The engineering team has been working tirelessly to improve the “what to wow” user experience, add more attack content, add indicators of best practices and improve analytical insights.
Improving our “what to wow” user experience – In security, there are two types of findings: critical problems that require you skip lunch, or cancel plans with your family, to urgently fix and everything else that you need to fix someday soon. With the “Critical Impacts” feature, identifying critical findings is a few clicks away.
Adding indicators of best practices – We just added the “Best Practices” feature that assesses your security posture against known best practices, so that you can quickly prove to your boss and the board that you’re doing a great job.
Adding more attack content – We’ve now expanded our attack content to include on-prem, identity/active directory, cloud-native, open source intelligence, and external attack paths. We have the first product to automatically assess and chain together your external web presence (eg. web properties, DNS hygiene, etc) with information we gather through open source (eg. Linkedin), and then laterally maneuver like an APT upon gaining access to your enterprise. We’re also the first to assess hybrid cloud environments, giving you a truly integrated understanding of the security posture of your entire enterprise, not just specific silos.
Improving analytical insights – A “critical” finding for you might be a “low” finding for another enterprise, because context matters. You may have an exploitable Bluekeep vulnerability (CVSS score of 10), but if that vulnerability doesn’t enable data theft or systems disruption, is it really a critical? Similarly, you may have a directory traversal misconfiguration (CVSS score of 0.1) that enabled an attacker to gain domain administrator access to your network, which is a really big deal. Our “context scoring” feature now takes impact into account and subsequently increases or decreases the severity of a finding.
Our engineering team focused on these categories based on two observations from customer engagements:
Our prospects kept comparing us to vulnerability scanners, which was very offensive (pun intended) because our goal is to disrupt those noisy legacy tools.
Our results have decimated the PDF reports produced by manual pen testing consultants. In a recent customer engagement, we proved that 22/28 (80%) of the critical findings discovered by an offshore pen testing company could not actually be exploited and were really false positives, reinforcing our point-of-view that being vulnerable does not mean you’re exploitable.
Anthony “Tony P” Pillitiere is the co-founder and Chief Technology Officer at Horizon3.ai, a cyber security company passionate about helping organizations improve their security posture through automated penetration testing. Prior to his position at Horizon3.ai, he served 21 years in the United States Air Force, 16 of which were spent in highly competitive positions at organizations with highly sensitive missions. His breadth of experience spans from supporting DoD research and development and education and training, to tactical communications and enterprise communications across six bases and five deployments to the Middle East. His twilight position was as the Deputy CTO for a U.S. SOCOM organization, where he drove the digital transformation that significantly increased the efficiency and capability of national mission force and the intelligence community. During his service, he earned two degrees in technology and military technical instruction; as a disabled veteran, he is extremely passionate about helping veterans any way he can. But his biggest passion of all is his family, his amazing wife and two beautiful children.
How can NodeZero help you?
Let our experts walk you through a demonstration of NodeZero, so you can see how to put it to work for your company.
We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
Cookie
Duration
Description
__cfruid
session
Cloudflare sets this cookie to identify trusted web traffic.
_GRECAPTCHA
5 months 27 days
This cookie is set by the Google recaptcha service to identify bots to protect the website against malicious spam attacks.
cookielawinfo-checkbox-advertisement
1 year
Set by the GDPR Cookie Consent plugin, this cookie is used to record the user consent for the cookies in the "Advertisement" category .
cookielawinfo-checkbox-analytics
11 months
This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional
11 months
The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary
11 months
This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others
11 months
This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance
11 months
This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
CookieLawInfoConsent
1 year
Records the default button state of the corresponding category & the status of CCPA. It works only in coordination with the primary cookie.
OptanonConsent
1 year
OneTrust sets this cookie to store details about the site's cookie category and check whether visitors have given or withdrawn consent from the use of each category.
viewed_cookie_policy
11 months
The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Cookie
Duration
Description
AnalyticsSyncHistory
1 month
LinkedIn - Used to store information about the time a sync took place with the lms_analytics cookie
bcookie
2 years
LinkedIn sets this cookie from LinkedIn share buttons and ad tags to recognize browser ID.
bscookie
2 years
LinkedIn sets this cookie to store performed actions on the website.
lang
session
LinkedIn sets this cookie to remember a user's language setting.
li_gc
2 years
LInkedIn Used to store consent of guests regarding the use of cookies for non-essential purposes
lidc
1 day
LinkedIn sets the lidc cookie to facilitate data center selection.
UserMatchHistory
1 month
LinkedIn sets this cookie for LinkedIn Ads ID syncing.
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Cookie
Duration
Description
_calendly_session
21 days
Calendly, a Meeting Schedulers, sets this cookie to allow the meeting scheduler to function within the website and to add events into the visitor’s calendar.
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Cookie
Duration
Description
_ga
2 years
The _ga cookie, installed by Google Analytics, calculates visitor, session and campaign data and also keeps track of site usage for the site's analytics report. The cookie stores information anonymously and assigns a randomly generated number to recognize unique visitors.
_ga_V462VSRXXS
2 years
This cookie is installed by Google Analytics.
6suuid
2 years
6sense is a B2B predictive intelligence engine for marketing and sales.
CONSENT
2 years
YouTube sets this cookie via embedded youtube-videos and registers anonymous statistical data.
pardot
past
The pardot cookie is set while the visitor is logged in as a Pardot user. The cookie indicates an active session and is not used for tracking.
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Cookie
Duration
Description
VISITOR_INFO1_LIVE
5 months 27 days
A cookie set by YouTube to measure bandwidth that determines whether the user gets the new or old player interface.
YSC
session
YSC cookie is set by Youtube and is used to track the views of embedded videos on Youtube pages.
yt.innertube::nextId
never
This cookie, set by YouTube, registers a unique ID to store data on what videos from YouTube the user has seen.
yt.innertube::requests
never
This cookie, set by YouTube, registers a unique ID to store data on what videos from YouTube the user has seen.