• No results found

OUR PORTFOLIO. Business intelligence. IT System & Service MGMT. Cyber SECURITY ERP CRM SYSTEM INTEGRATION SOFTWARE DEVELOPMENT PROJECT MANAGEMENT

N/A
N/A
Protected

Academic year: 2021

Share "OUR PORTFOLIO. Business intelligence. IT System & Service MGMT. Cyber SECURITY ERP CRM SYSTEM INTEGRATION SOFTWARE DEVELOPMENT PROJECT MANAGEMENT"

Copied!
52
0
0

Loading.... (view fulltext now)

Full text

(1)
(2)

OUR PORTFOLIO

ERP IT System & Service MGMT CRM Business intelligence Cyber SECURITY BUSINESS

(3)

DATA & FACTS

10.467.311.280 pwned accounts 2020 90% malware

comes from email

Over 43 billion yearly spent Threats constantly evolving 75% of violations

are caused by human error

(4)

CYBER SECURITY

OFFENSIVE

PENETRATION TEST SOCIAL ENGINEERING RED TEAMING

DEFENSIVE

PASSWORD AUDIT EXPOSURE ASSESSMENT VULNERABILITY ASSESSMENT GAP ANALYSIS SECURITY TRAINING

OneTime | SaaS | SaaS&Managed

(5)

EXPOSURE ASSESSMENT

One Time | SaaS | SaaS & Managed

(6)

Verification of exposed resources

Reproduction of the attacker's point of view Reconnaissance phase simulation

Mitigation and remediation actions WHAT

EXPOSURE ASSESSMENT |

One Time

(7)

EXPOSURE ASSESSMENT |

One Time

HOW

Company inputs collection Objects collection

Research of weaknesses Research of correlations

Creation of a detailed report Report presentation

Domain(s) | Keywords

Hostnames | IP addresses | Account e-mail

(8)

EXPOSURE ASSESSMENT |

One Time

WHERE

Surface Web Deep Web Dark Web

Paste Site Search |Open Bug Bounty | Brand Reputation Social Network | Blacklisted IPs| WayBack Machine| Telegram Groups & Channels | Data Leak Forums

Data Breach Databases | TOR Network | Cyber Attacker Group Sites

(9)

Verification of exposed resources

Reproduction of the attacker's point of view Reconnaissance phase simulation

Mitigation and remediation actions WHAT

EXPOSURE ASSESSMENT |

SaaS

(10)

EXPOSURE ASSESSMENT |

SaaS

HOW

Domain(s) | keywords

Hostnames | IP address | E-mail account

Graphs | Reports | Stats | Notifications

Company inputs collection

Continuous objects collection Research of weaknesses

Research of correlations

Autonomous use of SATAYO Portal API for Monitoring platforms

Notification via Telegram and e-mail Daily report generation

(11)

EXPOSURE ASSESSMENT |

SaaS

WHERE

Surface Web Deep Web Dark Web

Paste Site Search |Open Bug Bounty | Brand Reputation Social Network | Blacklisted IPs| WayBack Machine| Telegram Groups & Channels | Data Leak Forums

Data Breach Databases | TOR Network | Cyber Attacker Group Sites

(12)

Verification of exposed resources

Reproduction of the attacker's point of view Reconnaissance phase simulation

Mitigation and remediation actions WHAT

EXPOSURE ASSESSMENT |

SaaS & Managed

(13)

EXPOSURE ASSESSMENT |

SaaS & Managed

HOW

Domain(s) | keywords

Hostnames | IP address | E-mail account

Graphs | Reports | Stats | Notifications

Company inputs collection

Continuous objects collection Research of weaknesses

Research of correlations

Joinly use of SATAYO Web Portal API for Monitoring platform

Analysis and solution proposal Daily report generation

Ticket | Phone call | E-mail NetEye

(14)

EXPOSURE ASSESSMENT |

SaaS & Managed

WHERE

Surface Web Deep Web Dark Web

Paste Site Search |Open Bug Bounty | Brand Reputation Social Network | Blacklisted IPs| WayBack Machine| Telegram Groups & Channels | Data Leak Forums

Data Breach Databases | TOR Network | Cyber Attacker Group Sites

(15)

SATAYO provides detected evidences (per domain) appropriately filtered on the basis of sources and keywords selected by cyber

security analysts team1.

EXPOSURE ASSESSMENT SaaS |

DEEP & DARK WEB

Ursula von der Leyen

Presidente della Commissione europea

Ursula Gertrud von der Leyen, nata Albrecht, è una politica tedesca, membro della CDU e Presidente della Commissione europea dal 1° Dicembre 2019. Wikipedia

1 All members of our team are CEH (Certified Ethical Hacker) certified and

(16)

SATAYO is able to provide extracts of passwords and accounts used to register on services that have suffered data breaches; these are constantly updated by our cyber security analysts team.

DATA BREACH

EXPOSURE ASSESSMENT SaaS |

No metric can be used with certainty to indicate how costly the data breach of a single access credential might be. The potential actions stemming from that data breach are wide-ranging and the values are calculated on the basis of the risk assessment specific to each organization.

Some examples

 Unicredit (600k)  Università Campus

(17)

SIMILAR DOMAINS

EXPOSURE ASSESSMENT SaaS |

xn--teslamtors-dx3e.com  teslamọtors.com

SATAYO is able to detect registered

domains that are similar to the one used by your organization. In fact they could be potentially used to generate targeted phishing attacks (spear phishing).

(18)

SATAYO shows an extraction of the evidences (example: logs, config. files, passwords, etc...) detected within the repositories used by the developers of the organization.

REPOSITORY

(19)

SATAYO shows the weaknesses detected on the organization's resources:

 unmanaged social pages

 poorly configured mail servers  SSL misconfigurations

 management ports  insecure protocols

WEAKNESSES

(20)

VULNERABILITY ASSESSMENT

One Time | On-Prem

(21)

WHAT

VULNERABILITY ASSESSMENT |

One Time

Vulnerabilities identifications Vulnerabilities quantification Vulnerabilities prioritization

(22)

VULNERABILITY ASSESSMENT |

One Time

HOW

Private IP addresses | Public IP addresses

Scope of engagement definition Cataloging of assets & resources

Identification of vulnerabilities for each resource Vulnerability analysis and solution proposal

Creation of a detailed report

(23)

VULNERABILITY ASSESSMENT |

One Time

WHERE

Networking equipments WiFi

Server & clients IoT & IIoT

(24)

WHAT

VULNERABILITY ASSESSMENT |

On-Prem

Vulnerabilities identifications Vulnerabilities quantification Vulnerabilities prioritization

(25)

VULNERABILITY ASSESSMENT |

On-Prem

HOW

Private IP addresses | Public IP addresses

Scope of engagement definition Cataloging assets & resources

Continuous identification of vulnerabilities

Integration of 3rd party system Monitoring | SIEM

(26)

VULNERABILITY ASSESSMENT |

On-Prem

WHERE

Networking equipments Server & clients

(27)

GAP ANALYSIS

(28)

WHAT

GAP ANALYSIS

Identification of current risk controls Identification of residual risks

(29)

HOW

Interview to organization key people Use of CIS Controls

Analysis of «AS IS»

Identification of «TO BE» set of cyber actions​ Creation of a detailed report

Report presentation

GAP ANALYSIS

TM

(30)

WHERE

GAP ANALYSIS

Physical interview Remote interview

(31)

SECURITY TRAINING

(32)

WHAT

SECURITY TRAINING

Cyber Security Essential

Cyber Security Intermediate Cyber Security Advanced

Exposure Analysis with OSINT Social Engineering + ETEL game Industrial Control System Security

(33)

HOW

SECURITY TRAINING

Class room

(34)

WHERE

SECURITY TRAINING

Customer site Würth Phoenix Microsoft Teams

(35)

PENETRATION TEST

(36)

WHAT

Exploits detected vulnerabilities

Performed according to standard methodology

(37)

HOW

Vulnerability Assessment

Research on vulnerabilities exploitation Exploit

Creation of a detailed report Report Presentation

PENETRATION TEST

(38)

WHERE

PENETRATION TEST

Networking equipments WiFi

Server & clients IoT & IIoT

Web services

Web applications Mobile applications

(39)

PASSWORD AUDIT

(40)

WHAT

Dictionary attack

Rainbow Table attack Brute Force attack Hybrid attack

(41)

HOW

Company inputs collection Cracking execution

Creation of a detailed report Report presentation

PASSWORD AUDIT

Password hashes

One method | Multi method

(42)

WHERE

PASSWORD AUDIT

Active Directory Database

(43)

SOCIAL ENGINEERING

(44)

WHAT

Exploits of human factor

(45)

HOW

SOCIAL ENGINEERING

Phishing | Dumpster diving | Evil Twin

Impersonation | Baiting | Vishing | Lockpicking

Choice of Attack Vector(s) Info gathering

Attack simulation

Creation of a detailed report Report presentation

(46)

WHERE

SOCIAL ENGINEERING

Employees

Top management Key people

(47)

RED TEAMING

(48)

WHAT

RED TEAMING

Multi-layered attack simulation

Organization's detection and response capabilities test Focuses on the objectives rather than on used methods

(49)

HOW

RED TEAMING

Info gathering

Identification of weaknesses Attack simulation

Creation of a detailed report Report presentation

OSINT

(50)

WHERE

RED TEAMING

(51)

THE RIGHT SERVICE

PEOPLE PROCESS IT SERVICES ORGANIZATION INCREASING AWARENESS POSTURE COMPLIANCY SECURITY IMPROVEMENT INCIDENT DETECTION RESPONSE CAPABILITY SECURITY TRAINING SOCIAL

ENGINEERING PASSWORDAUDIT

GAP ANALYSIS PENETRATION TEST EXPOSURE ASSESSMENT RED TEAMING VULNERABILITY ASSESSMENT

(52)

References

Related documents

Materi yang kita bahas kali ini bagaimana kita meminta dan memberi informasi [ Asking and Giving Information ] dengan menggunakan Bahasa Inggris.. Menggunakan Wh-word

It seems to us that since modern warfare is total warfare, we must go farther and say that it now is waged by the assembly of State machine and General Staff against the whole

necessary to use these aspects. Before continuing with the actual calculations of the aspects, it is necessary to understand that the full strength of a Graha aspect is measured

There is other abundant testimony as to how this extraordinary physical vigor and ability to endure against adverse climate which is to be found in the average Russian

Beyer: “Matrix Adaptation Evolution Strategies for Optimization Under Nonlinear Equality Constraints.” Swarm and Evolutionary Computation , 2019... Design Principles for MA-ES

114 (1983) (stating ex parte contact between trial court and juror reviewed for actual prejudice); Smith v. 1996) (suggesting that the Remmer test has been reconfigured by

What follows is the story of how Floridians have cel- ebrated our most important holiday in the last four hundred years and how countless residents and visitors from near and

on the study of the acceleration of the body is considered to be valid and reliable for predicting the risk of falling or for discriminating between population groups with