Loading summary
A
Foreign
B
hey everyone, I'm James Wilson from Risky Business and welcome to this sponsored interview with the co founders of Airlock Digital, David Cottingham and Daniel Schell. In this interview, we started off by talking about an article that Spectrops released back in June that was all about how you can use LLMs to evade EDRs. They threw an LLM or a coding agent at a couple of different EDRs and found that they could extract things
A
like the rule sets and other things
B
that the EDR was relying on. Now that's a problem if you're relying on the same set of rules that everyone else is. If that's now in an attacker's hands, that gives them an advantage everywhere. An allow listing solution like Airlock Digital, of course, is a different thing. Those rules are not like one set of magic special rules that are deployed everywhere, but rather intentionally. The allowlisting rules are specific to every customer. The customer writes their own. Right? Maybe they start off with some building blocks, but there's going to be a lot of customization that happens. But this got us talking about, as David explains it to me, the overall industry shift towards more of a governance model for adr. Now, admittedly, I wasn't quite sure what he meant by that, so he does a great job of explaining exactly what it means and how customers are moving from off the shelf. Set it and forget it. Deploy these tools and you're done to having much more of, I guess, control over their own destiny to make sure that they've got very specific rules that match their very specific environment, which is all the more important at the moment
A
in this AI era.
B
But where does this go from here? It's going to be so interesting to find out, right? If humans are now taking more of a role in decision making around EDR and Endpoint security, is that a temporary thing? Do LLMs start to take on more of that? How long is it until we're back to, you know, almost completely autonomous, but still customized defenses being driven entirely by LLMs? These were some of the top topics that we covered in this interview. So I'll drop you in here where Daniel is talking about the Spectrops article and how for him the key insight from this isn't that an LLM can defeat an edr, it's actually how much manual work this would have been up until now. Enjoy.
C
Yeah, I think primarily just for the fact that they use LLMs with like an MCP to binary ninja to like disassemble the product and then just extract all the rule sets from for all the EDR vendors in a pretty short period of time. I think that just shows the game changing when before. I think that it just would have required so many man hours or months or years of manual reversing and such to try to even get that data. And it probably switches around enough to stay on top of it, but just the game has changed, right? Because you're like, well, you burn tokens and you get EDR rules is the ratio now. And of course that's like dangerous now in general as well, because attackers can then craft their way around that for the target attack. So that's sort of the first thing that really is like, hey, there's a danger out there now that you sort of have to assume that attackers have this vulnerability, like this sort of capability, I guess, to just sort of look under the peek under the curtains and see what's going on and then sort of react appropriately. So it's like nearly. I know it's not assumed breach, but assumed visibility maybe is what's really fair.
A
And was it a surprise to you that these were the findings? Because I sort of read it and went, wow, that's cool. But then you sort of take a step back and go, well, consider that an edr. You know, I mean, I guess there's different flavors of EDR and we can get into that. But I think the vendors that they went after are kind of the EDRs that are one stop shop, drop it onto the laptop and hey, you're good. And of course that's operating at a much higher level than something like an allow listing solution. It's operating on heuristics and behavior modeling. It's got such a surface area to cover. So it didn't sort of surprise me. But admittedly I didn't spend as much time like getting really deep into the articles. I was just curious as to whether it was a surprise to you as you were reading the findings.
C
Yeah, not really directly to me. I guess I've sort of known how the sausage is made for a while, but I guess and knowing how the sausage is made, I think an area that like AV vendors or EVR vendors will often struggle in is sort of having those. I guess the false positives are a big part of it when you're trying to like protect the whole world. The whole world runs so many different applications and such and people in one organization, it might be different rules and this thing's okay in this org, but not for this org, but they have to tune for the world to find that balance.
