Soap Box: HD Moore talks OT security, frontier fearmongering and more
Sep 29, 2026 · 34m
Summary
HD Moore discusses RunZero's recent acquisition by Accenture and its evolution into a critical OT/IT discovery platform. He details new capabilities for mapping non-IP industrial protocols like BACnet and Modbus, revealing vast hidden attack surfaces in enterprise environments. The conversation also covers the "vulnpocalypse," arguing that traditional CVE-based vulnerability management is obsolete in the AI era. Finally, Moore explains how RunZero integrated AI for secure, granular access control and automated integration building, drawing parallels to the Metasploit hype cycle.
Topics discussed
Intro: HD Moore, Metasploit, and the RunZero acquisition
Why RunZero merged with Dragos and the AI hype cycle
The problem of unmanaged network assets and shadow IT
OT security risks: HVAC, BACnet, and protocol gateway discovery
Chaining serial/IP connections and finding hidden devices
UPnP firewall holes and Shodan data gaps
The untenability of traditional vulnerability management
OpenBMC vulnerabilities and vendor disclosure failures
AI-driven bug finding and the shift to asset visibility
Defensive strategies: Honeypots and AI agent detection
2003 Metasploit release vs. current AI open-source debate
New RunZero features: Safe active scanning of OT environments
Interactive 3D network mapping and non-IP protocol discovery
AI Integration Generator: Building custom connectors
Scripting engine capabilities: WMI, IPMI, and Modbus
BYOK (Bring Your Own Key) and self-reflective codebase
MCP implementation: Context window optimization and usage
MCP deployment, permissions, and OAuth scoping
Iterative AI prompt engineering for better results
Balancing custom AI reports with opinionated dashboards
Listen ad-free on Castria