Gal Kapanawa May 2026

During this time, Kapanawa also developed a personal rule he called the "Two-Sweat Rule" : If a system requires more than two minutes of manual intervention to recover from a breach, it is fundamentally flawed. This principle drives his later work in automated incident response. In 2017, after a near-fatal car accident in Virginia that many in the infosec community (only half-jokingly) attribute to a nation-state's attempt to silence him, Gal Kapanawa re-emerged. He founded a new company, Resonant Security , and released the Phoenix Protocol .

In the fast-paced world of cybersecurity, where headlines are often dominated by splashy data breaches and larger-than-life hackers, most of the truly important work happens in the shadows. The name Gal Kapanawa is not one you will find on magazine covers or trending on social media. However, within the closed-door circles of intelligence agencies, Fortune 500 boardrooms, and advanced persistent threat (APT) research teams, Kapanawa is regarded as a legend. Gal Kapanawa

The result, released in 2007, was the —a microkernel-based security module that sat below the operating system, monitoring every single system call, memory allocation, and data flow. What made the Kernel revolutionary was its use of behavioral entropy analysis . Instead of looking for known malware signatures, it learned the "rhythm" of a healthy system. Any deviation—even a brand-new, never-before-seen exploit—triggered an immediate lockdown. During this time, Kapanawa also developed a personal

Unlike traditional disaster recovery, the Phoenix Protocol does not try to remove an attacker. Instead, it accelerates the attack's effects within a decoy environment while spinning up a pristine, parallel instance of the network. To the attacker, it looks like they are winning; in reality, they are feeding data into a honeypot while the real business continues uninterrupted. He founded a new company, Resonant Security ,

Critics called it dangerous. Proponents called it visionary. In 2019, a major ransomware gang using a variant of Ryuk penetrated a healthcare network protected by Phoenix Protocol. The gang spent three days encrypting fake patient records while the actual hospital ran normally on the cloned backup. The gang did not get paid. posted a single tweet after the incident: "Sometimes you don't fight the fire. You starve it of oxygen." Philosophy: The Ethics of Active Defense What sets Gal Kapanawa apart from other cybersecurity gurus is his unflinching stance on active defense. He famously refuses to call it "hacking back." In his 2020 keynote at Black Hat (his first and only public keynote), he stated: