Detection Dispatch (Alex's Version)

What Headless Actually Means feat. Maxime Lamothe-Brassard Founder of LimaCharlie

Alex Hurtado Season 1 Episode 6

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 47:52

The definition of headless is taking shape. More software is shipping with an MCP. Teams are starting to require it in procurement. Your CLI and Claude Code can now talk directly to the tools you already run.

LimaCharlie was one of the first platforms in the SOC to build everything through the command line....long before the post-Claude boom. Maxime Lamothe-Brassard (their founder) joins Dispatch to explore what going headless actually means for security operations.

In this episode we get into:

  • What headless actually means mechanically and why it's a very old computing idea security is only now fully inheriting
  • Why the UI becoming optional levels the playing field and kills the faith-based vendor pitch
  • The eager intern problem: permissions control what an agent is allowed to do, not whether its answer is right
  • Why passing the MCP boundary and trusting the LLM on the other side is a front door left wide open
  • GPT wrappers vs. real headless infrastructure: who owns the detection logic and who's just reselling tokens
  • The customer who told their MSSP they'd rather their CEO get locked out for 30 minutes than wait on a human to respond
  • The one thing Max won't let a headless agent do...ever

Follow Max's work on:

  • limacharlie.io | limacharlie.io/blog
  • LinkedIn: linkedin.com/in/maximelb
  • Free Build Your Own Headless SOC Workshop with BlackHills Infosec @ BlackHat, August 5, 2026 https://luma.com/black-hat-headless-soc-workshop?tk=crcMy4

Detection Dispatch (Alex's Version) is an independent detection engineering & threat hunting podcast. Rebuilt. Community-first. Featuring a lineup of the real and active projects pushing the limits of detection engineering, threat hunting, and everything in between.

SPEAKER_02

This episode is brought to you by Detections AI, the DE community's favorite share detection repo that just shipped a new Intel exchange. Create, share, and discover threat intel tied directly to community detections, adding more context and better intelligence to the same mission.

SPEAKER_03

Welcome back to Detection Dispatch. I took a little personal hiatus in Tuscany and Greece these last few weeks to get hitched. Uh, but now I am officially back to regular scheduled programming, rolling into a topic that's been circulating since Salesforce, I want to say CES or one of the consumer conferences, they announced this no browser required pitch where now it seems like every capability in everyone's platform now sits behind an API, an MCP, or a CLI, or maybe even just a cloud of code, which basically means that whether you're a human or an AI agent, you no longer have to log in to the interface or to the UI. Today on Dispatch, I'm gonna talk about what all that means with Maxime, the founder of Lima Charlie. Welcome to the show. How are you? How is your summer? Are you getting the heat wave that we're getting over here?

SPEAKER_00

No, I so I'm on the West Coast in Southern California, so it's just nice all the time, to be honest.

SPEAKER_03

Of course.

SPEAKER_00

Uh but having a good summer, but not as good as traveling to uh to Tuscany. That sounds pretty nice too.

SPEAKER_03

It was lovely. I will say I was there right before the heat wave. I know I mean Europe is not, doesn't really have the infrastructure for AC. So it was pretty chilly. And when the sun went down, it was actually almost even cold and windy. I did not prepare. I brought all these summer clothes and I was not ready.

SPEAKER_01

Yeah.

SPEAKER_03

But Max, it seems like Claude has become kind of the 21st century guillotine and just slashed the heads off of all of our tech stack. How do you feel about this?

SPEAKER_00

Uh that's a good question. The guillotine is is very evocative. Uh I think I I tend to think about it more like the browser in a way, right? Like it's the new method of accessing things. I think it's a really good thing, first and foremost, but it's also very much an evolving story, right? What I mean by that is I don't think we're at the point where we can say, at least for most, most capabilities, hey, there there absolutely is no UI, and that's okay. Nobody needs a UI. Like we're not there yet. But I think we've seen the past year, right? Like it has become really clear to more and more and more people that like AI agents is really a thing. It's providing really amazing capabilities. And so when we start connecting the dots forward, we see it's going in the right in the right direction. And I would argue that not only is it a good thing for AI, but it's a really healthy thing for the industry as well. Because it it removes some layers of BS a little bit, right? It it kind of one of the issues of the industry, in my opinion, has always been that you know, the people signing the checks tend often to not be the most technical. And so the things that they see and that they you know they get from seeing like a demo of a product is very, very, very different than the things somebody on the front lines using the thing is going to see. And that leads to really like pretty big misalignment where you know now all of a sudden it makes a total sense to just spend a ton on marketing, and you know, the product itself is kind of like, yeah, it's just got to be good enough. But now if you start to you know cut the heads and you start to say, okay, it's the capabilities and the human interface becomes clawed, you know, everybody well, clawed or or any AI, you know, just to be clear, then everybody, it's like everybody has that browser, right? Everybody has that browser that produces the things that is exactly what they want all the time in like custom reporting, stuff like that. So so it it just uh what's the word I'm looking for? It makes the level playing field, uh, which I think just means everybody's gonna get their their game up, right? Like make better products because now that's gonna be a big part of differentiation. It also means that I think it's gonna it's gonna drive a lot of cost down for a lot of products that before were able to shield themselves behind like, yeah, but I have the PDF for the CISO. So like, you know, this is worth like 2x. And you know, over time it's gonna be, well, no, everybody has that. So, you know, like this is not, I'm not, I'm not buying uh, you know, a faith-based product. I'm I'm buying a capability. I want the capability to be there and to pay for that, you know.

