Transcript
00:00 Welcome and Agenda
00:49 AI Adjacent vs Direct
02:04 MCP Server Overview
02:49 MCP Benefits and Data Quality
05:54 MCP Resources and Prompts
07:02 Live MCP Report Prompt
09:02 Roadmap and Claude Plugin
11:41 AI Adjacent Reporting
12:31 Report Builder and API Automation
14:17 LLM Built Report Templates
17:11 Custom Dashboards with LLM
19:16 Sensei Introduction
20:13 Sensei AppSec Live Demo
26:15 CSPM Auto Fix Workflow
27:27 AI Report Examples
30:51 Sensei Threat Modeling
35:04 Sensei Advisor Insights
38:13 Q&A and Wrap Up
41:45 Final Report Reveal
44:23 Closing Thoughts
Thanks everybody for spending a little bit of time with us today. This is gonna be, uh ... I'll try not to talk too fast, but we're kind of jam-packed with a lot of different, uh, things to talk about all related to AI. Um, I don't know if anybody's heard about AI, but it's a, seems like a recent kind of interesting topic.
So we thought we would, uh, kind of cover some different use cases, uh, especially use cases that we're seeing in the field with, uh, customers and users of both open source and Pro. So, um, we're definitely gonna be covering some, uh, Pro features, but we're also going to be covering some ways of using AI with even your open source.
And, uh, uh, I kind of describe those as AI adjacent versus AI direct. Um, AI adjacent just for everybody's kind of why am I c- creating a term here. Basically, AI adjacent means there's a lot of environments where you've got either high security or you've got reasons why you cannot connect AI tools such as Claude or, or GPT, et cetera, to, you know, customer data or confidential data, high security environments, those kind of things.
Um, so there's a lot of environments where you, you know, you're using some AI to do some things, but you're not allowed to actually connect to like an API or make a direct connection where there's customer data, right? There's kind of a, a wall there. But that doesn't mean you can't do things with AI tools.
So we're gonna give you some examples around reports, dashboards, uh, uh, dashboards custom in the Pro version. Um, but the, basically anything in the API because we do have, uh, essentially a, a fully open API. And then of course, direct integrations or where the AI model is connecting directly to an API, um, or and doing things that way.
So let's go first with kind of the AI direct stuff where you can plug that in, and we'll start with the MCP server. So in Defect Dojo, we've got an, our first, uh, of what should be several options for MCP. Um, for those of you who are kind of new to why would, you know, what would be the value of the Defect Dojo's MCP server, well- Everybody, you know, an MCP is essentially an abstraction on an abstraction, right?
APIs are there to be able to do things directly with an application, uh, programmatic interface on the back end, as we would say. Um, so an AI can talk to those APIs directly. It can write code, all those kind of things. But if you are connecting an AI to a, like say, a whole bunch of different security tools or maybe tools that are doing scanning and you've got a whole collection of scanners for containers and SAST and DAST and SCA and all these different ki- uh, approaches, right?
Well, you're asking the AI to do all the deduplication between these, the normalization. Um, no two tools really report the same format because everybody's got their own proprietary spin on everything. Uh, that's our biggest challenge at Defect Dojo. We're trying to build an application that can import from everywhere and normalize that data.
Um, even if tools provide an MCP server, it's an abstraction on abstraction. It's still their proprietary data. It's not normalized with other tools. Um, your duplicates, your false positives, all of those things are coming from the source, and then you're relying on your AI tools to do that normalization, deduplication, uh, you know, triage, along with all of the analysis that it's trying to do.
Um, so that's one of the reasons why we feel and we see that we are really well positioned to assist you using your AI tools because we're already doing all that normalization, deduplication, and enrichment. So you're getting very clean signal to noise when you're using Defect Dojo, not just for MCP server, but for any kind of reports, analysis, all of that kind of thing.
