Loading summary
A
Foreign
B
hey everyone, I'm James Wilson from Risky Business and welcome to this sponsored interview with Permiso CTO Ian Arle. In this interview, Ian's going to take us through what it's like to watch a Shiny Hunter style attack unfold. Both from the perspective of catching one in incident review, as well as what it looks like in real time as they start to pivot through your systems. We talk about how these identity led attackers move through cloud environments, SaaS environments, and even use those to tunnel down on prem. And also why AI is compressing these attacks from what used to be days down to just now four hours. And that time window will no doubt only get smaller. We also talk about how, as Ian says, the signals are abundantly present, but it's connecting the dots that remains difficult. And that's where Permisso can really help. I'll drop you in here where Ian outlines the overall shape of a Shiny Hunter's attack from initial access right through to extortion. Enjoy.
A
Yeah, for, for me, when I think about this group, it's like really three phases to their attack. So initial access, myriad of ways that can occur. You know, sometimes it is, hey, they stole some credentials from Salesloft back in the day, so great, I'll go ahead and use those if they want. Sometimes it's what they're notoriously known for. Just call the help desk, fish your way through. But honestly, regardless of how they get in there, the first thing they do afterwards is always a pretty good tell, which is they want to register their own mfa. So you'll see things like, ooh, this is somebody who's been an Android user in my environment for seven years. They just registered an Apple device. That's often a tell that you wouldn't think about from a detection perspective traditionally, but it's really honestly, I see a password reset, a device swap and followed by somebody landing in SharePoint and searching for AVD or whatever. The mission happens to be a lot of Azure virtual desktop searching around recently. But the first phase get in and establish a way to stay in. Second phase is they got to learn your environment and they have to learn it as fast as possible to be able to carry out their mission. So if they're going after a large software firm and maybe they want code signing certs, well how are they going to go and figure that out? The same way your engineer does. They're going to click into Confluence, they're going to click into SharePoint, whatever your document store is, and they're just going to search and My opinion, that is the most underrepresented area for detection opportunities out there. Nobody monitors searches and it's consistent. The search terms I see, there's like 30ish that I've seen for the last three years from this group. Sometimes they type them in the same exact order. You know what they're looking for. Search terms show intent, you know what they want when you can see what they're searching for. So yeah, phase two is all about just learn as much as they can through your own SaaS applications. Now it depends on what their mission is. If I'm going after that software firm, I need to get into your CICD pipeline if I want that code signing cert. So this initial phase, initial access, then recon, figure out where you're going to go. What happens here really dictates what happens in that third phase. If I'm going after an airline instead, well man, what are they willing to pay for terminals being shut down? So the goal there, get on prem as fast as possible and destruct. But they're going to go on prem from the cloud. They're going to use Azure virtual desktop as a pivot point because it always bridges those networks. So it all depends on the goal from there. But it is usually get on prem, get to data or get into your CICD pipeline. And for this group, they've gotten a whole lot better recently. Salesforce, Snowflake, Tableau. They're in those types of applications because that's where they're going to find the juicy data that they want to be able to extort you for and more credentials.
B
Right, right. And you mentioned there that there's the gap of not watching search, which would provide some pretty interesting signals. But I guess what signals do we have and where should people be looking for this? Is it still largely a problem of a human operator? May be augmented by LLMs, is having to sit across multiple event streams or have we gotten better about sort of high quality ways to detect this through I guess, higher signal to noise ratio sort of detections. I'm just, I'm trying to put myself in the position of a SOC operator or analyst and imagining like what is, what does their day look like when, when one of these attacks is, is happening?
