Video: How to Unify Threat Detection and Vulnerability Management to Lower the Risk of Breaches | Duration: 3608s | Summary: How to Unify Threat Detection and Vulnerability Management to Lower the Risk of Breaches | Chapters: Introduction and Overview (19.535s), Vulnerability Management Challenges (134.97s), Vulnerability Exploitation Trends (378.875s), Unified Security Approach (965.205s), Vulnerability Management Integration (1234.42s), ROI and Benefits (1598.52s), Mitigating Zero-Day Risks (2031.4s), XDR vs SIM (2072.5151s), Vulnerability Scanner Integration (2187.205s), BDR Subscription Details (2259.6702s), Remediation Tracking Features (2320.915s), Webinar Conclusion and Resources (2402.76s)
Transcript for "How to Unify Threat Detection and Vulnerability Management to Lower the Risk of Breaches": My name is Alexa Levine, and I am a product marketing manager here at Secureworks a Sophos Company. And I'm joined today by my colleagues, Lisa Washburn, senior director of product management, and Chris Ewell, who is the director of threat research for the Secureworks a Sophos Company counter threat unit, also known as the Secureworks a Sophos Company CTU. And we're here today to discuss the vulnerability landscape and the consequences of ignoring vulnerabilities and explain why combining vulnerability risk context with threat detection can help you significantly lower your risk of a breach. So let's dive into it. So just first things first, I do need to advise you that today's presentation will be recorded. So you can view it again on demand and share the recording with your colleagues. And the on demand recording will be available within twenty four hours at the conclusion of the webinar. And please submit your questions through the q and a window. We'll have some time at the end of the webinar to answer your questions live. But if we run out of time and we don't have a chance to answer any specific questions, we can answer via email. And then if you experience any technical difficulties, just click on the help widget at the bottom of your screen, and more resources are available in the related content widget. The webinar console you're looking at can also be customized, so you can resize or move any of the windows. And then if you happen to accidentally close the window, you can easily open it just by clicking on the widget options that you see at the bottom of your screen. So, finally, you know, we value your feedback. So just take a moment to complete a quick three question survey that you see in your console at the end of the webinar. And with that, I think we're good to move on to today's webinar. Vulnerability management team and the SOC. And these teams are really the foundation of an effective team. And I think it's really important that we are all just on the same page around the roles and responsibilities of the vulnerability management team and the SOC. And these teams are really the foundation of an effective security program, and they have different goals and responsibilities. So the role of the vulnerability management team is to identify, assess, and prioritize vulnerabilities within an organization's IT infrastructure. So by keeping an inventory of assets and continuously scanning for weaknesses, this team really acts as the first line of defense, and they're aiming to proactively patch any security holes before they can be exploited. And then on the more reactive side of the program, you have the security operations center or the SOC. And they're responsible for monitoring, detecting, and responding to security incidents. So SOC analysts have immediate insights into the nature of attacks, the tactics that are being used by adversaries, and, potentially, the vulnerabilities being exploited. So this real time information, it's really invaluable for understanding the threat landscape and responding to incidents as they occur. But the problem here is if both teams don't have insight into what the other one is seeing, their responses can end up being disjointed and ineffective. And that's really the primary topic of this webinar. So as organizations are grappling with increasing sophistication of cyber threats, this synergy between these two functions really isn't just beneficial, but it's essential for a robust security posture. And I also just wanna talk a little bit about the challenges. So to understand the importance of this collaboration, you do have to start with the challenges of vulnerability management. So we know that the proliferation of vulnerabilities has meant that IT and security teams have really struggled to manage and prioritize and mitigate them for a long time. And, you know, we know that organizations need to quickly address the most critical vulnerabilities, right, in the context of their own risk. But we also know that over 26,000 new vulnerabilities were published in 2023 alone. So given the sheer volume of vulnerabilities, it's nearly impossible for IT and security teams to patch them all. And, really, they often struggle to identify the right ones that they should work on first. And, you know, mean time to remediate critical severity vulnerabilities is sixty five days, whereas industry reports estimate adversaries can exploit a vulnerability within fifteen days of discovery. So this discrepancy between the time to remediate and the time to exploit really highlights this gap in cybersecurity defenses. And on your screen, you should see reactions. So just give me a thumbs up if these are also challenges that you've experienced when it comes to vulnerability management. Let me know if these are some of the challenges that you also face. Pausing for some reactions. Okay. I don't see a lot of reactions, but this is also what we see during our instant. Oh, they're they're just coming late. Okay. So this is also what we see during our incident response engagements with customers. So, threat actors are really seizing each new opportunity and making wide use of vulnerabilities in their attacks. And to talk about this more and the Secureworks a Sophos Company per set perspective and what we see, I'm gonna pass it to Chris, who, like I said, he works on our counter threat unit. So he's heavily immersed in this type of research. And Chris will give you a little bit more insight into some of these challenges. So, Chris, take it away. Yeah. Thanks, Alexa. Yeah. So in the CTU, we're focused full time on making sure that we understand the threat landscape that's facing our customers, and also making sure that we're protecting our customers. And a big source of the intelligence that we get is from the incident response engagements that our consulting team does. And when we talk about vulnerability management, although it it can often be a painful subject for defenders, When we talk about it from a threat perspective, it's certainly not a small issue. So this, pie chart here shows the, the the the the initial action initial access vectors, that we see across ransomware engagements that we've dealt with. And if you look at the the blue part on the top right of that pie chart, so scan and exploit or scanning for Internet facing systems that are vulnerable and then exploiting those systems to get into the network, they are really the top proportion of initial access vectors for ransomware incidents that we saw last year. And so 32%, alongside stolen credentials at 32%, commodity malware and then phishing attacks, following up after that. So vulnerabilities are really our prime contributor to to ransomware attacks and also all cyber incidents. And if we look across, the history of some of our data, so this is going back to 2020, and this is quarterly data, you can see that the the percentage of incidents that vulnerabilities are contributing to does rise and fall slightly, but it's always between sort of 2050% typically. So vulnerabilities, as you can see, really are a core contributor to cyber incidents and particularly ransomware incidents. To really kind of dive into what does this mean and how can we better defend against this, we need to understand what does the life cycle of a vulnerability look like. So when we start with a zero day vulnerability, so typically, if we work left to right here, the vulnerability has to be discovered by somebody. So this is either, that there's private companies out there that are tasked with finding vulnerabilities in systems. It could be a researcher. It could be a threat actor if they're well resourced. They find some sort of vulnerability in a system that they can use or sell. And either they'll they'll use it themselves or they will sell that on the dark web. Once that's obtained by a threat actor who wants to use it for nefarious purposes, they will then use that in targeted attacks. And at this point, the the the community still doesn't know that this vulnerability exists. Most threat actors, particularly APT nation state style actors who are the main users of zero days, will use them quite quietly, quite sparingly because they don't want the world to realize that this vulnerability exists. At some point, we hope that vulnerability will get discovered by defenders. And at this point, the vendor will get notified. They'll release mitigation guidance, hopefully, a patch. And then normally, shortly after that, and it can really be a small number of days from a patch being released to an exploit being published on the Internet. So at this point, everybody in the world, if they wanted to, could take some codes and try and scan the Internet for vulnerable systems to then exploit those systems. At that point, it's normally a matter of hours or days before we will see widespread scanning and exploiting of systems across the Internet. And then the system's path, there's a question mark there. So it's really up to defenders whether you've passed your system before that scan and exploit happens or after. If you look at an example, and there's many examples that we could have chosen, the the Levine about a month ago published about, a remote code execution vulnerability in GlobalProtect. And then a couple of days after that, Palo Alto CVE and said, yeah. This vulnerability exists, and this is the data that we have. Here's the mitigation guidance, that we've released. So this was published on the April 12. And then on the April 17, so five days later, we see in the news that exploit code has been released for this vulnerability. So at this stage, five days after the the the critical vulnerability had been, patched by Palo Alto, we then expect to see widespread scanning across the Internet. And our data bears that out. So if we look