CYBR.HAK.CAST

AI vs. AI with Scott Deluke

CYBR.SEC.Media Season 2 Episode 16

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 17:34

In this episode of CYBR.HAK.CAST, hosts Michael and Phil speak with Scott Deluke of Abnormal AI live from the inaugural CYBR.HAK.CON.! The conversation explores how email security has evolved from signature-based defenses to behavioral and AI-driven detection, especially as attackers use AI to create more convincing, scalable, and zero-day phishing campaigns. Scott explains why defense-in-depth still matters, including tools like DMARC, Microsoft or Google-native protections, and a “plus one” email security strategy. 

Sponsored by Abnormal.AI

Things mentioned:

  • Abnormal AI - https://abnormal.ai

Do you have a question for the hosts? Reach out to us at media@cscgroupllc.com 

In this episode:

Keep up with our Conferences and Events:

Keep up with CYBR.SEC.Media:

Learn About CYBR.SEC.Careers Non-Profit Efforts

Subscribe to the podcast: 

Listen to our other shows:

Thank you to our Media Partners:

SPEAKER_01

Hello and welcome to another episode of Cyber Hackcast Live from the first Cyber HackCon. I'm joined by my BBFF, Michael Farnell. How are you doing, man? So for the folks if you're just taking it for first time, BBFF is Paul's best friend forever. He already had a best friend, Sam, so I'm his BBFF. So how are you?

SPEAKER_03

How's your day going so far? Good. It's always the normal first day of a conference where you have stuff happen. Chaos. Yeah, chaos. But once you get past and being an inaugural one, it's even it adds to that. But no, it's going good. How about you?

SPEAKER_01

It's going good. It's kind of different being on the other side of it and not speaking, but it's going good.

SPEAKER_03

Actually having to uh get up on stage and introduce other people.

SPEAKER_01

Yeah, I'm not used to scripted stuff. I'm used to wing wing it is something different for me. I've had to read from teleprompters and do ads for sponsors and stuff before, but yeah, it's a little more of a challenge. But yeah, it's fun though. Something new. Conference seemed to be well received. A lot of great compliments from vendors and attendees alike, which is good to see. That's good.

SPEAKER_03

That's a good start. Well, who so we got Scott Deluc from AbnormalAI with us today. Field technical director, field CTO, field.

SPEAKER_04

Yeah, whatever you want to call it. That's somewhere in between. That's all about being one team and sharing those titles when they're appropriate and then being in the right place at the right time and using the one that makes most sense.

SPEAKER_03

That makes sense, yeah. So break it down for us. What do you do there?

SPEAKER_04

Sure, absolutely. Traditionally, I kind of came over here in the early days as a sales engineer and kind of became an SM SME of the product. But as we continue to evolve as an organization, I tended to be part of the larger deals in the company and really connected with customers. So I started to be an individual who would stop in and figure out what's important to our customers. What do they need next? What are the challenges that are coming over the horizon and how can we potentially help bring that back to product and hopefully build something that makes sense for them today and maybe in the future as well.

SPEAKER_02

Very cool.

SPEAKER_01

Very cool. Why don't you share your origin story, kind of how you got started in technology and cybersecurity?

SPEAKER_04

Sure, absolutely. It's actually kind of an interesting story. My dad worked for TI for 29 years, and so I started out with a Commodore 64 and a couple of books. So learn from there. In my 20s, I dropped out of geology and dropped out of college, and I joined Dell. I happened to be living in Austin at the time. Spent about nine years with Dell, and over time I decided I wanted to do something different. I hopped over to construction, and then it kind of got the itch back. I love being an engineer. I liked how things were built. I liked technology. So I got a job over here at a local VAR and started running their infrastructure. Did that for many years until I got sucked over to the dark side by a vendor? And I've always loved email. I like that it's a really interesting, evolving attack vector. And so I've been doing email for the last 10 years of my career on the vendor side. Very cool.

SPEAKER_03

So is Abnormal still just email, though?

SPEAKER_04

I don't think it has ever really always been just email. A lot of it's about the human understanding, right? It's a different approach of just using like uh a behavioral as opposed to the things that are known bad out there. That's easy, right? And unfortunately, with the way things are evolving, obviously AI plays a huge part of it. Zero-day attacks are the norm today. So using things that you think you know doesn't work anymore. So you got to kind of do it in a different perspective. So while we started with email, it didn't actually evolve from there. It started from ad tech. A lot of people don't know that was the origin of abnormal. It was originally anytime that you go to Hawaii and you search for it on Google, all those ads that pop up. Yeah, that's our founder's fault.

SPEAKER_03

Thanks. I think what what from an email perspective got you excited about that, not just abnormal, but what drew you to that specifically?

SPEAKER_04

Sure. I think a lot of it is being an engineer at heart, I like seeing the evolution of things. And I felt like different things like firewalls, and when I was doing an infrastructure architect, a firewall is a firewall, a switch is a switch, at least to me. I know there's nuances in there, and no offense to those out there who do that for a living, but email is always dynamic. It seems like every month there's something new out there. There's a new attack vector. And while maybe the end game is the same, ransomware or stealing credentials, that the methodology or techniques always changed. So with every email, there was something new to learn, and everybody has it. It's always that source of truth. It's the chain of custody, and it's the port and way that we communicate across the entire planet. So it also is something that's like there's job security in this, it's not going away.

SPEAKER_01

The threat actors just get more creative with that kind of stuff. So, how has AI kind of shaped and evolved your product?

SPEAKER_04

So it's a it is basically the basis of our product. So if as far as an evolution goes, it's kind of what's neat about abnormal, and the reason that I hopped over there specifically is because companies like the traditional or legacy security stacks have to tack it on or mature their products into that space. It started there. So it was really exciting to be on that cutting edge of where ML was starting to turn into AI. And so it really just fascinated me to see like how you can use these different types of algorithms to not just look at all these static variables, but dynamically track 50, 60, 70,000 things in milliseconds. That's something we just couldn't do in the past.

SPEAKER_03

Yeah, that was, I remember years and years ago just trying to get spam under control. I was in a small company and had Barracuda email filter, and it to your point, things changing. Hey, this is gonna fix your spam problem, and then every other week I was having to go in there and make adjustments, run my own any kind of detections that I could put in there just to compensate for what they were. And nothing against Barracuda, and that was a weird time that we didn't have any kind of ML or AI really to any great extent. Yeah, when I but I I worked for a VAR as well for years and kind of saw that that change as we went of how you just got to do it differently. It can't it was the same kind of structure as like when silence came around with the new way of coming after after malware. Like it could not be a signature-based thing anymore, and that that same evolution just happened across security in general, and then email specifically.

SPEAKER_04

Well, email is no different than kind of like the evolution you're talking about to EDR, right? It's just if you can see something from the edge perimeter, it's just like beating on a box or picking a lock. If you try hard enough to pick it, you understand how that methodology works, eventually you're just gonna get through. And today, Guy can develop fish kits or phishing as a service kits that are specifically designed. All they do is pull up your MX record and they know exactly where to go, which is another cool thing about using the API approaches, is that you can't see that from the edge perimeter. They don't know what's sitting on the back end. So sometimes they look at you and go, hey, there's a Microsoft tenant or a Google tenant. They're like, ah, free money. They don't really understand. There's something else sitting behind there. So it's still really interesting today.

SPEAKER_01

Yeah, it seems like you really have to have some kind of AI functionality in your products nowadays because the threat actors are able to leverage AI to scale what they're doing and perform more advanced attacks. And in some of the cases where English is not their first language, being able to craft efficient emails that sound more legit than they had in the past.

SPEAKER_04

It's even scarier than that. Just to put it in perspective and use some hard numbers, Abnormal just recently passed blocking 1.1 billion attacks over the time that we've been around. I haven't been around for very long. Last year, 500 million of them. So we're seeing that exponential curve, and that's what AI is doing to the industry because all these attacks are now zero day. So they don't have a signature. They're known good domains, they're using what they call FUD links where they're sending stuff over PayPal, they're abusing Microsoft services and the things that you can't historically stop with your legacy security controls, which is really making it very challenging. But also when you can create a batch of 250,000 attacks that all look completely different as opposed to spend two days creating two, it's just an absolute game changer. So we are in this total and complete war of AI versus AI. We're now we're no longer in a position where you can have a sock sitting forward. The humans have to start taking a step back and letting the technology be the differentiator and then work on those edge perimeters, you know. Just like we always talk about bumping it left and right. That's more your job today, because if you try to get in front of it, you've already lost.

