[2:03] hello everyone uh thank you for joining us uh I’ll with your permission of course I’d like to give one more minute for additional people to join and see uh more people are joining us for this webinar so we’ll give them one more minute and then we’ll start our webinar [3:23] so I’m...
[2:03] hello everyone uh thank you for joining us uh I’ll with your permission of course I’d like to give one more minute for additional people to join and see uh more people are joining us for this webinar so we’ll give them one more minute and then we’ll start our webinar
[3:23] so I’m excited to welcome you all to our webinar my name is Boaz Boaz Barzel and I’ll be taking you to a journey Beyond static application security and introduce to you the OX Security Active ASPM now this is not just a release it’s really a new approach to application security we are also opening this webinar for questions so please ask away I’ll dedicate the last part of this session for your uh questions to answer them and I’m also welcome you all to visit the OX Security website to learn more there’s new design a lot of cool things that we’ve created for you uh in the website so feel free and let’s start and deep dive into Active ASPM
[4:20] now before we really get started I would like to focus on the mission that OX Security takes uh upon itself and that mission is to eliminate manual AppSec really straightforward really simple and the reason we chose that mission is because we are seeing that manual AppSec processes are creating considerable disruptions in the software development life cycle and they’re dramatically slowing down the pace of innovation in application development the second part we’re seeing that happens because of manual AppSec processing is is that hiring and retaining skilled people and cementing that Reliance on the manual processes is really not sustainable it’s one of the causes to um have you know processes that takes a lot of time uh a lot of organizations really kind of thinking about that turnover hiring additional skilled people and they’re looking for Solutions around that aspect as well so our goal here is really clear is to eliminate the dependency on that manual AppSec practices that really hinder that speed scalability and Innovation that we’re expecting to see from businesses today
[5:53] I want to focus a little bit about the different problems that we’re encountering them to really get us to understand what drove us into that Active ASPM approach so the first thing that I’d like to focus is really on products that are being released today that are still released with critical vulnerabilities what it means it means that in spite of the effort that security teams and devops teams and development teams are running today at the end those released products still carry those critical vulnerabilities sometimes knowingly and most importantly sometimes unknowingly so those vulnerabilities really missed any kind of Discovery analysis or remediation process of the organization the next part is really about triaging issues this is still done manually we still need to find the right person to need to correlate manually information from multiple tools going out to the web and searching for threat intelligence and really to understand what we need to do in order to fix a problem but then we also need to chase developers in order for them to give us the attention and actually fix it there’s also constant friction because of that now that friction between security and Dev is always there and one of the reasons is that a it might take a lot of time for security team to bring an issue to a developer and it’s really close to the release and they don’t really have a lot of time to fix it or the information provided to the developer is incorrect or inconsistent maybe it be based on a false positive or any kind of action that gets the developer to lose trust with the tools with the different teams it’s really hard to find those skilled peoples and then to support a different sty of tools it sometimes feel like we are kind of grinding water in a sense and trying to find something that is really hard to find when we’re working manually and the information is not connected for us now these types of tool all share information differently sometimes in a different language and we really need that skills and expertise in every specific tool to be able to bring out the most out of that tool and what we can see is that we’re still missing a lot and we’re still missing those critical risks that are being released
[8:32] eventually security backlog the more manual operations we have the more security backlog because what we’re seeing is that security teams are of course much smaller than the development team and every time a developer builds their own code either copy it from something else brings a library or package or write their own code their mind is not around security and it takes some time until we’re able to identify the critical issues go back to development remediate fix them this whole process really creates a lot of backlog for everyone not just for security or development but for the entire organization
[9:17] and then we’re in another place where we’re looking at regulations at compliance you know SBOM is one example but there’s more we need to be uh SOC certified we need to be ISO certified PCI and so on and so forth and one of the problems is when we’re going to audits some of those issues that we’ve released have effects and implications on those audits on those framework or compliance standards which can you know in the um I would say good but it’s not good uh element is getting fined and we don’t want to pay fines but in the worst case we’re going to lose that certification and losing a certification is actually worse than not having one okay because then questions why You’ve Lost That kind of certificate and it really drags a lot of problems for the entire organization so these are the problems that we’re seeing that complication uh that we’re seeing on different organization different teams and then when we’re looking at the market we’re seeing reports from Gartner as an example where 70% of platform teams will integrate AppSec tools to scale devsecops practices and it’s not far away it’s two years from now this is a a Cool Vendor report uh that we’ve uh uh were part of the Cool Vendor in that specific report that was released in July uh last year and really what we’re seeing we’re seeing a trend towards integration of AppSec tools and devsecops practices but we really want to take it a step further okay we really want to tackle the root cause of the problems which are the manual processes
[11:12] so let me introduce to you the OX Security Active ASPM platform and before I deep dive into everything and I promise there’s also a demonstration up ahead I’d like to talk about it so the first thing that you’ll see is the ability to see everything across the pipeline which means that we’re unifying all the information consolidating it collecting it throughout the pipeline from the code to CI/CD registry and Cloud elements or ability to divide it and curate the information to the different categories to really help you understand the risk aspects the second part that will be bringing in that is the ability to understand the information correlate between the business context attack context your environment context pulling in threat Intel from various sources triaging the information for you and really consolidating different security issues to understand the root cause of what I need to do to solve it so instead of just showing you problems we are showing you what you need to do in order to solve a lot of these problems that we were coupled down together which means that instead of sending multiple vulnerabilities for development to solve you’re sending one or two but just by solving that you’re actually solving tens or even hundreds of other vulnerabilities and finally the ability to prevent risk at scale from code to cloud and this is what we’re also providing you with really the ability not just to eliminate a lot of the manual AppSec practices from triage but also from the different workflows the response and Remediation aspects but really get the ability to prevent the risk at scale as the business grows as you know we’re bringing more developers not necessarily more security people then we want to be able to be um to scale everything we’re doing from a security perspective and not to be caught up with the fact that I need to hire skilled people which is hard I need to buy more tools or I need to try and do something from that perspective instead of telling the business listen we need another week two weeks five weeks before we can release that uh piece of code or application
[13:51] so let’s talk a little bit about the pillars and I want to give you example so this is a sneak peek into the demonstration that I’ll be delivering later so when I say really see everything I’m talking about the complete coverage you can see in the middle part our pipeline bill of materials and this is a way for us to be able to expose to you everything that happens in the pipeline all the different vulnerabilities all different security issues and not just vulnerabilities we’re talking about posture issues Secrets we’re talking about container issues and so on and so forth so you can really see that across the entire pipeline but not just that even each issue and I’ll dig into that later each issue we’re creating an issue graph in an attack path visualization to really help you capture the entire issue within one place instead of moving between different tabs reading different uh arrays of text you’re seeing that with your own eyes and you can respond to that from that screen for every issue we’re showing you the different severity factors so this is the way that we can show you the different context we’ve collected so we’re looking at your business we’re collecting the context from there we’re taking your environment context we’re collecting that different attack context for example let’s say you’ve imported a package is that package actually used is the vulnerable function being used is the environment that is running for example that container has the variable needed for the attacker to actually exploit that vulnerability we’re taking all that information and we’re showing you the different severity factors to help you understand the OX prioritization and and why we’ve decided to do it it’s also to help you to provide justification for when you go to the development team and you can show them exactly the reason why this issue is critical and has to be fixed right now where the last part is we’re allowing you to build no code workflows which means that it’s not complicated it’s actually really easy I’ll show it later on it takes less than a minute to build that kind of workflow and start responding to multiple issues in a few minutes instead of wasting a lot of time manually open tickets sending Slack messages open PRs and so on so forth
[16:19] we’re also doing something that can help you further and map everything into OSC&R OSC&R developed by OX Security in collaboration with experts from Google Microsoft GitLab and it’s a MITRE ATT&CK-like framework which uses the same tactics but the techniques are software supply chain security techniques and what we’re able to do here is show you the exposure from an attacker perspective you are able to create that common language between the teams you are able to analyze your vulnerabilities your risks from the attackers tactics and the techniques so it really means you are able to understand the exposure but also collaborate with other security teams in order to mitigate issues so for example you had a risk and that risk was released it’s right now exposed running in your Cloud it doesn’t mean that you’re completely at risk and there’s nothing to do until development fixes that it means that if I know the right tactic and technique I can talk with other security team and get them to mitigate the risk through other means like network security or uh application security uh additional tools that I have so it really helps you to map everything contextualize the risk and help all the teams not just yourself to focus the attention on the attacker tactic and technique and try to mitigate that across the organization until development will fix it so once development fixed the vulnerability or the risk it doesn’t exist anymore that’s the best option but sometimes we don’t have that kind of luxury