High signal to noise, meaning you're getting much better data that has already been normalized, deduplicated, et cetera. Um, you can see, read all the benefits over here. But we see it in the practice. We know that this is, um, we are in the perfect place to help you with that kind of broad analysis or deep analysis Um, now from a previous webinar that we did, uh, last September, um, we kind of teased that this would be a 10X improvement over, you know, using just straight AI against an API.
Um, but it is a much bigger improvement because really, the AI is able to do things that would be very, very challenging to build into any tool, all the different customization and permutation that you can do with, with different prompts. Um, but the data that you're giving to it to do that analysis, et cetera, that's where Defect Dojo provides a multiplier.
So this is... You know, there's a, this term of, um, you know, force multiplying on both sides, um, but this is a real example of that. Um, and, you know, theoretically, it's, it's a huge improvement on both sides. You're saving tokens, you're making the AI use less costly, more performant, and then you've got, you know, everything that Defect Dojo is doing to clean up that data, enrich that data, normalize it, um, so that you're really getting the best results from your AI tools.
So I wanted to give an example. Well, before we give that example, uh, just at a very high level for those who, um, are interested, but some of the resources that are available as far as, like, the API connections that, um, you're able to use with this MCP server around findings, uh, the engagements test user group.
So a lot of the data, uh, objects that you would want to use for various reports. Um, we do have a couple of pre-configured prompts. Um, and also what's really important is the reference standards that we've built into this MCP server. Um, some of these have come as suggestions from customers, so we are looking to add more resources, but these just make it really easy to do reports that are very specific to these resources without having to rely on your LLM agent going out to the internet and having to pull these from websites and things like this.
So again, cost savings, a token savings, a speed savings, um, and allows you to get through to these or get... u-use these, uh, leverage those. Okay, so about 30 minutes ago because when you're doing a complex report like this, uh, it can take a while. Uh, this is actually comes from, if you go to our MCP, um, once you, uh, accept and enable the MCP, and this is, you don't have to have any additional license or anything like that, you can just enable it.
Um, and there's instructions. There's, these are fake tokens, uh, for those who are getting all excited. Um, and then you have down here some example prompts. So I just copied this example prompt, and I put that into my, uh, Defect Dojo or my, uh, Dojo MCP server. And so it has been working on this. This is a very intense report, um, and it is updating those commands right now, so it's actually been working on this for a while.
This is a very complex report to build. And again, if you wanna see what that looks like, um, this is that prompt that it is working on. So we're gonna check back in, uh, during this presentation to see what the results get, um, as it finishes working. But you can see it's, it's gonna do a, a security dashboard report for a board meeting, vulnerability trends, which development teams have the highest critical findings, current SLA compliance status, um, top five CWE categories that need attention, specific remediation recommendations, a six-month roadmap for improving the security posture, and create it as an HTML I can present to the board focusing on business risk and ROI.
That's a pretty heavy prompt, and that's, um, that is exactly what it is working on right here. So we'll come back to that, and we'll continue to check on its progress as we, uh, plow through that. Let's continue. Um, some additional, uh, items on this in-current MCP server. As I mentioned, um, we do have, uh, in the works, uh, some additional capabilities.
Um, I guess I would reference this as maybe additional MCP servers, but things kind of focused on reports, on dashboards, on other specific, uh, utilities, uh, within Defect Dojo that allow us to, you know, not to get too much into the MCP server thing, but when you're loading all of the tools, um, that come into this, so all the tools, all the resources, this takes up a lot of your context window.
So you wanna be kind of picky sometimes. You don't want to just load all the, every MCP server you've ever defined, because you are filling up your context window with a lot of stuff you may not be using. So that's a lot of wasted tokens and actually makes the LLM a lot less efficient. So, um, so the ability to kind of pick and choose which of these capabilities you want to engage for a particular task becomes important.
Uh, something that is coming, uh, very, very soon, we have also, uh, we're right on the cusp of releasing a Claude Code plugin. So this would... Um, our current MCP server is read-only, so it doesn't really allow you to change settings or go in and, and, and do a lot of, you know, any data changes. It is basically read-only and does analysis and all of that kind of thing.
