HomeCyber BalkansFiligran Introduces AI-Driven Attack Chaining to OpenAEV for Autonomous Pentesting

Filigran Introduces AI-Driven Attack Chaining to OpenAEV for Autonomous Pentesting

Published on

spot_img

Filigran has recently unveiled an innovative attack chaining capability integrated into its OpenAEV platform, a move designed to enhance how security teams assess the risks associated with multiple vulnerabilities within an organization. This new feature aims to simulate real-world attack scenarios more effectively, thereby providing security professionals with deeper insights into how various weaknesses can combine to create accessible pathways through a company’s environment.

This capability was introduced as part of the latest OpenAEV v3 release. The attack chaining functionality enables penetration tests and red team exercises to evolve dynamically based on the discoveries made throughout the simulated attack process. Unlike traditional methods that often focus on isolated techniques or fixed sequences, this updated platform leverages findings from one stage, such as acquired credentials, identified permissions, or exposed ports, to inform the next steps in the simulation.

The rationale behind this approach is rooted in the acknowledgment of how genuine attackers operate. Filigran suggests that what may initially appear as a minor vulnerability can serve as a critical foothold, thereby leading attackers to access additional systems, ultimately jeopardizing sensitive information or vital organizational assets.

The efficacy of traditional security validation techniques has been debated in recent years. While such methods can confirm whether specific techniques or controls are effective, Filigran contends that this narrow focus can overlook the broader risks created by the combination of different weaknesses. In their recent report titled “State of Threat Management,” it was revealed that a staggering 97% of organizations struggle to determine the exploitability of their security exposures. Moreover, 84% reported that attackers frequently exploit known risks that have not been properly prioritized. This study was based on responses from 550 security decision-makers and practitioners, highlighting a critical gap in the current security landscape where 88% still depend, to some extent, on manual processes for offensive attack simulations.

To bridge this gap, Attack Chaining adopts a model where the result of each simulated action serves as an input for the subsequent step. For instance, if a discovered credential successfully grants access to another system, the simulation can progress further into the organization’s environment. Should a security control block this endeavor, the chain can halt, or alternatively, pivot to explore different avenues.

Julien Richard, co-founder of Filigran, emphasized the necessity for security validation methods to evolve in tandem with attacker strategies. He noted, “The goal is no longer just to prove that we can block individual techniques; it is to understand whether those techniques can be combined into a path that leads to a real compromise.” As adversaries become increasingly adaptive and exploit artificial intelligence (AI) to expedite their attacks, the validation methods employed by security teams must also advance to keep pace.

Another noteworthy aspect of the new capability is its flexibility in operation. It can be utilized manually, autonomously through AI agents, or through a combination of both methods. In manual mode, security teams have control over defining the attack logic, whereas in the agent-led mode, users can simply outline objectives in natural language. The AI agent then autonomously crafts and modifies the attack chain based on its findings during the simulation. This could encompass generating phishing emails and creating landing pages for social engineering exercises.

Despite the autonomous capabilities, Filigran assures that the AI agent remains under predefined scope controls, with all decisions logged for transparency. This feature not only strengthens accountability but also provides security teams with a detailed audit trail that tracks how the simulation reached a particular outcome. This development is part of Filigran’s ongoing initiative to incorporate automation into security practices. The June launch of XTM One showcased an AI orchestration that integrates across OpenCTI and OpenAEV, streamlining workflows that encompass threat intelligence, attack scenario generation, validation, and remediation guidance.

The introduction of a live attack path graph within OpenAEV v3 significantly enhances situational awareness for security teams. This feature allows teams to observe the ongoing simulation as it navigates through the organization’s environment. Each step, branch, and discovery is visually represented, providing defenders with valuable insights into how far the simulated attacker has progressed and which specific security controls ultimately thwarted the attack.

Filigran underscores the importance of identifying “chokepoints” within attack pathways. Rather than treating every vulnerability encountered during an assessment equally, this approach enables teams to pinpoint the controls or weaknesses whose remediation would disrupt the broader attack chain. Jean-Philippe Salles, VP of Product Management at Filigran, articulated this philosophy, stating, “A validation outcome is only actionable when security teams can trace the logic that generated it.”

In tandem with Attack Chaining, OpenAEV v3 also rolls out a redesigned dashboard known as the Adversarial Exposure Command Center, unifying security posture, simulation results, and detection coverage into a cohesive interface. Furthermore, it introduces an Adversarial Exposure Score, a metric designed for tracking validation outcomes across various exposure sources. The platform also incorporates automated reporting capabilities and AI red-teaming injectors that permit organizations to conduct adversarial simulations against AI-powered agents and chatbots, utilizing the same validation engine employed to scrutinize traditional controls like EDR, SIEM, and email defenses.

OpenAEV v3 has already been made available, with the new Attack Chaining functionality included in the platform’s Enterprise Edition. This strategic enhancement is anticipated to elevate the standards of security testing and validation, enabling organizations to fortify their defenses against increasingly sophisticated cyber threats.

Source link

Latest articles

How China Built the Infrastructure for State-Sponsored Hacking

The Quartermaster Model of Hacking: A Deep Dive into QTFY Operations Over the past year,...

No Zero Trust in Zero Trust

In January 2023, the Cloud Security Alliance conducted a survey which probed deep into...

AI Vulnerability Surge Disrupts the OT Patch Cycle

IEC 62443: A Framework for Enhanced Operational Technology Security The IEC 62443 standard has emerged...

EP 179: Revisiting the Courthouse

In the latest episode of the popular podcast Darknet Diaries, listeners were taken on...

More like this

How China Built the Infrastructure for State-Sponsored Hacking

The Quartermaster Model of Hacking: A Deep Dive into QTFY Operations Over the past year,...

No Zero Trust in Zero Trust

In January 2023, the Cloud Security Alliance conducted a survey which probed deep into...

AI Vulnerability Surge Disrupts the OT Patch Cycle

IEC 62443: A Framework for Enhanced Operational Technology Security The IEC 62443 standard has emerged...