22/07/2025
๐๐ซ๐๐๐๐ก ๐๐ง๐ ๐๐ญ๐ญ๐๐๐ค ๐๐ข๐ฆ๐ฎ๐ฅ๐๐ญ๐ข๐จ๐ง ๐๐ฅ๐จ๐ง๐ ๐๐ฌ ๐๐จ๐ญ ๐๐๐๐๐๐ญ๐ข๐ฏ๐
While this tool can identify security gaps within your organization, it simulates techniques that are already well known.
Why would adversaries use those tactics that everyone knows? They will constantly spring up a surprise by coming up with techniques that no one knows. So, just by relying only on BAS, your business will be blind to unknown attack techniques.
Does that mean you should ditch the BAS tool? No
๐๐ญ ๐๐ง๐๐จ๐ฉ๐๐ซ๐๐๐ฉ๐ญ, ๐ฐ๐โ๐ฏ๐ ๐๐จ๐ฆ๐๐ข๐ง๐๐ ๐๐๐ ๐ฐ๐ข๐ญ๐ก ๐๐ฎ๐ฆ๐๐ง-๐ฅ๐๐ ๐๐๐ ๐๐๐๐ฆ๐ข๐ง๐ ๐ฎ๐ง๐๐๐ซ ๐๐ง๐ฏ๐ข๐ง๐ฌ๐๐ง๐ฌ๐ ๐๐๐๐.
This brings the best of automation and human creativity together to expose weaknesses before adversaries catch wind of it.
Here is how it works:
Imagine this: our red team approaches a customer support executive of a mid-sized bank that wants us to perform offensive security testing through LinkedIn.
They send him a fake resume, which is embedded with an AutoOpen macro. The VDI that the employee uses was poorly configured; it had local admin rights and unrestricted SMB shares.
Our team finds the plaintext credentials for a staging server, and they steal the hardcoded API key with access to the customer KYC microservice. They exfiltrate 10 dummy KYC records using legitimate API cells.
There were no alerts because it looked like normal API behavior, and DLP rules didnโt flag it.
Originally, BAS will not be able to stimulate macro-based document delivery, VDI lateral movement, chained misconfigurations, and cloud token abuse.
But our Red Team shares this attack chain with the purple team, and our BAS platform scripts this as a custom module. Now, BAS can perform an assumed breach scenario where a malicious Word file with a macro is executed It will now be able to continuously retest this entire attack chain and ensure gaps donโt appear after the issue has been patched.
In this way, our red team thinks like an attacker and finds the creative chains, whereas BAS ensures that the fix works through continuous validation.
https://www.infopercept.com/invinsense/invinsense-oxdr