Down the Security Rabbithole Podcast (DtSR)

DtSR Episode 716 - What if Context Replaced Alerts Entirely

Guests: Jason Vest, Josh Neil Season 16 Episode 716

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 32:47

Guests: Jason Vest & Josh Neil

TL;DR: Alert fatigue is still a problem; detection isn't generationally better - but we have all this AI. So what gives?

Description

Alert fatigue is not just a workload problem; it is a product design problem. We dig into a provocative claim sparked by a LinkedIn post: today’s “AI SOC triage” can be a band-aid if it only cleans up alerts after the fact instead of improving threat detection where it starts, in raw telemetry and early signal extraction.

We’re joined by Jason Vest (CTO at Binary Defense) and Josh (a statistician with experience from Los Alamos, the Department of Energy, and leading the Microsoft Defender for Endpoint data science team). Together we unpack why rules and detection engineering still matter: they encode what we know is bad, but rigid rule matches and atomic alerts can also trap teams in an endless false positive vs. false negative trade-off. Josh goes as far as to argue that alerts should “die in a fire,” pushing us to think in terms of attack stories and enterprise-wide context, not isolated hits.

From there we explore what actually scales: when anomaly detection works, why “model everything” breaks down, and how trigger-based just-in-time modeling can build lightweight models on demand, score the nearby context, then disappear. We also talk about moving from alerts to “situations,” using agentic AI to gather more context across identity, endpoint, and network, plus what transparency should look like for model validation and community standards.

Subscribe, share this with your SOC team, and leave a review. Where do you think detection should evolve next: better rules, better models, or a world without alerts?

YouTube Video: https://youtube.com/live/GYjePXCiKM0

Have something to say? Let's hear it.

Support the show

>>> Please consider clicking the link above to support the show!
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
YouTube home: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHq
LinkedIn Page: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/
X/Twitter: https://twitter.com/dtsr_podcast

Welcome And Guest Backgrounds

SPEAKER_00

Good morning, good afternoon, and good evening. Welcome down the security rabbit hole to yet another edition of the Down the Security Rabbit Hole podcast, cybersecurity's favorite podcast. 700 plus episodes and a lot of years running. Thanks for listening. Good to have you aboard. I have an interesting topic of conversation today, as I say often, these pod some of these podcasts just start with a really interesting blog post or something interesting in the conversation stream in LinkedIn. This one came from LinkedIn. I saw Josh post something, thought, huh, that's interesting. Grab another friend of mine, Jason, and we decide let's talk about it. So, first and foremost, introductions. Jason, go ahead first.

SPEAKER_03

Thanks, ref. Good to see everyone. Jason Vest, CTO at Binary Defense. Come through security by way of some time in the Air Force in the back end of the AWAX Airborne Warning and Control System, followed by some time as a special operations pilot. Did some work doing digital forensics for the government, Child Rescue Corps, uh special program there, and then pivoted into a cyber career done consulting, ran security ops for companies, and now playing at Binary Defense, trying to keep up with Dave Kennedy and all the fun things he's doing there. So I'll pass it over to you, ref.

SPEAKER_00

There there is no keeping up with Dave Kennedy. It's it's like uh it's it's like somebody gave a squirrel way too much Red Bull, and it's just you know, dogs go squirrel. No, squirrels don't go squirrel. Squirrel just go. There's no keeping up with Dave. I now know firsthand.

SPEAKER_03

But first place for the Yeah, first place for the performance review is based off of how much you grew your biceps in in the previous year as well. So that would be I love it.

SPEAKER_00

I I'm I'm working on it. I'm nowhere near you.

SPEAKER_03

Yeah.

SPEAKER_00

All right. Wow, before this gets weird. Josh, go ahead.

SPEAKER_04

Sure, yeah. Thanks, Raf, and thanks for the opportunity. I've enjoyed your podcast for a long time now. So it's it's great to be on. I am a statistician. And I started my career at Los Alamos National Laboratory. I spent 15 years with the field intelligence element of the Department of Energy, which means we protected U.S. national security secrets and also worked with the Five Bys. After a brief stint at Ernst and Young, they had licensed some of the technology I invented. So I went over to Big Ford Consulting. Then I ran the Microsoft Defender for Endpoint data science team for several years, chief scientist at Secure Onyx, and now founder of Alpha Level.