across our NDR telemetry, so Tejas network detection and response, if we deploy a countermeasure that then detects exploitation of that vulnerability, you can see that prior to the April 17, there was no scanning scanning attempts or exploit attempts. And then as soon as that exploit is released on the Internet, we then typically see scanning across our customer base, hitting most of our customers, looking for vulnerable systems that might exist on the Internet so that they can just find them, exploit them, get a foothold on the network. And maybe at that point, they don't use that access straight away, but they can try and sell that access on the dark web or maybe keep it it for for later use. This chart there's a lot going on in this chart, but this shows the the middle circle shows, the the different vendors that we've seen being affected by these kind of perimeter vulnerabilities. The middle circle shows the products that have been that are, written by those vendors that have been affected. And then the outer circle shows the number of different vulnerabilities that have been used. And this is from our incident response data going back for the last two years. You can see on the outer circle the sheer number of vulnerabilities that have been used to get access to organizations, really showing here that this isn't just, like, the one vulnerability that you see in the news that that that's the problem. This is a a consistent thing. We will have one thing this week, and then maybe we'll have one or two next week that will be exploited. So this has to feed into a constant process of making sure that we're identifying these critical vulnerabilities, that we're patching them as soon as possible, and that, crucially, as we'll talk about later, that we're we're adding in our vulnerability data into our security operations and our analysis, to make sure that we're responding to these incidents when they're attacking vulnerabilities that we have in our systems. If we look at the inner circle, so just to briefly touch on the vendors that are mentioned, so the the the green part in the top right, that's Citrix. So Citrix, and then working clockwise around, we've got Microsoft, and then Progress, Ivanti, and and Fortinet. And then we start going into some of the, the lesser affected ones. But all of these systems are kind of perimeter based systems, so typically firewalls, VPN servers, or in Microsoft's case, Exchange Server, IIS, SharePoint, things like that. All systems that are Internet facing, and then become vulnerable, and those vulnerabilities are used to exploit, organizations. And to give one of many examples that we have of when, the patching isn't done properly and the impact that that can have, this is one real world example from last year. This is a US based organization that ended up being ransomware ed, because of an initial, compromise on a vulnerable system. So this started last year, Jan July, when the Citrix NetScaler vulnerability was announced alongside patches, for that system. About ten days later, we then see public exploit code released for that. So, again, at that point, we expect to see mass scanning and exploiting of that vulnerability across the Internet. And then two days after that, true enough that they haven't patched the system. We see, the victim's NetScaler get compromised and the access for that used to deploy web shells and start to steal credentials, from that vulnerable system. Interestingly, we then don't see that access be used for a number of months. So and this, exploitation went undetected. And then a few months later in November, we then start seeing suspicious remote desktop logins begin to that system. So they're using the stolen credentials that they've, they've harvested to to gain access into that network. We then see, in December, so approaching Christmas time, that they start then doing lateral movement throughout the environment. So really trying to get access to as many systems as possible from that initial foothold, to try and compromise as many systems as possible. And then just before Christmas, we then see them deploy ransomware throughout the environment, and that's a pretty devastating impact for, the victim. So really a classic case study here of where, a vulnerability has got been announced. It hasn't been patched, in a particularly timely fashion. And then as soon as the the the the exploit code is released, we see huge scanning and exploiting the systems, exploited. And then a few days, weeks, or even months later, we see the access used for, for, ransomware or any other sort of cyber extortion. So key takeaways from us from the CTU, so exploitation of Internet facing vulnerabilities continues to be a significant cause of cyber incidents of various types. Mass scanning for vulnerable systems will typically take place within hours or days of exploits being available, and these single vulnerabilities can lead to enterprise wide ransomware events in the worst case. So how we triage vulnerabilities and how we apply those into our security operations is a is a constant question for for network defenders. So I'm gonna hand back to Alexa to talk about how we're helping customers do that. Alexa, you're muted. Thank you. Sorry. Thank you, Chris, for sharing your data and insights. I think, you