Perimeter Guard: Monitor the Risks Threatening Your Assets
In the previous article, we addressed significant threats from the external perimeter.
Today, we will discuss how we have stood up to these issues by introducing our Perimeter Guard service.
This service has proven itself with our clients and has already prevented the leakage of their customers' data.
Marek is an ethical hacker with a strong sense of detail. During his career, he has exposed vulnerabilities in several well-respected software products and systems used by companies around the world. At axelum, his main role is identifying security vulnerabilities in complex systems, making him a key member of the Red Team.
Marek holds the world-renowned Offensive Security Certified Professional (OSCP) certification for ethical hacking. Among other things, Marek also developed the Perimeter Guard service, which actively protects the perimeter of our clients.
Motivation to come up with a new service
The idea for Perimeter Guard arose during our Red Team engagements, where the goal is to explore the complete security posture and uncover potential flaws in processes or the overall security design. During these engagements, we discovered that many organizations had several vulnerabilities on their perimeter. We did not anticipate for publicly exposed weaknesses to be that widespread, especially considering that the organizations that commission these engagements are usually among the leading players in the field of security. We asked ourselves how these weaknesses arose and what can an enterprise do to detect and mitigate them.
Service or product?
We set out to develop a service that goes beyond the capabilities of typical vulnerability scanning tools. Our primary focus was on creating a complete solution that enables clients to detect and eliminate real threats in a timely manner. As there are many examples, when the vulnerability management proved to be extremely time sensitive, the service is based on continuous scanning to provide the critical data as soon as possible.
Additionally, we made it a priority to build a self-reliant platform that implements all key functions itself without relying on external providers. For many of our clients, it is crucial that their data be processed exclusively within the EU and entirely under strict control.
As vulnerability data are extremely sensitive and, in some cases, ready to be abused by threat actors we put security, strong access control and data separation as forefront properties of the designed service.
How does Perimeter Guard work?
One of the critical features of Perimeter Guard is its ability to provide a view of security from the perspective of an actual attacker. We leveraged our Red Team experiences and automated many tasks, which are usually performed before a typical Red Team engagement as a part of the external perimeter discovery as performed by the Perimeter Guard service.
This phase focuses on identifying various key elements such as domains, subdomains, IP addresses and IP ranges. It is also focused on the detection of operated services and open ports. The goal is to obtain a detailed overview of the structure and configuration of the target system.
Perimeter Guard scans network services and web applications, identifying both known and detecting configuration weaknesses, insecure interfaces, and other sensitive resources The scanning process enumerates the visible surface for potentially unwanted services and other anomalies.
Types of vulnerabilities and risks detected
Perimeter Guard is designed to detect a range of vulnerabilities and security risks that can pose a threat to an organization's perimeter. The main categories of vulnerabilities and risks detected by Perimeter Guard include:
This category includes misconfigured services, applications, and systems that may expose sensitive data or provide an opportunity for attackers to gain unauthorized access. Examples include weak passwords on administrative interfaces, open ports, and insecure communication channels.
This category includes common vulnerabilities such as SQL injection, path traversal, and cross-site scripting (XSS) attacks that may exist in an organization's web applications or services. Such vulnerabilities may allow direct access to sensitive client data.
This category includes critical data such as passwords, API keys, session secrets, and other confidential information that may be exposed through misconfigured services or applications. An attacker may use them to impersonate users, administrators or connected services.
This category includes outdated software versions that may contain known vulnerabilities or are no longer supported by the vendor. Vulnerabilities of outdated software can lead to a complete system compromise, potentially breaching the perimeter and letting the attacker to pivot into the more secure network zones.
And What are the Possible Solutions to Avoid these Problems?
Automation plays a key role within the Perimeter Guard allowing the service to scan large number of assets. The evaluation incorporates modern technologies as AI including a specific small-scale model trained specifically for preliminary classification of findings. The actual assessment and verification of vulnerabilities and associated risks is entrusted to a team of security analysts. Our goal is not just to add another tool that generates tens of thousands of reports. Instead, we provide clients with a pre-prioritized overview of the risks that are relevant to them. With this approach, we can dramatically reduce "false positive" results and eliminate vulnerabilities that do not affect overall security.
Reporting
Our reports are created using verified findings and enriched with valuable information to help our clients understand their significance and expedite the remedial process. We understand that organizations receive a large volume of findings from multiple tools, which can be difficult to interpret and prioritize with limited time and resources. Therefore, our primary objective is to simplify this process and enable organizations to concentrate on what is important to them.
Benefits
By detecting vulnerabilities and risks on the perimeter, Perimeter Guard enables organizations to take proactive steps to address potential threats and improve their overall security.
Perimeter Guard provides a comprehensive and effective solution for safeguarding the cybersecurity of organizations. Leveraging advanced technologies and expert evaluation, it aids in identifying and mitigating threats, reducing the risk of data breaches, and enhancing regulatory compliance.
With Perimeter Guard, organizations can swiftly and efficiently address the ever-changing landscape of cyber threats.
Track Risks that Threaten Your Assets
Are you ready to identify your organisation's external perimeter vulnerabilities? We have created a comprehensive Perimeter Guard service to respond to this issue. Our solution comprehensively scans online objects to identify areas to improve perimeter security. We currently supply it to organisations in the banking and retail sectors as well as large telecommunications companies. Perimeter Guard is suitable for virtually any organisation that has an Internet footprint. And who doesn't have one these days, right?
You Might Also Be Interested
Do you know the risks that may threaten your assets? Infrastructure, cloud solutions, third-party services and more. All of these form a virtual gateway that attackers can use to get into your business. Join us on March 21 at 10 AM for a webinar where security experts will reveal how an attacker could exploit your vulnerabilities, as well as give you tips on how to monitor and, most importantly, prevent these external perimeter threats.
Many people have a romanticised view from the films that an attacker is going to immediately pick the locks on a door in order to gain access in the depths of the night to steal sensitive information. Does it really work that way? Physical security is still one of the most overlooked and underfunded areas for major organisations.
Discover critical strategies that protect your business from potential threats. Are you ready to strengthen your organisation's resilience and safeguard its most valuable assets? Choose a proactive approach and ensure your company's security.
Right in Your Inbox
Stay up to date and get the newsletter. Every month you can look forward to exclusive educational content and news from the infosec world.