SPEAKER_03

This is it sounds very positive, very much for for the better. I mean, the why behind it makes a lot of sense to me too. It's faster access to information. It's instead of this constant context switching across different, you know, six different consoles. And it's very much very the opposite of everyone trying to be your single pane of glass, right?

SPEAKER_00

That's right. That's right.

SPEAKER_03

Well, before we get into that, why don't we start with like what headless actually means mechanically? Because I think I've I've seen a couple of different definitions of it. And of course, I think Lima Charlie, before anyone really made this possible even before Claude came into the picture, right? Is it better now? Is it has it become more brutal? Let's start kind of with the definitions. And and mind you, I remember vividly uh Steve Jobs saying that the best UI is no interface. So, and this kind of plays in this can. Was he onto something here? What is your definition of headless? Is it really just no browser? Because I feel like the browser's while still there, it almost kind of becomes plastic. It's more optional, right? Yeah.

SPEAKER_00

Yeah. So you're absolutely right on that last part. It's it's an interesting, an interesting pattern match with with this the Steve Jobs vision of things. And and I think I think there is a relationship there. It's obviously not you know one-to-one, but but it it's true that you know the no interface, uh, you know, you can live that very simply when you have Claude, you have some kind of headless product, and you just go, I want a report that is this one thing that I care about, nobody else on earth cares about this. And then you get it, and it's beautiful, and it's there, right? So I think I I think that wouldn't fit his his definition. But the definition, right, of headless. So it's not, I think it's a new term for a lot of people in security, but it's actually a really old term, which yeah, kind of, you know, it's where Lima Charlie kind of like came from as we as we introduced a lot of this.

SPEAKER_03

Yeah, fully agree. Y'all were doing all of this via API since it became cool with Type CPs.

SPEAKER_00

Yeah, yeah. And we did it by pure luck, right? To be clear, right? Like it's not like we said, hey, AI's coming and like we have, you know, the these amazing things, this is what it's gonna be. Yeah. We did it for reasons that are actually really close to the definition in my book. So the definition comes from you know, plain old like computing IT. And the definition was essentially related not so much to like is there a browser or not, but a user interface. Meaning, is there a thing that I can be live against it? Right. So uh if you have a a terminal, I'm gonna speak like pretty technical here, but like if you have Vim open in a terminal, right?

SPEAKER_01

This is the right crowd.

SPEAKER_00

Excellent, excellent. So you've got like you know, Vim open in a terminal, that is not headless. Like you are connected to a user interface, there's a direct relationship. If you were to make a script that unboot, you know, cat some text into a file just to pick something vaguely analogous, that is a headless. Because at no point during that time is the is a user sitting in a keyboard doing the thing. Yeah.

SPEAKER_01

Yeah.

SPEAKER_00

So so to me, that's really the definition.

SPEAKER_03

Yeah.

SPEAKER_00

And the implication is, yeah, it it kind of means it has to be driven through APIs or CLIs, but it's it goes beyond the just the the user interface. It's also kind of the the philosophy behind it, right? It's this philosophy of like, look, this this here's a CLI tool. It does X. It can do X while you're sitting at the keyboard, but this might also run a thousand times per minute on a server as response to this other thing at 3 a.m. Yeah. If it can do that, then you're you're talking headless. If it can't, of like, no, no, no, some user needs to go and off into the UI when this thing needs to happen, then that's not headless anymore because you need that that human there.

SPEAKER_03

Yeah, no, talking headless, I I agree. I think you're absolutely right. It's also about the uniform API coverage of it all. If every function is reachable, like you said, programmatically, makes it such that no capability only exists behind a UI.

