Transcript
Dylan Airy (0:00)
Foreign.
Patrick Gray (0:05)
And welcome to another edition of the Snake Oilers podcast series. My name is Patrick Gray and for those of you who don't know Snake Oilers, these Snake Oilers podcasts are where vendors come along, they give us some money and then they pitch their products to you, the listeners who run a skeptical ear over them and then decide whether or not you want them or not. But today we are going to be hearing from three, three vendors who've got some awesome stuff for you. We've got portswigger, makers of course, of Burp Suite. They also have like a DAST product which you're going to hear about in just a moment. We are also going to hear from Sondera today, which is a company that I'm very happily an advisor to. And they're making. What would you call it? It's not really guardrails. It's like deterministic controls for AI agents while they're in flight, sort of mid trajectory, like, like proper controls of AI agents for organizations that need that. Right. Which is frankly most of them, but only some of them realize it just, just right now. But yeah, basically Sundera has created a harness that you can use to instrument your, your AI agents and make sure that they're not doing stuff that they should not be doing. And they've done it in a way that's a little bit different. There's a lot of snake oil in that particular area at the moment. So Josh Devon will come along a little bit later on to explain that one. Then we're going hearing from Truffle Hog and Dylan Airy, who was on the show pitching this stuff like quite a while back. But yeah, we're going to hear from him now on. You know where Truffle Hogs at these days. Truffle Hog, of course, does Secrets Discovery. You can throw it against your repos, throw it against Slack, wherever, throw it against network shares, wherever data is stored, basically. And it will go and find things like API keys, cred pairs, all sorts of stuff. And not just find them, but it will actually validate them, help you remediate them and whatnot. It's a very advanced bit of software these days. And Dylan joins us a little bit later on to talk through that. We're going to kick things off now with our first guest, Daf Stuttered, who is the founder of portswigger and the creator of Burp Suite, which is a very well known tool in the security discipline. If you're a security tester, you, you are familiar with Burp Suite. Now what's Interesting is portswigger have, you know, made some moves in the last couple of years to really sort of AI ify Burp Suite. And in a way that is not crazy, in a way that makes a lot of sense, in a way that's going to help testers do more testing and also help people who might not be testers do some testing. So really it's just about making itself very useful to human operators. So DAF is going to fill us in on that and he's also going to talk through one of portswigger's lesser known products, which is a DAST tool that their customers, the customers who use it, certainly love it. So here is Daft started filling us in on all things Burp.
