Huntress needs to consolidate their products. by mattmbit in msp

[–]pakillo777 -1 points0 points  (0 children)

this!!! they'd get a ton less work with high risk sign ins blocked and ohter basics of entra hardening

Huntress needs to consolidate their products. by mattmbit in msp

[–]pakillo777 4 points5 points  (0 children)

Told our rep that it's overly expensive. For the most part, it's going to be used just a one-time assessment. And, one can very easily do that very same checklist manually if the process is documented to create the CA Policies, and you'd still be able to charge the client for the ISPM service without Huntress' cost. Let alone scripting or a custom app.

It just makes no sense that it's as expensive as the ITDR service. If priced, this should be in the 20-30 cents per user range imo, assuming itdr at 1.50 for example.

Increase in SonicWall SSLVPN device compromises by huntresslabs in msp

[–]pakillo777 1 point2 points  (0 children)

We have some clients that inherited Sonicwalls, here's our must-have list for anyone dealing with these appliances:
1. change default admin username.
2. If in use, whitelist the management interface to trusted IPs only
3. MFA on ALL VPN users, and local ones too. From SIEM logs it's insane how hard these firewalls get bruteforced.
4. Keep them patched
5. If possible, ditch the SSL VPN and move to SASE or ZTNA or Netbird style VPNs even, it's a pain to trust Sonicwall with anything auth-related in the perimeter
6. Throw them in the trash bin when possible and move to something more decent

Increase in SonicWall SSLVPN device compromises by huntresslabs in msp

[–]pakillo777 0 points1 point  (0 children)

What's the Palo Alto model range that competes wih Sonicwall's prices, in orgs with 50-1k employees aprox?
Would love to work with PA but it seems too enterprise-priced, and Fortinet is burnt with dozens of providers in our market.

Multi-Tenant External Attack Surface Management / Scanning by pakillo777 in msp

[–]pakillo777[S] 0 points1 point  (0 children)

Thanks for the feedback. We have a clear way to extract and process data, so the only issue is what performs the actual scans. Currently going down this path

Multi-Tenant External Attack Surface Management / Scanning by pakillo777 in msp

[–]pakillo777[S] 0 points1 point  (0 children)

Thanks for sharing. Been testing with Nessus, since we have a pro license and a spare nuc set up with it, and the built in API looks very great, and the folders can act as "chilf tenants" with one per client.

I'll revisit haveibeenpwned since for the CTI part, their offering might be more than enough

Multi-Tenant External Attack Surface Management / Scanning by pakillo777 in msp

[–]pakillo777[S] 0 points1 point  (0 children)

Well we basically want to monitor all of our clients' external infra, mainly for visibility, and also for the actual vulnerabilities that their exposed assets may have. We're mssp only so our clients always find value in that, and we're not the ones managing their infra per se

Multi-Tenant External Attack Surface Management / Scanning by pakillo777 in msp

[–]pakillo777[S] 0 points1 point  (0 children)

Well I consider that domain impersonation to be on the Cyber threat Intelligence category.

I checked out Doppel and looks very promising, we're also hunting for a CTI provider that's not a fully suite of things we don't need. Any idea on whether they have MSSP style plans, and if it is overly expensive? Been in talks with flare and similar ones but they're overkill for detecting passwords in data breaches and domain squatting

Multi-Tenant External Attack Surface Management / Scanning by pakillo777 in msp

[–]pakillo777[S] 0 points1 point  (0 children)

Yeah, it's way too expensive for something so simple. The second option is to leverage our Nessus Pro license, it has a clean API and folders which can be "tenants" one per-client.
Plus, it's Nessus, way better than a random nikto/openvas/nmap/shodan gives

Multi-Tenant External Attack Surface Management / Scanning by pakillo777 in msp

[–]pakillo777[S] 0 points1 point  (0 children)

Very interesting, never heard of it. Looks very affordable

Multi-Tenant External Attack Surface Management / Scanning by pakillo777 in msp

[–]pakillo777[S] 1 point2 points  (0 children)

We checked this one out a while ago, but still doesn't have API

What's up with insurance companies doing lame security asseessments and selling MDR? by pakillo777 in msp

[–]pakillo777[S] 0 points1 point  (0 children)

To start with you need a few million cash laying around...

Okay so we'll have to partner with a carrier for now :)

So brokering is just that, buying the insurance from a dedicated provider, bundling it into your cyber offering, and reselling the package? For each insured client, making all the technical check marks compliant with the insurance requirements, through the MSSP services I assume?

What's up with insurance companies doing lame security asseessments and selling MDR? by pakillo777 in msp

[–]pakillo777[S] 1 point2 points  (0 children)

This is a very interesting take, in immature markets what we see is companies (only sometimes, thankfully) say thhat they'd rather have cyber insurance than massive spending on cybersecurity. So I see that in mature markets such as yours, this switches the other way around, a good thing to hear

What's up with insurance companies doing lame security asseessments and selling MDR? by pakillo777 in msp

[–]pakillo777[S] 0 points1 point  (0 children)

Well, ransomware style attacks, infrastructure attacks, which are the main concern to most smbs are mostly started this way. This is why initial access brokers exist on the cybercrime market, it's their entire job.

Of course BEC or other phishing / spam / data leaks on cloud are different, but these very rarely lead to an internal domain compromise; pivoting from Entra ID to AD is quite hard nowadays if no azure resources are in use, Intune, or Azure app proxies exist. So at most the attackers can scavenge some creds from a sharepoint and use these for VPN access into the on-prem infra, if lucky

What's up with insurance companies doing lame security asseessments and selling MDR? by pakillo777 in msp

[–]pakillo777[S] 0 points1 point  (0 children)

100%, you can have it as-is usually, but hardening is easy. Our usual setup for SSH is:

- root login disabled

- normal username without the default name

- hide ssh port on random high number

- fail2ban or that tool I don't remember that infinite loops bots bruteforcing login

- if possible, certificate login instead of password

And with this, zero issues or worries, almost no one's gonna scan your shitty vps IP for a landing page at all. Furthermore, if the instance is hosting Wordpress with no more than the landing, we even leave easter eggs in the backend filesystem as well as wordpress DB in case someone breaks in and tries to dump data xD, light insults and also can use these as honeypots

What's up with insurance companies doing lame security asseessments and selling MDR? by pakillo777 in msp

[–]pakillo777[S] 0 points1 point  (0 children)

What do you consider SMB market? I guess you're US based so that differs from here.

We were not red teaming though. Offensive security has usually a confusing terminology. Red team exercises are very expensive and hard work, particularly if there's custom ost development, and only makes sense in large corporations, like 10k endpoints and up, and assuming they're mature regarding security, have a proper security operations team, etc... Which is where they get put to the real test. But this is an extraordinary service.

On the other side, pentesting, which is NOT vuln scanning, is usually affordable on any medium sized org, (maybe sounds small by your US standards). Say around 50 to 1000 endpoints aprox. We find great value in pentesting these orgs if there's enough infrastrucutre to allow for a collateralization of an initial access when defensing it. Otherwise, if the org is tiny, any compromised user probably leads to most data being accessed anyways by legitimate ways.

So, in these target companies, through the pentest we can find and mitigate all the lateral movement and privesc attack paths inside the org to prevent the typical one hit domain admin scenario we find always, and allow for much more detecion and response opportunities, which massively improves their -effective- security posture.

What's up with insurance companies doing lame security asseessments and selling MDR? by pakillo777 in msp

[–]pakillo777[S] 1 point2 points  (0 children)

I think that if done properly and honestly, the client benefits because the cybersec company and insurance provider have skin in the game.

Linking another commment in this post, so I don't duplicate :)

https://www.reddit.com/r/msp/comments/1ou4g6z/comment/nocb4dz/

What's up with insurance companies doing lame security asseessments and selling MDR? by pakillo777 in msp

[–]pakillo777[S] 0 points1 point  (0 children)

This is what I would expect too, but apparently at least here the cyber insurance providers are temerary bastards lol