Um, with a Claude Code plugin and future MCP servers that will allow to you to do some writes, um, but the Claude Code plugin will also allow you to do much more in-depth, uh, capabilities. If you want to learn more about that, you can actually go to our documentation, um, which I love the fact that we have documentation for this right before it gets released.
It's always the reverse, right? Uh, you get some new functionality and you're like, "How do I use this? Oh, well, we're coming with the documentation." No, we're actually, we're making a real effort to, um, not only improve our documentation, but anticipating other use cases, which you'll see in a few moments. But, um, so you can read all about that Claude Code plugin.
Just go up to the search bar, um, type Claude Code, and you'll see that plugin documentation, so you can kind of start to, uh, read about that. Not available yet, so a week from now, if you're watching this webinar, um, you can follow these instructions and you should be able to see, uh, where to add that. Okay.
With that, let's go back to our slides here So that's direct AI to the MCP that is absolutely touching data in Defect Dojo. So let's talk a little bit about when you can't do that. If you can't use the MCP server, um, and you want to make use of some AI tools, but you can't plug it directly in. So, um, first, it would be our reporting.
So, uh, this would work for the open source, although the open source you can't save, but you can actually have, uh, Claude build a report. And in the open source, you know, how you would need to continue to, to run that report or, or build it essentially every time that you run it. Well, you can automate that.
Um, in the pro version, we have added some capabilities. So let's go down to reporting. Yeah, you can see the classic report engine is, is still there. Uh, but the new report engine allows you to create colors, logos, um, header, footer, uh, content, you know, for internal use only. You know, kind of the theme for the report.
So just kind of the general how it looks. And then we have blocks. So this is very similar to the widgets that are in the open source. Um, you can create a new block. Now it is expanded capabilities in the pro version. You can do tables, detail blocks, charts. So there's lots of configurations and things to put into this.
All of the different filtering. I know we're gonna do another webinar that really goes, uh, does a deep dive on this. But those blocks get turned into templates, and a template would look something like this, where you got, you know, cover page, table of contents, you know, lots of blocks here. So this is a lot to kind of create by hand in the UI.
Um, so another approach you could take. So this is where we're actually gonna go to our documentation. In our documentation, if you just go to metrics and reports, and you can come down here to this report builder, and it'll give you instructions on how to build everything from the ground up, all of the different options.
Then we have automating reports with the API. So this actually does work on pro and the open source because the open source report generator has the API. So you can even have it build a script to not only build a report, but even continue to run that, um, in the open source. And in the pro, you can also do a lot of those kind of things.
And then we have building reports with an LLM, and this is where I get excited. Um, now you can have it do a direct API call. You don't have to go through the MCP server to do this. Uh, we are looking at building MCP server to do exactly this. But down here you have the prompt, and with this prompt, you can copy this.
You can either have Claude or ChatGPT or Gemini connect directly or not. I'm not gonna connect this directly. I want you to make me a Python script, and then I'm gonna run that Python script against my Defect Dojo instance, and it will build that report for you. And so the prompt is there. Copy the prompt.
Use that to build your reports. Um, as an example, so I do have a good example here. Um, in my templates, you'll see that I've got several of these, uh, plan of action and management. So we got a deviation request form, integrated inventory workbook, uh, the plan and POANM, and the executive summary. So you can see there's...
We got, like, four templates here. Well, the backstory of this is we had a prospective customer come to us about fifteen minutes before a meeting, uh, send us an email saying, "Hey, can you guys support these kind of custom reports?" And so I basically took their requirements, and I took that prompt right there, and I used Claude, and Claude built these templates for me and then ran them.
