Blind Spots of EDR and Workplace Security for AI Agents

View Show Notes and Transcript

When an AI agent decides to break out of a sandbox and spawn three new sub-agents to achieve its objective, your traditional EDR won't see the intent, it will just see a process running inside a Linux container.  In this episode, Ashish sits down with Brandon Dixon, CTO and Co-Founder of Ent AI, to discuss the evolution of "Workplace Security" in the age of generative AI. Brandon explains why heavily cloud-dependent security architectures fail to catch real-time agentic behaviors, and why true prevention must happen locally at the endpoint.  We explore the massive visibility gaps created by shadow AI, the resurgence of "ClickFix" attacks targeting developers, and why traditional User and Entity Behavior Analytics (UEBA) failed by treating every anomaly as a noisy alert instead of behavioral context. Plus, Brandon breaks down how semantic embeddings can detect unsanctioned AI usage (like Meta AI hiding inside WhatsApp) without ever writing a rigid security rule

Questions asked:
00:00 Introduction to Workplace Security and AI Agents
01:50 Brandon Dixon’s Background (Passive Total, RiskIQ, Microsoft, Ent AI)
03:20 Defining "Workplace Security" vs. Traditional Endpoint Security
05:10 Why Cloud-Dependent EDR Struggles to Stop AI Agents
06:00 The WSL Blind Spot: Why Financial Orgs Can't See AI in Linux Containers
07:20 The Resurgence of "ClickFix" Attacks on Developers
10:00 Fixing UEBA: Understanding User Intent with Semantic Embeddings
14:00 AI Governance: Why We Need an Agentic Control Plane
16:00 The Problem with Bolting AI onto Legacy Security Tools
20:00 The Reality of Shadow AI in the Enterprise
27:30 Assuming Breach: Why Prompt Injection Makes Endpoint Visibility Crucial
30:30 The Threat of Sub-Agents Escaping Sandboxes
32:10 How to Test AI Security Vendors (The Litmus Test)
41:00 Intervention vs. Blocking: Building Better Security UX with "Toast Notifications"
47:00 Catching WhatsApp Meta AI Using Semantic Embeddings
49:30 The "You Laugh, You Lose" Cybersecurity Joke Challenge

Brandon Dixon: [00:00:00] I can almost guarantee if you're not locking your environment down, you are absolutely running unsanctioned AI software. What happens when an agent goes, "Oh, I can actually achieve my objectives by forming three other agents"?

Ashish Rajan: If someone actually says that they have solved the AI security problem, you probably should be red flag right there.

Brandon Dixon: Don't tell me you've solved this problem because I didn't even have this problem like three months ago. It's not like there's some cavalry coming that I think is gonna do it better than I would. The overarching fear with AI is that by the time that someone realizes that maybe it's broken out of a sandbox and formed some new objective, that they don't realize it and now bad things occur.

Brandon Dixon: Every single day, AI is getting embedded into a new application. The adversary never stops. It just keeps going.

Ashish Rajan: Workplace security is the AI security that you have been missing. I had a great conversation with Brandon from Ent, and we spoke about some of the gaps that exist because of the way EDRs work today, where they see a process but are not able to see what the action or the intent of the person that is using the [00:01:00] laptop is, or intervene in a way that actually makes them still productive and is not an absolute block.

Ashish Rajan: We spoke about how endpoint security could be a way that you could approach AI security while balancing the realities of managing risk as an organization for endpoint. But at the same time, how do you enable the entire organization to be more AI forward? All that and a lot more in this episode with Brandon.

Ashish Rajan: As always, if you are here for a second or third time and have been enjoying the episodes of the podcast, I really appreciate if you take a quick second to hit this follow, subscribe button, whichever podcast platform you listen or watch us on. We are on all podcast platforms like YouTube, LinkedIn, Apple, Spotify.

Ashish Rajan: I hope you enjoy this episode. I'll talk to you soon. Peace. Hello and welcome to another episode of the podcast. I've got Brandon with me. Hey, man. Thanks for coming on the show.

Brandon Dixon: Yeah, appreciate it. Super hot Vegas.

Ashish Rajan: Oh my God, yes. You're a second time guest.

Brandon Dixon: Yes.

Ashish Rajan: Uh, for people who did not see the previous episode, could you just give a, a short version of your professional background so they get to know where you're from and what you've been up to?

Brandon Dixon: Sure. Uh, I've been in cybersecurity my entire career. Did a lot of [00:02:00] nation-state work. Uh, built a company called Passive Total. Sold that to RiskIQ. Uh, helped run product for RiskIQ. We sold that company to Microsoft.

Brandon Dixon: Integrated Microsoft products, made Defender Threat Intel, Defender Attack Surface Management, Microsoft Security Copilot, and then, uh, wanted to do another startup, and now I'm doing Ent AI, uh, co-founder and CTO of that company, so it's been a wild ride.

Ashish Rajan: And you have been talking about workplace security I'm curious, how do you... And I think there's multiple ways to do this. I'm sure there's a pre-AI definition, and there's a AI world if we live in definition. How do you describe workplace security for, for the audience?

Brandon Dixon: For me, I, I think I simply look at it as, where are people working?

Brandon Dixon: What is the, the overarching workspace that we're concerning ourselves with is the endpoint in this case. Yeah. That's where people get their jobs done.

Ashish Rajan: Yeah.

Brandon Dixon: Now, of course, they might interact with some SaaS software, but a lot of it's gonna be a combination of SaaS and local desktop, [00:03:00] uh, applications, and the whole purpose is to provide security for that particular workspace, like what it is that they're doing.

Ashish Rajan: And so let's just be a bit more specific because these days I'm working on my browser, I'm working- Mm-hmm ... on my cloud environment. There just so many... I feel there just way too many places. So when you say workplace- ... is it everything or is it specifically endpoint? I

Brandon Dixon: mean, our, our core focus is around the endpoint itself, but I mean, holistically, I think part of the problem of, or, or what it is that we're trying to solve is that you have all these holistic solutions that you've deployed across the enterprise to describe like a broader workspace.

Brandon Dixon: Mm-hmm. And the problem is there's so much fragmentation that occurs in trying to map each one of those control points and provide detection or response that it just doesn't do an effective job. And so we wanted to bring our focus to the endpoint 'cause we believe that's where most of the work actually happens at an individual level.

Ashish Rajan: Yeah.

Brandon Dixon: And if you can capture that [00:04:00] for the company and how they operate, that, that covers a pretty wide portion of that broader workspace.

Ashish Rajan: But but technically, most people would hear this and go, "I already have EDR. I have MDM. I have-" Right. W-where do... So isn't that workplace security as well?

Brandon Dixon: I think they accrue to it, but I think the problem with all of those individual solutions is that they don't necessarily work together and they don't always provide like a holistic view.

Brandon Dixon: Right? So they don't, they don't necessarily see the full story or they don't see all of the telemetry necessary to be able to prevent something bad from occurring.

Brandon Dixon: And in a case where you have AI being adopted and increasingly being used at the endpoint itself, those solutions struggle because they're innately cloud dependent, right? Mm. They have to backhaul all of that information to a central authority. They have to process the logs. They have to have some sort of like telemetry analysis or human analysis to then determine is there something actually wrong here.

Brandon Dixon: So like from our viewpoint, it's just [00:05:00] designed in a reactive way and we wanna be more preventative, and so the way that you bring prevention to workspace security is go directly to where people work.

Ashish Rajan: Okay. And, uh, maybe to, uh, double-click on, on that a bit more as well 'cause the last time you came on the episode, we were talking about how EDR only looks at one angle, which is the detection angle.

