Logo webu

Perimeter Guard: Monitor the Risks Threatening Your Assets

April 24, 2024 | 10 min read | author: Marek Malcovský

In the previous article, we addressed significant threats from the external perimeter.

Today, we will discuss how we have stood up to these issues by introducing our Perimeter Guard service.

This service has proven itself with our clients and has already prevented the leakage of their customers' data.

Marek is an ethical hacker with a strong sense of detail. During his career, he has exposed vulnerabilities in several well-respected software products and systems used by companies around the world. At axelum, his main role is identifying security vulnerabilities in complex systems, making him a key member of the Red Team.

Marek holds the world-renowned Offensive Security Certified Professional (OSCP) certification for ethical hacking. Among other things, Marek also developed the Perimeter Guard service, which actively protects the perimeter of our clients.

Motivation to come up with a new service

The idea for Perimeter Guard arose during our Red Team engagements, where the goal is to explore the complete security posture and uncover potential flaws in processes or the overall security design. During these engagements, we discovered that many organizations had several vulnerabilities on their perimeter. We did not anticipate for publicly exposed weaknesses to be that widespread, especially considering that the organizations that commission these engagements are usually among the leading players in the field of security. We asked ourselves how these weaknesses arose and what can an enterprise do to detect and mitigate them.

Service or product?

We set out to develop a service that goes beyond the capabilities of typical vulnerability scanning tools. Our primary focus was on creating a complete solution that enables clients to detect and eliminate real threats in a timely manner. As there are many examples, when the vulnerability management proved to be extremely time sensitive, the service is based on continuous scanning to provide the critical data as soon as possible.

Additionally, we made it a priority to build a self-reliant platform that implements all key functions itself without relying on external providers. For many of our clients, it is crucial that their data be processed exclusively within the EU and entirely under strict control.

As vulnerability data are extremely sensitive and, in some cases, ready to be abused by threat actors we put security, strong access control and data separation as forefront properties of the designed service.

How does Perimeter Guard work?

One of the critical features of Perimeter Guard is its ability to provide a view of security from the perspective of an actual attacker. We leveraged our Red Team experiences and automated many tasks, which are usually performed before a typical Red Team engagement as a part of the external perimeter discovery as performed by the Perimeter Guard service.




Sometime the vulnerable assets are those which slipped from the asset management and the enterprise is not aware of their existence.






1) Mapping the outer perimeter

This phase focuses on identifying various key elements such as domains, subdomains, IP addresses and IP ranges. It is also focused on the detection of operated services and open ports. The goal is to obtain a detailed overview of the structure and configuration of the target system.


2) Scanning

Perimeter Guard scans network services and web applications, identifying both known and detecting configuration weaknesses, insecure interfaces, and other sensitive resources The scanning process enumerates the visible surface for potentially unwanted services and other anomalies.

Types of vulnerabilities and risks detected

Perimeter Guard is designed to detect a range of vulnerabilities and security risks that can pose a threat to an organization's perimeter. The main categories of vulnerabilities and risks detected by Perimeter Guard include:

Configuration weaknesses

This category includes misconfigured services, applications, and systems that may expose sensitive data or provide an opportunity for attackers to gain unauthorized access. Examples include weak passwords on administrative interfaces, open ports, and insecure communication channels.

Common security flaws

This category includes common vulnerabilities such as SQL injection, path traversal, and cross-site scripting (XSS) attacks that may exist in an organization's web applications or services. Such vulnerabilities may allow direct access to sensitive client data.

Sensitive data exposure

This category includes critical data such as passwords, API keys, session secrets, and other confidential information that may be exposed through misconfigured services or applications. An attacker may use them to impersonate users, administrators or connected services.

Outdated software

This category includes outdated software versions that may contain known vulnerabilities or are no longer supported by the vendor. Vulnerabilities of outdated software can lead to a complete system compromise, potentially breaching the perimeter and letting the attacker to pivot into the more secure network zones.

And What are the Possible Solutions to Avoid these Problems?

Automation plays a key role within the Perimeter Guard allowing the service to scan large number of assets. The evaluation incorporates modern technologies as AI including a specific small-scale model trained specifically for preliminary classification of findings. The actual assessment and verification of vulnerabilities and associated risks is entrusted to a team of security analysts. Our goal is not just to add another tool that generates tens of thousands of reports. Instead, we provide clients with a pre-prioritized overview of the risks that are relevant to them. With this approach, we can dramatically reduce "false positive" results and eliminate vulnerabilities that do not affect overall security.

Reporting

Our reports are created using verified findings and enriched with valuable information to help our clients understand their significance and expedite the remedial process. We understand that organizations receive a large volume of findings from multiple tools, which can be difficult to interpret and prioritize with limited time and resources. Therefore, our primary objective is to simplify this process and enable organizations to concentrate on what is important to them.

Benefits

Complex view of security posture

Perimeter Guard provides a comprehensive view of an organization's security posture from the perspective of a real attacker. This allows organizations to identify and address potential threats before they can be exploited by attackers.
Proactive threat detection

By detecting vulnerabilities and risks on the perimeter, Perimeter Guard enables organizations to take proactive steps to address potential threats and improve their overall security.

Reduced risk of data breaches

By identifying and addressing vulnerabilities and risks on the perimeter, Perimeter Guard helps to reduce the risk of data breaches and other security incidents that can result in financial loss, reputational damage, and legal liability.
Improved compliance

Perimeter Guard can help organizations meet various regulatory and industry compliance requirements by identifying and addressing vulnerabilities and risks on the perimeter.
Cost-effective

Compared to traditional vulnerability scanning tools, Perimeter Guard is a cost-effective solution that provides a comprehensive view of an organization's security posture without requiring significant investment in hardware or software.
Expert assessment

The actual assessment of vulnerabilities and associated risks is entrusted to a team of security analysts, ensuring that organizations receive accurate and relevant findings that can be used to improve their overall security.
Customizable

Perimeter Guard can be customized to meet the specific needs and requirements of each organization, providing a tailored solution that addresses the unique challenges and threats facing the organization.

Perimeter Guard provides a comprehensive and effective solution for safeguarding the cybersecurity of organizations. Leveraging advanced technologies and expert evaluation, it aids in identifying and mitigating threats, reducing the risk of data breaches, and enhancing regulatory compliance.

With Perimeter Guard, organizations can swiftly and efficiently address the ever-changing landscape of cyber threats.

Track Risks that Threaten Your Assets

Are you ready to identify your organisation's external perimeter vulnerabilities? We have created a comprehensive Perimeter Guard service to respond to this issue. Our solution comprehensively scans online objects to identify areas to improve perimeter security. We currently supply it to organisations in the banking and retail sectors as well as large telecommunications companies. Perimeter Guard is suitable for virtually any organisation that has an Internet footprint. And who doesn't have one these days, right?

You Might Also Be Interested

Right in Your Inbox

Stay up to date and get the newsletter. Every month you can look forward to exclusive educational content and news from the infosec world.


* Required fields.


By submitting this form you give Unicorn Systems a.s. your consent to process your personal data. We process the personal data filled in above for the purpose of realization your request in order to meet your demand and prepare the offer. You can learn how we process your personal information here.

All infosec
We are an information security company. Our purpose is to safeguard the clients' most valuable information and protect their business.

© 2026 Axelum s.r.o.

Contact

Axelum s.r.o.

CIN: 25639056

VAT ID: CZ699004029

V Kapslovně 2767/2

130 00 Prague CZ

info@axelum.eu

+420 221 400 111


Created by uuWebKit
document_check.svg
We use cookies on this website to ensure its functionality and to personalise ads, solely with your consent and in accordance with our Cookies Policy.

By clicking on the "Accept cookies" button, you consent to the use of selected cookies and agree to the transfer of behavioural data for the display of targeted advertising on social and advertising networks. You can choose which information you want to share with us by clicking on the Cookie settings button.