D
Yeah, I mean, look, as an endpoint vendor, you have to be able to read the rules with your agent and therefore you need to be able to decrypt on box. And that's sort of just a reality you can never get away from. So I think for me it's like the key is somewhere. It's just about how much engineering hours you put into actually being able to hide it, obfuscate it, make it fancy to try and keep people out. Essentially. A lot of it is runtime protection as well, so making sure that while the agent is running, you can actually stop people from accessing the actual data itself. But I guess the danger here is more that the attacker gets a box where they just get the definition files and configure it out that way.
A
But if I contrast this to something like your solution with Airlock Digital, it's sort of like there's no secret source in the rule sets there, right? They're literally customer defined. And I would imagine that's kind of a strength of Airlock Digital here compared to these other EDR tools where it's like, well, an LLM spitting out what all those rules are. It's going to be like, it doesn't matter. We already know what all those are. Right. But at the same time, allow Listing is operating at such a granular, finite sort of level. That's always been the Achilles heels of these solutions because they're difficult to configure. So I'm just curious as to how this article, sort of did it shift
B
your thinking at all when you took
A
a step back from reading it? What was sort of your take on do you guys need to do something different? Are you guys even more important than ever now?
D
I think for us it's really a shift in the industry that's happening more generally, which is that the best protection against an attacker from getting a copy of a rule set is making sure that every rule set is different or customized in some way. And I guess the advantage there is that each customer configures their rule sets with airlock so that they can't attack one customer and then go to another and do that as well. But I think what you're seeing in the industry, or at least I feel I'm seeing it, is a lot of EDR players, endpoint players, you know, regardless of what discipline you're in, moving towards this more governance model for customers. So it's sort of like, you know, choose your own adventure in terms of implementation, configuration and management to get to a level of security rather than Just have a, you know what your home antivirus was, where, here's your static signatures, you know, you're good to go. You know, there's increasingly a heavy sort of more proactive configuration approach, especially in the age of AI, which everyone is shifting towards now.
A
Yeah, yeah, and you mentioned there that sort of shift towards a governance approach. Maybe you know that that's obviously something that you're very close to. I, I would say I'm less connected and I'm not necessarily intuitively aware of exactly what you mean there. So can you sort of give us a bit of, you know, expand on that a little bit more? Like, what is it that you're actually seeing, especially from the perspective of a CISO or a senior cyber security operator that might be listening to this, thinking, hold on, what, what's he mean there? And what, what, what do I need to be aware of?
D
Yeah, so with the Take a standard, like the Essential eight mitigation strategies, I think strategy is a really interesting word there. It's not saying implement and install something, it's saying do something in your business that you manage and configure and maintain over a period of time in order to get a great security outcome. It's sort of like patching, right? You apply the latest patches. It's what actually is the intent there is to shorten the time between when the patch is available towards when you're actually covered by it. That's a sort of strategy. And, and you seeing that with governance, you know, across, you know, particularly AI agents and endpoint, it's about configuring by taking capabilities away from the attacker because if they don't have the capability to do something, they can't use it in the first place. And also with AI agents, it's, it's been really interesting seeing, you know, what happens when you block an AI agent from doing something. It's sort of persistently keeps trying to get to its goal, but it does increasingly crazy things along that path. Like it might say, well, I can't do this because it's just not working, so I might download my own interpreter and try and run that code again to see if it's permitted. And you're not only burning tokens, but it requires a governance model where you actually need to explain to the model, hey, you're not allowed to do this before it actually understands and stops. You can't just prevent it. And it's sort of like having a really smart end user who's, I don't know, got fantastic administrative knowledge, but is cognitively sort of disconnected by all of the things that we have in terms of boundaries as a human experience, things that we should or shouldn't do, that is implied. So it's, you know, I think that taking capabilities away from an attacker at a foundational level is the thing that is solving a lot of security challenges now. And just about every endpoint security provider, when you're announcing new features now, a lot of it is about unlocking that customization and configuration for, you know, the organizations that increasingly demand that. And from a C suite level it's about what are we doing to lock down risk. And a lot of the conversations are about let's take squares off the chessboard.