[18:11] the next part is you’re probably asking yourself by now okay that’s very fine that’s fantastic it’s amazing what are the use cases you know if you’re asking me so why should we go and talk with OX in that sense so the first use case is really around asset and risk visibility to get that single source of truth instead of either doing it ourselves which takes a lot of time creates a lot of Maintenance integration every time there’s an update every time there is a change we need to work very hard just to maintain what we’ve built and it really helps you to immediately understand the risk the next part is around the consolidation of your security infrastructure we can help you reduce the Reliance on third party tools and this really is amazing because it’s not just the tools it’s also the information instead of looking at long lists of vulnerabilities we are consolidating it to security issues that are you’re able to face and you’re able to understand that if you save or if you remediate one issue then you’re actually creating a larger impact you have more influence more impact as part of the um as part of your operation with CI/CD posture and workflow automation it’s more than just vulnerabilities it’s the actual security posture which means for example that your GitHub repo has 10 admins this is a problem okay it’s not a vulnerability it’s a problem you don’t want as many admins on your repo or you don’t want them to Fork which means create a copy of your code somewhere else you want to prevent it you want Branch protection in that sense uh and there’s other things and other examples which are not directly a vulnerability but that situation that posture element that you’re are in right now can create issues later on maturity assessment and compliance we can really help you understand the current maturity and how to take it to the next level of your AppSec program we can also help you with different compliance standards regulation and understanding of every issue’s effects on your compliance so if compliance is really important for you then you want to know the effects of every issue that you’re about to release on the compliance especially when you’re going into audits continuing around that you’re all familiar with SBOM and one of the main aspects here and I’ll take an example of an attack like Log4j when Log4j happened organization took months just to understand where it is used and which are those packages that are vulnerable and I need to update with OX it really is a matter of typing Log4j and that’s it and you’ll see all the packages across your entire organization but most importantly you’ll see the packages that matter most to you that are vulnerable and the recommendation of OX on what you need to do in order to solve that vulnerabilities and finally production Integrity you want to know exactly what’s going from your code to your cloud and you also want to know if something goes into your Cloud that didn’t come from your environment your code your CI/CD pipeline it can be either you know I would say an innocent user that chose to have their own CI/CD process or they just put something in the cloud without going through those guardrails that you have or it can be even an attacker that decided to put their own container deployed in your Cloud but it didn’t really come from your CI/CD process
[22:15] and just a little bit before we jump to the demo just a little bit about the results that we’ve been seeing the past year from customers that have been using OX so we were able to take remediation time or mean time to resolve from weeks to days in some customers even hours to resolve and then the coverage that were providing is really broader coverage from design to production we can see that the onboarding it took five minutes so they connected it it’s agentless it’s API based the scan started automatically the mapping is on automatically triaged automatically so really it reduces a lot of the security load a lot of the time that it takes to solve an issue uh we see 40% increase in resolution of critical issues it’s really big we’ve also able with the no code workflows to cut 70% of the manual AppSec work and with fewer alerts less noise pipeline scans that take less than two minutes you can really start addressing the actual critical issue reducing the noise reducing your security debt and really make an impact in your organization
[22:36] so let’s go to the demo let’s start having that demonstration so what you can see in front of you right now is the OX Security platform and everybody can open their own account the uh ability to do so is through a website you can just click Start free create your own account you have 21 days of free trial with everything open all the capabilities everything that I’m going to show you right now you can do you can run it side by side with your current systems it’s running beautifully so let’s begin and try to understand how OX does what it does the first thing I would like you to focus on is really the pipeline bill of material the centerpiece of our dashboard it Maps everything from the source control CI/CD registry and cloud and it shows all the different issues the security issues across these sections now one of the most important thing to understand is that it can also help you understand what is connected or not connected so you can see different icons in the PBOM with uh a small uh broken link that means that we are also able to discover different Tools in your environment that might be running but are not connected to OX in the connectors page you can see that we have a very large support and this is part of our architecture we’ve built OX to be able to connect to many different tools from commercial tools to different Source controls and CI/CD elements Registries Cloud uh and more and more and we’re keeping adding those really really fast we’re also very strongly uh adding anything that our customers uh are asking and we’re kind of deep diving into that because we really want to make sure they have everything they need within the platform the next part is I’m going back to the dashboard is on the top left you can see the issue prioritization now in this demonstration environment which is also open to everyone so you can go in and work through this demonstration environment what you can see here is that we have more than 4,000 alerts this is what the tools provide us the first thing that we’re doing we’re actually aggregating the data removing duplication because the vulnerability can happen you know in code and then we’ll see it through the build time and then we’ll see it in the container and in runtime we’ll see the same vulnerability we don’t want to see them so we’re removing duplication normalizing the data so instead of having multiple tools sharing different types of output we have one output but when we take it to the next level we’re curating the data we’re enriching it with threat intelligence with our own research we have a very large research team that really helps us to create that level of accuracy and eventually understanding the environment that we’re running in understanding the business that we’re working in and the attack surfaces were able to focus the attention on those 28 criticals now 28 is a number I can work with so you probably asking okay where do I start let’s start with those 28 going into the issue print I can of course see the different issues and how they’ve been built by clicking on those 28 criticals I can now see all the critical issues that OX prioritized for me across the entire application pipeline these are the actual issues that I need to be solving right now so I can see posture issues open source secret issues for example an active GitHub access token now this is really important because I don’t want any active access GitHub token exposed now the tool itself says it was a high but if I look at the severity factors I really and immediately understand it’s an active secret exposure it’s an active code Branch it’s a secret with access which means attackers can reach it so really all that severity factors information and if you can kind of hover over that you’ll be able to understand more information you’ll be able to understand you know this a process related it’s lateral movement related single Factor authentication all of that aspects really increase the level of severity from high to critical now we’re not stopping there we’re actually going into the description and recommendation which means that for every issue we’re providing information that you need in order to be able to fix it to remediate it this information is automatically sent to the ticket that you can open directly from here so I just click on Jira choose the relevant project let’s do a task critical Secrets all all the rest of the information is sent to the ticket it’s really easy it’s really simple and it can shorten the response time really quickly now let’s say I want to understand more about that issue let’s take the open source for another example with that open source there’s a few elements first of all you can see on the right here is that we actually Consolidated 22 different issues into that and we’re providing in the recommendation the ability to resolve the direct and indirect and this is an important aspect because for open source we can help you build a dependency graph to show you all the other packages that were brought in because you were bringing out that Spring Boot package we’re able to differentiate between direct okay direct vulnerabilities and indirect one indirect one are usually you don’t have anything to do with it because the developer brought one package that package actually brings other packages what happens here is that if you don’t have that connection you actually need to go package by package manually go to the website search for the vulnerabilities that are tied in to that specific package which means you can spend days just searching for vulnerabilities and trying to write down and tie everything together we’re doing that for you we’re building that graph for you we’re showing you commit which means that we’re able to show you exactly who’s the person in charge which line of code is it relevant into we’re enabling you to open a PR which means that you don’t have to wait okay for the developers if you have a good strong process you can actually if you want to open a PR the next time the code merge will happen it’ll get approved and that’s it you’ve just fixed that issue you can analyze more going through reachable vulnerabilities SBOM information to understand the package you have links to the package managers and so on there’s a lot of SBOM check from license popularity maintenance really important and application info which application it’s relating to and so on so we’re giving you all that information but we can even do better and we can visualize that for you which means that instead of going through all these screens you can simply go into the attack path here and we’re adding more information and from here start to understand okay these are the severity factors this is why OX says this is critical and you can see the reachability exploitability and business impact the damage aspect you can see the application and a link to the app itself the business priority the language or the main language you can see the issue owner the commit when it was done in this case it was a year ago do I care about it I don’t know that really depends on you 10 months ago this was first seen so it really gives you all that information and then additional information so with open source I want to understand the library from the you know SBOM perspective I can understand vulnerabilities if you care about compliance you can see all the compliance standards that are being affected by this issue which means that if you want or in an audit or you want to make sure that these compliance standards or one of you’re using still stays intact then this issue will have an effect on that compliance standard and it’s also showing you OSC&R which means all the different tactics and techniques that are relating to that and from this place you can see description recommendation and I can go just for Slack and send a Slack message did you see that amazing okay it just really reacts and respond to everything from here I can also go on and change