SPEAKER_03

Yeah. So the the speaking as an old school guy, does DMARC and everything else still play a role? You still need to get that in place to keep your own domain from being used as for spam and things like that, or is that kind of really there's so many different techniques, and again, that's the thing that AI can do very interestingly that we just don't even think about.

SPEAKER_04

Like DMARC, yes, it would be awesome if everybody did it. Yeah, but it's a crowdsourcing tool, right? So those who actually have a good infrastructure and ecosystem of vendors and companies, I think DMARC can do some magical things, especially if you do a lot of like MA's, you know, making sure that you have that appropriate things for the different domains. But what happens is okay, your DMARC's perfect, then they start abusing direct send. And direct send's been something we've turned on for what 40 years? I remember back in my early days, like setting up printers like that. They're half authenticated, but those were a massive attack about two you two years ago. And there's still organizations today that are getting beat up really bad. They don't understand how. My DMARC's done, I got an edge perimeter firewall, I got Zscaler, I got all these things, but I'm still getting hit. It's because if you direct send in an attack, it goes right under all the layers, goes right into a mailbox, and there's no evaluation of that message. Yeah.

SPEAKER_01

So just out of curiosity, do you guys also handle like Gmail and that sort of thing? So many companies you see a lot of startups, a lot of companies are going to having Google manage their emails. So how do you guys manage that? Do you do that as well as yeah?

SPEAKER_04

So anything that's cloud-based, we absolutely do control. In fact, we're a GWS shop ourselves, and we're seeing more and more organizations migrate that way. Large organizations. I've actually been really surprised this last couple of years of some of the very, very large organizations that are choosing GWS. And I think it's because the tools are finally getting up to enterprise grade and what's very easy from a developer standpoint all the way to the maybe the AE that sits on the edge perimeter to be able to use the tool sets and make them work for the way they want to. Microsoft is a very cool ecosystem, but it can be very challenging for some of the newer users to walk in there because they're really powerful tools. Google's a little bit simpler.

SPEAKER_03

Yeah, I speaking from a guy who's been in IT and cyber for 30 plus years, I going to M365 and having to do it myself because I don't have an IT guy. It's still like I'm learning to be a sysadmin all over again because all of that stuff I did back in the day was all exchange server and all it's all different, just setting it up. So I using some of those Defender tools, though, do you still have these talk with the customers? Because this is when I was selling Abnormal when I first was working for a reseller when Abnormal first came around, it was all in our producer on the other side and I had many conversations about this back in the day, Sonny, where we would say, you know, it's you need to have Microsoft in there, but you need to have a plus one strategy. Do you still have that conversation? Are people still doing that?

SPEAKER_04

Absolutely. I think you should always have a plus one strategy. I mean, if you're using a cloud-based, you know, mail server, uh, you you have a secure email gateway built into it. If you're not using those controls, I think that you're hurting yourself. We always talk about, and I think it will always be a thing, which is defense in depth. You know, there's multiple companies right now run multiple EDRs. There's a reason for that, right? One misses, one catches. So absolutely, because you know, just because we are in an age of AI, just because we have all these zero-day attacks, doesn't mean like some of the methodologies are in the end and somebody pulls out a piece of 2016 malware to go throw out there. That sandbox is important, right? It is going to catch some of that stuff. Or if somebody did get burned somewhere, there's some really neat signature stuff that that Microsoft andor GWS or even some of the Secure EML gateways can do very quickly to drop all the bulk stuff, right? Yeah, and then something like a like a like an add-on that's going to catch more of the sophisticated attacks can really hone in on that piece as opposed to worry about too much of the extra noise. Gotcha.

SPEAKER_01

Yeah, you kind of mentioned a while ago that EDR is one of the things that we've kind of witnessed over several years that come from a pen testing background. It makes it a lot more difficult for pen testers and threat actors alike to get a foothold in the environment due to the EDRs. So threat actors are having to leverage more of things like fishing and social engineering to get a get a foothold in the environment. So, what are some interesting types of attacks that you guys are seeing that threat actors are using to try to bypass uh these controls through using email?

SPEAKER_04

Sure. Um, you know, the most terrifying thing out there is absolutely AI driven, and it's it goes down to the phishing as a service. You know, at one point it was just too expensive for attackers to have those 90 people in a room, you know, with the HR systems. We all saw those pictures of back in the 90s and 2000s. You know, now it's a couple of individuals who realized I can actually make more money by selling my services to people who want to attack, or maybe it's a pointed attack, or maybe they just want to do a prey and spray, if you will. The reality of these phishing kits, though, is that they're hyper advanced. Um, they'll business email compromise would be one. There's business email compromise as a service, but really what makes them interesting is how they do their proof of work. So what's changed is it's not always, hey, click here and go ahead and log into this Microsoft. Now they're using authenticators in the middle. Uh they can use AI detection engines so they can check your proof of work, even if you're moving a mouse. So, like if you were moving a mouse as like AI, go in a straight line. But since a human kind of has an arc, no matter what they do, it creates an uncrackable proof of work, and then they embed it in something like Cloudflare, which protects it from going all the way back to their ecosystem. It's absolutely wild. And we see a new one of these about every single week pop up. It used to be about once every two to three months, but now one gets dropped, one replaces it almost instantaneously. And what we're seeing now, and where it's really getting challenging, is we used to be able to track and trace using different techniques all the way back to some of these servers. In fact, we've been able to even download some of their source code and recreate what the phishing as a service tools look like. Now that they're using kind of that proof of work in Cloudflare or other known good systems, you just can't get back unless somebody drops a server and inadvertently leaves that IP range, you know, on the server. It does happen from time to time, but doing their own good OSINT. Oh man, it's scary.

SPEAKER_03

Wow. Well, man, uh I appreciate you being here. Appreciate obviously Abnormal AI being here to uh to sponsor this uh this inaugural event means a lot. Um just coming out and giving y'all's expertise and what you're seeing. I know Abnormal. Abnormal AI is uh winning some awards out there and is doing some great stuff. So um I I it's a company that I've sold, done a lot of work with over the years. So it just means a lot for you guys to be out here and in sponsoring this inaugural event and supporting this community.

SPEAKER_04

Well, we're super happy to be out of here because that's the one thing I can say is that you know, as I walk the halls today, like these are all my friends. Uh these are all people that I know in the industry. They're people who've potentially worked in the past, and I've all people I've worked with at other organizations. And it's really cool the amount of good people that you guys brought in here today. Uh, I think that's gonna be really relevant to the years that you continue to do this event. It's gonna continue to bring in extra people. I even noticed individuals who did not sponsor come out here just to kind of say hi to people, just say what's up. And I think that's a testament to you guys, like really throwing a good show and like you know, bringing in the right people. So we're we're privileged to be a part of this. Thank you so very much for having us.

SPEAKER_02

We appreciate that. Thank you very much. Absolutely. Any parting thoughts, Phil?

SPEAKER_01

No, thanks for joining us, Scott. Appreciate Abnormal uh sponsoring the the show, and uh thanks everyone for joining, and we'll see you on the next episode.

SPEAKER_00

This has been a cybersec media production. Cyber Hackcast is hosted by Michael Farnum and Philip Wiley. It's directed by Bill Brenner, produced by Lauren Andrus, and edited by Ivan Basconzillo. Our music is by Kike Guts. The views and opinions expressed in this show are those of the speakers and do not necessarily reflect the views or positions of any entities they represent. This show is for informational purposes only and does not render or offer to render personalized advice. Subscribe now so you never miss an episode. You can find all our podcasts, articles, blogs, and conference talks on cyberspecmedia.com. That's cyberwithout the e. And follow cyberstechmedia on LinkedIn, X, Instagram, Facebook, TikTok, and YouTube. You can keep up with CyberHackCon by following us on LinkedIn, X, Instagram, and Facebook at CyberstechEvent. And you can learn more about the conference or buy tickets at cyberhackcon.com.