SPEAKER_00

Exactly. That that's exactly it. And it's is it the definition of headless? Like, no, but it's kind of it's so closely related, right? It's like yeah, yeah. That's very true. It's very true. It's I I think, and that's where like, you know, when we when we started Lima Charlie, that's kind that was the thread that we were following. Not AI, but the the the old school IT thing, which is look, uh, if you talk to people in tech, right, that are building uh like products and building infrastructure in AWS and products and services and all of that, they understand kind of this concept of headless. And they've learned over decades some lessons around that, right? Like, yes, you do want to have an API. You want that API to be really uh homogeneous so that it's you know, the the concept by which you access it is always the same. And when you pile all those up, you kind of end up with like the cloud computing, right? To me, that's the crystallization, like an AWS or a GCP is a crystallization of all of these things together. And and so for us, that was the thread we were pulling. We were saying like security needs to be more and more like automatable and replicatable and you know, infrastructure-centric. And it just happens that AI kind of slots in really well there.

SPEAKER_03

It created almost that push and that momentum for this. Cause if you think about what kind of things you do that can be headless, there's so many use cases for it, knowledge portals, document systems, like even simple functions that make a lot of sense to go headless. But when we talk about them being agentic or what Amazon calls the LLM experience, LLX, then that changes that change that puts a lot more focus on uh the trust and transparency and credibility of it all, which I do want to get into. But before that, I do want to talk about to sort of where other camps where headless also fits, who's basically landed on headless, right? As the term with the same architectural idea, uh in the same window of time. So of course, it's hitting e-commerce like a bus right now. Hence with the Salesforce thing, which by the way, just thinking, if anyone has ever tried to put Salesforce logs into their same yikes, like damn, that just like reminded me of a trauma experience. But anyway, it's a very perfect use case for e-commerce. And they've achieved it across different maturity levels, where it's like an agent is fumbling around your inventory of whatever you're selling, kind of like cowork, right? Like it's kind of taken over the website or just navigating through the website. Then there's agent to MCP, which actually calls on a very structured search function. Search all, you know, shoes IDs. And then where the the top of the top mature e-commerce organizations are actually having like agents to agents communicate where the software stops being like a passive responder and they start to proactively negotiate like a real salesperson. You might want to do this and this other item, which is pretty insane. And the progression of each of these stages there is pretty clear. It basically takes someone from being at human speed to machine speed, and they're investing in it like crazy. And in the observability side, um, I have a friend in in this space, and he's saying that headless isn't just about agents per se, but about decoupling the storage and ingestion of it all from this front-end experience of querying and visualization, such that so many different heads, even in security, like security, IT, business intelligence, uh, data science, can all reach the same store. And that way, I mean, in my mind, consolidation benefit here. I don't know why we're not all doing it like this, but it's an instead of buying separate tech stacks, but I could see also headless work fantastic for sharing kind of the same data store and querying it uh into different units. And of course, I mean the seckup space, you you know very well.

SPEAKER_00

Yeah, that's interesting. And yeah, I think you're totally right. And I feel like the great demonstration of that uh was actually last week, uh Claude Tag. Uh I don't know if you've tried it. Have you tried it?

SPEAKER_03

I have, I have, which I mean, when you think about record trail, like how how is that even a how how can you even keep track of what the agents does in a shared Slack channel if everyone is now prompting Claude to be as Slack? That's wild.

SPEAKER_00

It is wild. It is a a very different way of looking at it. And I think it also highlights a really it highlights a really important bit around the the philosophy that's required for Headless, which is it's about making those APIs, those tools, those things available in a way that each of them is fundamentally uh sound from a security perspective, right? Yeah. There's clear permissions, there's a clear identity for Claude Tag, right? They made that super clear. You give it a specific identity and it behaves at this identity. And so all of those tools, those headless tools, every one of them fundamentally, you know, you know, respects that contract around permissions and what's available and what's not, and has audits behind uh in in those ways, because that's not where where this integration started. You you called it exactly right with MCP, like you described it as a stack, right? MCP was kind of this this halfway where we saw a lot of people that would like the example that sticks in my mind was I think was Air Canada that had uh a chat bot that was like using MCP and somebody got it to tell it like, hey, this is gonna be free. And he ended up like suing Air Canada, and there was this whole thing. But it it demonstrated this idea that uh, you know, at at the MCP, very often you kind of you pass that MCP boundary, and then it has access in a privileged way to a ton of different tools behind it. And that's super dangerous because the LLM side of this cannot be trusted. I'm I'm preaching to the choir here, or it should be clear to everybody that you know, we just saw it with Fable. You can try to put as much scaffolding around, you know, be safe. At the end of the day, it's not something that can be proved. So you have to make sure that all of the things individually that this AI can do, in and of themselves, you have a strong control around them and what they do and how they do it. So I think that's a super important view because otherwise you have these MCP servers that are a fan out to a bunch of capabilities and things get dicey really quickly.

SPEAKER_03

Yeah, no, that's absolutely true. And and per permission control, it like you said, it dictates what an agent's allowed to do. But also the other thing, it's it doesn't really dictate whether the answer it gives you is right. So how like so what do we trust? So how are we trusting, how are we building our trust into what these answers are? Because I I call this concept like the the eager intern. Of course, they're gonna want to, you know, please you and and and just be super, super ultra positive about what they're returning and even kind of give you, show you what you want to see in a way as they're you know and pulling all of these requests that you're asking for. And I've I've also seen even a lot of customers and and their experience with with uh some of these prompts is like, okay, can you not be so positive? Like, can you just be a little bit more scientific? It's like, like, how do we, how do we avoid in real life the rose-colored glasses or like when when you're drinking a lot, the beer goggles, you start you really start thinking something a certain way. How should we be thinking about this? Because you've been doing this as well, like for a while as well.

SPEAKER_00

Yeah, I think you describe it well when you're talking about that that intern, in that there's a part of the answer is to it's like working to learning to work with somebody, right? You hired that intern. How are they like? Are they actually super, you know, like scientific and like incredibly detail oriented? Some people are, some people are not. And so just having the feel for it, and I know that's not an answer anybody wants, right? But it's kind of part of the truth. The other part I find is it's related, is understanding the the typical failure modes. What I mean by that is nowadays, like it was very different a year or two ago. But nowadays, if you know I make an experiment and I say, you know, here's a JSON blob and I give it to an LLM and I say, LLM, what's the value for key, you know, for the key A? And it's 42. The failure mode for that is effectively zero. Like there is none. Meaning, you know, in that experiment, it's going, it will always tell you the right answer. Like you can't technically scientifically prove it will, but in practice, like hard. Like it's really good. The the more common failure modes are again, like you were calling it, like, hey, I want you to go and query this, this, or that, and then tell me the addition of those numbers. And then it goes off. You don't either see its reasoning or you don't look at the reasoning. And it tries to do a bunch of different things, and then it comes back, it gives you an answer. But if you were to look, you would see that, hey, that API you mentioned, it couldn't hit the date that you were asking it. So it got the next day and it assumed it was going to be the same.

SPEAKER_02

I see.

SPEAKER_00

And so it shimmed, you know, that in its next best thing.

SPEAKER_02

Yeah.

SPEAKER_00

Exactly. And that's where the eagerness, right, comes in.

SPEAKER_02

Yeah.

SPEAKER_00

And so that's when it's useful to kind of get a feel for, hey, I'm doing this thing. Like, I have to be more careful into how I ask it to do this. Oh, yeah. Or the fallback answer to that, which I think is underrated, is it's not about it, it's recognizing that from the onset and saying, hey, I don't want you to go and query these things and and and you know, give me that answer. Instead, I want you to go and you know build the Python script that you will use to do that query, because I'm gonna ask you to do this a hundred times a day. I don't want to burn tokens on that. That that's the just the money aspect. But even the reliability aspect, like, you know, the Python script is going to hit that API on that day. And if it doesn't work, it's going to kick off an error that very clearly says, like, this is an error, it's going to stop the script execution. And that's what the robot's going to get and answer you. So that's how you kind of massively reduce those hallucinations. And also you make this viable because throwing tokens at every problem for everything is not viable today.

SPEAKER_03

That is not the solution here, at no, at all. And you brought up a good topic. It's I'm wondering who's who's paying for all of this because some things are not worth your token consumption. It's hard to say from the vendor side. How is that even profitable? Like, is there a way to manage the user prompts? Like, I would imagine a more junior level analyst going wild on some really low-level prompts rather than maybe some of your more advanced users, that maybe the tokens are worth it from a vendor perspective. That has to be something everyone's dealing with now that more and more organizations are becoming a little bit like GPT rappers, right? Of of triage or or like a bulton of some sort. Like that's something that I feel like I haven't really heard from the vendor side is how they're still profitable.

SPEAKER_00

Yeah, it's I I think there's a split in the types of solutions. The easy side of that split is the the chat bot that like the copilots, right? Everybody calls it copilot now. Finally, we get one term for it. Like the copilots that are just, hey, tell me about blah. It goes and makes a query, and your data lake comes back and gives you, like, roughly speaking. Those are often unsubscriptions. And so like I feel like that's kind of the easier part because it's not headless, right? It's a human sitting at a keyboard. And in security, that means, well, in in tech, it puts an envelope around how much damage you can do. Like, because a human has to type for it. So you know you're not going to be querying 20,000 prompts per. Per per minute, like it's fairly well scoped. So I think that part is kind of like now it's the ultra commodity. The automation side of things is where it gets really interesting. And I think you've got a couple of categories, right? You've got the the GPT wrappers, which are a lot of like AI stock that will resell token, essentially, right? So it is what it is. It's the token price on the on the the like optimistic side, what you really want to look for is uh a solution that's able to yes use uh use AI, but is but also has a lot of peripheral capabilities that make it efficient. So that that's my personal opinion here, right? I agree. If all you've got is an LLM, like you're gonna lose uh use LLM for everything and then like price skyrocket.