severity or decide to exclude the issue I can also snooze the issue so I don’t want to see it right now but in two weeks when I’m finishing this Sprint I want that issue to pop up again so I can really respond to it based on my protocol based on what I want to achieve and that’s not over so right now we’re showing you that we’re doing so much work we’re triaging the information for you we’re creating that prioritization we’re aligning the severity and everything we’re doing for you but I still have to click that open Jira button I still have to click Slack I still have to open a PR we’ve taken a step further in our mission to eliminate manual AppSec we’ve introduced the no code workflows with the no code workflows anyone practically anyone can build their own customized workflows anything that they’ve using right now and they’re doing manually and they can build it here and we’ve created some examples that you can use some best practices around that so for example let’s create a new one let’s show how we can create a new one so I’ll just click create new issue let’s do new criticals this is what we see in most customers they start with new criticals they want to see it now I want to see it across the entire pipeline so any policy I can say just open source or sast or containers let’s go with any policy as we’ve created it we can see that we have 575 issues that are currently affected by that let’s add a condition so our condition is that I want everything that is equal or greater than critical because in OX we also have apocalypse apocalypse means that stop everything you’re doing really stop everything you’re doing and solve this issue right now this is the means of Apocalypse so I want to know everything and let’s take critical now we can see the 28 so you remember the 28 okay that we’ve looked before now we can see that we can further add conditions okay but before we add condition let’s uh send a Slack message so let’s add a Slack message choose a channel I can add parameters as well and new critical now it will give you the information that you need in Slack to better understand that issue now all I have to do is enable this workflow and immediately every new critical issue I’ll get a Slack message now I’ve gained more confidence in the system I also want that to open a Jira ticket so I can do it per application for application owner or specific project uh I can do it generally speaking to open a Jira ticket to my project where I will assign it later on and now I have Jira tickets now let’s say I want to also add another condition so it’s not just critical that I want I want another condition I want to make sure that let’s take a severity factor is active so let’s take active secret exposure no let’s take active attack usage so if there is an active attack usage I treat this as something that’s very severe because OX is telling me that this vulnerability is being exploited right now by attackers this is what it means which also show that we have four here now what I want to do with that I want to change the severity and really I want this to be an apocalypse so I can change the severity because this is what I decided for my organization but I also want to let’s say send a Slack message so I can add another action and then a Slack message and this is really how you’re building that workflow so we’ve created that workflow you can create more you can see all the issues even before you’re enabling the workflow you can see all the issues that will correspond to so if I click on these four issues then I’ll see exactly those four issues even before enabling that workflow that will be um will be affected by that so you can see those four critical issues that have active exposure you can see the issue owner you can see the application and one more thing that’s really amazing is that we’re correlating we’re linking between container issues and code issues which means that we’re enabling you to uh uh trace everything automatically from cloud back to code so you can see where that specific issue is located you can see the different counts you can see the container issue you can see the different artifact files and different artifacts from the container issue and you can go back to the in this case open source issue and then see other aspects like the dependency graph that we’re showing you you can even see the OSC&R tactics and techniques that can be used against that specific package so all the different tactics and techniques that attackers can use and we’re doing more than just that we’re actually showing you for every application that we’re mapping automatically we can show you the risk the application flow but also the different OSC&R tactics and techniques software supply chain tactics and techniques that attackers can use against that application so in this case this application has a high business priority we can see that there’s a lot of commits a lot of unique users the last code change was about 24 hours ago so we’re understanding that this is something that you’re actively working on and we’re showing you that you can see the critical issue around an artifact in that example you can see tags sorry you can see the critical so it actually has one critical issue and one high issue from a posture perspective and you can see it across the entire PBOM so PBOM is our technology to map everything to the application pipeline and finally you’re gaining confidence you’re gaining trust you’re eliminating the friction between the team you have started to eliminate manual AppSec work you want to prevent those vulnerabilities from ever reaching your Cloud your production and you can do it through pipeline integration so OX allows you to integrate into your pipeline where every code merge is getting inspected which means that we’re also able to prioritize it even before we’re doing that so if you decide that only criticals will be prevented it’s not just about the vulnerability being critical it’s about being critical in your environment in your business and this is really unique because we’re not just taking the CVSS score and saying okay this vulnerability is critical we’re also taking a lot of other context into that and then we’re able to accurately block really