SPEAKER_00

Love

AI Triage As A Detection Band Aid

SPEAKER_00

it. So as I hinted at the beginning, there was a uh you put up a relatively interesting, uh caught my attention anyway, LinkedIn post on detection AI. Give us a quick summary and we'll we'll kind of jump off from there.

SPEAKER_04

Yeah, it was meant to be a bit salacious. I tend to be a little bit uh salacious in that, you know, I claim that AI sock as it is today, or maybe more particularly automatic alert triage, is a band-aid on a problem that is actually earlier in the detection pipeline. And that is that we're not very good, or we could be a lot better at pulling the raw signal out of the noise earlier before the alert is created, and that a lot of this sort of effort to fix up our alerting is artificial, and that where we should be focusing much more energy is earlier in the threat detection pipeline. Okay, I could go on, but I'll pause there.

SPEAKER_00

Yeah, Jason, any any thoughts on that?

SPEAKER_03

Yeah, no, a lot of thoughts. And now that I hear your full background, Josh, I'm just gonna walk away and give you the floor. But uh no, that I'm curious to dig into that a little bit more, Josh. So are you saying earlier in the detection lifecycle, we're moving away from or moving towards things like anomaly detection and you know the big data model, where some of the people are like, send it to my black box and then let me apply data science? Are you saying changing the perspective, changing where you put the data together at the source? Like now, obviously, with AI, you can everything through API connectivity, you have access to the data. So I'm curious, are you part of what you're spurring here is is the question, which I agree with. It should be changed. We're definitely missing the mark, honestly, re-engineered because of what we can do with AI. But yeah, curious, curious what your thoughts are there.

SPEAKER_04

Yeah, let me try to say something cohesive or coherent. So rules encode expert knowledge and therefore are fundamental and profoundly needed. We gotta have the encoding of what we know is bad. Actually, in the early part of my career, I wasn't sure we needed that, but I have matured in my old age and admitted to myself that an army of expertise, which is looking at the threat landscape, determining what queries, basically rules we need to develop to us to encode that expert knowledge, is uh is absolutely fundamental and required. Whether that detection engineering is done by a human team or an AI team, I'm happy. We we need to encode what we know is bad. Okay. But that's where we stop a lot of the time, and that's insufficient. Rules tend to be fairly precise in that you know I can write down a thing I know is bad and then go search the data. I well it they they can be very rigid, or they are rigid in that if it doesn't exactly match the thing, I'm gonna miss it. Of course, the adversaries are motivated to do something that we didn't know about because if they do something we do know about, we're gonna catch them. So you can you can be pretty precise about what you know and then have low false positives, but then you're gonna have a lot of low of a lot of false negatives because you've been so precise in the definition of your rule. On the other side of the coin, you know, you can be fairly general with with Boolean logic or a rule or a query, and then you're gonna get a lot of false positives because it's too general. And what I've sort of observed over my career is that finding the sweet spot between those two is is kind of impossible. You can't ever really get that right. So, more more broadly, I don't think we should stop at presenting an atomic match with a known bad thing or suspected bad thing to a human or AI analyst. I think that's or here's something, I'll try to say something salacious.

Why Alerts Should Die

SPEAKER_04

I think rules, I think alerts need to die in a fire. Okay, let's see if we get some podcast folks to argue with me on that. But showing stopping at that point and showing either a human or an expensive AI, that alone is ridiculous. Okay, so then the next thing that we do is, and I helped build the XDR for Microsoft, is write rules to combine stuff together. Okay, and that's what you might call an XDR. And now I can combine multiple of these relatively weak signals together and not show an analyst or an expensive AI, you know, the individual atomic things, but hopefully eliminate a bunch of false positives by combining stuff together and getting consistent evidence that this is all pointing towards an attack and malicious. And that should reduce false positives and accelerate analysts in arriving at the true positives. What did the attacker do? What's the kill chain? What's the attack story? What holistically, what did they do? But again, that rigidity of the predefined rules for how one combines things together. If I see, you know, the stupidest thing that most XDRs did right out of the beginning was okay, if it's the same user with two different alerts within five minutes, combine them together, right? And that that's a that's again sort of a static way of defining, you know, what to do with all this telemetry. I'll provide an alternative.