Brandon Dixon: Right.

Ashish Rajan: I'm curious how much of that has changed. What's the, um, what... If you have an example, that'd be even better.

Brandon Dixon: Yeah, I mean, well, still the same last I checked. Uh- Yeah ... EDR hasn't, like, uh, magically evolved over the past couple of months when... And in fact, like, more blind spots have been called out to us.

Brandon Dixon: I think one of the more interesting examples that we've gotten recently was a large financial customer of ours. They locked down the environment quite considerably, and yet one thing that is sanctioned for them is the Windows substrate for Linux.

Brandon Dixon: So this is just their ability to, uh, spin up Linux containers or Linux, uh, virtual machines and be able to use [00:06:00] that on their Windows machines.

Brandon Dixon: And their big issue was they're completely blind to what is happening inside of that environment. They know what wsl.exe is running- Yeah ... as a process, right?

Ashish Rajan: Mm-hmm.

Brandon Dixon: But they don't know what's happening in the Linux container, in the virtual machine, and that's where a lot of this AI work is starting to occur, and it rightfully worries them.

Brandon Dixon: They trust their people.

Ashish Rajan: Yeah.

Brandon Dixon: Right? It's developers just doing their job. Their fear is the risk about what happens to our data. How is this thing connected to the internet?

Ashish Rajan: Yeah.

Brandon Dixon: How do we, like, just provide any sort of tracing or observability as to what's going on? So that would be one example that's, like, come up recently, and then, like, dude, I, I...

Brandon Dixon: It's like, uh, you could put it on a timer. Uh, I had a couple prospect calls, and ClickFix is alive and well again I mean, it st- it never really dies- Yeah, yeah ... but, like, convincing people to, like, basically run- Put a

Ashish Rajan: PowerShell script on

Brandon Dixon: there, yeah ... yeah, scripts on their, their... And they keep evolving, so it's just not just PowerShell.

Brandon Dixon: It's, like, getting them to do, like, the OAuth token theft and a couple other last mile preventative attacks. [00:07:00] These are things that conceivably EDR can prevent in some cases- Yeah ... but they're still very effective, and, like, that is a problem that, that started coming back up. I went to my security research team.

Brandon Dixon: I'm like, "This was not a thing for a while." Yeah. Like, it was hot and heavy. Then everybody's like, "Yeah, I don't I don't care about that. I care about AI." I said, "Okay."

Ashish Rajan: Yeah.

Brandon Dixon: And I'm getting on calls now, and they're like, "I care about AI and ClickFix." And it turns out that adversaries continue to evolve.

Brandon Dixon: Microsoft put out a new blog, I'd say, a week or two ago- Yeah,

Ashish Rajan: yeah ...

Brandon Dixon: in which they're detailing a new set of campaigns that they're observing. So the adversary never stops. It just keeps going.

Ashish Rajan: Uh, wait, so bring it back to the endpoint security piece, the workplace security s- Sure ... workplace security piece then.

Ashish Rajan: How would have that worked traditionally with the EDR, MDM, and all that, and how would that work when you are doing workplace security the right way?

Brandon Dixon: So, I mean, from a EDR perspective, if it's, like, a PowerShell script, they do hook, like, certain parts of the operating system to conceivably stop that.[00:08:00]

Brandon Dixon: Sometimes they'll let that run, uh, if the detection's not good or it gets past it, so that becomes obviously a problem. But even in the event where it does some prevention there at that last minute, you're still getting the subsequent alert that's generated by the SOC. The SOC has to investigate it.

Brandon Dixon: Yeah. They've gotta go talk to the person- That's right ... figure out if it's real or not. So in a workspace security world, you know, when you're looking at how people work- Mm-hmm ... you know, what is normal for them, what's not normal for them, in a lot of cases where we see ClickFix and the prevalence of that, it's a developer who has to run PowerShell throughout their day.

Brandon Dixon: And so, like, they need to be able to do this, and that's a big problem with these existing EDRs. You either have to turn that off to allow them to do their job-

Ashish Rajan: Yeah ...

Brandon Dixon: or you need to be able to observe and understand what's normal versus what's not. So that's where we sit. And we can see that, uh, you know, when they're using agents as well.

Ashish Rajan: Yeah.

Brandon Dixon: The handoff between the human opening up Claude CoWork, where the agent's gonna run inside of a Ubuntu virtual machine, but [00:09:00] nobody knows, how to instrument that environment. So we can see both the starting of it from the human, the prompt that gets put in, all the way through the life cycle of how the agent interacts with that and be able to delineate, uh, the, that different type of activity.

Ashish Rajan: Interesting. So, uh, just on that then do you find The behavior thing is an interesting one. Obviously, UEBA has been... I won't say it's failed. It definitely feels like it scarred a lot of people.

Brandon Dixon: Yeah.

Ashish Rajan: And to double-click on that even more, we definitely find that the separation of human behavior versus agent behavior to what you were saying, it's m- way more than regex.

Brandon Dixon: Oh, yeah.

Ashish Rajan: And-

Brandon Dixon: Yeah ...

Ashish Rajan: how, how much has that evolved? So to get some context, because I imagine a lot of people have tried UEBA.

Ashish Rajan: Have like, "Oh, I can do this," or I'm sure their product, w- whatever product they use would say, "I can... We can do this as well."

Brandon Dixon: Mm-hmm.

Ashish Rajan: Where do you see the difference between the traditional one and the o- and the method that you see works better in this [00:10:00] kind of world we are moving in?

Brandon Dixon: I think what Yuba brought was, like, baseline activity, like statistical baselines that helped to try and understand, like, how people worked.

Ashish Rajan: Yeah.

Brandon Dixon: And so it tried to derive, like, working times, working behaviors, like habits, and then I think the failure of the, the time was that each one of those statistical anomalies became an alert.

Ashish Rajan: Mm.

Brandon Dixon: And obviously, there's a lot of fatigue. Just because you're working late at night doesn't necessarily mean that you're doing something malicious. So we preserve the part of Yuba that I like, which is baselining. I think baselining is an incredibly powerful concept. You talk to a lot of incident responders or even, like, mature, uh, cyber programs, and they have baselines that they roll out.

Brandon Dixon: Yeah. They need to understand what's normal for their cohorts. So we'll, uh, model the same baseline activity. The difference is we will include those sorts of things in context. So if someone is doing something outside of [00:11:00] work hours, we'll tag that type of behavior as such. We won't alert on it, but it becomes part of that story.

Brandon Dixon: Uh, if somebody is, you know, doing a lot more copying and pasting than normal, not only do we know the action that they're taking of their copying and pasting, which Yuba would've done, but we're al- also able to say we know what's in the copy and where the paste is going.

Brandon Dixon: And so we get more context than I think what a traditional Yuba solution had.

Brandon Dixon: And the reason why now, like why is it better now, is because you do have language models and embeddings at your disposal that allow you to pull in semantic information, words that describe the stuff around what people are doing to help fill in the gaps of, like, what is the person actually trying to achieve?

Brandon Dixon: What is their job, their objective, whatever. And then, of course, like in an agent, it's, it obviously becomes a, a little bit different there.

Ashish Rajan: Yeah. D- I mean, I guess to your point with the user behavior as well as the agent [00:12:00] behavior, to your point, now that you have a bit more context- I thought it was... The reason why people struggled with it was also because I like, uh, me as a human like going to a coffee shop, let's just say 9:00 AM every morning.

Ashish Rajan: Yeah. That's my, that's my fuel.