A
Yeah, no, it's interesting when I see one of these attacks happen and I come in to analyze it afterwards, it is always very obvious, right? Like from the, from the IR perspective it's like oh yeah, somebody went from never downloading anything in SharePoint to downloading a thousand files with a Python user Agent like, okay, like that looks strange. But when you're trying to detect that in modern environments that kind of event happens 20 times a day, 100 times a day. So what I think you have to do is you got to bring the streams together, right? And yes, siems have been out there for forever and that can be a good place to do it. But you got to find a way to start getting your knowledge transferred to the event logs that you're bringing in and mapping them together. A good example of this is in the situation we were just talking about, you have somebody who just reset their password, they switched devices, probably not enough to raise an alert yet. Now they just clicked into AWS and they assumed a role that they've never assumed before, never assumed this role. So now they're in AWS and they're doing everything. But from Cloudtrail's perspective, that's all happening from an assumed role that you have to, you got to map these two together in order for you to know, oh yeah, this came from that same identity that just reset their password as well and just got a device change. And once you start putting these signals together over the multiple streams it becomes very obvious like oh yeah, Ian is definitely a baddie. He just reset his password, he just searched for 15 suspicious things and now he's in AWS for the first time using S3 browser to harvest anything he can out of your S3 buckets.
B
Right. Keeping sort of like a more industry wide view on this before we dive into some of the specifics of how permiso helps here. But like is there advice you would give to CISOs and to cybersecurity professionals out there about how to almost like, you know, what's the playbook here of the top three signals that you should be correlating or what's the top five data sources that you should always be looking to try to map together, you know, just to try to cut through. Like there's probably hundreds of data sources that I could, would and should be looking at, but I just don't necessarily have the time for. So how would you advise them to prioritize their efforts here?
A
Yeah, for me it's where do we see the attackers most often is the place I want to invest my good logging in. And that is your IDPs, that is your cloud providers, that is your knowledge area, whether that be confluence or 365 or something to that effect. And then what is the big target all the time now it's always Salesforce, Snowflake, Databricks, your big data lakes, your big SaaS, platforms like that. I'd be spending my money to make sure that we're logging the right things in those places and have a way of at least being able to investigate when something does occur in one of those areas.
B
I guess the attackers are still limited by their own resources and so they still triage and go after and prioritize the higher value targets. I'd imagine there's a risk though of like the long tail here of. Well, I guess have you seen these threat actors sort of change techniques over time? Like, am I right in saying they're still constrained by their own sort of resources and therefore they go after the things that you just enumerated? Or do you see sort of more attackers coming along, maybe going after the longer tail of things that are less defended, which presents its own sorts of challenges for defenders, I guess.
A
Yeah, a little bit of that. Right. Like they don't care inherently what knowledge software you use. They're just going to go into your IDP portal and click the button that takes them to it. So for them it doesn't matter as much where. I will say they have changed a lot. And I know that we weren't going to bring up AI in this episode, but it is like in 365. My search terms that I love looking for to know when a bad guy's in your environment are less and less effective now because they just go to Copilot instead and ask the question. And Copilot does a better job of bringing all that data in. Right. So convenience for us is also convenience for attackers. So that's one. And another AI one is in Snowflake. It used to be, you see, just a very standard select all copy into some external storage. And that was about as complex as they would get in Snowflake. And now they're creating stored procedures. They're doing their stored procedures in JavaScript instead of SQL. So they're getting around the detections. Everybody was writing for SQL. When they run into problems in Snowflake, they're troubleshooting. Well, they look like Snowflake admins. And why? Well, man, when it's obvious to anybody, it's, yeah, the ChatGPT is, is helping them out just like it's helping us out. Right. Even one of the store procedures, when a, when you try to create a store procedure in Snowflake, if it fails, the error log contains the entire stored procedure. I could see that didn't work. Then you see the ChatGPT style comments as they're iterating through four or five different times trying to get this stored procedure created, they're evolving with the times as well.
B
Let's delve into permiso and where it helps here you've sort of created a picture of some of the signals that you can see. But the challenge here is that there's so many signals that sometimes it gets lost. And the real value here is being able to correlate a lot of these things. And of course, as you said there, the IDP is one of the, you know, the richest sources of data here. So tell me how permiso helps in this sort of attack scenario.
A
Yeah, for us it's stringing all that identity together, all that identity data together. So when Ian takes an action in aws, if I did it through a role is still attributed to me. I'm still the person who did that action. And I got a team of 15 threat researchers. We're a relatively small company, right. Startup, we're a 60 person company. And for us to have 15 people dedicated to just detection and hunting on my team, it speaks a lot to Jason and Paul, our co founders, our co CEOs, about how much they care about that part of the mission. And that is a benefit to everybody because unfortunately, even if you had all this data, you still need to know what to look for. You need to know what the signals are. You need to know that when somebody uses S3 browser, man, very often S3 browser is associated with a bad guy, even though that's a normal utility. And if you don't live with that data day in, day out, it's a hard thing to keep up with. So bringing the frontline knowledge to the identity place and really honing in on the threat detection side is our bread and butter.