know, it's really helpful to understand the scale of the problem. And I know that one piece at the end about how one vulnerability can lead to a whole ransomware event. I think that's, you know, just really helps me understand the impact that that has. Right? So of not addressing vulnerabilities. And I really what I take away from this is that you need both a proactive and a reactive approach to cybersecurity. So it's not just one or the other, and these two sides really need to work together. And, you know, like I said earlier, vulnerability management security operations, they're the foundation of an effective security program. But the problem is that these two functions are operating in silos, which they tend to, it's this inefficient response to threats. And, you know, we know that forced to reach research says that when the next log for j inevitably occurs, security operations and vulnerability management teams need to be in lockstep. And I think this is a really powerful and true statement because, otherwise, these silos will create blind spots. And so I just wanna talk a little bit about, you know, the traditional versus a innovative approach, to vulnerability management. So the current industry approach requires that a user purchase multiple point solutions. And other vendors, for example, they'll bundle MDR plus vulnerability management, but it'll still be separate platforms, and they'll still lack integration. And an innovative approach would mean that these platforms are unified, and they're speaking to one another. And the traditional approach, it also evaluates vulnerabilities based on hypothetical risk and looking at what's being exploited in the wild. Whereas an innovative approach takes this another step further by also evaluating vulnerabilities based on real detected threats. So not just in the wild, but in the organization's actual environment, looking at real threats that the organization is seeing and correlating that with vulnerabilities. And this collaboration really allows these teams to prioritize vulnerabilities based on real exploitability and potential impact rather than relying just on hypothetical risk. And it also allows the SOC to be better prepared for potential breaches because they can understand the vulnerabilities that exist within their environment. And then finally, the traditional approach, you know, it requires a lot of manual effort for security operations and vulnerability management teams to work together. So this might involve manually sharing documentation and findings, manually stitching data to identify root cause, whereas an innovative approach automates these workflows and combines threat and vulnerability data in a single view. And so some of the benefits to this unified holistic approach, are a faster response. So visibility between these functions make sure that when a vulnerability is exploited, that the response is swift and it's coordinated, and it minimizes the potential damage. And another benefit is if there's better root cause analysis. So vulnerability data will provide insight into the potential entry points and methods that are being used by attack attackers. And we saw this in Chris's data. Right? So with insights from the SOC, the vulnerability management team can prioritize patching efforts based on real attack patterns and threat intelligence, right, and focus on the vulnerabilities that actually pose the greatest risk. And both teams get a better comprehensive view of the threat landscape, right, with this enhanced context. So this means better defensive strategies and more effective countermeasures. And, you know, you see more efficient resource use too. So security teams can ensure that they're allocating resources to the most important actions in the context of their overall risk. So now that we've talked about this unified innovative approach, I wanna just put these words into actions. So I'm gonna pass it off to Lisa who's on our product management team, and she's gonna talk about how Secureworks is really leading the way with our Aegis platform. So, Lisa, take it away. Okay. Thank you, Alexa. Alexa, sorry. So, yeah, Secureworks, let let's talk about really what Secureworks is doing about this, in the context of everything that Alexa and and Chris just talked about. And this is in association with what we recently announced, the latest version of our vulnerability management solution, Tejas VDR. And what this does is it enables organizations to bring vulnerability data into Tejas XDR. We have integrated vulnerability data into multiple areas of Tejas XDR, really influencing and and contributing to threat investigation and response workflows. So one such area is shown here in the alert details. So when reviewing alerts in Tejas XDR, there's a new vulnerability tab now available, and it will show vulnerabilities on the host associated with that alert. And what this does is helps provide context during investigations and enables organizations to take proactive actions to defend against threat actor activity that that may take advantage of a vulnerability. When Tejas identifies that an alert is related to the exploitation of a known vulnerability, then that vulnerability is kinda pinned to the top of this list as a means to identify root cause. Not shown here, but we've also