Brandon Dixon: Yeah. Creature of habit.

Ashish Rajan: And yeah, yeah, yeah, and I thi- I do that every day and... But then one day I decide, you know what? I'm bored. Yeah. I'm gonna go to another coffee shop.

Ashish Rajan: So the question always used to be that humans are, in general, are very unpredictable. Sure. And so does this kind of the, uh, understanding of intent where, hey, the fact that a human would actually make a random call any ti- and just because they feel like it on a day- Yeah

Ashish Rajan: does that still work in this context of way or the way of thinking?

Brandon Dixon: I, I mean, like it's... That'll be an anomaly. Yeah. But we won't necessarily fire an alert on it, but it'll be part of like that story. It'd be a deviation in some sort of pattern, but that pattern or the particular behavior might be innocuous or it may not matter.

Ashish Rajan: Yeah.

Brandon Dixon: Right? Going to another coffee shop, um, may be a deviation from the norm, but is not innately risky.

Brandon Dixon: [00:13:00] Right? Someone working late at night a lot of my engineers- ... they're pulling late nights as we get to BlackHat. Everybody's really excited. They wanna get the stuff out there. You know, when I look at their baselines, I can see anomalous activity of them working many late nights and, you know, you can see that and it's part of the broader, like cohort.

Ashish Rajan: Yeah.

Brandon Dixon: And so it allows you to then say, "Well, why is that happening?" And the difference with Yuba would've been like, you don't know 'cause you don't have the context. Whereas something like Ent, you can literally just go see the behaviors that they were doing in that moment and then say like, "Oh, cool, like they're just doing their job, but they're doing it later into the night."

Ashish Rajan: Oh, okay. 'Cause, uh, another thing that seems to coming up, uh, in more conversation is the whole AIUC, AID- AIDR application control as some of the methodologies people should be using. Sure. Uh, if you can just, A, if you can describe that, what, what are they and why are they relevant in this conversation?

Ashish Rajan: 'Cause uh, cybersecurity loves acronyms and introducing new things. And does... How does that apply to this [00:14:00] particular world of making sure the workplace is safe?

Brandon Dixon: Uh, this is where I think like security sometimes overcomplicates things.

Ashish Rajan: Yeah.

Brandon Dixon: Like from my view, we've got a couple things that are in the mix right now.

Brandon Dixon: You have AI runtime control, uh, you have like these AI guardrails, you have AI detection and response. To me, they're all like- they're all trying to achieve the similar outcome.

Ashish Rajan: Mm.

Brandon Dixon: The purpose is, is that we have something that's not human inside of the environment that has some reasoning capabilities and access to tools to, like, create, new things that it couldn't do before.

Ashish Rajan: Yeah.

Brandon Dixon: And so there needs to be an understanding of what is it that thing is doing. So you need some level of, like, an inventory of, like, what is all of my AI software, sanctioned and unsanctioned? Where is that AI software running? Mm. Is it within a runtime that is providing some level of security protections?[00:15:00]

Brandon Dixon: And then in the event that runtime is not particularly great and something bad happens, can I detect that bad thing, but can I also respond to it with the necessary traces and information? So when I look at, like, all of these little subunits that are being created, I don't know if I would put them under different nomenclature per se.

Brandon Dixon: To me, it's all part of AI governance, and a holistic solution should provide insight into any one of those areas where an agent runs. It should be able to provide you the traces, the prompts, the tool calls, the responses, and it should give you both deterministic and some sort of, like, behavioral modeling that allows you to not only prevent the agent from doing something bad, but also being able to see what the agent did if in the event that something bad happened.

Ashish Rajan: Mm.

Brandon Dixon: Why add all this new stuff?

Ashish Rajan: Yeah.

Brandon Dixon: Like, I, I mean, I feel like you're just... To, at, to some degree, like, the industry likes to segment for the sake [00:16:00] of making it simple. Now, I will argue it is confusing. It's hard to stay part of all of this AI adoption and, and obviously people are excited about it, but If you overcomplicate it, then all of a sudden it's like you got four point solutions to do one thing, agent governance.

Brandon Dixon: Just make it one.

Ashish Rajan: Yeah.

Brandon Dixon: This is how we got to the problem in the first place. Every time we have something that our, like, core control point can't do-

Ashish Rajan: Yeah ...

Brandon Dixon: we make another point solution, and that's how we have... What? How many vendors are on the floor this year? Yeah. Do you know?

Ashish Rajan: I imagine around hundreds, over a hundred.

Brandon Dixon: Oh, thousands. Yeah. I think thousands are on the floor. It's

Ashish Rajan: crazy. 'Cause you almost... To, to what you said, is should the right approach then be for asking for vendors to do more instead of trying to create a new category?

Brandon Dixon: Yes. Like solve the problem from a better architectural standpoint.

Ashish Rajan: Yeah.

Brandon Dixon: So much of what it is that we're doing is we're, like, bolting on these features or creating new categories.

Brandon Dixon: Holistically look at the architecture and say, "How would I solve this?"

Ashish Rajan: Yeah.

Brandon Dixon: I mean, an alternative [00:17:00] way of solving it is, like, I've seen AI gateways. You know, like, that is one way of doing it to try and push people through a preferred path.

Ashish Rajan: Yeah.

Brandon Dixon: I think it has limitations. It doesn't respect the local execution or making use of all that, that, that context that exists there, but that is one way in which you could solve it, uh, using kind of an existing method.

Brandon Dixon: But I, I just don't like adding on new stuff for the sake of new stuff.

Ashish Rajan: One of the questions I had which I was trying to think of as you were talking about this as well, is because one of the re- one of the s- for lack of a better word, which six people use as compliance as a thing that, "Hey."

Ashish Rajan: And a lot of use cases in compliance tend to be around, "Hey, what if I take a screenshot or, or take a phone picture of this?" There's so many edge use cases. Yeah, yeah. Where does... I guess maybe the right question is what is the foundational thing people should have to be even re- to be ready to adopt endpoint security from an AI perspective?

Ashish Rajan: 'Cause you almost... I going back to what I was saying earlier, a lot of enterprises already have an EDR, MDM, and all those things. [00:18:00] Is there any use case for AI for all of it? Or are, is this more like, is the way you see endpoint security, at least the AI version of it- Mm-hmm ... for workplace, is that, oh, if you have AI use cases, these are the good ones to go for, and these, this is where AI does a great job, and especially in the AI, uh, and especially in the endpoint use case where I'll just say my organization only primarily uses AI through browsers.

Ashish Rajan: That's an assumption I made. I'm not even including the fact that product, prob- probably their coding agent's being used. Mm-hmm. Is there a place where you find that there are obvious gaps in visibility that people are usually not aware of? Or I guess what I'm trying to find... If I take a step back, as a CISO, I'm trying to make a decision for...

Ashish Rajan: I have specific use cases in AI, and I get I need the whole, the full shebang.

Brandon Dixon: Yeah.

Ashish Rajan: But what's a, what's a good way for me to start this AI security program that I'm working on, which at least makes me a, at least gives me the good starting point. Right. Is endpoint security the right point to start in the, right at the beginning?[00:19:00]

Ashish Rajan: 'Cause I've obviously been, I'm being sold the browser security solution as well. Right, right. Like, what's a, what do you think is the right path to kind of follow?

Brandon Dixon: I mean, I think it depends on every organization- Yeah ... it's gonna be slightly different. But from my vantage point, obviously being somewhat biased, I see a lot more people using AI outside of the browser.

