One Amazing Thing About Cyware with Sachin Jade

Getting from insights to action for cyber threats can take anywhere from several days to several weeks, given the sheer volume and breadth of data sources and information. But what if there was a way to cut that down to hours or days? 

Welcome to One Amazing About Cyware. Today we’re talking with Sachin Jade , Chief Product Officer at Cyware and they will be sharing one amazing thing about their platform with us today.

Watch the Demo

About The Guest

Sachin Jade is Chief Product Officer at Cyware, where he leads product strategy for the company’s threat intelligence and security operations platform. His work focuses on helping organizations operationalize threat intelligence by integrating intelligence workflows directly into detection and response environments. Prior to joining Cyware, Sachin led key product portfolio including P&L and innovation at Verizon focused on CX, Strategy, Corporate Development, Partnerships, Team development & Execution around security, AI & Intelligent networks.

Sachin Jade on LinkedIn: https://www.linkedin.com/company/cyware

Subscribe to One Amazing Thing on YouTube: https://www.youtube.com/playlist?list=PL-BawE82qIM111hMVR5AJbE1uLdCMdYog


Get every episode by email: https://www.gregkihlstrom.com

Resources

Cyware: https://www.cyware.com

The One Amazing Thing with Greg Kihlström website: https://agilebrandguide.com/the-agile-brand-podcasts/one-amazing-thing-about-with-greg-kihlstrom/

Sign up for The Agile Brand newsletter here: https://www.gregkihlstrom.com

Get the latest news and updates on LinkedIn here: https://www.linkedin.com/company/the-agile-brand/

Check out The Agile Brand Guide website with articles, insights, and Martechipedia, the wiki for marketing technology: https://www.agilebrandguide.com

From the creators and host of the award-winning The Agile Brand™ with Greg Kihlström podcast, comes One Amazing Thing About… with Greg Kihlström, a show that puts the spotlight on the latest and greatest MarTech products and platforms by showcasing one feature that makes them… amazing.

Transcript

Greg Kihlström (00:00)
It can take anywhere from days to even weeks to get truly prepared for cyber attacks and understanding cyber threats. But what if there was a way to get everything together in a matter of hours to days to truly understand, get deep insights, and be ready to act, whether it’s in a manual or automated way?

Welcome to One Amazing Thing About Cyware

Today we’re talking with Sachin Jade, Chief Product Officer at Cyware and he’s gonna be sharing one amazing thing about their platform with us today. Sachin, welcome to the show.

Sachin Jade (00:39)
Thank you so much, Greg. Glad to be here.

Greg Kihlström (00:42)
Yeah, looking forward to seeing this in action in a minute here. Before we do though, why don’t you give a little background on yourself and your role at Syware?

Sachin Jade (00:49)
Yeah, thanks much again, Greg. so yes, I am Sergeant Jade, the chief product officer of Cybare. Cybare is a operational engineer of threat intelligence platform. so going from all the way from getting threat intelligence to actually actioning, and you’ll see that in the quote unquote when I show the product. Myself being in the security risk and cyber area for the last twenty odd years now in lots of different areas.

Built my own product firm as well from ground up with a good exit. And then for the last few years as a CPO of Cyber, my chite my charter is kind of threefold. One is looking at the industry and what the customers need. I’m a very customer-centric individual, so what they need. Second is the entire roadmap, the strategy around it, etc. And last but not the least, this small thing called AI.

Greg Kihlström (01:39)
Nice, nice. so yeah, before we dive in, I know you’ve you briefly mentioned what the what the product does, but why don’t you give us give us a little taste of what are you going to show us today? Who’s the audience for it? Why’s important why is it important?

Sachin Jade (01:54)
Yeah, fantastic, Greg. Yeah, so our platform, the core platform that I’m gonna show is called Cyber Intreat Intel Exchange or CITIX in short, geared primarily towards primarily the CTI team and the SOC team, depending on how it’s configured within the CSO infrastructure, so to speak, especially the maturity of the enterprise. And we’re gonna go through a quick idea of the entire whole nine yards of the day in an analyst’s you know life, so to speak.

