty good about working around it. Say, let me do a sampling across these records
Starting point is 00:28:47 or giving it the top X to the bottom X of the, this particular table. And where does your MCP live? Is it like, does it tend to be like behind the firewall on an enterprise network on prem or is it in the cloud or like where do people tend to do that? Oh, we're brave. It's directly in the product. So wherever your product is installed, it is also the MCP server. So it's remote, each be streaming. So you connect to whatever your runs or instances, whether self-hosted the cloud and off you go and that's it. And there's no separate standard I.O or whatever to manage. It also uses the same max controls. What sort of agents are people plumbing through to it, right? Cloud's by the most common one. We see some folks doing
Starting point is 00:29:19 like either Cloud TLI or Cloud Desktop. We all see a lot of codex. We had somebody trying to find, like, phones in the product while back, and they're just, like, spewing the API request into it. So fortunately, we cut things off after, like, if you're especially with a free account, we'll turn it off the API request fairly quickly,
Starting point is 00:29:34 which also shuts down the MCP access as part of it once you go over the limit. Something else we noticed early on is that folks, like customers that we want to be using the product, we're blowing through the API limits per day, like hundreds of thousands requests per day by using MCP. We're like, what the heck is going on? And we found out that MCP was just, like,
Starting point is 00:29:49 hammering our back end for the dumbest reasons until we fix the context, give it better tools. Yeah, so and how are you handling like the permissions and the Oath scoping and everything for that? Sorry, I know we're getting into like product engineering, engineering talk, but you know, this is, this is relevant to my interests at the moment. Yeah, we had like really granular permissions until about a month ago. You could say like read only or reprite and that was about it. And then admin mode. So we went back to let's, let's do it from, you know, from the beginning again.
Starting point is 00:30:16 Let's create every little scope permission, granular access, like inventory read, inventory via user manage, user read, like every category of data in the product that has multiple privilege levels. And we map those back into roles. But you can now do custom roles for everything in the product. So if you go into SSO and you log into a particular SSO group, you can then assign that group to a very specific set of roles. You can do X and Y, but not Z, across a whole bunch of organizations or mix of them. And then the MCP Oath layers all the same thing. You create a custom credit that can only do exactly whatever you want it to do. So you can safely give your MCP server or something that has reaccess to everything.
Starting point is 00:30:47 And it reacts only to certain orgs or certain types of data. And that's all over to touch. But rewriting that whole thing was a monster. So, you know, AI is helpful when you're doing massive bulk rework like that, especially when you need to do like comprehensive back testing on it. Well, the reason I'm asking you about it is because you tend to be two years ahead of everyone else, right? And I might be dabbling with building a product in this space. And I don't want to know where I need to be in a year.
Starting point is 00:31:10 So that's cool. And it's interesting that you say you're getting the, you know, you're getting the adoption now that the product, now that the MCP actually works properly. Yeah. Like you have, you can't just throw an MCP on and expect to be good. You have to actually try the experience. If it takes you five minutes, get a result, try again, figure it out, chop it down, shrink it, add better context. Like, it's not enough just to bolt something on to it. Same thing with our in-product reporting for AI.
Starting point is 00:31:34 You can now create arbitrary AI reports, what if you want. But, you know, if you start off with just, you know, your engine and with user types in, you're not going to get there. You have to give it charting tools. You have to give it the ability to draw like mermaid diagrams. You have to get a color guide, style guides. There's a whole lot that goes into it. Well, you can't just say like, you know, Claude, give me a reporting engine. You really have to go pretty deep to make it actually usable.
Starting point is 00:31:53 But I am curious, right? Like, because you're in this situation where you're having to develop these like dashboards and, you know, visualizations and Pugh Pue Maps and right, right? And make it really cool. But I'm thinking most interaction with a platform like Run Zero in the future, it's probably going to be MCP or an agent using sort of, of run through a specific skills to go to X, Y, Z through an API or whatever. Like, is that, you know, where do you see the future going in terms of the split between, you know, dashboard versus Igenti? The challenge of, I think, you know, we've had lots of customers reach out and say,
Starting point is 00:32:26 hey, we built this cool report, put it in the product. And our take is like, that's great. You can put in the product yourself, copy and paste the prompt in, off you go, have fun. The reason we don't do it is because the reports that you specify like that only give you what you want to hear. So you say, give a report showing X. It's going to do exactly what you told it to do. and to ignore everything else that's contrary to your goal.
Starting point is 00:32:43 And so it's really difficult to build a report, this objective that tells you things that might surprise you if you're only asking to tell you things that you know about. So that's one of the biggest challenges. So I think you do need a set of visualizations of the product that you don't necessarily agree with. You need someone to tell you your baby's ugly. You need someone to say, hey, you've got my agenda like crap,
Starting point is 00:32:59 you need to go fix. I mean, that's really important. You can't say give me your report that makes me look good. You need a report that tells you what that actually real. So to some extent, you need to provide all the customization of the world in the product. You also have to have an opinionated visualization whether it's your dashboard or queries or charts that helps users really kind of pin themselves to you know where they should be in the world well i mean you've always been a pretty accurate
Starting point is 00:33:19 forecaster of how these things go so uh i'm gonna i'm gonna i'm gonna go ahead and uh just agree with you because it's um it usually turns out to be right uh we're gonna wrap it up there hd more thank you so much for joining us if people want to have a look at run zero you can still try it for free run zero.com slash try uh but yeah man Congratulations on selling the company because it has closed now. And, you know, good luck with all of this, right? Because it's a lot and I can't wait to chat to you again soon. Thanks for joining me.
Starting point is 00:33:48 Thank you. Thank you for being our advisor.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.