Everything You Should Know Before Mythos Arrives | Nebulock, Damien Lewke
A cyberattack used to take an elite team and a decade of hard-won instinct. Now it takes two people and a GPU.Damien Lewke spent his career on defense - at t...
Watch on YouTube →Transcript
Chapters10
- Intro
- Love the Problem, Not the Solution
- How the Security Talent Gap Collapsed into a Subscription
- Quitting with No salary: The $0 Test
- How One Person Actually Hacks with AI
- 6 Steps of Cyber Attack
- Assume You're Already Hacked
- The Three Signs an Attacker is Already Inside Your Environment
- Don't Fear AI, Fear Inaction
- What You Need as a Founder
Intro
00:00Mythos changes the balance of power in cyber. [music] Two people in a GPU who with enough conviction can target a company. And I think that that [music] will happen. But I also think like mythos to me is not like existentially scary. Mythos is what [music] we in security have been saying for years.
00:17Really the question we should be asking is okay after mythos what's coming after? What are we ready for? We have a very unique window of time right now where we understand what is coming and we have the ability to adopt technology. The question is can defenders adjust as quickly as the attackers can.
00:36I'm Damian Luki. I'm the founder and CEO of Nebulock. Nebulock is a contextual [music] security platform. Really what we do is look at all the existing security tools that you have and we find potential [music] threats hidden between the layers.
00:51We raised the $25 million series A led by First Mark with participation from all of our existing investors. So, Bane Capital Ventures, Decible, Zeta Venture Partners, and Step Function.
Love the Problem, Not the Solution
01:14I'm very fortunate. I discovered my passion my first day on the job as an intern at a company called North of Grumman. [music] So I started my career in the DoD building out cyber ops and threat hunting teams before [music] being a relatively early employee at Crowdstrike, joining after the series C, being there through and after the IPO.
01:33My first job when I was in the DoD, I actually worked full-time and went to grad school at night to get a masters in aerospace [music] systems engineering. What that taught me was not to be a hero every single day. But what was most important was that you showed up and did your best as best you could day in day out.
01:49That's really expanded as I've gone throughout my career. So on the personal side, I have a challenge where I run 1,000 miles a year. It's the same kind of idea, which is like at 10:30 in the morning on a Tuesday in [music] February, can you show up and do your best the same way that you would on a Friday morning when everything is going great?
02:09I then had a chance to experience network security at Palo Alto Networks and and [music] managed detection and response running the AI detection security research product teams at Arctic Wolf and I I took a stint [music] at MIT writing a graduate dissertation out of the computer science and AI lab there.
02:26What led me to start Nebulock really was a [music] two-sided problem. So the first is beginning as an operator. I saw the real problem that all of our existing customers [music] had at Arctic Wolf and also what our 1200 person security operations center had.
02:43The dissonance was everybody had already invested in these [music] best of breed tools and despite owning the Audi or Ferrari of security, everybody was still getting compromised and it was because different [music] point solutions to specific problems were not the way to solve how to get breached.
03:02It was rethinking everything from first principles. Two years ago, my thesis was adversaries, so bad actors are going to use AI to automate tailored access operations. They're going to be able to automate the entire life cycle of targeting an enterprise, compromising it, achieving their objective, and slipping out undetected.
03:23[music] And it was those two problems that led me to build Nebulock. The idea being we can
How the Security Talent Gap Collapsed into a Subscription
03:30democratize the most high lever activity in security to all organizations regardless of size, skill set or budget in a way that's flexible and integrates with the existing systems that they have. I'd say the power distribution has already happened.
03:43Much like how AI has enabled productivity for developers, it's also allowed both attackers and defenders to uplevel themselves. elite AI engineering or elite security judgment. Certainly elite security judgment that gut instinct takes a decade or more to build and that it's a very small subset of people.
04:04But a mythos allow a script kitty so a non-sophisticated thread actor to be able to do things that used to be reserved to a very elite group of people. What the actual power convergence means is not hey can I do things faster but rather the talent gap has collapsed to a subscription model.