Dynamic Context Beats Static Detectors

SPEAKER_04

The context available to determine whether something is malicious or benign is is only there when the action's happening. Pre-defining what to look for, well, who knows if it's true or false until you have the context of the whole enterprise at the time that that thing happened. So I think generally one of the innovations that I'm happy to see in terms of AI triage is that there that is a process that's examining the context around an alert at the time that the alert happens and not at the time that the detector was defined. So I think that's profound. Whether we use a large language model or an agent or some other technology, the important thing here for me is that we're looking at the dynamic context available at the time of the alert as opposed to pre-defining everything at the detector definition time. And now I'll just stop because I said a whole bunch of stuff and I'll just pause.

SPEAKER_03

Yeah, no, that I mean, at face value, I'm I'm tracking what you're saying. And that's where Raf and I were discussing potentially maybe some alternate approaches. It's kind of like when we talk about about six months ago, people were saying what we're seeing out of AI is probably going to fulfill the promises of SOAR. Now I would say six months fast forward, AI is obviously what you can build with AI, some of the ways you think about workflow, some of the things you can do with AI, it's probably going to make SOAR irrelevant. And I would I would argue the same approach to how we've looked at detection engineering as a community. We don't need AI to make detection engineering better, to make our behavioral detections tighter. I think we actually need to step back and approach how we look at, like you said, and this is where we agree, the entire context. And the context is a lot greater than what you see in a sim. With what you can do with agentic technology as well, you can go get more context than we've ever been able to get and put all of that information together, make a decision, go get more information, make another decision all immediately, something that a human couldn't do. So, because of that, it's kind of like if you think about AI, in my opinion, is one of the biggest transformations since I've heard somebody say since gunpowder. Like, we're talking about muzzle loaders here, how we look at detections. Let's put gunpowder in a muzzle loader. We're not even into like a 50 cal Barrett, or we're not even too like the M4 semi-automatic.

SPEAKER_00

I like these re-engineer.

SPEAKER_03

Yeah, there you go. We need to re-engineer as a security community. Now we have all these tools available. Is in and the way some of the things that the people I'm working with are looking at is we're calling it a situation. It's not a detection, not an alert, not alarm. I love when you said alert should die. And obviously, you know, we'll see where the sims go and the sores go from there. But at the same time, let's get the information and then let's apply a new application of determination. We're going, we're going with situation. Well, it's the situation, but obviously that's just tons more context than we've previously got in the past.

SPEAKER_00

Yeah. Hey, can I can I throw in? Because I'm probably you you guys I qualify me for the ability to talk intelligently here, but I I'm gonna throw uh an every man's comment here. Uh, I think when I think about detections, right, there's still some fundamental way we have to figure out what's what's normal, what's abnormal, what which one of these is not like the other, what doesn't belong. I think the the the identifying bad, and everybody used the like the bouncer example in a nightclub, like determining what was bad probably stopped being useful around the time of semantic antivirus in about 2002, right? Like we went from hundreds of thousands to tens of thousands to hundreds of thousands, and like it just became impractical. Some version of that persists today. But with all the machine learning and the ability to create statistical models based on which assets do what kind of communication at what time, in what way, with what payload, over what protocols, in what duration, like all of these things, these metrics matter. And when you start modeling this, do we have the uh do we have the horsepower to do this kind of analysis at a scale that could look at like a typical, we'll say a typical mid-sized enterprise and model all of their traffic? Because I imagine that from a statistical perspective, that model gets really, really large, really, really fast. Is it is it economical? Like is it feasible?

SPEAKER_03

Well, this is definitely Josh, you're gonna have a great answer with a data science background, but this is what people have been trying to do with data lakes, data science, anomaly detection pre-the AI boom recently. So, yeah, Josh, I I'm very curious to hear your perspective on how you're actually enabling this.