C
I'd say definitely in my experience in the past when I was talking to more senior executives at larger organizations, the conversations would be more like, well, we just need to get app control running and we enforcement and then we're good. Right? And now the conversations and they've achieved those goals. But the conversations now tend to be much more tactics based where it's going to be like, well, what are we going to do about this class of malware? It's like we've had findings from our regulators or from our pen testers that qlik once malware is a problem for us and we are controlling, we know we're getting some level of control, but how do we deny this whole class or just roll that out completely? So I feel like everything, like that's definitely a lot of conversations I have are like all the time I spent thinking is okay, yeah, we can stop them executing this code, but how do we stop them even having the attempt to use this method? And there's only a, if you call them ttps, there's only a limited amount of them. So control stopping the TTP from even happening preventively rather than again just allowing and responding as soon as you can. That's all our focus and that's where people sort of get excited because you just go, you know, we're worried about this, we're worried about ClickFix, we're worried about XYZ. And if you just go across them off the list, then you know they know they're making progress. Yeah, it's measurable, I guess, and the confidence is higher rather than, oh, they've slightly tuned the rule a little bit, they've made a different parent process or they've just used a different scripting library. But it's the same attack. Denying that just that capability in the first place is sort of where I think the Well, I spend my time thinking a lot of my customers do as well. So again, controlling that is getting more. That's the conversation. So hardening is cool again.
A
Yeah. Actually speaking of things that were cool again, I remember last time we talked we were covering how you'd build sort of a really neat system around not just sort of doing tracking of individual binaries and allow listing, but actually sort of grouping things together and understanding I guess the, the lineage or the threads on that. And I think that was going to market relatively soon after we talked. So how's that going? What's the reception been like?
D
Yeah, it's been great. That's out now and available and it's really interesting seeing the shape of what applications are and how they're associated together. And it's actually been the biggest thing has been really interesting seeing the gap between what that system finds versus what is actually reported as installed. And they're often very different things where a lot of customers have actually come to us saying hey, can you pull the ad remove programs list and add it to this data set? Because I'm missing a few things that are here. But that's not to us what's actually executing and running and being seen so challenging. The notion of what an application is has been a really interesting thing to pull to market. And look, it just shows the, it's almost a supply chain conversation when you're looking at the sort of cross pollination of items on a computer that an application uses where things are so interlinked and shared. You know, I think Daniel mentioned that why there was a certain application showing up and it's because he uninstalled one app, but it was still a cross shared library with another one and we could see sort of the connection between them. So you know, and, and, but to be able to easily explain that was a really nice thing about that.
A
Yeah. And I imagine getting back to that concept of the industry shifting to this governance based approach. Right. It can be, I would imagine for a lot of folks having to get yourself into that mindset and considering doing something like allow listing of binaries for the first time ever is quite daunting. Am I right that this sort of helps in that? Because it's not as daunting. You don't have to be enumerating like all the binaries and creating all your rule sets around that you can come up a level and start looking at the application and apply your governance again, your controls at that level. Is that sort of what the traction is that you've been Getting, yeah, definitely.
D
It just makes decisions more simple to understand and categorize. And rather than, hey, here's 400 separate decisions you need to make for binaries. Here's one or two because it's a high level app and do you use that app? Well, yes. And then there's the decision rather than what is lib170dll? So when you can see that association, it just makes it so much clearer.
C
What's been really interesting while I've talked to customers about it is that they've been shocked to see their internal apps recognized as apps. That's, I think something interesting because we didn't like when we first discussed this, I was going, oh, we'll probably need an app catalog of the top 50, 100, 200 apps and let's start there making these definitions. And then David's like, oh, but then we have to maintain it and it's never going to be good enough and see everything that's there. And then through some very clever design, LLM enhanced I think, but not using it. The we've ended up in a situation now where I'm like, oh wow, like, you know, and people are like, oh, there's this temporary file in this folder. What is that? But then they click on it go, oh, it's related to Slack. It just saves people time to go, Yep, I know what this is. It gives me the context to make better decisions and understand the edge cases where people can be stuck before.