04:28It impacts it in a cascading series of events. So it starts with the individual and then onto companies because an individual can quickly adopt AI. A company can adopt AI relatively quickly but ultimately this will go towards nation states.
04:41We see that nation states already US cyber command is using AI as a part of its components that is really really concerning but I also think like the broader more existential question is what happens when the citizen hacker when one person gets access to a mythos level model because they aren't governed by geopolitics and rules of engagement they can do what they want and I think that that will happen the number of potential threat actors is dramatically increasing you know you've gone from a you score highly sophisticated groups to honestly two people in a GPU who with
05:18enough conviction can target a company. [music] You see earlier stage companies being targeted. We've seen this in the headlines recently where growth stage companies like Verscell have had
Quitting with No salary: The $0 Test
05:30breaches. [music] That's no fault of anyone's but just when more people can do these [music] things, you're going to see a greater indication and a and a greater veracity of threats. I got to a point in early 2024 where I decided to quit my job outright and focus on this problem.
05:49There was a core moment where I genuinely asked myself, could I try and solve this problem and make zero dollars doing it? And the answer was a resounding yes. And it was at that point that I knew I was ready. Thankfully, we've been able to grow and scale as a business.
06:02I'm joined by some amazing folks. We get to partner with organizations from the Fortune 500 to growth stage security companies like Cribble as customers. Why was I okay making zero dollars and going after this? As a founder, I think what you really need to be obsessed with is the problem, not the solution.
06:19Ultimately, you build a team to help you design the solution and you validate your idea with the market to design the solution, but like you have to fall in love with the problem. [music] And to me, the problem was just so pervasive. I realized like I had to do my absolute best and you just got to show up day in day out and see like, hey, wait a minute.
06:39Is this something you can really go after? And I was fortunate that I did early market discovery that validated the thesis and ultimately allowed us to build what we've built today. No matter how right or wrong the world tells you that you are about the idea you're pursuing, as an entrepreneur, the key is that you have conviction and that you continue to back yourself up with that.
06:59I think that's really important as a founder.
How One Person Actually Hacks with AI
07:06So, do I think that cyber attackers are not just targeting governments or the Fortune 100, but normal people? Absolutely. They're able to remotely access your Google Workspace account. Once they have access to your Google Workspace account, they're able to access elements of your Google Drive and eventually are able to find a way to work their way onto your endpoint system.
07:30Once they're in your endpoint system, they can basically go wherever they want. They can move laterally and access critical cloud resources because again, they look completely normal. Those are the hardest to spot because those are the ones who in isolation have green flag activity, but it's only when you take a step back, [music] you look at the sequence of events and the context of their actions that you can actually spot a glaring red flag.
07:56Whereas about 10 years ago, cyber attackers [music] behaved in bad ways. I think that's what's changed a lot, especially since I started in security, [music] right? Attackers are going to try and blend in. They're going to log in at normal hours.
08:09They're going to [music] steal your username and password so it doesn't look suspicious or malicious. Can I distinguish what Damian as Damian versus [music] Damian whose account has been compromised? like what that actually sequence what that actual sequence of behavior looks like and based on that sequence [music] can I say
6 Steps of Cyber Attack
08:30oh that's Damian it's totally cool or hey wait a minute Damian's doing [music] something he shouldn't be he's been compromised the real concern here is everything I described is being done by one person so you don't need a team to do all of these things anymore you can do it as one very patient person so if I could draw an axis across the cyber kill chain, reconnaissance, targeting, exploitation, persistence, lateral movement, and then action on objectives.
09:01AI is already automated kind of the first three core components, and humans are being orchestrated on the last part. And then if I had like a cost on my y-axis, like the cost would be very low and then it would get very high. So you'd kind of have like killchain on your x-axis, cost on your y-axis.
09:16If I were a thread actor right now, reconnaissance basically 0. [music] Writing a fishing email also very cheap. Vulnerability exploitation is getting significantly cheaper. Establishing persistence is also relatively cheap. Right now, lateral movement and ultimately like achieving your objective still requires a human.