Why Always On Modeling Breaks

SPEAKER_04

Well, so I mean, that's what my PhD dissertation was on was modeling of network pairs of communicating computers and then forming them into a graph and identifying lateral movement. It's basically anomaly detection. And then as a young uh starry-eyed researcher, I thought, okay, let's let's have a model for everything. And the models are running all the time, and they're updating, self-updating. We're methods and statistics for exponentially weighting the past and learning the future and forgetting the past and very sophisticated stochastic process models that I think have been poo-pooed because AI is a shiny thing, but this is very sophisticated mathematics and statistical modeling. And so I, you know, had this ambition that I'm gonna take over the world with models for everything. And I'm gonna have a score for any time something significantly changes. The probability that this is coming from the model is very low, right? And so I've learned what's normal, excuse me. And then and then I can score everything in the entire enterprise. Yeah, that doesn't that doesn't scale. You nailed it rough. That's that's expensive and noisy, and you're subjecting yourself to false signals a lot, and there's something called the multiple testing problem that will basically magnify your errors if you do this and stuff. So that's uh that's something I had a go at, and then was sort of had to think more deeply about it. Nowadays, where I'm at is sort of triggers. So consider that a rule could be a trigger, uh, an alert could be a trigger, or more generally, what I have what we do is sort of just in time modeling. So we get something that causes us concern. And I'll give some examples. So a rule or an alert, an anomaly on some some subset of data, for example, authentication data, logins. Okay, yeah, we probably should have models for every user. This is the UEBA thing, have that running all the time. That you can afford that. You got 200, you know, 20,000 models for a 20,000-person organization or something like that. And you can you can with Spark and some good hardware, you can keep up, and it's not too expensive and so forth. And then those anomalies would then trigger or alert matches or something else, would trigger more deep modeling. Now, then the models need to be lightweight enough that they can be estimated on the fly. Right. Like within five milliseconds or something, it models up and it can score the data that is in front of it, and then die. And you get the score, and then you can combine it with other scores and stuff, but you don't have to maintain the model for scale at all times. You you kind of use some triaging of lightweight, inexpensive models on certain things, plus probably the rules, take those alerts, those are very valuable, and that can be the triggering system for scaled anomaly detection wrapped right around the anomaly or the alert. Just look around it. You know, what did the what did the user log into? What what processes did that machine run? What other machines connected to it? And maybe like a one-hop or two-hop context graph around the trigger is sort of the is sort of the idea.

SPEAKER_00

That sounds good at a interaction level based on either I think human or maybe even machine, right? At a what where am I logging into from an identity perspective? What am I doing? I think that that starts to fall apart in terms of just the the sheer capability and the sheer model size required. We're talking packets, right? Yeah. When you look at like a system or an IP address on the network, let's take it down. Let's look at a MAC address on a network, right? It pulls an IP address, it starts doing stuff. It's never like a packet, a packet, a packet, a packet. It's like you know, 10 meg, 20 meg, 10 meg, 5 meg, 1 meg, 200k, 200k, 10 meg. Like it's doing rapid exchange of packets. Modeling that with all the bits that that requires in terms of right, like it, like the source destination, report protocol, payload size, you know, all that, like all even if we scale that down, I think it's doable on a smaller scale, but it it it it starts to collapse when that model gets huge. And and there's no, I don't think there's a way to build it just in time.

SPEAKER_04

Well, I'll I want to Jason, I'll give you Jason you some space. Let me just jump in for a second, because this is actually my dissertation work. So I like really strongly about network modeling. So certainly stay at the metadata or net flow sort of router collected layer four statistics on connections, right? You can't afford to, but I'll give you a head trip. Look, I think every electron that we could measure, electrons of an enterprise has some probability of being malicious. So where do we so where do we start worrying? Well, we got to be practical about that. Get to some level of resolution, logs, metadata, raw packet content. Yeah, that's for a monitoring system, that's very expensive. You want to have these things go to some static analysis. So once you find there's evidence, okay, you can get a payload and reverse engineer it or something. That's a very expensive manual process, but you don't do that in a monitoring, scaled monitoring setting. Yeah.

