Perfect. So a very warm welcome to today’s webinar and also launch of Ontinue’s latest add on service, Dark Web Monitoring. My name is Stephan Fust, and I’m leading the DACH account, the key account management team here at Ontinue. Dark Web Monitoring is an amazing addition to our portfolio, which also the overwhelming interest in this webinar confirms with over 100 sign ups. But you’re not here to listen to me. And as we only have thirty minutes planned for this webinar, I’d actually hand over to our experts, Vijay, Balajz, and Alex, who will walk you through everything you want and need to know about Ontinue’s Dark Web Monitoring service. Great. Thank you very much, Stefan. A very warm welcome from my side as well. My name is Vijay Viswanathan. I work with the Ontinue product team. And as Stefan said, let’s get right into it. So what so before we get into our solution, let’s take a step back. And, what we see on the screen here is hopefully a relatable depiction of our internal environments. So we see the the security controls in place across endpoint, email, cloud, network. We have best practices, everything from conditional access to regular device patching. We have a SecOps program in place that detects, investigates, and responds to suspicious activity, but not just that, also actively learns and prevents. So I realize that this might be an ideal depiction, but it’s something that is either in place or we’re very much working towards. But all this is our internal environment. There’s a lot happening outside our environments in the clear, deep, and dark web. Now some of it is more visible, some of it is less visible, some of it involves, employees of our organization or it could involve partners, and all this creates risk. And I want to start first with this question about what it means for organizations, not just this risk, but what the challenges that organizations face when trying to address this risk. And in order to answer this question, I would like to invite, Balazs Gretzka, who leads our advanced threat operations team. He’s an expert in threat intelligence, threat hunting, emerging attack techniques. He really works at the front lines of how threats evolve, how attacks are pieced together. He has hands on experience with the deep and dark web, so I can think of no one better to answer this question for us. Balazs, what are the challenges that organizations face in addressing this kind of external exposure and risk? Thanks, Vijay, for the work warm welcome, and I would like to also welcome everybody in this webinar. So the main risks. As we discussed also since the last TI report that we released, identities are still a flight risk, and that this is where most of the risk materializes. And if you take into account that, you know, most ransomware actors, exactly 54% of ransomware weak teams actually have their credentials exposed in Stellar logs prior to a ransomware attack. Also, it’s not a causal relationship necessarily that they were breached because of that, but it kind of paints the picture where, you know, the identities are at risk and will be misused. This is, by the way, from Verizon DBR report. And we also see a lot of risk related to lookalike domains, which are also being misused for fraud, you know, brand related attacks, and other, like, phishing and adversary in the middle type of activity as well. Yep. Excellent. Thanks thanks for that overview. So identities are a top attack factor, and there’s a risk of brand impersonation. Organizations are aware of this. Right? And sometimes there’s a dark web monitoring tool in place. And we’ve spoken to organizations about this. No one has told us that the challenge is not enough notifications. You know, we we we don’t necessarily have visibility about this. The the challenge has always been an okay. That alert comes in, that notification comes in, but who from our team has the availability to then pick it up and piece everything together? Right? Pivot through all the different tools, validate that this is a true positive, and then go through and be able to take some actions around that. Balazs, share also maybe if you could add some more color to what, what the challenges here are around this. Right. So I think, what you will really need is, consistency, and you will need a response, on the exposures and findings. It doesn’t mean that you need to be, like, immediate, but you need to be quite reliably, you know, responding to these findings. This will help to reduce risk. And, also, we have seen it with our co-design customers as well. So some of the successes during this phase that we have actually had a number of true positives from credential leaks. And, also, we have noticed in this region, manufacturing customer had also issues with lookalike domains, which were then used to, you know, impersonate the brand. So we it’s it’s definitely one of the top issues that we see and can be difficult to address if you are not automating in this space. Yeah. Yeah. So a very real concrete tangible example where an entire website was just duplicated and then used for malicious purposes. Yeah. Okay. Excellent. So we’ve been talking about challenges. Let’s talk about how we address address this challenge. Right? There’s one one thing is clear. An ideal solution, of course, is based on monitoring. Monitoring is an important starting point. But I think the real key, that makes this an ideal is that it goes beyond just monitoring, that it’s able to enrich, validate, and ultimately take action if necessary, with accountability, clear handoffs through the entire process. This is what I would describe as an ideal solution. In order to go into more detail on how we’ve designed our implementation of the solution, I’d like to hand it over to Alexander Louis, who’s our senior director of product management. Thank you very much, Vijay and Balazs, for the introduction and the problem statement. Super happy now to announce officially the ION for Dark Web Monitoring service. If you could go to the next slide. First of all, I’m super happy that we we are able to to announce this today. I know we already discussed this since quite a while with with a few of you. So first of all, thank you very much to everyone involved. This is the idea that came from many of you who talked to us and said, okay. An ION for Dark Web