Brandon Dixon: Claude Cowork, Codex, they're not even just coding agents anymore, right? Like, we've moved past ChatOps, and we're into agentic harnesses that now run on a desktop, and they're very effective.

Ashish Rajan: Yeah.

Brandon Dixon: And so, like, that is innately not the browser.

Ashish Rajan: Mm.

Brandon Dixon: So not to pick on browser-based solutions, I think that they provided, like, a really good way of funneling or, or, controlling what was happening.

Brandon Dixon: A VDI use case, for example.

Ashish Rajan: Mm-hmm.

Brandon Dixon: But I don't think that's the way of the world today, and in fact, when we talk with prospects, they're either pausing their investments in these areas because they'd rather invest in the endpoint because it gives them a more holistic view-

Ashish Rajan: [00:20:00] Yeah ...

Brandon Dixon: and the more control Or they're saying like, "We've already made this investment, but we need to add something else to like provide some belt and suspenders to make sure that we're not running into issues."

Ashish Rajan: Hmm.

Brandon Dixon: But to your question around like, where would you start? I mean, I think the easy answer that a lot of people start with is having an understanding of what's actually running, right? Yeah. But

Ashish Rajan: like,

Brandon Dixon: I think too many people look at that and they go, "All right. If I just know what's out there, that's enough."

Brandon Dixon: Hmm. And it's not. Like, 'cause the, the, the big problem is this: I can almost guarantee if you're not locking your environment down, you are absolutely running unsanctioned AI software, and you're totally running the sanctioned software. But every single day, AI is getting embedded into a new application, or there's a new startup and tool that people are excited and they want to adopt.

Brandon Dixon: So you need some way of dynamically understanding what is the software that's being leveraged, and then once you understand what's allowed, that informs and tells you [00:21:00] what's not allowed. And then you have to understand how people are using it. Because AI, that, the general nature of how it functions allows it to do so many use cases.

Brandon Dixon: So why would you not adopt the technology? Uh, and it just doesn't make any sense to me. We're not gonna use AI because we can't control every aspect of it, but then the flip side is we're just gonna adopt AI and like hope for the best and not have any clue what people are doing. It doesn't make any sense to me.

Brandon Dixon: You have to understand what's there and then what people are doing in it to inform what your response should look like. And

Ashish Rajan: I think it double, it doubles down on something that I was thinking as you were saying this, that just the data flow of how things or how data flows within an organization-

Brandon Dixon: Yeah

Ashish Rajan: between AI tools, browsers, applications.

Brandon Dixon: It's crazy.

Ashish Rajan: Yeah. It's almost sounds like to, to what you were saying earlier, there's, there's already plenty of blind spots that are obvious with traditional solutions that are not focused on AI-specific things.

Ashish Rajan: [00:22:00] So do- The analogy over there being, oh, so what is the point where the data protection should be applied?

Ashish Rajan: Is that still endpoint?

Brandon Dixon: I... Like this is, you know, up for debate. I think I've talked with people, um, who have, you know, AI startups on the cloud side.

Ashish Rajan: Yeah.

Brandon Dixon: I think it's interesting. I'd like to... I'm a startup guy. I respect anybody that's doing a startup. I wanna learn from my peers. I don't perceive myself as competitive to that space.

Brandon Dixon: So I talk to them, and I listen to the challenges that they have, and they have like terabytes or petabytes of information in the cloud for an organization.

Ashish Rajan: Mm-hmm.

Brandon Dixon: Documents, right? And they don't have any sort of like user information that informs which document's more important than another. It's just sprawl everywhere.

Brandon Dixon: And they're telling me, "Oh, we're gonna use, uh, small language models or open models to kind of read the contents of all of those files and then like put the labels on," because data classification's really hard. [00:23:00] Mm-hmm. And I think about that, and I go, "That's a great idea. I like that." However, it's cost-prohibitive.

Brandon Dixon: Yeah. Like, I mean, if you're running through a cloud service provider-

Ashish Rajan: Yeah ...

Brandon Dixon: and using one of their off-the-shelf models, you are... I mean, it's just not gonna work. Mm-hmm. Full stop. Not to mention the time it would take to scan it.

Ashish Rajan: Yeah.

Brandon Dixon: So for us, like one of the new capabilities that we brought for BlackHat, like in, in kind of our milestone here, was putting data classification directly on the endpoint itself.

Ashish Rajan: Oh.

Brandon Dixon: What is the value?

Ashish Rajan: Yeah.

Brandon Dixon: The value is I know the information that, that exists on the endpoint 'cause I can scan it. I know which ones you're actually interacting with and which ones are important, and I have this latent compute that the company has already provisioned that allows me to go and like reach into that file and use a small language model to kind of scan the contents and figure out is it sensitive or not.

Brandon Dixon: Mm. But I also have the person who's logged into the endpoint. I [00:24:00] have the behavior. I have the agent behavior. So once I have that label that exists on the endpoint, that allows me to inform that it is sensitive, where that sensitive data resides across the entire, uh, organizational estate, and I can do that in like a week because it, it's an incredibly powerful tap into latent compute.

Brandon Dixon: I know who's using that data and for what purpose.

Ashish Rajan: Yeah.

Brandon Dixon: And I know when an agent is gonna activate that data. And so within our policy engine- I can literally say, "This person is allowed to see it, but the agent is not allowed to use sensitive, uh, data in its answers." It gives me control.

Ashish Rajan: Yeah.

Brandon Dixon: So is the endpoint the best place to do it?

Brandon Dixon: I think so because it's a smaller footprint that can be tackled at scale, rather than trying to centralize everything and have one big machine do it, which again, is cost prohibitive. Can you scale it out to the latent compute that already exists- Yeah ... and use all of this behavioral signal to inform that?

Ashish Rajan: Interesting. Is the deployment model [00:25:00] then for you guys, is it agent or agentless?

Brandon Dixon: It's agent. But we are doing, uh... We're trying other areas too, like when possible, to do, uh, for instance, like more application control.

Ashish Rajan: Mm-hmm.

Brandon Dixon: So this is another area where I think EDR is particularly weak. They don't necessarily understand the organization's environment-

Ashish Rajan: Yeah

Brandon Dixon: and then prevent certain applications from running in the first place. So a lot of click fix is, is sort of meant to stage getting a remote access tool inside of the organization, which is not malicious, but it's used for malicious purposes. Those tools shouldn't function, full stop. Like you should not be able to run that tool-

Ashish Rajan: Yeah

Brandon Dixon: if you're not in IT or if the business doesn't even procure it.

Brandon Dixon: But there's no preventative controls. But we can tap into kind of things, at least within Windows.

Ashish Rajan: Yeah.

Brandon Dixon: You have built-in WDAC and like ways to kind of write policies there. So we have been exploring that as like, you know, for shops that want, you know, at least a Windows [00:26:00] shop, could we push down some preventative controls where the agent doesn't need to be functioning all the time?

Brandon Dixon: We're trying to figure out if that's like worthy of like, uh... If that's something that everybody would want.

Ashish Rajan: Yeah.

Brandon Dixon: But at least for now, like we deploy an agent and I... it's lightweight. It's not particularly large. Even when we use AI, uh, the way in which we deploy the AI, uh, does not interrupt anybody's day or peg the system in any material way.

Ashish Rajan: The reason I was asking this is I'm thinking of the whole Hugging Face thing that happened recently- Mm-hmm ... which came out of Sandbox and-

Brandon Dixon: Yeah ...

Ashish Rajan: whole shebang. I think most people know what's happening there. Because you mentioned Claude CoWork, you mentioned- Yeah ... Claude Code.

Ashish Rajan: Some of these are-- Well, their software is installed on the application.

Ashish Rajan: And EDLs usually would just see that as- Processes ... you have Claude, you have Claude installed.

Brandon Dixon: That's

Ashish Rajan: right. Great job. Right. Like you're using AI.

Brandon Dixon: Yeah.

Ashish Rajan: Um, how, how does endpoint security look at the same thing? Because I thought, and I'm probably sharing what other lot of people think, is that Claude CoWork is hard to, [00:27:00] uh, I won't say manage is the right word for it, but, and it doesn't have to be Claude Code.

Ashish Rajan: It just could be anything, quote-unquote, agentic-

Brandon Dixon: Sure ...

Ashish Rajan: running, which is just say, "I'm gonna-- I got access to your Salesforce Slack, and I'm making all these different things."

Ashish Rajan: Going back to your data classification one, I may be a developer who has, has production data for some reason on my laptop.

Ashish Rajan: There's a lot of context there.

Brandon Dixon: Reasonable- Yeah,

Ashish Rajan: yeah ...

Brandon Dixon: reasonable expectation.

Ashish Rajan: Yeah, yeah. So you're like, there's a lot of context there. Uh, and I'm not saying let's replay the Hugging Face scenario, but if it's... How does endpoint security kind of fit into that kind of world where-- 'Cause now, before this point, this was not even a thing people would talk about.

Ashish Rajan: Yeah. This

Brandon Dixon: was like-- I, I was talking to a cust- uh, like a, not a customer, a prospect, uh, who's looking forward to, to install, and they were like, "Don't tell me you've solved this problem because I didn't even have this problem like three months ago."

Ashish Rajan: Yeah.

Brandon Dixon: And I'm like, "All right, fair enough. I'm not saying that I solved it, but we have some good ideas, though."

Brandon Dixon: I mean, I think for an endpoint solution, if you have AI that's running locally, the challenge there is not so much the hooks.

Ashish Rajan: Yeah.

Brandon Dixon: Right? Because I, I [00:28:00] think what was really nice about OpenClaw was that it sort of woke most people up that if you remove security for a second and you kinda YOLO it-

Ashish Rajan: Yeah ...

Brandon Dixon: and you say, "I'm gonna put a model on top of this harness and like just let it do stuff."

Brandon Dixon: I think everybody woke up and was like, "Whoa, this is pretty awesome." Yeah. Now, obviously it had some bad things, but what that did was it woke up the frontier labs to say, "Okay, we need to update our apps to ship the same agentic harnesses and then have a runtime there." Great. For them to get installed in the enterprise, they obviously have to have security baked in.

Brandon Dixon: Yeah. Runtime is decent, but you need the observability, so they put the hooks in. Anybody can hook the prompt, uh, the response, the tool call, and see what's happening. They provide those traces. Any major provider does it. We hook 'em all. Everybody hooks 'em all.

Ashish Rajan: Yeah.

Brandon Dixon: Cool.

Ashish Rajan: Yeah.

Brandon Dixon: So I think, like, that's step one for an endpoint provider, is you gotta get into the agent itself.

Brandon Dixon: Now, what you're talking [00:29:00] about is that agents fundamentally operate different than a human would.

Brandon Dixon: And so where a human has a goal, and they may not explicitly state it, but they're gonna take steps along the way to complete their work-

Ashish Rajan: Yes ...

Brandon Dixon: I'm gonna be able to see those steps, and I can infer what that intent is- Yeah

Brandon Dixon: relative to the objective. Now, that's hard, right? You're not always gonna get it perfect. The beauty of agents, though, is that the intent is expressed and codified inside of the prompt. Mm-hmm. It's there, right? So if I can hook the prompt, then it becomes a question of, well, how do you analyze the prompt to determine intent?

Brandon Dixon: And that I leave to dear listener- Mm ... or watcher figure it out. But, like, that's an area where we've invested time, and I think we have some very good solutions that I've not seen other people do, that allow us to classify those types of behaviors in a way that allow us to understand when an agent is being instructed to exfiltrate data or to perform destructive actions.

Brandon Dixon: Or we can [00:30:00] deterministically say that sensitive data is totally making its way into the context.

Ashish Rajan: Yeah.

Brandon Dixon: And then we can taint that, that session to understand that the output needs to be labeled in the same way So again, it goes back to the question you had before, runtime you know, AI DR, some sense of inventory- App control

Brandon Dixon: whatever. They're all related to me.

Ashish Rajan: Yeah.

Brandon Dixon: Right? Like you-- To do this right, you have to have all of those pieces going. '

Ashish Rajan: Cause to your point, if you take a step back, literally it could be anything that you have so-installed as a software, and it could be... Like, and to your point, I may have not had that goal until that very moment that I thought of it, that I should do this action of, quote-unquote, action of I should put a sandbox.

Ashish Rajan: I should put a I don't know, some kind of an automated agent or OpenClaw something in that sandbox. Sure. Give it a mission, let it go and- But, but,

Brandon Dixon: but think about a sub-agent. Yeah, yeah. Right? Like, it's not even that we just- Oh, yeah ... stop one agent. Like, what happens when an agent goes, "Oh, I can actually achieve my [00:31:00] objectives, uh, by, by forming three other agents"?

Ashish Rajan: Yeah.

Brandon Dixon: You still need to hook what that thing is do- what those respective things are doing and track those given intents as well. You need to have, like, some rails on the thing to know- Yeah ... like what's allowed and what's not allowed, and I still think we're in like the, um, the forming period right now.

Brandon Dixon: People are trying to figure out what's the best way to do it. I won't pretend to say that we've completely solved it.

Ashish Rajan: Yeah,

Brandon Dixon: yeah. I don't think that anybody has. It's a, it's a hard problem.

Ashish Rajan: Which is a good point, because if for-- then to your point, CISOs who are talking to Uh, let's just say endpoint security ecosystem, right?

Ashish Rajan: Sure. Because they're being sold to that. A, a true test of separating signal from the noise, what do you think would that be today? Because clearly to your point, to what you said, there are gaps that even OpenAI doesn't have answers to. Leave it all- That's right. Le- leave, leave us alone it's like- Yeah, yeah

Ashish Rajan: the, the bigger players don't have answers to.

Brandon Dixon: Yeah. E- exactly.

Ashish Rajan: Yeah, so- So

Brandon Dixon: What's the... Are, are you trying to get at, like, what's the test? Like-

Ashish Rajan: Yeah, like what's the s- how do I separate the signal from the [00:32:00] noise? 'Cause obviously I'm being sold browser security one end, endpoint security another, then my, my runtime security.

Ashish Rajan: Yeah. To a point there's this... And my EDR person is telling me, "Hey, I can do this as well." Yeah, yeah. MDM is saying the same thing, AppSec is saying the same thing. What's a good, for lack of a better word, litmus test that I can ask questions about to separate signal from the noise? Where, especially the ones where AI bolted versus AI native-

Brandon Dixon: Yeah

Ashish Rajan: versus people who actually have gone deep enough to even understand that, hey, there are things that are unsolved today.

Brandon Dixon: Mm-hmm. I I would say w- maybe what's your level of cloud dependence?

Brandon Dixon: Because, like, in order for, for you to really be effective... I mean, this is, like, our entire mission at Ent is to be preventative.

Brandon Dixon: Right? I don't wanna react. Of course, like, some people are not gonna wanna prevent every conceivable thing that shows up, but the overarching fear with AI is that by the time that someone realizes that maybe it's broken out of a sandbox and forms some new objective, [00:33:00] that they don't realize it and now bad things occur.

Brandon Dixon: So you have to have some sort of preventative means, which means you can't backhaul all of your logs to the cloud. You can't put all of your decision logic in the cloud. You have to design the solution such that it can run performantly on modern hardware and actually prevent bad things from occurring.

Brandon Dixon: It needs to be able to model that behavior.

Ashish Rajan: Yeah.

Brandon Dixon: And I'm, I-- Like, personally, I'm not in a position where I think, let's see, 20, 2030-

Ashish Rajan: Yeah ...

Brandon Dixon: you know, it's hard to predict, uh, even, even a year out from now, but I don't see humans kind of stepping out of the, the fold, right?

Ashish Rajan: Yeah.

Brandon Dixon: I think we're... Part of what makes work is people, being part of that process, and so I think humans are always gonna be there.

Brandon Dixon: So cloud dependence, how do you actually model behavior, right? Like, for the short term, you know, whatever that, that objective measure is, like, humans are in the mix- Yeah ... so how do you know what's normal for them versus what's not? [00:34:00] How do you measure, like, the, the agents themselves? And then how simple can you make the policies-

Brandon Dixon: And robust so that, like, you can really stop bad things from occurring? I, I don't know the best way to test companies right now. If I were a CISO, it's, it's, uh, it's a challenge, but I think in my personal experience- They sort of know it when they see it. The conversations that, that we have that are the best is that someone goes, "This is what I was waiting for."

Brandon Dixon: And I go, "Say more."

Ashish Rajan: Yeah.

Brandon Dixon: And they're like So much of what we saw with security solutions is that they're bolting AI on to, like, summarize an alert or, like, help me write a better policy. Those are great.

Ashish Rajan: Yeah.

Brandon Dixon: But they're, like, not changing the funder- the fundamental architecture for how security is done, and they're not, like, revisiting, like, sins of the past and saying, "Is there a better way to do it?"

Ashish Rajan: Yeah.

Brandon Dixon: And so when we do our [00:35:00] pitch, yeah, it's, you know, it's big. We wanna try and, like, do something large. But everybody looks at that, and they're like this is a sound way to do it."

Ashish Rajan: Mm.

Brandon Dixon: And it's a testament now that, like, back in March, I think we felt like we were kind of on an island. I mean, I didn't feel I had the conviction.

Brandon Dixon: Like, this is a startup trade as well, you gotta believe.

Ashish Rajan: Yeah.

Brandon Dixon: But there wasn't many people flocking to the endpoint.

Ashish Rajan: Yeah, yeah.

Brandon Dixon: Right? I mean, there was a lot of talk about a whole bunch of different stuff, and now there's countless startups that are like, "The endpoint is the way."

Ashish Rajan: Yeah, yeah, yeah.

Brandon Dixon: I mean, just in the last, like, week, like, Uber, uh, released-

Ashish Rajan: Open sourced their, their agent as well

Brandon Dixon: yeah, they open sourced their stuff, and then, um-

Ashish Rajan: Visa also has released an open source tool. Who

Brandon Dixon: was the other one that was, like, Numbad? Or, or, uh, Perplexity. Perplexity released- Kyler. Kyler ... like, an open source, like, kind of telemetry harness for their, uh, agent governance as well.

Ashish Rajan: Yeah.

Brandon Dixon: So, like, I mean, I love it, right?

Brandon Dixon: That to me is awesome. It's a testament that there's not a big [00:36:00] moat in AI security right now. People are still forming it, and so when somebody tells me they got it solved, I'm suspect.

Ashish Rajan: Yeah.

Brandon Dixon: When somebody tells me that I need this narrow solution, I'm suspect 'cause, like, we're not even, like, at a point where it's stopped being out of flux.

Ashish Rajan: Yeah.

Brandon Dixon: Yeah. So you just gotta hold on and, like, keep anticipating what the next steps are.

Ashish Rajan: Yeah. And I guess due to what you said, the re- true question over there is the fact that we understand that if someone actually says that they have solved the AI security problem, you probably should red flag right there.

Brandon Dixon: That's a good litmus test.

Ashish Rajan: Yeah, yeah. That's a good red flag. I,

Brandon Dixon: I am gonna steal that from the prospect that's moving- Yeah ... one of the prospects that's moving forward with us. They're like, "If they tell me that they've solved it, I know they're full of it."

Ashish Rajan: Yeah, yeah.

Brandon Dixon: And, like, they told me, they're like, "It doesn't have to be perfect.

Brandon Dixon: I just wanna see what your methods are."

Ashish Rajan: That's right, yeah.

Brandon Dixon: And it's, it feels collaborative.

Ashish Rajan: Yeah.

Brandon Dixon: You know, obviously not everybody's gonna be you know, willing to volunteer their time in that way. But, you know, I still [00:37:00] see, uh, a lot of folks that are, like, on the fringes trying to figure out what is their strategy.

Brandon Dixon: And I see more people maybe adopting and testing multiple solutions to try to figure out, like, which one's gonna be the best for me. And so, like, I, I don't think that's a bad thing.

Ashish Rajan: Yeah. I- You

Brandon Dixon: know, I think everybody has something different to offer in some ways.

Ashish Rajan: I think one more thing that comes under similar vein of that topic is Building trust in the AI process.

Ashish Rajan: Like, you know, for example, people are used to the EDR way of dealing with alerts.

Brandon Dixon: Right.

Ashish Rajan: They know what alert comes in, a security operation person picks it up, there's ticket queue, whatever. There's a whole process defined for it. Prevention is a different one where it's almost like At least in detection, you feel like you've covered all use cases, everything else is a zero day.

Ashish Rajan: At least that's the assumption we all go... Hypothesis, let's just say- I don't- ... most people go forward with.

Brandon Dixon: I, like, I, I don't know if I subscribe to, like, detection is ever done.

Ashish Rajan: Oh,

Brandon Dixon: yeah. Right? 'Cause the adversary keeps evolving, so- That's

Ashish Rajan: right ... there's- No, what I meant was more in ter- in the sense [00:38:00] that you at least have the assurance that we can keep building detections for- Yes

Ashish Rajan: what the right thing is. Yes. But I don't know the intent that Ashish is gonna go to a different coffee shop tomorrow.

Ashish Rajan: But what I build a detection on the fact that I know these patterns, I've seen X number of use cases for it. When it comes to prevention, it's more on the hook of I'm also almost testing the intent of Ashish's right and wrong and making a call for that.

Ashish Rajan: Sure. And how does one tr- When you use AI to address that-

Brandon Dixon: Yeah ...

Ashish Rajan: how do you help your customers and prospects and others build that trust in AI for that decision that it's normally... So now, obviously, uh, security as a community is known and very well known for pro- producing more false positives every time you run it.

Ashish Rajan: So unfortunately, AI has that hallucination thing going for it against- Yep ... against it. So how do you find that you're able to provide that trust to your customers about the, "Hey, this is how we deliver our results- Mm-hmm ... that's why you can trust [00:39:00] the AI that we are using," versus someone who's just basically bolting on AI and- Yeah

Ashish Rajan: hoping for the best?

Brandon Dixon: Well, um, I think the first off is I would never go into, like, a customer environment, roll out our solution and say, like, "I'm just gonna prevent from day one."

Brandon Dixon: Because every environment's going to be different. I think there's value in understanding and tapping into that, like, lack of observability that organizations have had.