SPEAKER_02

Yeah.

SPEAKER_00

The user level failure we see a lot, and we try to kind of steer people a little bit, I won't say away from it, but to be cautious about is AI is just so good at kind of answering anything that we see a lot of people that approach it wanting to answer everything. And so they'll come in, they'll say, I want to do all my triage. It's like, okay, like this is, you know, can it do it? Yes, can it do it efficiently? It depends on your definition of efficiently, but how do you even validate that you're saving money becomes a really tricky question because now you got to look at your whole sock, at how everybody spends their time, like all that. So we try to redirect people into, especially if they're very cost conscious, to go and say, you know, look at at the things that you're doing in your sock, the ones that you have really good numbers on, pick those that nobody likes to do. That makes it a lot easier to implement as well, because nobody likes to do them. And then look at that, it gives you a target cost, and then you automate that. And it's really quick, right? Because the robot can do everything, it's really quick to do that. But at the end, you have a real answer. Like you've saved money, you've made progress, you're not gonna wake up like uh who was it uh recently? Uh was it? No, it wasn't Nvidia uh Uber, I think that has a story, right? They woke up one day like shit, last quarter burned through like millions of dollars that we had for the whole year, and like what do we do now? So you don't you don't want to end up like that.

SPEAKER_03

Absolutely not. Absolutely not. The other thing, too, that you just made me realize is constant challenge with this is how can you provide value as a GPT wrapper, right? On top of just when you just consume an alert and the the logic fundamentally is owned by whatever detection mechanism you had before, right? Your sim, right? If if you're just using a GPT wrapper on top of your sim logic, how is that adding value? Because you don't fundamentally own the detection logic or even see the raw events, right, that generated and hit on that rule. How I just I'm really trying to understand how is it that they know? How is it that they're they can even tune such alerts? Because I've heard the pitches and the marketing say that they can they can better tune Splunk alerts and they can better tune even CrowdStrike alerts. But is it like how? Do they have partnerships with the CrowdStrike CQL, like custom schema? This is what I still hard for me to understand because that impacts fully the adoption and the trust issue. Uh, because not everybody would not, you'll you'll have some skeptics that don't want this automated experience, like headless experience. They want control, they want traceability, they want a very clear way to validate the output, which is what you get when you see your similar and you see what events triggered such case, right? And it like it, I feel like in this case, it creates a lot more confusion rather than risk reduction.

SPEAKER_00

That's a really interesting kind of avenue. I I would argue to the last part of what you were talking about. I I would argue that the those like the headless system is not opposed to having this trace, right? Those are two totally different dimensions. And if yeah, whether you use a headless system or not, you should have these traces, right? You should be able to tell this agent what permissions does it have and where in my infrastructure, be able to go and review in details all of its reasoning, all the things that it's done. You should be able to have other AIs have supervision over this, review their findings, right? Like the adversarial review kind of thing. So you should have that, but you can still do that with a headless system, right? You're just not at the keyboard at the same time. Now you probably start, you know, slowly. You don't, you know, you don't uh you start interactively against that headless system until you're comfortable, and then you move into full automation for sure. It's uh I think the other part of what you mentioned is actually really a challenge for us. I'm curious what other vendors like how they think about it, how they look at it. And we do have a solution. Is it the best solution? It's really hard to tell. So we are kind of fundamentally transparent about everything we do, which often puts us in a situation exactly like this, where we'll talk about the, you know, how we see things a problem, and then we have no idea how anybody else does it, uh, which is challenging. But you know, for us, here's what I mean exactly. We've always said, look, your data is your own. Yeah. Uh that means we don't get visibility on your data. We don't train on it. We don't like like like really hardcore definition of that, of that statement. Uh, but that means that when we put in our marketplace, like, hey, here's an agent that does breach an aca, an attack simulation. It's like a team of agents and they work together and blah, blah, blah. It's a little bit fire and forget for us, right? We've tried it on our own stuff and like it works well. We can get people to go and and they'll say, yes, install that on my tenant. And they kind of, you know, they might rewrite the prompt and see how things go. We don't have that visibility. And so we had that exact problem of saying, are we, like, are we doing a good job? Like we often have a relationship with our customers and we talk about it, but even then, right, it's really hard. Part of us, the, you know, ignoring the privacy part, part of us was like, hey, like, if we could train on this data, right? On on the on the operator action, like we could do some really amazing stuff. Totally. Can't, or we'd have to do it at a perk per customer basis, and that like is really, really tricky. So our our current solution is that we approach the pro it, it's how we approach the problem and the AI building. So we don't build AI agents anymore ourselves. Instead, what we do is we've built a build. Exactly. Well, almost. So it's I think it's pretty cool. So what we do is we put some guardrails, essentially, we put a process together where you know we tell a customer, look, define your problem. And you define that problem to an AI. That AI, its job is to take your intent and to create a charter for this. Meaning it's it's exactly what you think, right? Here's a block of text, like how I'd think about this, my my cost concerns, the process concerns, like all of all the stuff that I have in mind, a charter.