SPEAKER_03

Yeah, no, I think I think we're

Triggers And Just In Time Modeling

SPEAKER_03

on to something. Thank goodness it's your your dissertation, Josh, because uh there's some credibility behind where we're headed. But what I'm seeing too, it's it's kind of funny the ramp up of, like I mentioned, with let's do a data lake so we can do our own anomaly detection, or even some vendors use that as their way to find outlawers. Again, that's just based off of single points of context. For the most part, there's some behavioral patterns in there. But then we really open the aperture with what we can do as far as a behavioral analysis of all the context. We're not just looking at network traffic, we're not just looking at endpoint traffic, we're looking at behavior across an enterprise of an attacker and building models around that. So, like just take an isolation forest, for example. I mean, in the most simple form, you're just isolating anomalies. Now we've moved into a space where we can gather a lot of this information, go get more information if we need it, bring it back to some of this data science approach. And what's funny about it is we're experiencing that too, is you've ramped up a lot of AI technology and AI expertise. But guess what? You still have to go back to traditional data science to do something with it. And so that the door is revolving around and that factor. But they they really are dependent on each other. I just don't think we're thinking big enough with what we can get our hands on with AI to apply and re-reinvigorate some of the original data science work that we've learned. And that's I think where Josh was headed. So yeah, I'm excited. And it was in the post a little bit, it's in your dissertation. In that context, is again our we're very much narrow focused on the traditional behavioral detections, the traditional data we have. And as we all start training our private models and we look for new ways to detect malicious activity again, like calling maybe like a situation where you're looking at what happened the past 24 hours, 48 hours, past week, and you're able to make a decision based off of that, and it's not just one data source. That's like thinking big. That's like getting out of the muzzle loaders and into the 50 cal, right?

SPEAKER_04

Something like uh gunship. There you go.

SPEAKER_03

AC130. That's a that's a good one. Yeah, yeah.

SPEAKER_04

So infantry support.

SPEAKER_00

You guys remember the days where we went from like in so in security, I feel like we've we've the pendulum has swung multiple times. We went from log everything to oh my god, that's too much, select what you log selectively, turn everything off until you need it, to this is the cloud, log everything. Space is unlimited, space is cheap to oh my god, we don't even know what to do with all of this, stop logging. Where are we now?

SPEAKER_03

Yeah, yeah. Well, now we're by data management, so we can we can minimize but still have access and control the data pipeline to save money. But then no, that's a good point, ref. And and I'll second that with another topic that's similar as a security community that I think is worth noting. And this just like we were with Red Intel and sharing, if we can come to a point where we share some of these AI models and AI concepts as a community and and don't move into you know monetizing it over basically advancing the community, we could really and I bring this up, and this is what happened just by necessity in the 90s with the fraud space. They had to come up with a model, otherwise, the credit card, you know, one in a hundred transactions at in the 90s, I think, was was fraudulent. If they didn't work together, it wouldn't have survived. Um, you know, I'd like to see the same with some of our AI modeling and these discussions that we're having with Josh, like for us all to come up with something we're able to work on together.

SPEAKER_04

Yeah. Yeah, generalized modeling frameworks are attractive to me, you know. So, you know, if I could provide the community with you push a button and a million models get built, run on the data, give you scores back out. Now you've got a tool you can apply to lots of use cases, right? And and we've done some of that, but uh, you know, the well I'm I may be digressing from you guys' point, but the I have not I have a very high bar for what's a good model, and I have s been a part of less than good, you know, modeling. And the there's a reason that the hedge funds pay a quant, which is sort of my profession, sort of a statistician, sort of if I wanted to make the most money I possibly could, I'd do that. But they you know, these these people are making seven figures, and the reason is that they're very, very good at modeling. Modeling is actually a very hard thing. You you have to understand the aspects of the day that matter, what we call the data generating process. And I think we have underestimated that as a as a security industry. And I haven't I've seen engineers, and I am almost an engineer myself. I have a I've I've hang out with engineers, I write a lot of code, but we have used engineering trained folks for something that's really the domain of another specialty, and and I think that's a natural consequence of IT security was born from IT, which was born from computer scientists. And so now they build a lot of the machine learning and stuff. But we I yet to see very high quality stochastic process models applied to threat detection, except what I've been doing. And now I'm probably gonna get an email from somebody that's listening to say, I did it, and here's my work, and it's good. And so I don't mean to insult anybody, but broadly I think we've not done well enough. And these packages, you know, like just use the latest whatever isolation forest or whatever, and apply it to the data and see what you get. I think we can do better than that, but it actually takes skilled people to do it.

SPEAKER_00

Well, people like Yeah, I've I've repeatedly heard the quote, all models are bad, some are useful, right? Yeah, that's tough.

SPEAKER_04

That's that's a statistician who said that.