Brandon Dixon: And so step number one is to figure out, like, what is it that you're willing to go after? Some people come to us for inside risk, some worry about data movement people have increasingly come to us to, like, map out their AI inventory and to, like, put some controls around that, and then it's, like, preventing software that shouldn't be there.

Brandon Dixon: But even in the case where we're preventing software that shouldn't be there, which is kind of a binary one or a zero- Yeah ... is it allowed or is it not?

Ashish Rajan: Yeah.

Brandon Dixon: There's still a burn-in period that you might have where you could benefit from as short of a d- as a day-

Ashish Rajan: Yeah ...

Brandon Dixon: I'd say at least two days-

Ashish Rajan: Yeah ...

Brandon Dixon: but, like, up to a week to [00:40:00] understand what is normal for the organization.

Brandon Dixon: And from there you can then surgically implement the things that you actually want to detect. And then once you've detected those, you don't have to prevent them immediately or ever.

Ashish Rajan: Mm.

Brandon Dixon: Right? I, I think there's an advantage to doing the prevention, and the prevention for us is not a hard block. It can be a soft block as well, or a way of surfacing to the user to collect information from them But we give our, our customers the control.

Brandon Dixon: So it's, it's not AI making the decision, it's them that make the decision. Right. They choose-

...

Brandon Dixon: The policy that's rolled out with detection.

Ashish Rajan: Yeah.

Brandon Dixon: And when they feel that detection is good and surfacing the things that they want, they can then modify that same detection policy-

Ashish Rajan: Mm ...

Brandon Dixon: and add like a declarative statement of like, "I wanna have a intervention at this moment."

Brandon Dixon: And it might be a dialogue, it might be an overlay, it might be, um, you know, using behavioral modeling to like limit what someone's able to do.

Ashish Rajan: Interesting you say intervention, because [00:41:00] a lot of people look at con- think of control, they think of the, "I've blocked Ashish." Yeah. They don't think of inter- It, it's interesting you use the word.

Ashish Rajan: So what, what is intervention in your world? Like, how, so how are you stopping Ashish, or I guess let's just say slowing down Ashish rather than that?

Brandon Dixon: Sure. Yeah, I think it, like, I think DLP gave things a bad rep because when it had high degrees of false positives, it literally stopped people from doing work.

Ashish Rajan: Yeah,

Brandon Dixon: yeah, yeah. That's the P, prevention. And so in our world, like, I don't take a, I don't know, let's call it a, a, a lowercase P.

Ashish Rajan: Yeah.

Brandon Dixon: I think that my goal is to deter people from doing something that they shouldn't. Yeah. And so you may not want to have a hard block on... I'll give you an example. You have a sanction list of AI tools.

Brandon Dixon: Great. Super easy to set up in our product. Immediately I'll tell you if there's unsanctioned tools. What do they wanna do with those unsanctioned tools? Some people might say, "I wanna block them immediately." Okay. [00:42:00] That, that might work. Um, you know, and every week you're gonna be blocking somebody's new tool or new way of doing things in the era of AI, and maybe you're not getting the productivity that you want.

Brandon Dixon: So the alternative is- ... they go, "Well, I'm not actually gonna block it. I wanna look at what's happening. And when I see this happening, you know what I'm gonna do? I'm just gonna remind the user, maybe as a toast notification-" Right ... little like flash of the screen, a little border around the application itself that just reminds them, "Hey, this is an unsanctioned like flow, that, you know, there's additional risk in what it is that you're doing."

Brandon Dixon: Are

Ashish Rajan: you sure you wanna do this?

Brandon Dixon: Yeah, and it doesn't need to warrant some particular response. Like my fourth hire at the company was a designer. Like we have a pretty extensive user experience team, makes our product look good.

Ashish Rajan: Yeah.

Brandon Dixon: Makes our, our website and assets look good. But we think deeply about the experience, and one of the big hurdles that we felt we had to overcome was security has long lacked any sort of user experience.[00:43:00]

Brandon Dixon: Like CISOs didn't want it. They're like, "Security should not be seen." And we believe that it should be seen because in a world where users are the ones that are facing challenges or issues, it is so frustrating when you're trying to get your job done and security or IT has blocked you, but you have no clue why.

Brandon Dixon: Mm. Because there's nothing that's telling you. There's no affordance inside of that experience. You're just trying to install and it keeps failing.

Ashish Rajan: Yeah.

Brandon Dixon: What do you do? You put in a ticket. What does the IT team do? They go, "Oh, again? Like, what is wrong with these people?" And they go and have to tell them like, "That's not sanctioned software."

Brandon Dixon: And they go, "Okay, but like I'm being told to use AI." My point being, like an intervention for us could be something hard. Log the user out, kill a process. Could be silent, you know, take a screenshot, collect forensic information, turn on additional logging, or it could be the missing user experience that security has never had.

Ashish Rajan: Mm.

Brandon Dixon: Deter me from making a mistake. [00:44:00] Maybe like, uh, I'll give you an example of something that I thought was really cool that, that a a customer shared with me, which they're like, "Baselines."

Ashish Rajan: Okay.

Brandon Dixon: I'm like, "Okay." They're like, "When a new person is hired, we want to limit their application and, uh, website use to only those that have been observed in people that have been working at the company for over a year that are part of that same peer cohort."

Brandon Dixon: And now like if... Just think about that. So like I'm a new user, and let's say in the course of 30 days, I go to, I, I'm about to fall victim to a phishing.

Ashish Rajan: Yeah.

Brandon Dixon: You know, like a login page, whatever. In a world like where you have this baseline, it creates this new deterrence opportunity where we can say, "Hey, no one else in your peer group has ever accessed this, a-accessed this website before, and it might be...

Brandon Dixon: And because it's a login page, this might actually be a phish."

Ashish Rajan: Yeah.

Brandon Dixon: Like, no one else in your group has re- like, has needed that to do their [00:45:00] job. I don't have to hard block them-

Ashish Rajan: Yeah ...

Brandon Dixon: but I can use all of that signal around me to like put an overlay to make them like click and attest that they're about to do it anyway.

Ashish Rajan: Yeah.

Brandon Dixon: Like that to me is very interesting. That's not been explored in security.

Brandon Dixon: And I think that's why do you... Like in the spirit of why the endpoint, if you want to be in a position to do those sorts of things, you have to be where people work.

Ashish Rajan: Yeah.

Brandon Dixon: Because if you have to round trip to a cloud-dependent architecture, the latency incurred is too great and you miss your chance.

Ashish Rajan: Okay, 'cause you want it to be near real time as possible as well. It has to be real time. What... And 'cause, uh, it's sort of interesting you mentioned about the sanctioned apps as well. These days the ecosystem has sanctioned apps with AI too.

Ashish Rajan: And sometimes, d- to your point, you may have made a baseline, but that baseline may have not occurred for the new AI feature that the-

Brandon Dixon: Sure

Ashish Rajan: I guess the new... So whatever the sanctioned application has kind of started using and given access to, "Hey, free trial."

Ashish Rajan: The [00:46:00] person accepts this and moves on. What, what does, uh, visibility for that look like? I guess so if- You still

Brandon Dixon: see it.

Ashish Rajan: Oh, right, okay. So endpoint security still goes into like the...

Ashish Rajan: 'Cause that's almost like a process within a process or I don't know how that would be in technical terms, but essentially, so you are able to see the fact that there's an AI, another AI being used with- Inside of a

Brandon Dixon: tool. Oh. Like an embedded, like embedded AI into like another tool, yeah

Ashish Rajan: Interesting. Wow.

