Home / Companies / Detectify / Blog / October 2022

October 2022 Summaries

5 posts from Detectify

Filter
Month: Year:
Post Summaries Back to Blog
Organizations must tailor their internal security policies to their specific risk tolerance and business context, as not all elements on an attack surface are vulnerabilities. While some industries, like SaaS, can handle frequent production releases, others face stricter regulatory requirements, necessitating more cautious security measures. To address this, flexible and resilient solutions are needed, such as the newly introduced Attack Surface Custom Policies. These policies allow security teams to efficiently validate their compliance with internal rules by using an "IF-THEN" logic system to monitor open ports and receive alerts for unauthorized changes. Surface Monitoring is essential for accessing these features, and the tool is set to expand its capabilities in the coming weeks to include scoping policies to specific domains and technologies. Users interested in trying these features can book a demo or sign up for a free trial with Detectify.
Oct 18, 2022 691 words in the original blog post.
Detectify has introduced Attack Surface Custom Policies, a new feature within Surface Monitoring, to help Product and AppSec teams set, enforce, and scale customizable security policies. This tool addresses the challenges faced by security teams, such as verifying the implementation of security policies and managing the rapid increase of Internet-facing assets due to cloud-hosted technologies and shorter development lifecycles. Attack Surface Custom Policies use an "IF-THEN" structure to provide insights into policy violations, allowing teams to monitor and manage open ports, enforce security headers, and remove unapproved technologies. Detectify offers comprehensive coverage for external attack surface management, boasting a 97.7% accuracy rate in vulnerability assessments, supported by real-world attacks from a global community of ethical hackers. The feature aims to provide complete visibility and control over an organization's attack surface, ensuring that security teams can effectively manage risks and protect their digital assets.
Oct 18, 2022 1,488 words in the original blog post.
External Attack Surface Management (EASM) has emerged as a significant focus within the cybersecurity industry, driven by the increasing complexity and expansion of attack surfaces, which Gartner identified as the top cybersecurity risk in 2022. EASM is a subset of the broader Attack Surface Management (ASM) framework, which involves the continuous monitoring and assessment of IT assets to identify exposures, with EASM specifically targeting the discovery and analysis of unknown internet-facing assets. Despite its growing relevance, many users are still unclear about EASM's role and its integration into existing security workflows. The e-book titled "External Attack Surface Management (EASM): What it is and what it isn’t" aims to clarify EASM's definition, its relationship with other ASM categories such as Cyber Asset Attack Surface Management (CAASM) and Digital Risk Protection Service (DRPS), and how security teams can utilize EASM to address critical questions about asset vulnerabilities, focus areas, and remediation strategies.
Oct 07, 2022 360 words in the original blog post.
Detectify has introduced several improvements and features over recent months, particularly enhancing its subdomain takeover detection capabilities. These improvements have led to a threefold increase in the discovery of subdomain takeovers, with over 50,000 new cases identified in the past two weeks for customers using Surface Monitoring. The company's proprietary tools outperform many open-source alternatives, identifying 6.3 times more takeovers, and are constantly updated through a feedback loop to maintain accuracy. Additionally, vulnerability findings now load 80% faster, improving user experience when managing large volumes of data. Other product enhancements include a new UI for the Recorded Login Validator, better error messaging for failed scans, and improvements in organizing the UI, particularly the "Members" page. Detectify continues to add crowdsourced vulnerabilities, with new modules of varying severity levels integrated into Surface Monitoring and Application Scanning. The company is actively expanding its team, seeking engineers, product managers, sales personnel, and other roles.
Oct 06, 2022 734 words in the original blog post.
Detectify has been recognized as a leader in the G2 Fall Report 2022 across multiple categories, including Website Security, Penetration Testing, and Vulnerability Scanner, owing to high user ratings and significant market presence. Achieving the top position in Website Security and Alerting, Detectify is noted for its ease of use, quality support, and customer satisfaction, earning the "Easiest To Do Business With" and "User Love Us" badges. The company is praised for effectively helping security and software development teams manage their attack surfaces and vulnerabilities through its Surface Monitoring and Application Scanning products, which utilize input from over 400 ethical hackers. The recognition highlights Detectify's commitment to aiding security teams in efficiently managing their growing attack surface, with features that are easy to set up and manage, providing comprehensive results at a fair price.
Oct 05, 2022 492 words in the original blog post.