Home / Companies / Detectify / Blog / April 2023

April 2023 Summaries

6 posts from Detectify

Filter
Month: Year:
Post Summaries Back to Blog
Attack Surface Custom Policies, integrated into Surface Monitoring, are designed to help AppSec teams validate and scale their security policies by allowing the setting, enforcing, and scaling of customizable rules, especially regarding the use of approved technologies. These policies assist in identifying and managing technologies across an organization's attack surface, ensuring compliance with approved technology lists and facilitating the exclusion of vulnerable open-source tools. The feature aids in modernization efforts by automating the discovery of deprecated technologies. Additionally, notable product updates include the introduction of a "Last Scan Status" column in Application Scanning and the ability to remove root assets via the Detectify API. New modules from ethical hackers have been incorporated into Surface Monitoring, enhancing its capabilities in identifying vulnerabilities.
Apr 28, 2023 478 words in the original blog post.
External Attack Surface Management (EASM) platforms are essential tools for organizations to safeguard their digital domains from cyber threats by managing and protecting the entire external attack surface. Effective EASM platforms should empower developers with actionable insights to remedy vulnerabilities efficiently, provide continuous monitoring to adapt to rapidly changing tech environments, and combine automation with crowdsourced security research for enhanced threat detection. They should feature user-friendly interfaces with customizable dashboards, cover the entire attack surface comprehensively, integrate seamlessly with existing systems, and have robust capabilities for discovering both known and unknown assets. These features ensure that organizations can maintain a proactive and comprehensive security posture, effectively reducing the risk of cyber attacks and enhancing the overall security infrastructure.
Apr 26, 2023 999 words in the original blog post.
Detectify has been recognized as the Market Leader in Attack Surface Management by Cyber Defense Magazine’s Global InfoSec Awards at the RSA 2023 Conference, highlighting the company's innovative approach to External Attack Surface Management (EASM) through the use of real payloads tested by a crowdsourced community of ethical hackers. This recognition underscores the importance of monitoring and identifying changes in an organization's external attack surface, especially given the increased use of public cloud services and interconnected supply chains. Detectify's method provides 99.7% accurate vulnerability assessments and offers actionable guidance for accelerated remediation, delivering a holistic view of security health. The Global InfoSec Awards, now in their eleventh year, are judged by certified security professionals, and Detectify was selected for its significant impact on combating the rise in cybercrime. With over 1,765 modules submitted, 300+ 0-days received in 2020-2021, and nearly 240,000 vulnerabilities found, Detectify continues to contribute significantly to cybersecurity innovation.
Apr 24, 2023 377 words in the original blog post.
Detectify transitioned from a single AWS account managed by a Platform team to a multi-account strategy, aligning each account with specific product domains and environments, to enhance infrastructure stability, security, and scalability. This transition was guided by AWS best practices and the Team Topologies framework, enabling domain teams to take full ownership of their services, thereby reducing their dependency on the Platform team and alleviating the latter's bottleneck issues. The multi-account setup improved cost observability and reduced the blast radius of potential disruptions, while also fostering a higher rate of developer satisfaction and expertise in AWS services. Detectify's journey involved designing a scalable account structure using AWS Control Tower, establishing governance frameworks, and implementing security policies to ensure compliance and security. Through this strategic shift, the company achieved greater system stability and empowered its developers with increased autonomy and proficiency in cloud infrastructure management.
Apr 13, 2023 2,230 words in the original blog post.
In the context of increasing application and network complexity, integrating comprehensive application scanning with External Attack Surface Management (EASM) is crucial for enhancing security measures. Web application scanning, a form of security testing, focuses on identifying vulnerabilities within web applications by using automated tools to examine code, APIs, and user interfaces. EASM solutions are designed to discover and monitor an organization's Internet-facing assets for vulnerabilities and misconfigurations, with automated scanning and reporting features. The combination of application scanning with EASM allows for more detailed analysis of web applications and a broader assessment of digital assets, improving security coverage and early detection of vulnerabilities. Detectify’s platform exemplifies this approach by combining Surface Monitoring and Application Scanning to efficiently manage and secure digital assets. Such integration offers benefits like reduced manual testing costs, faster response times, and compliance with regulatory frameworks, ultimately providing a comprehensive security posture for organizations.
Apr 06, 2023 698 words in the original blog post.
Detectify has introduced new features to enhance security management by automating SSL/TLS certificate assessments and organizing internet-facing assets into manageable groups. The automated assessments help identify issues such as expired certificates and domain mismatches, reducing the risk of security breaches and website inaccessibility. The introduction of "Groups" allows security teams to organize and manage assets like domains and IP addresses more effectively, offering detailed vulnerability and risk information. Additional updates include the ability to save filters for easy access on the vulnerabilities page and new API endpoints for scan statuses and profiles. Detectify has also expanded its crowdsourced vulnerability database with new modules contributed by ethical hackers, enhancing its Surface Monitoring and Application Scanning capabilities. These updates aim to streamline security processes and improve the management of large attack surfaces.
Apr 05, 2023 635 words in the original blog post.