And in fact, if I go to the generated here, and I do a, um... Let's see. Uh, POA. There we go. So you can see here, so these plan of action. Now, the date on these, this was, you know, a few months ago, but you can see the timestamps on this. So nine fifty-one oh four, nine fifty-one fourteen, six seconds later. Um, so y- And then I reran a couple of those.
But this was... Like I said, they sent this fifteen minutes before the meeting, and we showed up to the meeting with an example of how they could build these reports that fast. Um, so needless to say, this can save you a lot of time. Allows you... And of course, you're gonna verify, and you're gonna go through these with a fine-tooth comb, as you should.
But the best benefit about this is once you have built these templates, you're not using AI anymore. You're just running these reports. These are verifiable, direct, just traditional kind of go get me the data with, you know, SQL command type stuff So that's one way you could use, uh, AI adjacently build scripts to do reports.
Um, oh, yeah, live review. Oh, and there was also one more. So in the pro version, you may have noticed that we now have completely customizable dashboards, which means you can change the layouts. We have some pre-built templates that you can use. Um, you can export them as a PDF. You can move things around where you want them.
Um, use those starter layouts. Then if you customize them, you can share them. RBAC is at the organization and asset level, so if you share a dashboard, the folks you share it with can only see the data that they have permission to see. Um, so again, a lot of things that you can do here. You can add different new widgets, um, or you can use widgets that are from the catalog are already pre-configured.
Um, again, the best part to me about this is if you need a custom dashboard for some very specific requirements, maybe for an executive level type person, you can go to the documentation under Metrics and Reports, go to My Dashboards. So yep, you can automate them in the UI. You can automate the dashboards with an API, meaning you could just write a script or have Claude, Codex, et cetera, write a script.
And then here we have building dashboards with an LLM where you can, um, yes, you can do it directly or again, adjacent, have it generate a script to build this. And then here is the prompt that you can use that allows that LLM to know exactly what it's doing, what the context is of the, of the dashboard, how to build the dashboard, all of the different components, et cetera, et cetera, et cetera
Uh, let me check in with Chris. Chris, any questions so far or comments? You guys can ask any time. Just wanted to check in and see if we're, how we're doing. Yeah, nothing yet. Um, yeah, definitely folks, post any questions in the chat or the Q&A if you had any questions about any of the stuff we covered today Excellent.
All right, now let's talk a little bit about Sensei. So this is the Defect Dojo Pro, uh, built-in ... That's supposed to be a T. Built-in art- artif- gosh, artificiation intelligence. So you can tell that I typed this late. Um, yeah, so this is Sensei. Sensei is... Basically, you can see here we've got the AppSec, CSPM, and all.
So what you're able to do here is you can add a repo, and then you can scan that repo, and then it'll create auto fix candidates, and then you can remediate them automatically. And Defect Dojo will do the auto remediation. It'll update the library. It'll change the code. So this is not limited to just, like, versions of modules or libraries that just need to be updated.
This can actually go in and change code, change settings, those kind of things. So we're gonna do a live demo of this, which I just jinxed myself. The live demo gods have just woken up. So the way this works, I've already set up my, uh, repo, and so I'm gonna hit this scan now. Now, before I do, just so that you can see the configuration, you can see we've got the scanning mode, uh, PR reporting, the automated fixes.
So we're gonna stage those after the scan. If I wanna fix something, I can just click to fix it. Um, I can also set thresholds as far as what I want to allow for an auto fix, um, which p- uh, branch to open the PR against, and also which branch to actually do the, the scan on. So you can see I've got this pointed at our dev branch for this environment.
And, um, yeah, so let's do a scan. Now, this scan is going to, while this is running- I press the button The scan is now running. And so while that is running, uh, I was just going to give you a little... One of the big questions that we get is, well, which scanners are you running? Um, and the real answer is it's a proprietary thing.
The, the scans that we are running have been designed, because first of all, we don't know exactly what's in that repo. There's all different kinds of technologies, languages, artifacts, everything that can be worked, uh, be built into that. And so we're really, what we're doing is a, it's a combination of static analysis, uh, software composition analysis, SCA, um, secrets finding, um, and the, what we're doing is basically by analyzing what that repo looks like and what technologies are, then we can use different approaches to do those scans.
