Risky Biz Soap Box: Stairwell will offer platform to researchers
Oct 29, 2023
auto_awesome
Mike Wiacek and Eric Foster from Stairwell discuss their platform for analyzing executable files, emphasizing its flexibility and sharing tools. Stairwell is compared to VirusTotal but offers more features. The platform is described as a 'social network for CTI nerds' with advanced analysis capabilities and data accessibility.
Stairwell offers extensive analysis of executable files, evolving into a flexible platform for selective file forwarding.
The platform integrates data sources for comprehensive threat analysis, setting it apart from traditional security tools.
Deep dives
Stairwell's Analysis Platform Evolution
Stairwell, a sponsor of this soapbox episode, initially focused on collecting and analyzing every executable file in an environment. While still offering this service, they are expanding their platform's use cases to allow customers more flexibility in choosing which files to forward. This evolution positions Stairwell as a robust analysis tool, similar to VirusTotal but with enhanced privacy features.
Advanced Data Capabilities and Cross Referencing
Stairwell CEO Mike Wysack highlighted the platform's advanced data capabilities, including the integration of over a year of passive DNS data. The ability to cross-reference artifacts, network indicators, IPs, and host names sets Stairwell apart, offering comprehensive linkages for threat analysis. The platform stores billions of resolutions, enabling detailed analysis beyond traditional security tools.
Potential Customer Accessibility and Features
Stairwell's potential to cater to individual researchers and enterprises alike was discussed, with considerations for broader access beyond current deployment methods. The conversation hinted at Stairwell's plan to offer accounts for personal analysis, enabling threat research without extensive endpoint coverage. The platform aims to provide enterprise-level capabilities to a wider user base.
Community Interaction and Security Superheroes Concept
Stairwell's unique community interaction approach was revealed, allowing researchers to share findings within a private network. The platform's goal of empowering users, from tier one analysts to advanced researchers, was emphasized. By fostering a collaborative environment and offering enhanced analysis capabilities, Stairwell strives to elevate defenders and streamline threat intelligence operations.
In this edition of the Soap Box we hear from Mike Wiacek and Eric Foster from Stairwell.
Stairwell makes a product that collects and analyses every executable file in your environment. You deploy file collectors to your systems and they forward all new files to Stairwell for manual and automated analysis. You can do a lot of really cool analysis once you have all that stuff in the same place.
But as you’ll hear, Stairwell is broadening out the use cases for its platform. You don’t want to forward files from every system? You don’t have to. It’s still very useful as an analysis platform. It’s sort of like VirusTotal, but private and with a bunch more bells and whistles. There’s also a bunch of sharing tools in the platform, which gives it a “social network for CTI nerds” flavour.
Get the Snipd podcast app
Unlock the knowledge in podcasts with the podcast player of the future.
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode
Save any moment
Hear something you like? Tap your headphones to save it with AI-generated key takeaways
Share & Export
Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode