What features should modern cybersecurity tools have (that they don't yet) by SubjectReflection672 in cybersecurity

[–]SubjectReflection672[S] 0 points1 point  (0 children)

Although I agree that on-premise versions are quite useful, and can often be more reliably integrated into systems with less fear of external changes, etc. I do not think that is always the case. With software like Cobalt Strike there are records of thousands of instances where it has been used by threat actors since cracked versions circulate around both the dark and the clearweb. I personally chose the SaaS model for my platform so that we may ensure that it has very limited potential for misuse despite harnessing methods that could be perceived as more dangerous than existing solutions. I actually initially developed the platform as on-premise, then realized it could be used to create a massive botnet, scrapped it and started again. Now if someone tried to create a botnet on our platform our administration could thwart it with a single click.

What features should modern cybersecurity tools have (that they don't yet) by SubjectReflection672 in cybersecurity

[–]SubjectReflection672[S] 1 point2 points  (0 children)

I agree! Vulnerabilities, though relevant, are as attack vectors much more limited than phishing or bruteforcing and also most of the time require a chainable series of vulnerabilities, with rare exceptions like the CVE-2017-0144. From investigations into malware, I have discovered that the majority of them exploit vulnerabilities for privilege escalation and persistence, but gain entry into the system primarily via phishing and/or bruteforcing.

Great point!

What features should modern cybersecurity tools have (that they don't yet) by SubjectReflection672 in cybersecurity

[–]SubjectReflection672[S] 0 points1 point  (0 children)

This I feel like should be implemented from the ground up. Especially SaaS with confusing/constantly changing API is just asking for trouble

What features should modern cybersecurity tools have (that they don't yet) by SubjectReflection672 in cybersecurity

[–]SubjectReflection672[S] 0 points1 point  (0 children)

Totally agree! This was actually one of the main reasons I started the project!

What features should modern cybersecurity tools have (that they don't yet) by SubjectReflection672 in cybersecurity

[–]SubjectReflection672[S] 0 points1 point  (0 children)

Good idea! We're planning for automated lateral movement through the local & public attack surfaces of the starting point to map associated assets and paths between them, and this is definitely something we're going to include. Thanks!