SPEAKER_00

Yeah, that's right. And and and I I I have a particular love for creating models of things because behavior behavior is an indicator. At least it's not a it's not a conviction, but it's an indicator. Just because I'm walking in that direction doesn't necessarily mean anything. It's just it gives you some weight or some direction or some you know, some idea. I I I don't know where this where this ends up in the future, because I like the idea of creating a series of models that's like essentially opened to the community to to raise the raise the tide so all boats lift, right?

Model Validation And Community Cooperation

SPEAKER_00

Do we I'm gonna ask this. I know the answer to this, I'm gonna ask this anyway. Do we think this industry can stow its ego long enough to cooperate?

SPEAKER_03

That's a great question. Well, it before I answer that too, I I would say because I I would say I wish we could, and I'll be a proponent of that. But it goes back into transparency of AI, what you're using. And the question should be to vendors can you show me your model validation process? Right? Why would we trust someone to protect our environment when I'm a buyer if I can't show you how something as simple as I validate my models? And if there's not a governing standard to do that, should we create one as a security community and then in that use that as an opportunity for collaboration? You know, that might be a gate into it. Yeah, I I mean I think we've done some of that. We tried to do some of that with Red Intel sharing and different different models there between the diamond model and some of the other things we do with taxi and sticks. I think with AI, it's going to be birth. And yeah, RAF, I mean, if I had my way, we would do this as a community and not as a as a vendor-led approach.

SPEAKER_00

Yeah, I think I think that I think there's a there's a certain for the common good, we must, dot, dot, dot, right? And then we can monetize on top of that the implementation of and the things around it. But at some point, when you have when you have the formula for the cure for cancer, it needs to be opened to the world because the greater good has to win. I I I've been doing this for long enough to know I don't think we have enough, I don't think we have enough integrity as a as a community at large. I'm sure I'll get plenty of hate mail for this, but I just don't think as a community, by by and large, because of the money involved, we'd rather continue to sell aspirin and and and help the you know help the patient feel comfortable while they're while they're slowly decaying rather than helps address the root cause. But that's my cynical opinion. I'll tell you what, we're down on time.

Final Words And Listener Reviews

SPEAKER_00

So I'm gonna give you guys you know 60 seconds, kind of final word on this. And since since you opened, Josh, I'm gonna give uh Jason, I'll I'll give you a minute to to give me what your thoughts, and then we'll go to Josh and then we'll close.

SPEAKER_03

Okay, yeah. Great to meet you, Josh, and we'll we'll stay in touch. A lot of fun topics there. Thanks for the time, ref. And I'll just kind of close on, you know, I I I'll tell you what, I'll be optimistic, Raf, because you do watch the CISO community as a whole. We're stronger together, and I think that has evolved, you know, at least for the the companies I've worked with too on the vendor side, we'd rather make the world a safer place than than put monetizing things over. So I'm gonna I'm gonna leave that on optimistic approach that as we launch into the future here with what we're doing with AI, uh, we're going to be willing to share if we've got a you know a model that we think is is the pinnacle and it's gonna help. You know, I I could see some ways for us to share that and get that out there and collaborate with guys like Josh, for example. So I'll I'll leave it with that. But yeah, this is a fun, fun, fun pod. Thanks, ref.

SPEAKER_04

Yeah, it's good to me too, too, Jason, and and I detecting a friend and and collaborator. So I'm happy about that. And I've always been an open source guy, so I I certainly echo that sentiment. I'll I'll sort of go back to the original thesis and just remind everybody that yeah, I I I think we have a lot more work to do in the in the left. Raw telemetry, threat detection, extract a signal from the noise. And I want to educate or remind the the community, don't forget about that because I think that's where we're gonna get the biggest bang. And that the AI for trio for system two, sort of triage, automatic response, SOR functions, great, amazing, but we're not done with that system one threat detection bit. There uh there's my thesis.

SPEAKER_00

I like it. That's a good place to end. Josh, thanks so much for spending your time and sharing some of that. Jason, thank you for jumping on and giving us some of your time. And of course, thank you for joining us and listening along. If you get a chance to drop us a comment, leave us a review, let me know what you think of the show. These guys are on LinkedIn, you'll find them both. I'll post in the uh show notes for those of you that read the link to the original LinkedIn post so you can follow that along. And uh, until next time, we'll catch you guys another time, another place on another down the security rabbit hole podcast. It's Jennifer. We'll see you guys later.