A
Yeah. And you mentioned a couple of times there people reviewing this and people making decisions. But before we wrap up, I guess last question for me is, is it just people interacting with this sort of app level understanding or is it LLMs of course also starting to like how,
B
how far away are we from Almost
A
like an autopilot of Allow listing that actually gets you something that you can trust.
D
We're going to get there. You know, I think the main thing is just about, you know, again
A
it's
D
about finding the right balance to have ownership of the decisions and being able to outsource that but still trust that it's going to make the right choices for you. Pretty much the only thing we're talking about internally at the moment is about how do you make this easy and scale it and the natural thing is to use a language model to classify these items. So there's a lot of different ways that we can go about approaching that topic. But the biggest thing is actually about how do you give trust to the human that's behind it to sort of outsource give them visibility and transparency in terms of what decisions are actually being made on the other end, I think is key.
A
Yeah. Building that, that durable confidence is still a difficult thing, Right?
D
Yeah. But it has to happen, you know, And I think that you'll see a lot more in this sort of governance, proactive security space because of LLMs for this reason.
C
Yeah. And customers will have different sliders there as well. Right. On what they're accepting or not. Like, we see lots of contracts now from when people are buying, they're saying, where do you use LLMs or AI? Can you tell us? We're not going to use it. You'll never use it near our data or you're not using it in the background, that we might end up with some risk we don't know about suddenly being realized. So I think it'll be like a land where some customers are going to be like, hey, I just want the LLMs to make the decisions. And I think a lot of them will be like, hey, just make the easy ones. Summarize me. The tricky ones. I'm not sure again. So the user at the end of the day gets a summary and goes, hey, I've got four decisions to make. Oh, yeah, this looks good.
D
Go.
C
Done. Not. I'm going to spend 10 minutes going through every pay note and making like five adjustments, like summarizing things up, I think is the way that I see this.
A
Yeah. Very cool. Well, Daniel, David, it's great to see you both again and I'm sure next time we catch up, maybe we'll be a little bit further along in this journey of LLMs. Just doing it all for us, no doubt.
D
James, thanks so much.
C
Cheers. Thanks, James.
D
Sam.
Podcast: Risky Bulletin (Risky Business Media)
Date: July 26, 2026
Host: James Wilson
Guests: David Cottingham & Daniel Schell, Co-founders of Airlock Digital
This episode delves deep into the evolving landscape of Endpoint Detection and Response (EDR) in the face of generative AI, specifically large language models (LLMs). Host James Wilson discusses with David Cottingham and Daniel Schell from Airlock Digital how AI is shifting the balance of power between defenders and attackers, why customization and governance are becoming central to endpoint security, and how emerging models are forcing organizations to rethink traditional EDR approaches.
[02:19] Daniel Schell comments on a June article by Spectrops, revealing how LLMs were used to extract EDR rule sets in record time—a task that previously took months or years of manual analysis.
[05:18] Contrast between mainstream EDR products (relying on universal rules/heuristics) and allowlisting solutions like Airlock Digital (which are fully customizable per customer).
[07:41] David Cottingham discusses the security industry’s movement from “set and forget” tools toward ongoing, strategy-driven governance.
[10:08] Daniel Schell shares how conversations have advanced—from enforcing basic app controls to tactical, proactive measures against specific classes of malware or attack techniques.
[12:10] A discussion on Airlock Digital’s system for tracking application lineage and context, simplifying the administrative burden compared to binary-level allowlisting.
[15:16] Host inquires about the prospects of autopilot-style allowlisting. The guests discuss the gradual shift (and challenges) toward trusting LLMs to automate decisions.
The episode is conversational but incisive, focusing on the practical realities faced by both endpoint vendors and defenders. There’s a strong theme of adaptation: from attackers leveraging AI to security teams needing governance, transparency, and smarter automation. Both guests reiterate that the industry is trending away from “one-size-fits-all” controls toward tailored, actively managed, and eventually, semiautomated defenses—where human trust remains paramount.