Um, so it is kind of a specific, uh, detection logic, um, that we're building that's, that's a bit proprietary. Um, let's do a refresh here, and you can see, and now I have, uh, 14 active findings. If I go to my auto fix candidates, you can see that we had a bunch of candidates here, um, that, uh, are coming in that look like there's, we've got some high fixes here.
So I'm going to look for, let me make sure that this scan has completed, because I feel like I'm missing some of these, but maybe not. And then I'm looking for one that I want to fix. So I see we've got this AppSec here. I believe that these are fixable because obviously they have come in like that, so what I can do is just approve this.
Although I was looking for another one that had a different issue. I, like I said, uh, no remediations, just making sure that is done
And it is loaded, 'cause I thought I was gonna get an SQL. So this might, this may be where we go off-road. All right. I'm going to fix this credentials ones right here. So this has got a pattern that may include some, indicate some AWS credentials may be included in there. So I'm gonna fix that one. So I can select that.
I can also select multiples. I'm gonna approve that one, and I'm gonna say fix it. So that fix is now going in. It's going to make the fix. The fix has now been dispatched. You can see that the progress bar has changed to in progress. And if I go to my remediations, you can see that that has now been moved.
So it is an in-progress remediation that is happening right there
And if I come here, it's still in progress. Now, this usually takes about 15 to 20 seconds. That was the whole point of the demo, is something that would work fast. And PR is open. So now if I go to, uh, this finding right here, so you can see the target, and this is gonna go to our GitHub repo. There is the PR.
So this PR is now sitting in open status, which means now you can review the PR, um, and approve the merge request, and you're done. So definitely can have a human in the loop, uh, depending on, you know, your practices with pushing fixes into defect or into GitHub. Uh, but that is essentially how, uh, that would work.
So I still have other auto fix candidates. Um, also, i- if it scans a repo and you go to, like, the findings, the findings... Well, let's just take a quick look. If I went to my active findings here, uh, you would see, so if it was Sensei, can I do a filter on any here? Let's do any that are not fixed or a candidate.
So I could do a filter here, apply that filter, and so then we see that I've got these other candidates, and so I can fix them here as well. So anything that Sensei has done a scan on that is fixable, those will show up anywhere that those findings are, are visible
So we got the remediation, we got the scan, uh, auto fix candidates, scan activity. You can trigger these on a web hook, you can also trigger them manually. Um, you can see here the view of the PR for some previous fixes, et cetera. So, uh, that's essentially how the app sec portion works for Sensei. Uh, one capability I will not be demoing today, because it was released yesterday essentially, is the CSPM, so Cloud Security Posture Management.
Same story, second verse. It allows you to scan a s- cloud environment. We will check all of the security settings against the best recommended practices, et cetera, and we will, um, show those as auto fix candidates, which you can then say, "Yep, fix that." And what it will do is it will not actually go and fix, it'll create kind of a, a, a PR for, um, you know, IAC, in- um, Infrastructure As Code, but it'll have an approval step so that you can say, "Yes, I want that to be actually approved."
We don't want, uh, AI going directly to our cloud environments and just making a bunch of changes automatically. We definitely wanna have that kind of a human firewall, if you will, so that those things are not automated that way. Uh, but this is a big, uh, direction that we are headed in, is this auto remediation, uh, using Sensei I'll take a pause.
Are there any questions on this, Chris? I think maybe more, one and more general is that what is the biggest surprise you've had when using AI with Defect Dojo? The biggest surprise, um
I don't know if it's, if it's so much a surprise as just the how impressive it is. Well, let's see. Can we be... Oh, it's still working on this report. I knew this was gonna be a big one. Um, let me show you what kind of, uh, impresses me. So if I go to, I've got some AI reports that we've built in the past. So you can see here, I know it's a little small, you can see this, uh, tools effectiveness report.