B
Right. And so I guess before we wrap up, I'm curious as to where you see this going from here. And I want to explore this from two angles. First is sort of where are you thinking about the product going in terms of like a product roadmap? But also how is that being informed by what you're seeing and or sort of hypothesizing about where these threat actors go now? Right. You touched on one thing there around how AI is making them seemingly much better and much more skilled, I would say, at certain attack paths. But you're the expert here. Where's this go from here in terms of the capabilities and the way these groups operate and how does that inform your product roadmap?
A
Yeah, I will say first off, they're Going to get the same benefits we all get. So every intrusion. I should have brought this up earlier too. Um, common intrusion from this group three years ago, about 72 hours before you're, you know, seeing data theft and they're trying to extort you. Last case about four hours. Four hours from getting into the environment to taking everything that they need and already sending that extortion notice.
B
And what's the limiting factor there? Like what's, what's changed? What's keeping it at four hours? What's allowed it to go from 20 plus down to four hours?
A
I think some of it's repetition. They've learned a lot themselves. Others, unfortunately is the AI side of this. I don't need to go and search through 30 Confluence articles. I can go to the AI helper and ask it where can I find code signing certs or how do I get into the code signing cert process? It's a lot easier for them to do that initial phase, or I guess the middle phase is a lot easier now of learning enough about the environment to be able to carry out your mission. For us, we've always really been very good at detecting the malicious thing. We never really got into the blocking game. So that's an area we're heading towards is everyone wants the ability to flip the kill switch. Now we stayed away from that. We thought that's something people ask for, but nobody ever really does it. And I think we're actually getting to a point where people are willing to go farther with that. The other thing is when we think of ourselves as an identity security company, we've always been good at detection, but identity risk is more than just detection. So we built the posture side of our product not too long ago. So you'll see more coming into. How can I tell you, hey, scatterspider did these 15 things to get into this environment. These are the 15 things maybe you want to try to fix for your users in the meantime, preventative wise. So more prevention, more blocking. Same great detection.
B
Awesome, man. That is a great way to wrap it up. Ian, thank you so much for dropping by. Ian Al, CTO of Permiso. Great to chat with you.
A
Great to chat with you as well, Sam.
Podcast: Risky Business Media
Date: August 3, 2026
Host: James Wilson
Guest: Ian Arle, CTO of Permiso
This episode explores the evolving landscape of identity-led cyberintrusions, focusing on "Shiny Hunters" style attacks in cloud and SaaS environments. James Wilson talks with Permiso CTO Ian Arle about the telltale signals and attack phases, the compression of attack timelines (increasingly due to AI), and practical detection strategies. The core message: the signals are present, but effective defense depends on connecting the dots across disparate data streams—something Permiso specializes in.
[01:02]
[04:19] & [04:59]
After-the-fact Attacks are "Obvious," Real-Time is Not:
Key to Detection: Correlating Multiple Data Streams
[07:34]
[08:50]
[11:11]
[13:00]
Attack Timeline Compression Fueled by AI:
What's Enabling Faster Attacks?
Permiso Product Direction:
On Detection Opportunity in Search Logs:
"Search terms show intent, you know what they want when you can see what they're searching for." – Ian Arle [02:38]
On the Impact of AI:
"Convenience for us is also convenience for attackers... Copilot does a better job of bringing all that data in." – Ian Arle [09:19]
On the Speed of Attacks:
"Common intrusion from this group three years ago, about 72 hours... Last case about four hours. Four hours from getting into the environment to... extortion notice." – Ian Arle [13:16]
Ian Arle emphasizes that although detection signals are "abundantly present," the art lies in connecting the right dots across cloud, SaaS, and identity logs. The rapid evolution of attacker techniques, especially with AI accelerants, means defenders must focus on holistic, real-time signal correlation and evolving their playbooks just as quickly. Permiso aims to stay ahead with deep domain knowledge, identity attribution, and new capabilities around prevention—not just detection.