Monitoring service extension would be amazing. Thank you very much for all the ideas you brought into the service to make this happen. But the most important point was you also gave us a challenge and said, okay. We don’t need another reporting service. We need a service that is actionable for you as an MXDR services provider. So no additional report where we need to read through by ourself. We we need to validate the findings. As Vijay mentioned, really an end to end service where we cover from initial monitoring to the response action execution if required. On the next page, I quickly want to mention how it works. Overall, on the left side, you see the different threat intelligence sources that we use in the background. So we get the findings from the environment, but then based on on your recommendations for us, it was super important to fully integrate this into the overall existing security operations. So no additional process, no additional involvement on your side. We have the threat intelligence sources integrated. We have the key asset information, like domains, keywords from you. We are using our existing threat intelligence sources. We integrate the information into your Microsoft Sentinel. So there is a dedicated table in Microsoft Sentinel. If you subscribe to ION for dark web monitoring service, where we store all the findings from our TI sources, and then we create based on this security incidents in your Sentinel and then triage and investigate with the ION SecOps platform. Here, deterministic automation workflows will go into details, understand the findings to the preliminary investigation. We have our autonomous investigator and then the cyber defense center that investigates. As always, fully integrated Microsoft Teams so that you just have one interface when it comes to escalation. All this completely backed up by your existing service with Ontinue’s Cyber Defense Center, so it’s the same team that investigates the dark web monitoring incidents. If you have any questions, your Cyber Advisor is fully enabled and can provide you with additional information. And, obviously, when it comes to response action execution, this is fully integrated and uses the existing rules of engagement. Two use cases are integrated at launch. So on the left side, we have the lead credentials. On the right side, the typo squatting. Again, during the different discussions with with a lot of you, we said, okay. How can we make it actionable end to end and don’t provide another report when you need to involve a lot of time to go through, go through all the findings, and really make sure, is this the finding? Yes or no? Is this outdated, or is it up to date? So we decided to to go over two actionable use cases at the launch. On the left side, as I said, the lead credentials where we monitor for your user accounts in the dark web. If we find something, then first of all, we confirm that the user exists in your environment. We do this based on the Microsoft’s locks available in Sentinel. If the user exists, we have a couple of additional checks we execute. And then if we haven’t seen the leaked password that we store as a hash in your Microsoft Sentinel, then we also execute the response actions. On the right side, then the type of squatting domains as a second use case. So, mainly look alike domains in case there’s something popping up that looks like one of your domains. Then here as well, we do the investigation based on Microsoft Sentinel, and then we have as well the options to block the IOC across your Microsoft ecosystem. So two use cases initially that are end to end actionable for us from the monitoring of the dark web monitoring sources to the enrichment validation to really make sure it’s a true positive incident to the execution of response action. Completely without your interaction, everything happens in the background. And then if required, if we need additional information as today, as part of the iMXDR call service, we escalate based on escalation metrics to you. But, obviously, the target is to handle all these incidents in the cyber defense center. Let’s jump into the live demo. And here, I prepared a small sneak peek around also what’s next when it comes to the ION portal. I assume a few of you already saw the ION portal. We are currently working on the revamp of the menu on the left side with additional information with new portals, new functionalities, new insights. But today, are focusing on the dark web monitoring incident that is here on top of the queue. If we open the incident, then we also see that the new ION portal incident overview has a different look and feel. So on the top, you see all the key information. And then in this case, the incident is currently still in progress. So the deterministic automation finished. The autonomous investigator already finished as well. We have an initial verdict. The initial verdict proposed by AI is that it’s a true positive. We see that also here in a structured way. In in future, we will have an assessment. The assessment is created and published by the cyber defense center. The cyber defender, in this case, also used the opportunity to update the assessments. Maybe initially, he or she up published an assessment that was not complete. So here, the assessment has been updated. You have the key findings as well with all the key information. So in this case, as it’s a dark web monitoring incident, we found the information in the dark web. We validated the sign in. We saw that there are IP addresses from Amsterdam are involved. We also here, the Cyber Defender found some information around new forwarding rule in the inbox of this user. In the key findings, we also mentioned already that response actions have been executed, and super important at the bottom is that there was no data leak. Additionally, here, you directly see the response actions that are executed, so you don’t have to scroll in future through the audit log to understand what has been executed. You directly see this on the fly with the recommendations regarding the next steps. And if you really want to go into each and every detail, you have the evidence at the bottom where you can, yeah, go into each and every detail where you see the different deterministic automation workflows that have been executed. In the case of dark web