Demo Series 10 minJan 24, 2025

Synack OSINT Testing: Take Action on Your Risk

According to research, roughly 80-95% of cybersecurity breaches originate from Open Source Intelligence (OSINT). OSINT is often the first step malicious hackers take before planning their next move. Organizations need to understand these potential external risks and take action to mitigate and prevent these threats.…

Tim Nordvedt Solutions Architect, Synack
Simon Harper Senior Director of Product, Synack

Overview

According to research, roughly 80-95% of cybersecurity breaches originate from Open Source Intelligence (OSINT). OSINT is often the first step malicious hackers take before planning their next move. Organizations need to understand these potential external risks and take action to mitigate and prevent these threats.

Solutions Architect Tim Nordvedt and Senior Director of Product Simon Harper walk through the benefits of Synack’s Attack Surface Analysis (ASA) and how it augments our PTaaS platform capabilities. Our cutting-edge technology provides actionable intelligence, giving organizations a broader understanding of where they’re most vulnerable, how to identify high-value targets upfront and the benefits of streamlining their pentesting efforts.

Full transcript

Read transcript

I'm Simon Harper, a senior director of product here at SYNNAC, and I'm here today with Tim Nordvitt on our solutions architecture team. And we're really excited to talk to you today about SYNNAC's open source intelligence product that we call attack surface analysis. And it's a great product for our customers who are looking for an adversarial's perspective on the potential exposure of their digital footprint. So it's a little bit different than one of our traditional pen testing solutions where we present our customers with

specific bond findings. Instead, what we do is we actually look at how an adversary might approach attacking a customer's external asset environment. And we do that by looking at publicly available information on websites, networks, and cloud assets, and we identify things like open ports, expired certificates, subdomain issues, exposed cloud resources, or really any other potentially sensitive data. And then the output is what you see on the screen,

a comprehensive report that will show both all of the analysis and the test that we ran, but we also highlight the top attack vectors in an executive summary that gives a lot of color and context on where we believe an adversary may be most likely to engage. So, Tim, as someone who's delivered a number of these products, can you help us understand why enterprises should care about open source intelligence? That's a great question, Simon. Yeah. As you know, we're both around SYNNAC for a while.

One of our main value adds is in noise reduction. Security teams today, they've got a lot of tools that produce a lot of results, and and it can be a tall order to sift through the results and turn that data into actionable information, understanding where to prioritize, what's true, what's false. So if we started talking to enterprises about this product, it's a common question, like, why should we care about OSINT data? Isn't this just another feed? Is it gonna be duplicative of kind of what I'm already ingesting for my current tools? But the fact is that OSINT is often the first step that

attackers take when they're looking to uncover weaknesses and accompany defenses. By analyzing this publicly available information, you already touched on some of the data points that we're finding in the other things such as exposed credentials, misconfigured systems. There's a variety of potential entry points that these attackers can use to plan their next move. And and when you read the news and you look at most breaches, you'll see that most breaches originate from information that was freely available online. And we see this, you know, for the organizations we partner with as a critical

opportunity to, just as you mentioned, see their attack surface through an attacker's perspective and understand where that potential risk is. And an OSINT like this, what it does is it allows you to proactively leverage this data to put yourself in a position to prevent vulnerabilities before they happen. You can look at where those potential weak points are. And we see this as a powerful complement to internal security measures because it bridges the gap by identifying these potential external threats that traditional tools might miss.

And we see OSINT as essential in mitigating and staying ahead of these risk in such involving threat landscape of today. Yeah. That's that's really interesting. So are are there specific, use cases or scenarios where this, OSINT product may be particularly relevant for a customer or an enterprise environment? No. Absolutely. There's a number of use cases where we've deployed this type of report already. You know, the couple that come into mind, one of the most impactful is the process of merger and acquisitions. When you're doing m and a,

understanding a target company's external risk is essential. Yet during this process, active assessments is often restricted or there's extreme guardrails around it. Similarly, in the supply chain security under where trust and visibility into third party vendors are vital, Passive OSINT based approach like this report helps uncover those potential vulnerabilities without violating agreements or disrupting operations. You know, interest and I was at a conference recently, and I was talking to a CSO, and they are a growth by acquisition company.

And he mentioned that when they look at target organizations, their current security process is just to perform some Google searches on the company because that's all they feel comfortable doing within the constraints of these agreements. But with a product like a tax surface analysis, it gives them a much deeper insight and better line of sight into that external risk of the target company while still staying within those guardrails. Another key use case is in the financial services and banking industry. And what we're finding is that most companies we're working

with, they have a shrinking attack surface. They're working hard to minimize what they're exposing to the public Internet. But when you look in the financial services and banking industry, they must maintain an extensive public facing attack surface in order to support customer access, which creates a unique challenge of balance and accessibility and security. And many of these organizations are utilizing our tax surface analysis report to ensure that exposed systems are secured, properly and puts them in proactive position of having

confidence in their defenses. Yeah. That makes a ton of sense. So as, someone who's delivered a number of these for your Synack customers, are there any specific customer stories we're running in attack surface analysis as being particularly impactful? Yeah. There's a couple of reasons ones that I I can share. One organization we were working with recently, the researcher was looking through archive web pages utilizing the Wayback Machine, one of the many sources we pull from for this report. And as they started looking through this, they found a page that contained sensitive information

about the company. And they dug a little further, and they found multiple pages that exposed sensitive data. And as they look for correlation between these pages, they actually identified an IDOR indirect object reference vulnerability that allowed anonymous anonymous access to, sensitive data. We're able to give this information to the customer right away. They're able to resolve it. And the interesting thing about this is it was all passively without ever actually touching the customer's application. Whereas an active assessment or if a threat actor was,

you know, actively probing the customer, it could potentially trigger some SOC alerts, where with a passive OSINT data gathering, we can identify this vulnerability, without ever triggering any such alerts. Another interesting one recently is we were running one of these reports on an organization's web application, and the researcher during the process of enumerating the application, they found a stale blog page, that unintentionally was stood up by marketing but never, completed. So it was just a placeholder.

And as the researcher dug further, they found that the URL where this page was hosted was susceptible to subdomain takeover. What that means is that a threat actor could have come in and actually take ownership of that URL, and that would have given them control over a blog within the customer's larger application and could have potentially caused some reputational damage to the customer. So again, we are able to use this passive OSINT gathering to identify this issue, pass along to the customer, and they're rapidly able to take that and close down that

potential threat vector. Yeah. That's awesome. That's a great story. So if, this data is publicly available, can you just clarify why it makes sense for Synack to deliver, an OSINT product? No. Absolutely. And kind of hearken back to some of their initial conversations you and I had with some other members internally is that, as you mentioned, this data is publicly available. Like, anyone can access it. So Synack, if we're gonna develop a product, we wanted to make sure that we are gonna bring value to the table, and it was gonna be something that the customer saw value in

and that there's a differentiator that made Synack the right, organization to partner with to deliver this. And as we kind of looked at at what we do, what we realized is that we combine cutting edge technology with the expertise of a highly vetted global security researcher community. This combination of technology with human insight allows us to deliver unparalleled insights not typically seen. And with our platform approach to test, testing by incorporating this OSINT product, we're able to utilize tools and methodologies that simulate an

attacker's reconnaissance process, which allows us to identify those potential vulnerabilities that might otherwise go unnoticed. Another thing that sets Synack apart kind of in this kind of vertical is our ability to validate finance real time, which makes the information that we provide accurate, actual, and relevant. And kind of lastly, it's our ability to integrate this product with a much larger portfolio of security offerings, such as attack service management, penetration testing as a service, and other security offensive offensive security testing products.

This allows us to create a comprehensive security solution that allows us to partner with organizations and strengthen their defenses from every angle. And just kind of reiterate, we feel that our unique blend of human intelligence and technology enables us to deliver a report that identifies risk proactively, which gives customers confidence in their external security posture. Yeah. That's awesome. That makes a lot of sense. Thanks, Tim. So what what would you recommend as the next step for somebody who's interested in running a tech service analysis?

I mean, simply reach out to us. We we would love to talk to you and see what we can do to help you and how this product can fit your use case. Now if you go to our our website, you have two options where you can schedule a demo, hear more about our full portfolio of offerings, or just simply if you have questions about this product, you can talk to one of our product experts, get us some time to get some more information. But I've enjoyed today's conversation, Simon. On behalf of SYNNEC, we look forward to seeing how we can help you better secure your external attack surface. Yeah. Likewise. Thanks, Tim, and thanks for tuning in, everybody.

Speakers

Tim Nordvedt

Synack

Solutions Architect

Simon Harper

Synack

Senior Director of Product

Next step

Run the test instead of evaluating the idea.

Define a scope, run a Sara AI pentest against it, and see which findings are confirmed as real and exploitable. Then compare that with what your current testing returns.