added vulnerability data to the endpoint summary and detail information in Tejas XDR, where endpoints are assigned a vulnerability status. Users can filter by the vulnerability status as well as get more detailed information regarding the vulnerabilities when drilling down on a specific host name. Other, other features and capabilities with this integration, Tejas XDR has been enhanced to also include a new vulnerability management page as part of its main navigation options. Options. So organizations that have integrated their vulnerability data from Tejas BDR into XDR will have summary information regarding vulnerabilities in the context of the threats identified in XDR. Shown here, the summary page will provide a view of vulnerabilities that are present on the most alerted upon endpoints in the environment. Other views in this vulnerability management page, also provides some reviews of recently identified vulnerabilities. I'm gonna shift over to to, a slide here that just kinda shows how this data flows into Tejas XDR. So really to to bring that up to date vulnerability information into Tejas, customers can either leverage our Tejas vulnerability scanner, which is a lightweight network based scanner that automatically discovers assets and, of course, identifies vulnerabilities, or they can integrate third party scan data. We're starting with Qualys on this integration. And, just a note, this vulnerability integration into Tejas, it can also be used for customers that are using a a hybrid scanner approach as well. So with the scan data coming into, in from either, you know, Tejas scanner, Qualys, etcetera, Tejas VDR prioritizes the most critical vulnerabilities based on context from the environment and from continuously updated threat intelligence. VDR also provides built in remediation planning and tracking as part of that solution. And then as we've discussed, the vulnerability data is automatically brought into Tejas XDR to identify vulnerabilities associated with real time threat. And this really augments the the customer's detection and response workflows as well as, assigning, you know, better, visibility into the criticality of those vulnerabilities. Okay. So, really, Alexis Alexa talked about this. Sorry, Alexa. Alexa talked about this, but augmenting theoretical or inferred risk with threat data is really, you know, what we're what, this solution does. And this will help organizations better prioritize their not only their vulnerability remediation activities, but they can also better respond to threat data by adding that vulnerability context. So some of the expected outcomes of the integration are, first, it brings together that proactive and reactive, those proactive and reactive activities into a single workflow for for customers using that unified platform as Alexa talked about. Second, customers have flexibility. They can leverage, their current vulnerability scanner, again, starting with Qualys, or leverage Tejas' vulnerability scanner. Third, the integration of vulnerability scan data into Tejas XDR helps analysts perform root cause analysis. So this helps with, you know, faster response. And then lastly, the solution can help companies break the silos that Alexa talked about between vulnerability management and security operations teams. So with that, I'm gonna turn it back over to Alexa. Thank you. I'll unmute this time. Okay. So thanks, Lisa. So that was a really great overview of what we're doing in Tejas. And I think before we wrap up, I just wanna highlight some of the qualitative and quantitative benefits. First, we're just gonna start with this customer quote that says Secureworks a Sophos Company provides justification for taking remediation actions, including showing what the possible impact would be if we don't fix an issue. It saves us time on getting the information that we need to decide what to do. So this organization is saving time and effort. They have a better understanding of which vulnerabilities to prioritize and remediate, and they know what the potential consequences would be if they don't fix the issue. And I think that's just really, meaningful information. But I do wanna talk a little bit more on what exactly is the return on investment study found that organizations can avoid over 280,000 in costs due to data breaches and save 70,000 in people costs by using Tejas BDR. And the representative interviews and financial analysis found that a composite organization experiences total benefits of about 520,000 over three years. And Forrester also found that customers can achieve a 352% return on their investment in TEGIS BDR, and that's via cost savings, risk reduction, productivity gains, and they can break even in less than six months. So interview interviewees were sharing that after investing in BDR, they saw confidence in their organization's vulnerability management processes increase organization wide. So from cybersecurity teams and IT operations to corporate executives. So if you'd like to read more about this study, we have it linked in our related resources, which you could access here on the platform. And I think it's just a great testament to some of the tangible benefit benefits of Tejas VDR. But while today, we did focus on vulnerability management, I do just wanna remind everyone that