How do they get the data in? What can they do with it? How do they look at the threat data quote unquote? How can they leverage AI in some cap in some capabilities? And then the final orchestration or the actioning that is natively built into the platform as well. So the intent is very easy, which is to make the analyst job as much easier as possible because they get overloaded with so much data that the signal-to-noise ratio has to be pretty robust and good. And so there’s a fundamental principle in my product development, which is when we bring in a feature.

Does it help the analyst do their job better? If don’t, if it doesn’t, do not bring the feature in.

Greg Kihlström (02:57)
Yeah, yeah, love it. Well yeah, let’s take a look. Why don’t you share your screen?

Sachin Jade (03:01)
Awesome. thank you, Greg, again. So let me share and let’s get the party started, so to speak. hopefully you guys can see it. So this is our you know classic dashboard that everybody sees in the beginning. And you can actually you know do the dash dashboards in multiple different areas. You can create your own dashboard, you can deliver some of the out-of-the-dash, out-of-the-box dashboards as an analyst.

figuring out what the threat data objects are, you know, PIR, which is our core new feature as well, which in you know increases the intelligence relevancy that you’re looking for, priority intelligence requirement, the attack navigator, the rules dashboard, you can you know go more and more, you can have vulnerability feeds that you can look at, you can look at certain priority dashboards. So you can look all the dashboards. So this is typically an analyst comes on day zero, he or she is starting up, he’s looking at this particular you know feed source

Seeing what are the things that are being ingested and so on. And when you look at it from an integration standpoint, because you are getting in data from different areas, quote unquote. So you can go all the way from different areas, whether it’s your classic feeds, the sticks, and the power of Intel Exchange is we are sticks native and we are the only platform that is sticks native.

And so everything makes it extremely easy for all the interoperability that is needed in the CTI space, so to speak. We’ve got API integrations if you need to. You can get the information sharing from the ISACs and the other groups as well. 80% of the ISAC market or matching modeling of 85% of the ISAC market leverages cyber product on the covers. And so from the distribution standpoint, anything with respect to the advisories, the alerts, what the individuals have to do on the other side, etc.

You can have collections around it, you can get the data from the ISACs and you can make your decision appropriately. All the other areas as well, whether it’s RSS, email, and so on. And so you get pretty much every variation of integration that you want to bring in. And once the individual is coming in, you’ve got some key capabilities around here that I would like to show. One is the risk scoring engine.

Predominantly, when an analyst is working on anything in the CDI space, they are inundated with data. And so, how do you start figuring out what the priority is? Which one do I work on first? What data is important? How do I contextualize to relevant to my a you know my domain, my area, etc.? So this is a fully fledged risk-scoring engine. There’s a default capability behind it. You can

you know, completely customize it to what all the things that you are needing, whether it’s you know what’s coming from the source, you may have certain preference in terms of the weightage that you want to give in, you can change it, you can actually write as a quote unquote you know scenarios, you can create scenarios, you can modify them so that you know exactly what kind of risk prioritization you need appropriately. And one of the beautiful things about this is which no other platform either has as well is

what we call the DK information. And what this DK is, is as ev everybody in the industry knows, indicators and threat data objects sometimes have a half life cycle, half life you know, time period, after which the efficacy of those kind of starts to break down as well. So you can create that from a DK standpoint and you can identify which one is important after a certain element and so on. So you have the entire risk scoring framework exists for you to

Edit, modify, create the scenario so that it’s the best scoring mechanism for you. Once the scoring is done, you’ve got the dashboards on the other side, the integration, the data comes in, you’ve got score have it scored appropriately, and then you go to the core of it, which is everything related to threat data. And this is, you know, you’ve got your AI engine here if you want to ask something. You’ve got your filters that you can filter by, whether it’s the indicators, the malware, the threat attackers, the vulnerabilities, all of those things.

