runZero Hour, Ep. 7: Fascinating Payloads & New Revelations in Threat Intelligence

In Episode 7 of runZero Hour, we welcome our first guest, Brianna Cluck, Security Research and Detection Engineer, from GreyNoise Labs!

Brianna shared insights on her fascinating work using honeypots to hunt and tag CVE-related traffic in the wild, flagging potential threats for defenders. She is a passionate cyber detective and enthusiastically cracked open the vault to reveal vexing, unsolved security mysteries. Tune in for a live brainstorming session to see how GreyNoise Labs and the runZero research team worked together to solve the 'x-files' mysteries that Brianna has collected in her cybersecurity travels.

The runZero research team also uses honeypots; however, instead of searching for threat activity like GreyNoise Labs, honeypots are goldmines for CAASM-related research, revealing new types of attacker techniques that can then be applied to asset discovery protocols. Learn how HD Moore sets up small honeypots to collect traffic and classify unknown packets quickly, aka 'the lazy way.'

Next, Tom Sellers takes a deep dive into his recent work probing Microsoft servers via TLS and explains how direct customer feedback can help the runZero research team develop more precise fingerprinting for improved asset discovery.

Last, but not least, we shared the most recent Rapid Response highlights. Find potentially vulnerable systems using queries in posts below; fun fact, you can use these with our free trial and Community Edition, along with our licensed Platform. Enjoy!

    Meet Our Speakers

    HD Moore

    Founder & CEO, runZero

    Rob King

    Director of Applied Research, runZero

    Tom Sellers

    Principal Research Engineer

    Brianna Cluck

    Special Guest, GreyNoise Researcher

    Subscribe Now

    Get the latest news and expert insights delivered in your inbox.

    Welcome to the club! Your subscription to our newsletter is successful.


    Related Resources

    Webcasts
    Attack Surface Management: Continuous discovery, external attack paths
    Your attack surface no longer ends at the firewall. With SaaS apps, cloud instances, IoT, and shadow IT multiplying, organizations are exposed in...
    Webcasts
    runZero Hour, Ep. 24: Attack graphs with runZero and BloodHound!
    In this episode, runZero's Tod Beardsley, Rob King, HD Moore and Jared Atkinson, CTO of SpecterOps, dive into the tangled world of modern attack...
    Webcasts
    Fixing a broken system: why legacy vuln management tools can’t keep up
    Watch the on-demand webcast on the future of exposure management, featuring attacker-driven strategies, continuous visibility, and rapid remediation.
    Webcasts
    How North Carolina secures K–12 schools with runZero
    In this webcast we unpack how runZero supports a statewide exposure management program to protect 343 Public School Units across North Carolina.

    See Results in Minutes

    See & secure your total attack surface. Even the unknowns & unmanageable.