this is just one piece of the SecureWorks portfolio. So we have a robust XDR platform, extended detection response that collects and ingest data from all your security controls. So think endpoints, network, cloud, apps, logs, etcetera, to prevent and detect and respond to threats all in a single platform. And then on top of the XDR platform, you can also employ managed services or MDR. Plus, Tejas has been powered by Advanced AI from the beginning, and the platform was really designed to leverage our threat intelligence and automation capabilities. In this framework, we look at vulnerability management as a control point. So since we know that over a third of breaches, like Chris said, start with an open vulnerability, our goal is to tie that information into an organization's overall threat detection and response program. So I think that this slide really gives a view of our, you know, comprehensive solution. And I think right before we get to q and a, I'm just gonna end with a quote here from Dave Gruber, who's the principal analyst at ESG, who says that the integration of vulnerability management and security operations is not just a matter of convenience. It's a strategic imperative, and Secureworks a Sophos Company latest innovation bridges the gap between these functions, bringing vulnerability risk context and threat detection and response together to reduce risk. So, again, I think another powerful statement, talking about some of our latest innovations and how we're bridging that gap. So with that, I think that we can get to q and a now, and I know I saw some questions in the chat. So maybe I'll start with you, Lisa, and just go through some of these questions. I saw a couple around, you know, are we planning to add other third party vulnerability scanner integrations and specifically questions around, integrating with Tenable. Could you speak on that and our road map and what we're planning? Absolutely. So, yeah, I saw those questions as well. We absolutely are, looking at other third party scanners. We like I said, we started with, Qualys, but Tenable.io is definitely on the list, and so we are investigating that now. I I anticipate that, you know, we're we're gonna be gathering feedback from from this new capability that we just released, and also improving their, other some of the other features, but additional scanners is on the road map as well. Yes. Great. And then I see another one here. Chris, if you wanna answer. So you've spoken about known vulnerabilities and patches, but how do zero day vulnerabilities play into this? Can you talk about that one? Sure. Yeah. Good question. So, obviously, when we talk about vulnerability management as a function, as a process, we're always talking about known vulnerabilities. So things that have been announced as a well and have been patched. But, of course, yes, zero day vulnerabilities are something else that we need to be worried about. Historically, zero days were always the kind of domain of very well resourced nation state actors. And so the the message could always be we don't most organizations don't need to worry about zero days. That has shifted slightly because we've seen, suddenly zero days being used widely, and particularly, the ransomware group clock or Gold Tahoe as we call them. So last year, they're campaigning against things like the the the MoveIt servers. So, basically, they've been targeting file transfer appliances, and widely exploiting vulnerabilities that they've found. And so it's definitely something that we need to be concerned about, but that does fall out with the the classical realm of vulnerability management. Protecting from a zero day vulnerability is really hard, and we don't know what we don't know. So that's when you have to get into the domain of, good monitoring. So making sure that if they do exploit a a vulnerability, that you're monitoring the systems, that you have good threat intelligence and countermeasures and behavioral based countermeasures that can then detect the unusual activity that that that follows from that. So in the example I gave, the exploit was used to deploy web shells, so you want to make sure that you can deploy you can detect things like that, which certainly we focus on with Intagious XDR, and our endpoint agents. And things like file transfer appliances really just following best practices. So assume that anything that's on the Internet and facing the Internet could at some point be vulnerable to a zero day vulnerability exploitation. So what things can you do to mitigate that risk? So in the case of a file transfer appliance, making sure that you're encrypting the data at rest and you're not just putting unencrypted data on there, that you're only putting data on there for a short period and not leaving data there for for months and years to to be harvested by by threat actors. So, yeah, it's really a combination of good monitoring for unusual behavior and assuming that something could be compromised and taking appropriate mitigations. Great. I see another one here, which I can answer. So can you define XCR and explain how it differs from traditional security solutions like SIM and EDR? So let me give you some background here. So SIM stands for security information and event management, and SIMs aggregate, normalize, and