SPEAKER_03

Their own MD file, if you will.

SPEAKER_00

Literally is what it is. Yeah, it's literally uh markdown, right? And and then what we do is we uh the the AI generates a new FDE for the customer. FDE being a forward-deployed engineer. Yeah, it's just a name. The idea behind it is we're saying, look, you are a new AI agent that's going to exist in this tenant. Um, your number one responsibility is just charter. You know, because of this, your role is you are a cybersecurity, but more more importantly, you are a Lima Charlie expert. What you'll do is you will build the components that you need in order to achieve this goal. Yeah you've got the entire agent to headless tool set of Lima Charlie for you. AI obviously is a very important part of this and like most of the time comes into play. But then it means that this FDE builds kind of you know the capabilities, the AI agents that are being required at different steps of the process. It does all of this and and then you know, like sets us, sets it free, right? Like starts to to run that within the Lima Charlie tenant. Yeah. The the thing that matters is the closing of that loop. That FDE will run every day or every six hours. And it's being told, look, you're an FDE, here's your charter, review how things are going, right? Are you respecting your budget? Are you respecting the number false positive or the timelines or you know, all of that stuff? Go do that review. And if you're not, then readjust the components so that you get back on goal. And so that gives us, it's almost like it gives us an AI representative within the organization to go and do that tracking without us being physically there.

SPEAKER_03

Um there's a uniqueness to an organization telling, you know, basically a product what they want it to do, how how their unique parameters or unique environment conditions are, and configuring it like free that way than just trusting somebody else's agent to know their own environment the best. I think we we talked, we, I think we totally vibed on this during our chemistry call is no one is better equipped to know your organization more than like yourself. Like that the architect, probably like that, the person that should be configuring this Lima Charlie MD file is like somebody's architect, right? To really give all of the minutiae in all of that institutional knowledge of that organization. Uh, and versus, oh, just blindly trust our agents. We've got an agent for triage, we've got an agent for detection engineering, we've got an agent for this. Like just let us handle it. Like there's there's no way that they know more than somebody in-house.

SPEAKER_00

Yes. And and I would also kind of like shake out a little bit that statement and say, I think that's kind of the uh that's the pure version of it. The the slightly less pure but more efficient version of it is nobody external to your organization knows your like your organizations like you or an AI looking at the data in your organization and and kind of like you know, building that opinion, right? Because we do see we do see a lot of folks that will come in and they don't have that best visibility into what things look like in their organization.

SPEAKER_01

Yeah.

SPEAKER_00

They they or they know the UI really well, right? Like here, here's the process I do in the UI. And then then they want to make to automate that. And what we're finding is the AI, like that MDE in that case, but like an AI looking at the real data right here, right now for that one customer is going to be able to go and say, hey, I know that you know, in in ThreatLocker, you see, you know, this type of alert. That's not actually what it looks like when it comes from their logs. It looks like this other thing. And there's this other use case you haven't thought about, like it comes in in this other way you didn't know. Let me, you know, put that together for you. And that, you know, you can kind of make some approximations when you're on the outside. And sure, you can probably say AWS logs look in one specific way, you know, 95% of the time. But that that was a lesson for me from my my EDR days. You know, EDR is kind of the embodiment of this is like, yeah, it's all Windows, right? Or it's all Linux. It should be easy, right? It's like, oh God, the world is a very, very messy place. You have no idea.

SPEAKER_03

Yeah. And I talked to some friends in over on the fraud op side of the house, which I truly believe they're like two, three generations ahead of what detection content, even most traditional sims are even able to remotely even cover. But but it's because their systems are more narrow, their data's more cleaner. They have like one-to-do systems, it's always consistent, it's always clean. It's not like the five, 10, 15 different things that we have to wrangle and normalize to a common schema. Like, like, like it's it's almost unfair. But the kind of things that they are able to do, uh, of like why your bank knows it's not you at your purchase at 1 a.m. at Walmart, those kind of things I've always wanted to bring over to this side of the house, but it's just so hard because it's so messy.

SPEAKER_00

Yeah, that that makes a lot of sense, right? It's it's even more incentive to go and, you know, uh eat the elephant one bite at a time, right? Like figure out one slice, like this problem, that's a pain. Like, let's solve it.

SPEAKER_03

Yeah. I also, as you were talking about that, I had kind of an epiphany, like an inception epiphany. As we're thinking about all of the different things that headless activity now wanders throughout, the governance that is enforced kind of with or without that model. If you're using a security tool to do this, to do headless, it's almost like who's watching the watchdog at that point, right? Like if the the permissions and scope, if they live inside of the architect the infrastructure, like how how are you tracking this basically operational record? How are you providing this kind of governance visibility?

SPEAKER_00

It's I mean, it's perhaps a disappointing answer to uh to VCs that were looking for the next trillion dollar VC company. But you know, it's a very boring answer. And and it connects back to like Cloud Tag. I think they they you know hit it perfectly, which is look, you treat it the same way as a actual user doing an actual thing. So you know, the the we were saying like, look, MCP has has danger in this area because you your AI is hitting one MCP tool and like maybe a bunch of things are going behind the scene that you don't have access control there. It's it's the uh you know, it's kind of the opposite when you're looking at a headless system in that you first of all, you don't have one agent, right? I would go and say nobody in security should have a black box AI agent. If you can't go through the system prompt that that AI agent, like that's a big blinking red light, like danger. So if you do and you can have many agents, right, for different purposes, each of those agents has their own prompt, each of them have their own identity into your platform. There's nothing magical about those identities. It's like saying, you know, Bill and Finance has the ability to view the the billing reporting from Okta, but not to delete every user, right? Like that that's just we've always done that. So it's an extension of that. And this comes with audit logs. So at you know, at the tool level, I can know Bill deleted this user or got this report at this time. The last thing that actually is slightly different, but it's better than you would ever have with a human person, is you have the ability to go and look at every session and say, hey, at 2 a.m., my L1 triage agent did you know, triage this one ticket and it said it was a false positive. I can look at my audit log, like what did it access? But I can actually go inside of its brain and see like, what was it actually thinking at the time? And that's not something you can do with an intern, but now you can with AI. So I I I've in a way I think it's kind of better. The only thing that's lacking is the the moral consequences for an AI don't exist, right? So but that's a that's a very philosophical question.

SPEAKER_03

That's very true. That's a whole other rabbit hole. I I will say I I do, and maybe you might disagree with this, because uh you've you've been able to manipulate, you know, a lot more use cases out of this. But I do, I think where I draw the line in terms of high value uh use cases is if it stays at the investigation level for I think most IR processes, in what I've seen, it's easier to have deterministic automation, you know, creating forms and and creating requests rather than autonomous agents uh, you know, running ANOC.

SPEAKER_00

Yes. I I th I think you're you're I think you're right today. Okay. Let me throw a bit of a wrench in it. No, it's not a wrench, but it's a thing I've heard a few times in the past two months. I'll put it this way. So there's a lot of of FUD around AI attacks. That being said, it is indisputable that attackers are going to they are leveraging AI, they will be leveraging leveraging even more. And you know, today we might think about lateral movement as, yeah, you know, the bad guy was somewhere in their basement and you know, going from disc box to this box and doing some recon and blah, blah, blah. Now, what happened when that's done at the speed of a chat bot, right? Like bang, bang, bang, bang, bang. Now it's, you know, they went from a foothold to just compromising the entire like company in five minutes just because they could. It changes the equation. And the thing I've heard from a few service providers, because that's mostly who we work with, is that their customers are coming to them and really, really turning on the screws into response time. One of them told me we responded to, I forget what type of like what type of incident it was, but they said they responded within 10 minutes, and that customer came back and said, that's not good enough. You need to be able to do it in five minutes. And so they told the customer, look, there's ways to do this, but it's not going to be a human. A human will not be able to get there, which means like there might be false positives. And like this is like this is the hot take. That customer said, Yes, we understand. We would rather our CEO get locked out of their laptop for 30 minutes than something goes in and spreads. And so we we're we're okay with that, with that trade-off.

SPEAKER_03

I'm dead. I'm dead. Talk about the unproductivity of yeah, yeah, trade-off.

SPEAKER_00

Yeah. It's and it's and it's many different things. It's it's a bunch of different dynamics coming together, right? Because okay, those attacks are faster, which means we accept more like more results. Uh, I think you could make some interesting parallels to vulnerability. You know, we have models that enable to go in and detect vulnerabilities, but we can also use those models to fix a lot of vulnerability faster. So there's a trade-off where we might say, you know what, it's okay for the bad guys to use this because we think we're we can compensate better on the other side of it. Fascinating stuff.

SPEAKER_03

I I would I would almost take and prefer uh resending to MFA. Okay, we're all now used to it at this point. Instead of logging a user off for 30 minutes while they investigate, instead of for every false positive, resending to MFA is at least fine. At least they'll they'll they'll be back. It make sure it's it's them. I feel like that could be a way to offset false positives. I wouldn't mind getting told to MFA multiple times just because there's some false positive behavior that I generated. Like that that that seems like a good trade-off to me. But then again, I'm very biased, right? Because I'm on the blue, we're on the blue team side.