monitoring, obviously, we first need additional information about the user. We need to understand if the user really exists in your environment, if the user is active, how the user behaved in the last couple of days or ninety days depending on the lock retention. And then if this is really an an leak, then we execute the response action. At the bottom, you also see that Cyber Defender added additional information and the evidence. So the invoice rule in the mailbox has been created manually by the Cyber Defender. So this incident is still in progress, would be executed in a couple of minutes directly to your team to make sure that the follow-up recommendations are flying to your Microsoft Sentinel, or if you use an ITSM tool, that it’s also visible there. So this is a quick sneak peek in how the ION portal will look in future. I’m super excited. We are currently working on the internal part, this Cyber Defender Workbench, where we need to all integrate all this new functionality. And then beginning of the year, we will also provide this to you. But super important for me, it’s in the same environment end to end, so there’s no difference between an ION MXDR and an ION for dark web monitoring incident when it comes to the incident handling process and the escalation metrics and rules of engagement. Initially, we have, two use cases included, in the service, but the great part as always is we are always, developing additional functionalities as for the ION MXDR call service. The other add ons, we are following the same strategy for dark web monitoring. Initially, with the launch, we have the two use cases, lead credentials and lookalike domains, then we will extend to additional use cases. Our plan for q4 is to also integrate file leaks, supply chain risk, dark web monitoring, form alerts, and take down actions. We are currently working with additional TI providers to to get all this information, and then the idea is for the file leaks to do some additional checks regarding these files in your Microsoft Sentinel. If we see these files in in your Sentinel, instance based on the logs as well, then we can escalate this information as a notification to you. Supply chain risk is regarding the monitor of critical suppliers. So our idea is to integrate, let’s say, five to 10 super critical suppliers for you so that we also monitor them and the dark web. If we see anything, regarding the suppliers, we can also do checks in Microsoft Sentinel based on the available logs and then notify you. The same for the dark web form alerts, and we are also working on an internal process to enable takedowns. So in case we really find it lookalike domain, that we can work with our threat Intel providers to perform takedown services. Great part here. You start with the first two actionable use cases, and then step by step, we extend the portfolio to more actionable use cases. The idea here is really for all of these use cases to add additional investigation value. We want to avoid that this is a notification service and always have the part where we add really depths of the incident into the investigation on our side before we if we need to escalate to you. With this, I hand it back over to Vijay and Stefan. Thank you, Alex. Thanks for that detailed overview of the ION for dark web monitoring solution. So we’ve gone on this journey from understanding external exposure, what it means, what are the implications, what are the challenges in addressing it, to looking at what a continuous version of a solution looks like, something that goes beyond a notification service, but that actually has response actions tied to each use case. As Alex mentioned, two concrete use cases already available launch and four others in in the pipeline. I would now like to look at what does this all mean, you know, two use cases as we expand to additional use cases. Really, the ultimate goal is to move from this kind of state of where maybe exposure is not known or you’re just getting notified on it. It’s not continuously being validated. Is this actually a true positive? There’s a a disparate set of tools and workflows. Things are falling through the crack. So the goal is really to go from this state to this on the right side. We not only know when there’s exposure, but we are able to validate it. We have concrete actions, titled. Ideally, things that are preapproved so can happen right away. But if needed, it’s escalated to your team for further consideration. And all of it tightly integrated into your existing program, into your existing security operations. So that’s really the objective of this service, to go from the left to the right. With that, now I would like to invite Stefan back for a special offer that we have for MXDR customers. Yes. Thank you very much, Vijay, and all our experts for those insights. Just to take a step back, there was a a question raised. Target monitoring is an add-on service to the core MXDR service, so it needs an additional subscription. But to celebrate this launch, we have a special offer, especially for you, our existing customers. So if you sign up to the service until end of November this year, you’ll get the service free of charge until March 1 next year if you commit after that for at least a twelve months term. If you want to discuss this in more detail, please reach out to your account manager, to your cyber advisor, and they’re happy to go through all the use case again, provide additional information or, of course, also discuss the offer in detail. Excellent. Thank you. A very exciting offer that’s available between now and the end of November. And with that, I would like to leave us all with this final thought. The question is not whether there’s sensitive information about our organizations out there. There is. The question really is, can we identify it when it matters and take action before threat actors use that to make their attacks more successful? That’s really, I think, the open question for all of us and, yeah, the guiding question that inspired this service. Excellent. I would like to say thank you very much from my side and from all our side at Ontinu. Excellent. Thank you, Alex. Thank you, Stefan, and thank you everyone for joining. Do we have any questions open questions in the q and a? Looks like we have that answered. Excellent. Thank you, everyone. Thank you.