09:37It's a bit more expensive. A human plus an agent [music] can get there together, but you still need a human. But the first four components of that is basically automated. As attackers go to machine speed, do we think that defenders are going to machine speed as well?
09:51I think we have the opportunity to do that now.
Assume You're Already Hacked
10:00The core thread that I saw was that as defenders, we're always one step behind the attackers. In the DoD, we had to operate with the information that we had access to without knowing everything the adversary could. At Crowdstrike, we scaled that effectively on the endpoint, but the endpoint was only part of the enterprise puzzle.
10:15The same at PaloAlto Networks, right? We had the network, but that was only part of the puzzle. And then finally, from the managed detection and response side of Arctic Wolf, you had best of breed solutions, but you could only solve problems as best as the existing tools that you had, and you were responding to everything reactively.
10:34So the common thread was attackers were always one step ahead [music] of defenders. And that's because we were always reacting to alerts as opposed to proactively leaning into how threat actors might be getting around our systems. And it was that gap that prompted me to start Nebulock.
10:49That's really where threat hunting comes in. Threat hunting is analogous to cyber security operations, much like the difference between a fire marshal and [music] a smoke detector. So in cyber security, when you have an alert system, [music] that's your smoke detector.
11:08there's a fire going off and I'm alerting you that something [music] bad has happened. Whereas a threat hunter is like a fire marshal. They go into a building before the fire and they point out the risks or risk areas that might [music] be impacted should there be a fire.
11:22Threat hunting exists under the opice that you should assume a breach. You should assume that an attacker is within your environment. So does this
The Three Signs an Attacker is Already Inside Your Environment
11:30specific person with these specific permissions have access to the kind of data they're touching? For example, there are really three key things that an attacker will do that show compromise. The first is [music] there will be a slow but consistent exfiltration of data that looks much like backup behavior.
11:51All desktop files being uploaded to a personal Google Drive. The second piece will be performing outside the scope of their initial role. So the marketing intern accessing financial [music] information and then the third is at some point you will see some sort of persistence mechanism [music] that could be a remote management tool being installed so that they can access a system from any time or that might be the multiplication of accounts that they have access to.
12:25So opening up service accounts when they're a human user for example. Those are the the three things that's exactly why we exist, right? Like Nebulon is a contextual security platform. Really what we do is look at all the existing security tools that you have and we find potential threats hidden between the layers.
12:43Cyber security very quickly is becoming like an existential question which is not hey will something bad happen but when something bad happens what do we do about it? The key that we all have to accept is at some point a threat actor will target us.
12:57That's not to fear monger. It's just the reality of a world
Don't Fear AI, Fear Inaction
13:01where the democratization of cyber attacks is a reality. I would not fear that AI is going to catastrophically destroy everything when it comes to security, but rather that AI is here both to [music] create and solve the challenge for network defenders.
13:20So the sky is not falling. What I would tell them to fear or be concerned about is inaction that we don't see these warning signs and instead do nothing. So I think we have again like a very rare window to act and that whole thesis [music] that whole idea is exactly why Nebulock exists to democratize the highest leverage thing which is all about finding bad activity before it becomes like a persistent breach [music] and giving that back to the people.
13:50Yeah, I
What You Need as a Founder
13:53think one thing that as a founder most people don't think about is there's you the business person and then there's you the person. [music] Having a personal support network is really really important. I think what makes my dad so great as a mentor to me is he understands me deeply.
14:10He's my dad. I'm very fortunate in that regard to have access to someone who I have a a long-standing [music] and deep and meaningful relationship with. And he also reminds me to show up as like my truest self as opposed to hyper optimizing to be like just Damian the CEO, but rather like Damian the person, Damian the founder, Damian who wants to build an environment where people can thrive and grow and do their best work.
14:38[music] So I was not anticipating that question. It got me a little emotional. [snorts]