Um, so this is an- the other prompt that we provide. This is just kind of like a SaaS tools. You know, I want my CISO to get a report on how effective our tools are. I wanna see false positives, I wanna see meantime to remediation by severity, um, vulnerability patterns, as well as maybe a de- a developer team performance capability.
So again, the prompt that generated this report we're looking at is here under MCP, so it's actually this prompt right here our CISO wants to evaluate. Now, use your own prompts, right? We're just giving you a couple of examples here. But, um, that report, wherever I had it last, there we go. So yeah, tool configuration improvements, training gaps based on CWEs of findings that we're getting that are repeated, so maybe if we get some training we'll actually have less findings.
Um, a cost analysis of the current tools used. You could even plug in the costs that you're paying and find areas where you can either replace tools or more commonly, where you start to stack, uh, scanners, where maybe you're paying for a particular scanner for containers, but then you stack a couple of open source scanners because any time I've done a bake off between scanning tools, I never get the same result from all of them, right?
The majority of the findings are the same, but there's always a small percentage that are not, and those are the ones I'm kinda like, "Well, why did this find it, but this one didn't?" You know, is this a false positive, false negative? Um, recommended training, uh, implementation roadmap. So that's a, that's a crazy intense report.
Um, other reports, for example, EU Cyber Resilience Act, that's a big report. Uh, so this is like a gap analysis report. Um, we've got the Cyber Resilience Act built into the MCP server. So you can see here that it's, uh, looking at some active findings, and then it gives you a readiness scorecard against all of the CRA requirements.
So this builds you out, uh, you know, a plan of action essentially to begin to, you know, address any gaps that you may have as you're preparing for, um, when all of this stuff gets implemented Let's... Oh, it's still working. You never know how fast or how slow this is going. We've got more stuff to cover, so we'll continue All right, we talked about the CSPM.
Sensei threat modeling. All right, what is this? Okay, if you're familiar with any kind of threat modeling, this is generally where you're getting some requirements, maybe a design from engineering, and you're supposed to build, like, a threat model to understand how are you going to test this, um, for various type of attacks.
Uh, stride is a very popular approach, so you got your spoofing, tampering, repudiation, which is, uh, basically does the p-person have, um, if they deny that they, "I didn't change that setting," well, do you have audit logs that show every action that a user takes? Um, information disclosure, where maybe something sensitive could potentially be exposed.
Denial of service capabilities, where maybe somebody just starts asking you to build a thousand reports all at once. And, uh, elevation of privilege, you know, those kind of things. So those analysis vectors are going into this. Uh, we do have some protections built into this to prevent hallucinations, so constant verification, don't cite anything that you don't have proof for.
Uh, always check the evidence. Um, allow the LLM to say, "I don't know." It's a powerful thing, uh, because then it can... it won't always just give you an answer no matter what. Um, and anything that is unverifiable, we flag that, don't just drop it. Make sure that it is, it's there. So how would this look in Defect Dojo?
Well, let's go to advisor. I'm sorry, threat modeling. So now we're in threat modeling. Uh, so that we don't have to wait, I've already done this, so we'll show you the results here. But how it works, you create a new threat model, you pick which asset or new asset that that threat modeling is gonna be associated with, because you may create findings from this, things that you need, already know that you need to have fixed.
So you pick one of your assets, um, give it a name that you'll remember and a description, uh, this is foreign, and then you pick a design document. So for example, I've got this markdown document that basically has a deep overview. Can I make that bigger? Yeah. You can see it's an order, customer order submission and payment system.
Very kind of simplistic, just for the sake of our demo. You load that, uh, markdown, plain text, PDF, and then an architecture diagram. So I have a PNG of this diagram that I will load. Um, you can see that right here. So again, pretty simple approach, just to kind of s- you know, RabbitMQ, so you got some of the, all of the network paths that are happening here.