You’ve got the query language that you can run off of as well. And the beauty of this is let’s say, for example, you’re looking at an indicator and you want to now figure out, hey, you know what, I need to generate certain summary around it. Instead of the analyst having to work by themselves every single time, you can leverage the inbuilt AI capability to generate the AI narrative that you need. Now let’s say you want to understand, hey, I need to do a little bit more around it from a analysis perspective.

We’ve got also the agent around it as well. You’ve got a whole bunch of different agents that you can leverage appropriately, you can find the contextual intelligence, you can get threat intelligence around it, thread bulletin and so on. So let’s say for example, if I go to thread bulletin agent and I say use this particular indicator and create the entire, you know, thread bulletin for me because a lot of the analysts work off of thread bulletins in one way, shape or form that can be distributed, that can be shared, that can be not disseminated to other parties who can take the information.

and take their decisions around it as well. So I can leverage this, it can keep coming in in the back, and I can you know start doing other elements as well. And one other thing in this particular space is let’s say I’m actually doing I I’m in this pay this particular indicator and I want to understand you know what are all the relationships that might be interesting to look at and so on. So I’ve got the actions here that I can

leverage, I can see it, I can send it to somebody and so on. And I can open it in a completely threat investigation canvas, which means I am looking at this particular indicator from lots of different areas. I can add the entire matrix around it. I can do analysis around it, diamond analysis, behind the scenes AI is doing certain capabilities of identifying who is using this hash, who how is the malware getting used, all of those things. So it makes the analyst job that much more easier.

And once I get the AI summary that was being created, I get a notification. I can get you know, I can go back and I can see what it created, I can edit it as much as needed, and so on. And you know, we have the identification around that piece as well. let’s go to that area. I’ve got the AI summary, it has created every single area around it, it has inferred certain things.

I can edit it if I want to as an analyst or I can share it appropriately behind the scenes, all of those elements. Now, this is the core of the thread data, which is what I’m working off of. Now let’s say you know I I want to do certain other analysis around it, and I can go back to the thread bulletins where I you know may have created the thread bulletin that came from there. I can open it up. It allows me to do all the analysis that is within this particular thread data object.

And everything here is completely configurable. So you can create your template, you can have the bulletins created, you can analyze it, you can send it and so on. Until now it has been pretty much like get the data, risk score it, identify capabilities around it that you have to take a look at, do some more further analysis, etc. And then you know, still a little bit more on the transactionary standpoint. Now

One step further, which is, you know what? I need to see if I can run playbooks and certain other capabilities within this context in an orchestration framework. So we’ve got a completely full-blown Intel operations natively built in to Intel Exchange. What that means is I can bring up any playbook that I may I may have written and I can see it, I can

Edit it, I can modify it. It’s a VisiVig, you know, quote unquote, and we have the agent tick capabilities on underneath the covers as well. You have agents, you’ve got normal playbooks if depending on the maturity of the organizations, more mature enterprises can create their own agent tick playbook as they need to. You can leverage AI to help you create the playbook as well, which means it’s an NLP-driven cap capability. You basically talk about English, you can actually talk about

know what you want as a prompt and it will start to create the playbook behind the scenes. In in in addition to that, you can go and you can actually create, you know, normal playbooks if you want to, just a WYSIWYG, drag, drop, etc. So you have all those capabilities around creating playbooks, running the playbooks, and if I just go into any one of them, you will see how the you know agent playbook also looks like. It’s the entire framework behind it. You can chat around it. You it does the

multi-agent component underneath the covers, you’ve got the tooling capabilities, you’ve got the capabilities around how to reason the analysis that is being done. You can change the prompts appropriately, you can create a custom capability, out-of-the-box capabilities, all the things that is needed for an analyst to do their CTI and SOC job in today’s world. So you’ve got this entire thing pre-baked and integrated into Intel Exchange, which means in a threat context world.