collect security related data. So oftentimes, this is data that syslog information, and it's used for compliance and regulatory purposes. And, you know, SIMs were first coined by Gartner in 02/2005. They've been around since as early as the nineteen nineties. And, really, it was that need to consolidate security logs into a single system. But due to changing IT environments, more sophisticated threat actors, there's been this evolution to extend the range of protection and integrate threat intelligence and automate response. And that's really where extended detection response or XDR comes into play. So XDR refers to a new generation of security solutions, and it basically consolidates multiple security tools into a single threat detection and response platform. And, XDR really evolved from EDR or endpoint detection response. But XDR goes beyond endpoint to include things like network, cloud, identity, apps, etcetera. So many organizations have invested in EDR technology, and it's really essential. But if you're using a SIM, there are some cost constraints, telemetry that it can be kinda cost prohibitive. Whereas what's great about XDR is the fact that it came about in the post EDR era. So XDR was really built to utilize EDR telemetry, which is hugely valuable for threat hunting and detection analytics, without having to worry about those extra costs. So that's just kind of an overview of those, various things. Lisa, I also saw a question that I think you can answer. Why should someone go with Tejas over other vulnerability scanners? Okay. Thanks for the question. So couple things. One, we can we can certainly, you know, talk with anyone here and happy to about, the the Tejas vulnerability scanner and, you know, look at demos and proof of concepts, etcetera. One thing I I wanna note here is that, the the solution we're talking about is really around integrating vulnerability data into the the XDR and the managed XDR solution. And so, you can and customers will and have integrated, TEGIS vulnerability scanner data. But like I said, we're also making that flexible so that if you're already using another third party scanner that that you can take that data in. So, like I said, we've started with Qualys, and we'll be adding Tenable and others, down the road. So, it's not a requirement that you use the Tejas vulnerability scanner. Tejas vulnerability scanner may be the right solution for you. And so we can chat about that, with anyone who wants more information. Yeah. And playing off of that, someone else also asked, you know, is BDR a separate subscription, or is it available to current XDR subscribers? And the answer is I or I can go for it too. But the answer is that, yes, BDR is a separate subscription. It's a separate product, and it can be used, you know, for vulnerability management. But like Lisa just said, the scanner is separate. It's optional. So you don't have to purchase the scanner. You can just purchase VDR where we actually prioritize the vulnerabilities. And then from VDR, your data can be sent into XDR. And I also just wanna say, you know, it's very price competitive. It's, like, 15% of the managed XDR price. So it's, you know, it's a smaller initiative for you to take. And like I said, you don't have to have, our scanner. You can bring your Qualys scanner if you're already a Qualys customer or, like Lisa talked about on our road map, we're planning to integrate other third party integrations. Lisa, there's a question here. Can you talk more on the remediation tracking part? Yeah. So, the the piece of the the solution that Alexa was talking about in terms of, you know, additive to the MXDR is is our, you know, VDR solution, scanner being, you know, optional. And that VDR solution provides a a number of things. One, it it provides, a a robust machine learning based prioritization model for, for those vulnerabilities that looks at and learns about information specific to the customer's environment to prioritize those vulnerabilities. And then there's a a workflow within the the VDR solution to, to set up remediation plans, for fixing those most critical vulnerabilities. And so, users can can go into the vulnerability tool and manage and track remediation and what's, been, you know, what's been remediated, what hasn't, etcetera. So so that is within the VDR solution. Sounds good. Yeah. We did we got a couple questions here just about if, we'll get access to the presentation after this. And, yes, the webinar is recorded. You'll get the access to the recording, after this after conclusion. Yeah. I think that is all. I think we can probably wrap up. And then any other questions that we get, we're happy to answer, via email. So we can follow-up after that, but I think that we're good. And I'm just gonna end here. So if we didn't get your questions, we'll answer via email. And for next steps, you can access additional content in related resources. So there we have the buyer's guide, a blog, the Forrester Report, which I talked about, and other resources. So be sure to access that. And like I said, you'll get access to the the recorded webinar, within twenty four hours. So thank you all so much for your time today. We hope that you learned something new. And, yeah, hope you had a a great, time listening in. Thank you. Thank you. Thanks.