And then you hit generate threat model. And with these two- The results would look something like this. So you can see here we get a summary. There's, uh, some assumptions, open questions. Um, it has identified all of these different threats. So you can see we've got some denial of service, elevation of privilege, information disclosure.
So it has identified a lot of threats that should probably be addressed. And then we have, these are the requirements. So these requirements should match up with those threats so that you can actually create findings. So I could say, "I wanna create all of these as findings," which then they become findings in Defect Dojo, which now you're tracking just as you would any other kind of vulnerability.
So you can implement a threat model and the things that need to be fixed to, um, make your application, um, more secure and hardened against, uh, those STRIDE requirements. I really like what we're doing with the architecture. So you can see the architecture here, um, and how kind of it compares to what was imported.
So we get, you know, more information about that and the analysis from both this, uh, the graphic as well as the, the document that you imported So that is an overview. And again, this is Sensei-driven, so Sensei is behind, um, the modeling of this And then the last Sensei feature is what we're calling Sensei Advisor.
And what this does is this does an analysis of your Defect Dojo implementation, uh, particularly around deduplication and prioritization. Uh, the prioritization engine, if you're not familiar with it, it's a way to customize how the prioritization of different findings is done. It's based off of both the severity of the finding itself as well as the environment in which it was found.
So the location, the, you know, the context of where this thing also plays into this prioritization. If it's a very sensitive environment and it's a high severity finding with lots of endpoints, maybe it's a CatKEV status, all of those things are included in that prioritization, and it is customizable per asset, so you can even customize that.
Um, so this will basically do an analysis, and then from that analysis, you will get a bunch of recommendations, and a lot of these, you know, informational, you can just kind of dismiss, but some of them will say apply, meaning that you can remove a dead deduplication configuration or something like that.
So here I've got a, a deduplication configuration that we're not even using, so I could just say, yeah, fix that, remove it so it's not in there. Uh, but it'll do that kind of analysis to help you with deduplication or identifying things that you may not even know are happening until you do a report and maybe see something amiss.
So, uh, the advisor is there to help with that. Cross-tool deduplication hygiene and anything that has to do with the prioritization engine
All right, we already covered MCP. Uh, yeah, this was the slide for the example I was just showing you. Um, just some of the things that it is, uh, finding across. Uh, we've got a bunch of different deduplication scanners. We test scanners all the time Okay. Well, the whole point of this is that you can mature your environment essentially overnight using some AI tools, either for reports, um, you can use the MCP server.
Uh, let's check. Did our, did our report finish? Oh, my goodness. No, that's a heavy, that's a heavy one. Uh, so it's still working on it. Um, I can't speed Claude up, so sorry about that. I, I bit off too much for Claude to chew on, but you can see it is, it has been working on this, uh, for a while. It's got the design palette going.
So I am disappointed that it's not finding more, but, uh, we'll ... maybe we'll add it to the end of the recording after it's done. Uh, it's actually right on the verge of ha- being done. We'll see after we answer some questions. Any questions? Got a few here, Tracy. Um- Sure. First one is, and I can probably answer this too, is, is Sensei only available for, for GFI Dojo Pro?
Yes. Yes. And it is also an additional license because, um, uh, because it requires the additional tokens to, uh, actually do that analysis. Um, so yeah, it is a, uh, it is Pro only, and it is a addition to your license. Nice. And another question here, which I think is a really good question actually too, is do you see the same results with Opus as you would with Sonnet running the report builder?
Oh, that's a good question. Um Well, I can't say that I have compared and done a, a side-by-side comparison. My expectation would be they would be very close. Um, any report that you have an AI tool generate, you want to verify. So you would want to go through and, and really kind of look at it, um, take a look at the templates.
For example, like this EU Cyber Resilience Act Critical Finding Report, you know, that also pretty heavy report. But you would want to go into each one of these and at least take a look at exactly... Like here we're, we're building a, um, a block or a chart here. So you would wanna understand, uh, the filtering down here, so this looks like it's doing a filter on some, uh, findings, and you can see that the organization filter is set right there.