As soon as the threat comes in from different areas and you’re looking at it from an external attack surface or an external threat perspective, not only do you get the data so that you can figure out the entire whole nine yards, the duplication, the normalization, the risk scoring, prioritization, etc. Now you take it to the actioning part as well, which is the last step always, which is if you’ve identified what is important, what is contextually relevant to you.

Then you do the actioning based on normal playbooks by dissemination, distribution, and then agency capabilities as much as you need as well. I’ll give you a I’ll show you a few other things inside the inside the platform as well. This is our other fantastic capability, which is all about rules. let’s say you know you want to create any rule for that matter. What this allows you to do is anything that is coming in underneath the covers.

Again, bec depending on the maturity of the organization. If some of the organizations want to go by the traditional rule-based methodology and not yet in the agentic part, the the AI strategy is still being worked on as well and so on. You can do the classic rules-based, you can get the data that you’re looking for, you can figure out what actions you want to build on top of that, and you can completely chain it. So you can have the capability around getting the data, figuring out what to do with it, actually doing the actioning.

And multiple actions if you want to, multiple events you want to trigger based on, etc. So can the complete chain of events that you are looking for as well. and one more thing that I will showcase is our you know priority intelligence requirements module. This becomes extremely important because the theme and the concept around relevancy is extremely important to me. When I was a practitioner as well, the intent is no pun intended.

Is analyst is trying to do something with an intent in mind with an objective in mind. For example, looking at in today’s geopolitical situation, trying to figure out what might be the impact of what is happening in the Middle East and so on. So you can build your PIR as simple as from an English perspective. You can try you can write your intent, it will try to figure out the elements behind it, and it will also allow you to identify.

Other PIRs that have might have already been created. And in addition to that, what the efficacy of that PIR will be. Now, once you actually build it out, you can you know go in and it you see the health score, etc. There is multiple agents underneath the covers as well as the math that tries to identify is the PIR increasing in efficiency, getting all the relevant data, or the data is getting stale, etc., and it’s degrading because it’s not giving the right element.

your data might not be there properly, etc. So you can take an for example, if you, you know, this is a high priority with a good health score, you can get into it. You can look at the entire thing, how much of that mass intelligence exists, who are the threat actors in this particular space that are looking at it, what’s the kind of malware that they are leveraging, quote unquote, from an exploitation standpoint, and and different mechanisms that is browser extensions, imports, etc. You can see all of those things. You can see the report objects that

Are being used in this PIR as well, what kind of attack patterns that you’re leveraging? Because this is can then starts to get into the behavior of the adversary, what kind of vulnerabilities are being used in the exploitation technique as well. And when you look at the massed intelligence that goes along with this PIR, you can start to see all the different data objects, the bulletins that the data that’s coming from in the RSS feeds, all the integration that you saw in my first foray into this product demonstration.

Everything that comes in. So it’s looking at everything from a data perspective, but contextualizing it to the intent that the analyst had just put in, whether it’s with respect to threat actor, campaign, threat data objects, etc. So gives that entire whole new you know, whole line yards. the last capability that I will show, and then you know we can go back to our discussion, is

this this concept of you know triggers you can now have triggering events that you can now run off of for any of the capabilities that I just showed so that the playbook can run appropriately. Everything that we showed in in in case of the elements data the rules the actual playbook the orchestration and so on can be run off of trigger. I actually missed one more element which is what we call creation of the Intel itself.

You as an analyst, when you come on board, a lot of the times you have Intel that you’re trying to create as well. So which means that when you want to create an Intel that very quickly, instead of having to go through 20 different steps, we’ve got the classic regex plus and AI component underneath the covers. You can upload a file, you can get it from a URL, you can do a free text, you can upload the information, it will extract the

SDOs appropriately, what the metadata should be, you can add the metadata metadata if needed, and then it actually creates the appropriate relationships, the SDOs, the SROs, everything underneath the covers for any particular element that that’s needed. So that’s kind of all the elements within cyber threat intel exchange. So if I have to paraphrase it and bring us back to the equation, an analyst in a the day in an analyst’s life.

