HN user

ejcx

2,871 karma

Evan Johnson runreveal.com evan at runreveal dot com

Former Cloudflare sr director of security engineering, first security hire at Segment.

Posts78
Comments423
View on HN
techcrunch.com 2mo ago

Vercel says some of its customers' data was stolen prior to its recent hack

ejcx
3pts0
blog.runreveal.com 3mo ago

RunReveal in Kubernetes for On-Prem and in VPC SIEM

ejcx
1pts0
blog.runreveal.com 10mo ago

Scheduled Prompts: Automated Security Reports with AI

ejcx
1pts0
blog.runreveal.com 11mo ago

RunReveal Raises $7M Seed to Build the AI-Native Security Data Platform

ejcx
1pts0
blog.runreveal.com 1y ago

We shipped 4 new integrations in 1 day with AI (and you can too)

ejcx
1pts0
blog.runreveal.com 1y ago

Shipping 4 new integrations in 1 day with AI (and you can too)

ejcx
2pts0
blog.runreveal.com 1y ago

Custom Pipelines for ETLing Security Logs

ejcx
1pts0
blog.runreveal.com 1y ago

We Built the RunReveal MCP Server

ejcx
2pts0
blog.runreveal.com 1y ago

Security Operations with RunReveal's MCP Server

ejcx
1pts0
blog.runreveal.com 1y ago

Security Operations with RunReveal's MCP Server

ejcx
5pts0
blog.runreveal.com 1y ago

RunReveal provides an MCP Server for your security logs

ejcx
2pts0
blog.runreveal.com 1y ago

A RunReveal MCP Server for Your Security Logs

ejcx
1pts0
blog.runreveal.com 1y ago

Why RunReveal helps companies detect threats with their Okta logs for free

ejcx
1pts0
sigmalite.dev 1y ago

Sigmalite, an open-source runtime for detection rules

ejcx
1pts0
blog.runreveal.com 1y ago

Sigmalite. An open source sigma rule evaluator

ejcx
3pts0
sigmalite.dev 1y ago

Sigmalite, a detection runtime for sigma detections

ejcx
1pts0
blog.runreveal.com 1y ago

Sigmalite. RunReveal's open source sigma rule evaluator for detection

ejcx
2pts0
blog.runreveal.com 1y ago

We shipped SSO support in a day, how?

ejcx
3pts0
blog.runreveal.com 1y ago

RunReveal Enrichments because every log needs a little more context

ejcx
4pts0
blog.runreveal.com 2y ago

Detection as Code Beta Support in RunReveal

ejcx
2pts0
blog.runreveal.com 2y ago

RunReveal announces $2.5M fundraise to reinvent SIEM

ejcx
2pts0
blog.runreveal.com 2y ago

Correlated Alerting. How to optimize for high signal alerts

ejcx
1pts0
blog.runreveal.com 2y ago

CVE-2024-22412 Explained – A caching problem in the ClickHouse query cache

ejcx
1pts0
blog.runreveal.com 2y ago

CVE-2024-22412 – A classic caching problem in the ClickHouse query cache

ejcx
2pts0
blog.runreveal.com 2y ago

RunReveal Destinations, your security data streamed where you want it

ejcx
2pts0
pql.dev 2y ago

Pql, a pipelined query language that compiles to SQL

ejcx
262pts131
blog.runreveal.com 2y ago

Pql, a pipelined query language that compiles to SQL (written in Go)

ejcx
4pts0
blog.runreveal.com 2y ago

Introducing Detection of Tor Exit Nodes

ejcx
2pts0
blog.runreveal.com 2y ago

The history of centralized logging

ejcx
2pts0
blog.runreveal.com 2y ago

Announcing impossible travel detection for all customers

ejcx
25pts9

RunReveal | Engineers, Customer Facing | Full-Time | REMOTE, SF, Austin | runreveal.com

We're helping companies manage their security logs. We've built a fantastic product for a company our stage and signed up some amazing customer logos in the process. We're working on moving up-market and building a product that can displace some of the enormous vendors in the space.

Email evan @

We made pql.dev that works with the different sql syntaxes by translating kusto like queries to sql (using CTE). It's worked really well thusfar and I wish someone would make a standard pipelined query language that gets supported across most databases

I know prql exists, but the syntax is pretty cumbersome and not something I enjoyed writing, but I do understand why folks would gravitate towards it

We're incredibly biased since several members of our team worked at Cloudflare, but we spend ~$20 a month on Cloudflare for our startup and it is fantastic.

- Marketing videos on stream

- Pages for multiple nextjs sites

- DNS + Domain Reg

- cloudflared / tunnels for local dev

- zaraz tag manager

- Page rules / redirect rules for vanity redirects we want to do.

The list gets longer every day and the amount of problems we can solve quickly is amazing. The value to money is unmatched

The main goal was to help security engineers / analysts, who _loathe_ sql (for better or worse).

I tend to think this is a little more user friendly, personally, and it's nice to give some open-source competition to the major languages that are used in security (SPL, Sumologic, KQL, and ES|QL).

We were surprised that there weren't syntactic competitiors (i.e. -- while prql has some similar goals, the syntax and audience in mind were very different)

I hate to shill in this thread, but that's exactly what we built at runreveal, so I completely agree! We saw the power of clickhouse when we were at segment and cloudflare, so built a company around it.