So you want to take a look at what's been... You know, this one's done for EU customers. So you would want to take a look at exactly what's being filtered so that you still understand what it produced for you and verify that it is accurate, right? Um, because you will then rerun that report just as you would any other report.
You can trigger them from a schedule, things like that, um, but it won't use the AI after you've made the updates and things like that. So my answer was I would expect they would be very close. I would not necessarily expect them to be exact, um, and you should always check
Nice. And one more question actually here, uh, and folks, d- definitely post your questions here if you have other ones as well as we wait for the cloud to, to finish up. But, um, in regards to, I guess, AppSec or probably AppSec is, uh, what happens if Sensei automatically fixes a vulnerability? Like if... And let's say, for example, your team doesn't want to actually fix that thing.
How do you... Is there a way to revert things? Like what can you actually do to... Oh, there's a button. Okay, nice. Like a revert button? Exactly. Nice. It's a very popular name for babies.
Awesome. Uh, I don't see any other questions though. This is Vert and Revert. Um, yeah, I don't think, I don't think there's any other questions, uh, that have come in All right. Well, I predicted we'd run about 45 minutes, and it's the first thing I've predicted right all day. So, uh, appreciate everybody's time.
Oh, and it did finish. So publish? No, I'm not gonna publish this. But let's take a look at the dashboard or the report that it took an hour and a half to build. So over 2,000 findings, 545 criticals. A whole bunch of these aren't getting fixed because we just don't have enough engineers in sales to fix the sales environment.
That's a joke. Um, trend is going the wrong way, so I get an executive summary. Here's the metrics dashboard from that prompt. Um, open findings, priority and risk scores, vulnerability trend probably not looking great. Again, sales data. Uh, Claude often thinks that we run a gaming company because we have a whole bunch of Mario Kart and Pac-Man and Mario World data for different kinds of applications.
So you can see the 90-day window here. Backlog, yeah, we're not clearing much out because that's not something we do. Uh, critical and high findings by team. We use the research and development organization a lot. And, um, so yeah, that is a pretty significant report that we're building here. Um, obviously, if I download this, it might take care of some of the spacing that you're seeing here.
But this is just a raw, uh, a raw report. Now, I asked it to create an HTML. You could also ask it to create a markdown of that so that you can paste it somewhere and, and then edit it. Um, weaknesses needing immediate attention, so I bet that's a long list. Well, maybe not. What to do about each one of them.
High volume categories. So a lot of broken access control, insecure design. I'm not surprised. Uh, we're not great in development in, in sales. Uh, risk assessment, things that attackers actually can use. I guess this is why it took so long. It's a 30-page report that is absolutely packed full of data that I'm sure that if you shared this with somebody, they'd be like, "You know, seems like there's a lot that we need to do.
Maybe we should give our security department more money." I don't know So there you go. That's how you build a 33-page report in a live demo. Why this is worth funding? Did I just mention the money? Yes. Um, this is also... I feel like this is also one of the ways, just a little, you know, for security folks, um, you never get enough attention.
Um, I always make the joke when we're doing demos that, you know, engineering teams would always ignore me if I was ever doing any kind of security work, uh, because I was always giving them things to do that was also going to probably extend their timeline, things like that. Um, but obviously, uh, especially in the day of AI type of attacks and all of this kind of thing, uh, we see more and more environments that are absolutely beefing up security and becoming more regimented about this.
EU Cyber Resilience Act, definitely a part of that. Um, so a very, very handy tool that, again, part of our vision is that we can improve security anywhere. Whether you're using the open source, whether you're using the pro version, you can improve your security, your exposure, your ability to communicate to those in, in control of the, of budgets and things like that, um, of what it is you need to, to secure an environment or make it more secure
I think that brings us to the end of our webinar.