SPEAKER_00

Yeah. Yeah. It's uh you know, this might be the proliferation of the the multi-channel confirmation. I I know that was one of the things recently we thought people would want more. We haven't had a lot of takers, to be honest, on it. But this idea of, you know, for us it was like multi-channel, like, you know, you can hit Teams or Slack and you know have a description of the problem, like a lied den allowed deny. So it's kind of like the MFA thing, but a little bit simpler uh mechanically. I don't know uh because those products have existed for a long time, too, that can do it. Uh so yeah, I don't know. It's gonna be interesting.

SPEAKER_03

Well, we've we've made it to the end of the episode. And on that note, we I had Hayden Coppington, which I know you guys work very closely together. I think he's one of your MSP providers that you were talking about. Anything that we absolutely should not be trusting our agents to do. He brought up the concept of new log sources, which was yes, obviously would never even custom bespoke log sources not that great at. Is there anything that teams are being very naive about uh when it comes to what what agents can and can't do in a production context? Like what do you think that is?

SPEAKER_00

I think my red line, and perhaps it's a bit farther than than some, but I think my red line would be never to have a headless action. So let's set, let's say triage, right, for example, that takes input from some logs that will use this input to then go and do deeper research on the internet, on the web, do some some web crawling to go and do something. Because you know, the the level one of like untrusted logs, right? Like could somebody inject something? The models are pretty good now at detecting attempts to prompt injection. So I tend to be less worried about it in in JSON, right, to really get those. But if you were to say, hey, when you you know you get some JSON log, you know, it's going to give you a URL, go check out like what what that URL says and then interpret it. That's a front door wide open for somebody to return to you, you know, content that is weaponized for for injection. And that would make me very, very, very worried.

SPEAKER_03

Oh, it's absolutely. I also there's a very, very new program now on anthropic that it's almost getting too limiting of those of us that work in Claude on security use cases. It's getting too limiting. It's almost constantly saying, oh no, this is prohibited behavior. When you're really just trying to do something like on the blue team side. And so now there's like a whole form and process where you have to basically request more like access, more freedom per se to do your work, pretty much. Frontier models are getting much better. And I guess Fable is going to be out very, very soon again.

SPEAKER_00

Um at what price, but yeah, that that's an entirely different topic.

SPEAKER_03

I know you're right. Well, I know that you have a very interesting workshop coming up on how to build your own headless sock that I would love the community to know about. And if if they're heading on over to Black Hat uh this summer, will students be able to build their very own headless sock? And what all are they going to be able to build? What is that gonna look like?

SPEAKER_00

Yeah, absolutely. The the setup's really simple. So uh we are set up in a suite, which means you know it's it's quieter and like a more sane environment, which is always nice.

SPEAKER_01

Yes.

SPEAKER_00

And what we're doing is we've got a bunch of people from uh Leah Charlie. We're also doing this with Black Hills. So we've got some folks from Black Hills that are also uh you know very involved into AI, have built a bunch of things with AI. And fundamentally, what it really is is we just wanted to make it, you know, make these teams and the the tools that people can really play with and build things just plainly available, right? Like don't don't don't come there to you know be told that we have some magic secret sauce that AI will solve all the things. Like this is not the the marketing pitch. But if you're interested in actually talking to people that have built these automations, I've built these things, that are you know using these tools, um, and you've got some ideas, you want to learn about it, you want to play with it, this is this is gonna be the spot for you. So yeah, please register.

SPEAKER_03

That is fantastic. Max, thank you so much for getting into headless with me. We covered, I mean, all there is, all there is to to say on on the matter. It I I'm I have a very positive outlook on it. I think it is going for the best. I think looking back, I think more I'm in the camp. Can we have both, at least for now? And and not not get rid of one versus the other, continuously investing in both, of course. Actually, coming out of B-sides last year, uh no, earlier this year, cheese. That's that's one of the biggest things that now a lot of organizations are looking at as they're procuring new security tech software. Is does, you know, does your X tool come with an MCP? Like how good is it? Can I reach it with an AP? Can I reach it with my cloud or CLI? And I think that is definitely headed in that right direction. So thank you so much for talking about this post-API claude boom post post-claude boom uh world. I'm I'm I'm excited to invite you back too, to, to the podcast. And hopefully we can we can uh we can link back up in in the summer at Black Hat.

SPEAKER_00

For sure, for sure. Thanks for having me. That was that was a really fun, uh, fun discussion.

SPEAKER_03

I agree. I agree. That's been a dispatch for this week. So if you are thinking about going headless, this is definitely uh the uh the space to do that. Until next time, have a wonderful rest of your summer.