And since clickhouse is open source, we hope that people will stop giving their security data to vendors who then charge you rent for it. I think the future is writing this data to clickhouse, but also our customer's clickhouses

Founder of runreveal here, if anyone is interested let me know. The news today was big, but not necessarily too surprising.

There have been instances in chess where cheaters get caught and they receive light bans and many top players say the punishment is too weak. It's intuitive, if you've been caught cheating then you should be banned from competitive chess. I think that's more likely what Magnus thinks.

What was missing was the server side ownership check. We decide which customer owns the real "example.com" which is very battle tested logic, but had missed the check in this new service. The client side validation is expected too, though

I lead Product Security at Cloudflare, thanks for the writeup Albert and the fantastic security research throughout the past year.

Once this issue was fixed we investigated all prior email routing configurations to ensure that this had only been found as part of Albert's responsible disclosure to us.

Since some comments are addressing that this happened 7 months ago. Our disclosure policy is to allow researchers to write about us once the issue is fixed, but give us a week heads up before they publish so we aren't surprised, can coordinate any public comms we want to make, FAQs that need to be written for inbound questions from customers, and can tailor our response to the issue at hand. Can answer other questions if you have any.

We disclosed the issue here earlier this week once Albert told us he was writing a blog: https://hackerone.com/reports/1419341

I lead Product Security at Cloudflare (and I'm one of Albert's biggest fans, he's contributed a lot to our bug bounty, thank you Albert).

Once he reported the issue we investigated all prior email routing configurations to ensure that this had only been found as part of Albert's responsible disclosure to us.

We disclosed the issue here earlier this week: https://hackerone.com/reports/1419341

(I work at Cloudflare). You can sign up just a subdomain (sub.foo.xyz) as an enterprise customer and then add an NS records from your DNS provider to Cloudflare for that subdomain.

Tunnels also has a testing domain you can use. It should give you a subdomain like xxx-xxx-xxx.trycloudflare.com for basic "How do I get this thing working" testing.

Alpaca Attack 5 years ago

Yes, you do in fact need CORS to set the arbitrary header in the example if it's even possible to send from a browser. I suppose it might be possible to send as `HELP xss:` which is close

Like you said, you can send requests, but not the one listed in the example and you're severely limited in cross protocol interactions to valid http where you don't need to receive a response... (which some of the example attacks require btw)

I think this is an interesting issue to consider, but the examples are based on wildly different threat models that include TLS being hijacked, maybe DNS if it was performed with rebinding, the FTP server being hijacked for one of the attacks. It is not at all concrete. Interesting, but not really worth worrying about.

The interesting cross protocol attacks that I've seen involved SSRF talking to memcached, as a classic example. Something private. In practice I think they would struggle to find a single real world instance where they can pull off an attack enabled by this behavior. Which is fine, it's academic. Just not what I expected given the coverage.

Alpaca Attack 5 years ago

In the example image, why is ftp.bank.com:990 responding with CORS HTTP headers allowing attacker.com to establish a cross origin connection?

The whole thing seems a bit impractical to me.

Spreading Jam 6 years ago

Congrats on the launch. As someone who has used this and denied it the product has a ton of potential

(I work at Cloudflare and manage the Product Security team, so...disclaimer).

WAFs definitely help. No WAF is perfect, but having an additional layer to make exploitation harder, and having a tool designed to block specific attacks (like when a new CVE is issued for a CMS) is powerful.

Not to mention that WAFs are a requirement in regulated industries. PCI mandates it. And your SOC2 + ISO auditors probably will ask about it too.

Nothing changes. No matter what certification, there’s a scope of what parts of the business and product are in and out of scope of the audit. Fleetsmith having SOC2 doesn’t bring the rest of Apple into scope

I'm a Cloudflare employee, so obviously biased (shilling incoming).

Cloudflare Access is worth having on the list (and it's free right now [1]). It is a pretty flexible identity aware proxy, and ssh gateway. We use it internally for those two things for basically all of our infrastructure and internal applications.

If it works for you that's awesome, if not (or you have just general questions) I'd love to hear feedback about why not / what else you might be interested in. I work on our security team but work really closely with the access team, so would be happy to pass on feedback to them.

1 - https://blog.cloudflare.com/cloudflare-during-the-coronaviru...

Very good post. This ticks all the boxes on the fundamentals when spinning up a security program.

SOC2 Type2 is really where you want to be, but it takes time. Navigating compliance for startups is pretty challenging and I see so many not having a clue how to navigate sales without certs but it's super doable, and getting these things finished get you pretty far along towards Soc2 type1, and shows a lot of goodwill to share these practices even _before_ you have any certs

I’ve never heard of Erdos Bacon numbers. My university professor Dr Tjaden pioneered the Bacon Number and it was a pretty obscure claim to fame he had.

I’m guessing his Erdos Bacon number was 3+1=4. He appeared in a documentary with Kevin Bacon about the 6 degrees of Kevin Bacon, and has a peer at the university with an Erdos of 3. What a world we live in!

The Cruise Origin 7 years ago

This is probably the last thing to knock Cruise on. They've hired a lot, a lot, a lot of good people on the security front

Definitely a little cynical =]. I think the same thing about a lot of 3rd party security consulting.

OpenVAS is free, but the big issue we've had with it is the complexity of setting it up and maintaining it. We are a security team, and would rather not spend our time managing servers, especially since we aren't the best people to do that at Cloudflare.