Uploaded March 2026 | Updated September 2026, 3 weeks ago
Check out KnocKnoc here: https://ul.live/knocknoc_yt
In this episode of Unsupervised Learning, I sit down with Adam to discuss KnocKnoc, a platform created to solve just-in-time network access and drastically reduce attack surfaces. Join us as we explore how hiding services behind pre-authentication modernizes default-deny security policies and keeps your infrastructure completely invisible to attackers until trust is proven.
What we talk about:
The Evolution of Port Knocking:
How Knock-Knock was born out of traditional port knocking and evolved to completely hide network services, eliminating pre-authentication attack surfaces.
Security vs. Obscurity:
A deep dive into the "security through obscurity" debate and how hiding the mechanism while requiring a specific "key" drastically increases the cost, effort, and time required for attackers to map a network.
Real-World Infrastructure Shielding:
Practical use cases for the platform, from protecting frequently targeted services like Citrix from zero-day exploits to completely cloaking cloud development and test environments from the public internet.
Self-Defending Endpoints at Scale:
Expanding just-in-time access controls beyond edge firewalls directly to host machines, including Linux, Windows, and even legacy systems like HP-UX and Solaris SPARC.
The Future of Universal Policy:
How this foundational default-deny approach paves the way for universal security policies, translating human-readable business rules into strict access controls across all network levels and data layers.
00:00 - Introduction
01:54 - How vulnerability data is delivered directly into developer workflows
05:02 - The underlying technology combining AI and static analysis
07:02 - Real-world workflow examples using the Log4j vulnerability
09:53 - Securing legacy containers and managing golden images
17:42 - Applying context and guardrails to autonomous AI coding agents
26:00 - The future of automated security and the evolution of test-driven development
29:27 - Upcoming events and where to find more information about Endor Labs
Subscribe to the newsletter at:
danielmiessler.com/subscribe
Join the UL community at:
danielmiessler.com/upgrade
Follow on X:
https://x.com/danielmiessler
Follow on LinkedIn:
linkedin.com/in/danielmiessler
Check out KnocKnoc here: https://ul.live/knocknoc_yt
In this episode of Unsupervised Learning, I sit down with Adam to discuss KnocKnoc, a platform created to solve just-in-time network access and drastically reduce attack surfaces. Join us as we explore how hiding services behind pre-authentication modernizes default-deny security policies and keeps your infrastructure completely invisible to attackers until trust is proven.
What we talk about:
The Evolution of Port Knocking:
How Knock-Knock was born out of traditional port knocking and evolved to completely hide network services, eliminating pre-authentication attack surfaces.
Security vs. Obscurity:
A deep dive into the "security through obscurity" debate and how hiding the mechanism while requiring a specific "key" drastically increases the cost, effort, and time required for attackers to map a network.
Real-World Infrastructure Shielding:
Practical use cases for the platform, from protecting frequently targeted services like Citrix from zero-day exploits to completely cloaking cloud development and test environments from the public internet.
Self-Defending Endpoints at Scale:
Expanding just-in-time access controls beyond edge firewalls directly to host machines, including Linux, Windows, and even legacy systems like HP-UX and Solaris SPARC.
The Future of Universal Policy:
How this foundational default-deny approach paves the way for universal security policies, translating human-readable business rules into strict access controls across all network levels and data layers.
00:00 - Introduction
01:54 - How vulnerability data is delivered directly into developer workflows
05:02 - The underlying technology combining AI and static analysis
07:02 - Real-world workflow examples using the Log4j vulnerability
09:53 - Securing legacy containers and managing golden images
17:42 - Applying context and guardrails to autonomous AI coding agents
26:00 - The future of automated security and the evolution of test-driven development
29:27 - Upcoming events and where to find more information about Endor Labs
Subscribe to the newsletter at:
danielmiessler.com/subscribe
Join the UL community at:
danielmiessler.com/upgrade
Follow on X:
https://x.com/danielmiessler
Follow on LinkedIn:
linkedin.com/in/danielmiessler