He or she is coming on board, they’re looking at the data that is coming in from several different places, whether it’s your internal information, whether it’s the asset cla the CMDB, the quote unquote your seams, your EDRs, etc., get all the information from there, all the external threat attack vectors, data information as well, whether it’s coming from your ISACs, whether it’s coming from another feed source, etc. Contextualizing, correlating in

Deduplicating it, normalizing it, the entire you know TIFF platform, so to speak. Then, in addition to that, leveraging the native inbuilt orchestrate component to help you take the last mile, which is the actioning, which is probably one of the most important elements after all the data cleansing, the everything that has been done. What is important to you? What do you do with it now that you have the right data? What do you do with it? You run the playbooks, you run agents across it, which reason, which figure out what you need to do, how do you do it, etc.

And then create the metrics around it. You want to build the dashboard appropriately, both at the exec level as well as the analyst level in his or her day’s life. And then finally wrap it up with our core concept called the PIR, which everything which brings everything together, which is what is this relevancy of this threat intel, how does it map to a mitre quote quote unquote? What are the malwares? What are the thread data objects that are involved in it and how the analyst can then take it forward.

So that is in in a nutshell in the last twenty minutes or so. Hopefully that gives you a pretty good idea of what Cyber Trendal Exchange platform is. It is making the analyst in the CTI or the SOC team much more useful in terms of what they can deliver in a day’s life.

Greg Kihlström (19:35)
So I mean, you know, from from my perspective, I’ll I’m a little less familiar with this area of of the business than than some others. But I mean it it sounds like, you know, a a big part of the analyst’s job is just, you know, even pulling information together and and getting to the point of having insights about those

that information, but you know, it sounds like you know you’ve built something that enables getting to the action part of it and not just generic action, but very specific actions that can either be manually done or or automatically triggered. So I would imagine this saves a considerable amount of time on the the parts that an analyst maybe it’s required of them to do, but they get to spend more time being strategic and

being thoughtful about what happens, right? Yeah.

Sachin Jade (20:23)
Hundred yeah, hundred percent. Hundred

percent. so day day zero operationalization of this that you know prior to this platform, so to speak, would take anywhere from four to six weeks because you’re trying to get the data, then you’re trying to figure out what the algorithm

Greg Kihlström (20:37)
Yeah.

Sachin Jade (20:38)
should be for the risk scoring, then how do you prioritize it, etcetera? It’s now down to like a couple days because everything is baked in, everything you have out of the box rules, out of the box templates, everything to that gets done. And once the analyst also has now said, hey,

my you know quote unquote apps that I connect to because our Orchestrate platform has already four hundred plus integrations already built in. So if you say, hey, I’ve got a Splunk or I’ve got a CrowdStrike, I’ve got X and so on, those integrations already exist. So for the analyst then it’s like, yep, you know what, I figured out what the thing should be blocked or which you know device should be patched. Let me tell CrowdStrike, patch this, or let me tell FI firewall, block it. You’re good to go.

Greg Kihlström (21:19)
Yeah, yeah, love it. Well, Sasha and thanks so much for sharing this with us today. if people want to learn more information about it, where should they go?

Sachin Jade (21:29)
first of all, yeah, thank you so much for having me, Greg. hopefully the audience loves what we have presented in terms of both what they’re trying to do as well as how we’re kinda going forward. Yeah, if you want to know more about this, absolutely go to our website, www. dot cyber dot com. All the information with respect to products, even booking the demo, etcetera, is there and I look forward to that.

Greg Kihlström (21:49)
Well again I’d like to thank Sachin Jade, Chief Product Officer at SciWare for joining the show. You can learn more about Sachin and SciWare by following the links in the show notes.


The Agile Brand Guide®
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.