critical issues really what you need to care about and you can see that issues you can see that block you can see other information from that and you can see this issue was actually blocked from reaching the um production there’s additional areas that you can see here uh and you can go in and kind of go through that you can open your own demo or you can connect your environment you can connect anything uh for 21 days you can uh do uh everything it’s a trial it has all the features open all the capabilities you can start connecting your even Slack Jira if you want you can start sending yourself messages and so on and so it really is powerful it really is amazing and it really is what makes it an Active ASPM because it doesn’t rely on the different tools it doesn’t rely just on information provided to it it actually goes in and actively collects that information the context from different areas the intelligence connects it together using our own research and all the work that we’ve done for that to really help you eliminate manual AppSec to restore that balance to help you scale and innovate and really when you’re going to development tell them listen you have to fix that you have a full confidence in that decision and you can explain it from an attacker perspective from severity perspective the effects it will have on the business and so on and so forth
[42:15] so right now I’d like to take the rest of the time and really respond to your questions so feel free to write your questions in the uh uh Q&A section and I’m really going to go through that right now and really talk about it so the first question is does OX push updates and patches to software or code what we’re offering is first of all we’re offering a multi-tier approach one is being able to open a Jira ticket as I’ve shared before second is to open a PR so for SCA issues an example you can open a PR that once approved will go into code sorry it will go into build which means that you don’t have to get the developer to do it you just need to see that and approve it again it really depends on your processes further is the ability to create a workflow to react to that automatically in real time and finally to be able to stop or prevent the vulnerable code from ever reaching production now the developers will see that in the log so the build will fail and what they’ll see or the merge will fail and what they’ll see they’ll see all the information they need in order to understand what they need to do in order to solve it as I’ve shared with you they don’t need to go into our uh dashboard they can if you allow them but they don’t have to so how does OX determine risk prioritization Okay so we’ve explained that and you’re right about risk being subjective and this is exactly what we’re doing we’re actively collecting information from your environment from your business from the way that the attack is relating to your uh environment which really means that we’re not just showing you vulnerabilities based on CVSS score or if everybody’s talking about some sort of vulnerability then it has to be critical no it’s not the case it really is for example if the application you’re developing is not deployed yet so it’s you’ve only built an artifact you have that artifact in your registry and that’s it is it critical if the other severity factors indicate that it’s critical then it might be critical before you deploying it but if the other severity factors indicate it’s not critical then there’s no reason because we don’t see it’s deployed or exposed to the internet there’s no reason to push the criticality higher another question we don’t require any sensor or agent deployed so it’s API based it’s agentless which means that you can connect in less than two minutes you can connect it will automatically start scanning everything collecting the information consolidating it enriching it triaging it for you curating it dividing into different categories and prioritizing it for you so this is done automatically all you have to do is just connect to your Source control CI/CD registry and Cloud um Source control of course is mandatory CI/CD registry highly recommended and Cloud it really depends on your environment and the way you want to uh deploy it it’s also recommended because we can trace back issues directly to the owner can sensitive data or results be processed via an internal setup uh versus sending to OX yes so we have two flavors that’s a very good question we have two flavors the first flavor is a SaaS flavor what I’ve shared with you right now the SaaS flavor allows you to directly use OX without any maintenance any installment nothing just connect and start using OX the second flavor is what we call on premise you get the entire platform within your environment so you can deploy it in your environment and then you can connect it to your resources it will have the same effect the only difference is that for example when we’re pulling updates or Intel from the internet then we like to have that kind of Connection open to be able to pull in information we’re not sharing information just pulling in information helping with that layer of correlation and prioritization let’s see if we have additional questions so this was answered fantastic very good we’ve just uh completed our introduction to Active ASPM I really hope that you had a good time and understood a little bit more about OX Security what I’m showing you right now is that you can try it right now okay so let me just put the slide on what you can see you can try it right now now you can go and browse to the OX website click Start free and start using the system so I really recommend doing so uh you can choose to try the OX demo as you’re uh signing in you have an option to try the OX demo you can see the same demo don’t worry you’re not going to break anything so that’s fine uh feel free to use it if you want to connect your environment that’s even better you can do so side by side without interfering your current processes your current tools it will not create any kind of interference so I welcome you all uh to do so I would like to thank you all for staying with me for listening to us and have a great rest of the day stay active and see you soon


