WEBVTT 1 00:00:10.093 --> 00:00:15.557 Hey everybody, this is Christian Galladora I am the principal business development engineer here at ThreatQuotient. 2 00:00:16.057 --> 00:00:20.353 I'd like to show you some of the work we've done towards our PolySwarm integration. 3 00:00:20.353 --> 00:00:22.272 It's a very cool capability here. 4 00:00:22.689 --> 00:00:24.482 What is PolySwarm, first of all? 5 00:00:24.733 --> 00:00:27.694 It is crowdsourced threat detection 6 00:00:28.028 --> 00:00:32.866 and so folks are able to look up scan files URLs, 7 00:00:32.907 --> 00:00:36.077 do a little bit of sandbox type activity, historical hunts 8 00:00:36.202 --> 00:00:38.413 leveraging the PolySwarm marketplace. 9 00:00:38.580 --> 00:00:44.044 And they are effectively able to use many different engines and different data sets 10 00:00:44.085 --> 00:00:47.964 to make more informed determinations about what they're looking at. 11 00:00:48.131 --> 00:00:50.717 And I'd like to show you what that looks like in our platform here. 12 00:00:51.384 --> 00:00:54.345 In this case, we're looking at a SHA-256. 13 00:00:54.763 --> 00:00:56.306 It's been identified here 14 00:00:56.639 --> 00:00:58.767 by one of our threat Intel providers 15 00:00:59.100 --> 00:01:00.727 But one of the things we could do here 16 00:01:01.061 --> 00:01:04.397 is ask PolySwarm “You know, what do we know about this thing?” 17 00:01:04.731 --> 00:01:05.732 Can you scan it? 18 00:01:06.149 --> 00:01:07.400 Do you know about it already 19 00:01:07.734 --> 00:01:08.735 and in this case 20 00:01:08.943 --> 00:01:11.362 you could see we could jump to the PolySwarm scan 21 00:01:11.529 --> 00:01:15.742 but most of the data I need is going to be right here in ThreatQ 22 00:01:15.992 --> 00:01:18.328 I could bring in additional indicators 23 00:01:18.995 --> 00:01:23.041 different types, filenames, there's associated URLs, and so forth. 24 00:01:23.625 --> 00:01:26.503 I've got the context here 25 00:01:26.878 --> 00:01:29.839 I could bring all that in and I've got my verdicts from my different engines. 26 00:01:30.507 --> 00:01:33.635 All of this data is now brought into my threat library 27 00:01:33.927 --> 00:01:40.058 and I'm able to use it within the context of my scoring policy to reprioritize things that matter to me 28 00:01:40.308 --> 00:01:44.062 and make sure that my infrastructure and teams are able to use that. 29 00:01:45.438 --> 00:01:48.233 Now another cool capability that PolySwarm has 30 00:01:48.608 --> 00:01:50.860 is the ability to use signatures 31 00:01:51.069 --> 00:01:53.154 to do hunting style activity 32 00:01:54.155 --> 00:01:56.825 You could do live hunting. You could do historical hunting 33 00:01:57.158 --> 00:02:01.412 but we've actually integrated this capability within ThreatQ here 34 00:02:01.704 --> 00:02:04.040 so in this case I've got a Yara signature 35 00:02:04.374 --> 00:02:07.877 and one of the things I could do here is launch a historical hunt 36 00:02:08.378 --> 00:02:10.964 and so I could send this over to PolySwarm 37 00:02:11.422 --> 00:02:17.470 and I could then jump straight into their console and see the results of this communication here. 38 00:02:20.849 --> 00:02:22.100 You could see in this case 39 00:02:22.392 --> 00:02:26.354 we're pending our historical hunting activity on this YARA signature. 40 00:02:27.522 --> 00:02:30.692 Additionally, we could leverage their sandbox capability. 41 00:02:30.984 --> 00:02:33.319 In this case I've got a spearphish attachment 42 00:02:33.695 --> 00:02:36.406 and I'd like to send it out to be scanned. 43 00:02:38.283 --> 00:02:42.829 And in this case, we might take a little bit because I've selected to wait for the response. 44 00:02:43.329 --> 00:02:44.956 So while we're waiting on that 45 00:02:45.290 --> 00:02:50.879 let's look at some of the other indicator types available to this type of sort of scan look up activity. 46 00:02:51.379 --> 00:02:53.590 We could do queries on CVEs. 47 00:02:54.132 --> 00:02:57.302 These we could do queries on FQDNs, URLs. 48 00:02:57.760 --> 00:03:01.139 You could see some of that here with this FQDN 49 00:03:01.598 --> 00:03:04.559 doing a metadata search or doing a look up as well. 50 00:03:07.145 --> 00:03:09.314 In this case, again, we've got our indicators. 51 00:03:09.647 --> 00:03:11.691 We've got our contacts. We've got our verdicts. 52 00:03:11.983 --> 00:03:14.652 This one looks pretty good to these engines here. 53 00:03:15.236 --> 00:03:17.405 Let's see if we have anything on the metadata. 54 00:03:20.742 --> 00:03:24.454 And we could seamlessly jump into their platform to view our results. 55 00:03:31.294 --> 00:03:33.087 Lastly, I'd like to show you 56 00:03:33.296 --> 00:03:37.634 this is what the configuration looks like and if it looks pretty minimal, that's because it is. 57 00:03:38.218 --> 00:03:40.929 So we showed the Yara capability here, 58 00:03:41.095 --> 00:03:45.516 that's the ability to use signatures for live hunts, historical hunts. 59 00:03:45.892 --> 00:03:48.686 We've got these indicator look ups that we can use 60 00:03:49.312 --> 00:03:51.356 to search the Poly swarm data set 61 00:03:51.856 --> 00:03:53.316 get detections or verdicts. 62 00:03:53.816 --> 00:03:57.445 And see what they have on all of these different indicator types 63 00:03:57.779 --> 00:03:58.905 and attachments 64 00:03:59.072 --> 00:04:01.616 being able to send these up for scanning 65 00:04:01.824 --> 00:04:06.454 and quick retrieval of the context around those behavioral analysis 66 00:04:06.788 --> 00:04:09.624 And so I'm very excited about this integration. 67 00:04:09.916 --> 00:04:12.252 I look forward to it on our marketplace.