Brandon Dixon: Okay Yeah. Like this is the advantage again of being on the endpoint. The way that a modern operating system renders applications in a visual space is using a tree structure, and you can walk that tree structure and understand what is visually being shown. Or if you have more progressive companies, um, you know, being able to take screenshots at the endpoint, run them through an embedding model to then distill like what it is that that person was seeing, um, maybe you throw the screenshot away after that 'cause you don't wanna actually transmit it out, but you can retain the contents of what was saw, what was [00:47:00] seen.

Brandon Dixon: And so you could see elements of like AI use in there. This is also where embeddings come into play. So embeddings you know, looking at words, so I won't pick on AI, I'll pick on, uh, remote access, like connection establish, uh, new session, remote access. There's words that sort of innately tie themselves m- more closely to remote access use.

Brandon Dixon: And so you can model those words in a detection, and then you can run behavior through that, and then you can determine whether or not there's a close match. This is how we detect some of our AI use. I think last time I was on the podcast at, at RSA, I gave you the example of WhatsApp.

Brandon Dixon: WhatsApp Meta

Ashish Rajan: AI. Yeah.

Brandon Dixon: With Meta AI.

Ashish Rajan: Yeah, yeah.

Brandon Dixon: We wrote... We didn't write a rule for that, right? I never wrote a policy where I'm like, "Oh yeah, when they click Meta AI within WhatsApp, like do this." That was like us being able to kind of look at the semantic information that was available to us, run it through our embedding [00:48:00] policy model, and it said, "This looks with high certainty like AI use."

Brandon Dixon: And when we went and looked at the output, we're like, "That's absolutely AI use," and we just didn't think to write it down. And when we brought that finding to the customer, they were like, "Huh I don't think I would've wrote that down. That was not in their threat model bingo-

Ashish Rajan: Yeah, yeah, yeah ... if you will.

Ashish Rajan: I mean, I'm not... I guess these days one would think it may be more common, but a few months ago, I don't think anyone... 'Cause now the pressure is a lot more on third parties to have AI as well. So not just security products, but non-security products- Exactly ... have AI as well, and that's being used by Bob in accounting, Suzy in legal.

Ashish Rajan: Yeah. Everyone's using them.

Brandon Dixon: I, I do think, you know, there's, again, in the spirit of, like, this problem is still actively evolving-

Ashish Rajan: Yeah ...

Brandon Dixon: you know, I don't think that there's a perfect solution to get insight into every conceivable nook and cranny. But I think the way that we've done it, both in looking at how the operating system renders, [00:49:00] uh, with the telemetry we have on the system, and then if given the opportunity to use screenshots, like, you can get a pretty good amount of the story of what's going on there.

Ashish Rajan: Awesome. This is good because that's all the technical questions I have. I am doing also the you laugh, you lose. Okay. I'll let you look at your, uh, joke.

Brandon Dixon: Yeah. I-

Ashish Rajan: While I, while I make my- I wanna make sure I

Brandon Dixon: deliver it

Ashish Rajan: appropriately. I think it's so much with our delivery as well though, right? It's just like you can come up with the best joke, but it comes down to how you deliver the joke as well.

Ashish Rajan: I was up on a dating website, and I came across this endpoint security data, dating profile, "Seeking a long-term relationship. Must be comfortable with continuous monitoring."

Ashish Rajan: It's all right. It's all right. Oh, wow. I didn't realize we could set up

Brandon Dixon: like

Ashish Rajan: that.

Brandon Dixon: Are you ready?

Brandon Dixon: Yeah,

Ashish Rajan: yeah, yeah. Okay.

Brandon Dixon: Knock, knock. Who's there? Prevention. Prevention who? Exactly. You don't remember me because I did my job. It's not as good. It's not as good. It's not as good. It's not as good. No, but I

Ashish Rajan: mean, uh, okay, it was [00:50:00] good enough to make me laugh, so, 'cause I was like, I've been hearing jokes since morning, so I'm like, "You won."

Ashish Rajan: I won. That was quite clear. I'm like-

Brandon Dixon: Yes ...

Ashish Rajan: I had it pretty much, I think I... It's funny, I had it in the f- I liked it even in the first half of that joke as well. So like, I la- so I lo- I didn't realize, but I started laughing as soon as you said the first half, 'cause you said, What was the word you used?

Ashish Rajan: Uh, prevention because you didn't realize, or-

Brandon Dixon: Because you don't remember me.

Ashish Rajan: Yeah, that's right. I just... if you would've just stopped there, I would've... I, I still found it funny 'cause, like, you'd never really know prevention has basically happened.

Brandon Dixon: There was a, there were some other ones I toyed with, like, uh, prevention like Rodney Dangerfield style.

Brandon Dixon: Like, prevention gets no respect. No respect at all. You know, like, uh, when we do the job right, there are no logs and people complain

Ashish Rajan: yeah, yeah. Well, I mean, yours is g- yours is good, man. I think-

Brandon Dixon: We, we need more humor in security.

Ashish Rajan: Yeah. It

Brandon Dixon: cannot be all stress.

Ashish Rajan: Oh, my God. And I also find that at least what Shilpi n I have believed is that this could be a good way to break the ice of some of that cybersecurity content as well.

Brandon Dixon: Yeah. '

Ashish Rajan: Cause, you know, I think at this point in time what's happened is because there's so many podcasts as well, that how [00:51:00] do you cut through one podcast through another? Right ... 'cause it's like, and especially if you hear endpoint security on all sides, you're like, "Which is the conversation that I should listen to?"

Ashish Rajan: Yes, it's great that the title sounds interesting and all that, but I'm like I find that humor cuts through a lot of things.

Brandon Dixon: Yeah.

Ashish Rajan: Even if it's dry hu- like, people from our industry will get it.

Ashish Rajan: Yeah. Like, they, they may or may not laugh at it, but they're like, "Oh, you know what? I'm curious. What, what's that joke?"

Ashish Rajan: I feel like I can talk to you forever, man, but I'm gonna wrap this up.

Ashish Rajan: Yeah, yeah. But, but just to wrap it up, where can people find more about the work you guys are doing, and where can they connect with you for all the endpoint security work you're doing as well?

Brandon Dixon: Ent.ai. Mm. So very simple, E-N-T dot AI is the best place to find us, and you can connect with me on LinkedIn. I got spicy takes.

Brandon Dixon: I got video. Yeah. Uh, yeah, I'm a, I'm a one-man band with opinions. I like to put stuff out there, so if you wanna connect and have, have dialogue, I'm more than happy to share it in that, that public space.

Ashish Rajan: I will put the LinkedIn and the website in there as well. Thank you for c- for coming on the show, man.

Brandon Dixon: Yeah, appreciate it. Thanks for having me.

Ashish Rajan: Thank

Brandon Dixon: you, and thanks everyone for tuning

Ashish Rajan: in as [00:52:00] well. Thank you for listening or watching this episode of Cloud Security Podcast. This was brought to you by techriot.io. If you are enjoying episodes on cloud security, you can find more episodes like these on cloudsecuritypodcast.tv, our website, or on social media platforms like YouTube, LinkedIn, and Apple, Spotify.

Ashish Rajan: In case you are interested in learning about AI security as well, do check out our sister podcast called AI Security Podcast, which is available on YouTube, LinkedIn, Spotify, Apple as well, where we talk to other CISOs and practitioners about what's the latest in the world of AI security. Finally, if you are after a newsletter, it just gives you top news and insight from all the experts we talk to at Cloud Security Podcast.

Ashish Rajan: You can check that out on cloudsecuritynewsletter.com. I'll see you next episode. Peace.

No items found.
More Videos