custom white shadow vectorcustom white shadow vector

Continuous attack validation

Continuous attack validation

The number one issue with traditional scanning tools is the lack of precision. Run different scanning tools, and you get different results. Most will definitely err on the side of caution and flag up many false positives - in the vain hope they won’t trigger so many false negatives, and fail to alert for the real attacks. See this article on how VerifiedThreat reduces the noise from false positives.

Most scanners run a pre-determined set of tests, looking for known vulnerabilities. As a result - inevitably they fail at detecting new threats and don’t look for the unknown unknowns. 

When cybersecurity teams are already spending too much time chasing shadows working on alerts that prove to be false positives, the idea of doing this continually is the equivalent of Sisyphus pushing a very large rock up a huge hill, only to get close to the top, and for the stone to roll right to the bottom again. 

For a general overview of continuous attack validation check out our Knowledge Centre article here

VerifiedThreat approaches the problem differently.

Threat scoping. 

It’s incredibly difficult and demanding to absorb the latest threat intelligence, read the detailed reports and then look at how each potential attack vector can be used against your organization's specific platform. The threat landscape is changing daily, and with the latest AI threats, with the inevitable rise in zero day vulnerabilities from source code genAI tools - its only going to get worse - much worse.

First we map each and every threat against the MITRE ATT&CK framework, as shown in the screenshot. This now gives us a dynamic map - that maps each and every threat coming into our sector and domain. If we have specific threat intel on your actual domain, or generalised threat data on similar attacks in your sector, geography or technology stack, it all gets surfaced at the MITRE ATT&CK mapping stage.

VerifiedThreat uses over 12,000 agents. These agents are orchestrated, which means that they don’t just run as discreet agents, each in their own bubble, but are deployed to act dynamically in response to their findings. The intelligent agents examine the incoming threat intelligence and deploy accordingly - spending additional time to thoroughly investigate the  most likely attack paths, as well as those flagged by the threat intelligence. So when we say continual - it is continual but orchestrated smart continual! We’re not talking about mindlessly hitting the same endpoints time and time again. 

Now we’ve got a sophisticated validation platform, with a constant feed of threat intel searching for specific threats across the attack surface that are continually changing as the threat intel feed changes. 

Achieving this manually is of course possible, but would require some serious resources. The threat intel alone is hard to digest, you have to read through the intelligence briefing, understand the context of threat, the attack vectors, and how it could theoretically be applied to your own platform or organisation. This needs to be communicated to the relevant risk stakeholders - who can then assess the risk,  and if necessary then write up some test parameters to understand the nature of the risk in the platform, and then thoroughly test multiple variations on the attack vector. We will need dedicated threat intelligence experts, red team and blue team teams, as well as co-ordination with IT and the main risk owners at each relevant stage. Realistically, smaller teams can’t hope to achieve this level of co-ordination.

Attack Validation. 

Now that we’ve got a method of understanding the attack vectors, we can turn to the attack validation. It’s here that the agents come into their own. The orchestrated agents allow us to develop comprehensive methods for fully investigating possible vulnerabilities, the ML can be used to vary the attack parameters to evade the existing defences. This is taking up far closer to zero day discovery. This red team emulation is then prioritised according to the actual vulnerabilities discovered. Each stage of the process is recorded, the code captured, along with the time stamps. This allows the IT or blue team to quickly validate the incoming threat, and the actual vulnerability at each step of the attack chain.

VerifiedThreat pulls together the threat intelligence, asset discovery, asset prioritisation to the business as well as the attack validation - all in one place as you can see on the screenshot. 

Here were showing a short attack chain, with the risks at each stage clearly labelled. Once you  have proven evidenced vulnerabilities, on assets that actually are important to the business, you can clearly triage the most important risks, and work on the mitigation, and planning to then actually start reducing the risks.

custom vectorstar

Engage with our Team

Schedule your Demo Below

We're committed to your success!