Risky Biz Soap Box: Mike Wiacek on lazy mode threat hunting
Jul 17, 2024
auto_awesome
Mike Wiacek, CEO of Stairwell, discusses file analysis for threat hunting. Stairwell provides transparency and customization for malware analysis and file relationship identification. The importance of active threat analysis, APIs in security tools, and automating threat hunting are key topics. The podcast also addresses the challenges in threat reporting and advanced malware detection.
Stairwell's unique file analysis platform enables efficient threat detection and tracking within organizations.
Using a customizable and programmable security stack like Stairwell promotes proactive security measures and trend identification.
Deep dives
The Concept of File Analysis as a Security Tool
Stairwell, founded by Mike Wierssek, offers a unique file analysis platform that enables organizations to analyze and track every unique file within their system for enhanced security measures. By collecting and analyzing files in real-time, users can swiftly identify potential threats, track file movement within the network, and uncover file relationships to detect and address security issues effectively.
Addressing Data Overload and Signal Extraction
Stairwell's approach contrasts the massive volume of log data typically stored by organizations for security purposes. By focusing on collecting unique files instead of logs, Stairwell streamlines data analysis, providing valuable insights into file contents and behavior. This allows for more efficient threat detection, prevention, and response, offering a clearer and more actionable view of potential security risks.
Empowering Proactive Security Measures Through Advanced File Analysis
Stairwell's platform empowers security practitioners to shift from reactive to proactive security measures by enabling deep file analysis, threat hunting, and trend identification within their own organizations. The tool's programmable and customizable nature enhances flexibility and transparency in security operations, allowing users to perform detailed file analysis, threat detection, and response without solely relying on external security tools or black box solutions.
This Soap Box edition of the show is with Mike Wiacek, the CEO and Founder of Stairwell.
Stairwell is a platform that creates something similar to an NDR, but for file analysis instead of network traffic. The idea is you get a copy of every unique file in your environment to the Stairwell platform, via a file forwarding agent. You get an inventory that lists where these files exist in your environment, at what times, and from there you can start doing analysis.
If you find a dodgy file you can do all the usual malware analysis type stuff, but you can also do things like immediately find out where else that file is in your organisation, or even where else it was. From there you can identify other files that are similar – variants of those files – and search for those. And you can unpack all this very, very quickly.
This is the type of tool that EDR companies use internally to do threat hunting, but it’s just for you and your org – you can drive it. And as you’ll hear, the idea of a transparent, customisable and programmable security stack is something that’s on-trend at the moment. Mike lays out the case that doing this sort of file analysis in your organisation makes a whole lot of sense.
Get the Snipd podcast app
Unlock the knowledge in podcasts with the podcast player of the future.
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode
Save any moment
Hear something you like? Tap your headphones to save it with AI-generated key takeaways
Share & Export
Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode