The What, Why, and How of AttackSurfaceMapper

Presented by

Andreas Georgiou, Security Consultant, Trustwave

About this talk

The primary goal for any security professional today is to present less of a target-rich environment for the slew of cyber swindlers aiming to compromise critical assets. However, as businesses continue to scale, leveraging multiple clouds to upgrade their operations, larger sets of dispersed data are expanding the battleground and presenting overwhelming challenges from a data protection standpoint. One effective method that more businesses are wising up to is penetration testing, which allows them to locate the root of many problems before attackers do. To be successful against your adversary, you have to think like them, and penetration testing allows for this to happen. To aid pen testing professionals, the Trustwave SpiderLabs team is always at work developing new ways to make their jobs easier and more productive. Dubbed AttackSurfaceMapper, the tool is intending to speed up and simplify the reconnaissance process for pen testers, allowing them to focus on the exploitation process a bit more, according to Andreas Georgiou, security consultant at Trustwave, and one of the tool’s creators. By taking a single IP address or domain, AttackSurfaceMapper analyzes it by using passive OSINT techniques and effective reconnaissance methods. This results in hard, actionable data that security professionals can use to spend more time on the testing, and less time on manually performing reconnaissance. In the full video interview above, Trustwave outlines what you need to know about this open-source tool and how it can benefit your security efforts today.

Related topics:

More from this channel

Upcoming talks (0)
On-demand talks (45)
Subscribers (24108)
Trustwave helps businesses fight cybercrime, protect data and reduce security risk. With cloud and managed security services, integrated technologies and a team of security experts, ethical hackers and researchers, Trustwave enables businesses to transform the way they manage their information security and compliance programs. More than 2.7 million businesses are enrolled in the Trustwave TrustKeeper® cloud platform, through which Trustwave delivers automated, efficient and cost-effective data protection, risk management and threat intelligence. Trustwave is a privately held company, headquartered in Chicago, with customers in 96 countries. For more information about Trustwave, visit www.trustwave.com.