Digital Shadows competently helps reduce digital risks

Digital Shadows competently helps reduce digital risks
Perhaps you know what OSINT is and have used the Shodan search engine, or are already utilizing a Threat Intelligence Platform to prioritize IOC from different feeds. However, it's sometimes necessary to continuously view your company from the outside and receive assistance in addressing identified incidents. Digital Shadows tracks digital assets of the company, and its analytics suggest specific actions.

Essentially, Digital Shadows seamlessly complements an existing SOC or fully covers its functions for monitoring the external perimeter.The ecosystem has been building since 2011, and it incorporates a myriad of interesting features. DS_ monitors the Internet, social media, and the darknet, extracting only the important information from the vast flow of data.

In its weekly newsletter, IntSum the company provides a table that you can use in your daily life for assessing the source and the information obtained. You can also find the table at the end of the article.

Digital Shadows can detect and mitigate phishing domains, counterfeit social media accounts; find compromised employee credentials and leaked data, uncover information about planned cyberattacks against the company, continuously monitor the organization's public perimeter, and even regularly analyze mobile applications in a sandbox.

Identifying digital risks

Every company, in the course of its operations, builds chains of connections with clients and partners, making the data it seeks to protect increasingly vulnerable, and their volume only grows.

Digital Shadows competently helps reduce digital risks
To begin managing these risks, a company must start looking beyond its perimeter, monitoring it and receiving timely information about changes.

Data Loss Detection (sensitive documents, accessible to employees, technical information, intellectual property).
Imagine that your intellectual property was exposed on the Internet or internal confidential code accidentally ended up in a GitHub repository. Malicious actors can use this data to launch more targeted cyberattacks.

Online Brand Security (phishing domains and profiles on social media, mobile apps imitating the company).
As it is now difficult to find a company without a social network or similar platform for interacting with potential clients, cybercriminals try to impersonate the brand of the company. They do this by registering fake domains, social media accounts, and mobile applications. If phishing or fraud is successful, it can impact revenue, customer loyalty, and trust.

Attack Surface Reduction (vulnerable services on the perimeter with the Internet, open ports, problematic certificates).
As the IT infrastructure grows, the attack surface and the number of information objects continue to increase. Sooner or later, internal systems may accidentally get published to the outside world, for example, a database.

DS_ will alert to issues before they can be exploited by an attacker, highlighting the most critical ones, analysts will recommend further actions, and takedown can be done immediately.

DS_ Interface

You can use either the web interface of the solution directly or take advantage of the API.

As you can see, the analytical summary is presented as a funnel, starting from the number of mentions and ending with actual incidents received from various sources.

Digital Shadows competently helps reduce digital risks
Many use the solution as a Wikipedia with information about active attackers, their conducted campaigns, and events in the field of information security.

Digital Shadows can be easily integrated into any external system. Both notifications and REST API are supported for integration into your system. Notable mentions include IBM QRadar, ArcSight, Demisto, Anomali, and others.

How to Manage Digital Risks — 4 Key Steps

Step 1: Identify Critical Business Assets

This first step is, of course, to understand what the organization cares about the most and what it wants to protect.

Can be divided into key categories:

  • People (customers, employees, partners, suppliers);
  • Organizations (related and service companies, shared infrastructure);
  • Systems and operationally critical applications (websites, portals, customer data databases, payment processing systems, employee access systems, or ERP applications).

When compiling this list, it is advisable to follow a simple idea—assets should revolve around critical business processes or economically important functions of the company.

Typically, hundreds of resources are added, including:

  • company names;
  • brands/trademarks;
  • IP address ranges;
  • domains;
  • social media links;
  • suppliers;
  • mobile applications;
  • patent numbers;
  • document labels;
  • DLP identifiers;
  • email signatures.

Customizing the service ensures that users receive only relevant alerts. It's an iterative cycle, and system users will add assets as they emerge, such as new project names, upcoming mergers and acquisitions, or updated web domains.

Step 2: Understanding Potential Threats

To best assess risks, it is essential to understand the potential threats and digital risks to the company.

  1. Tactics, Techniques, and Procedures of Adversaries (TTP)
    Framework MITRE ATT&CK and others help establish common ground between defense and offense. Gathering information and understanding the behavior of a wide range of adversaries provides very useful context for defense. This helps to understand the next step in an observed attack or to build a general defense concept based on Kill Chain.
  2. Adversary Capabilities
    An attacker will exploit the weakest link or the shortest path. Various attack vectors and their combinations—email, web, passive information gathering, etc.

Step 3: Monitoring for Unwanted Appearances of Digital Assets

To identify assets, it is necessary to regularly track a large number of sources, such as:

  • Git repositories;
  • Poorly configured cloud storage;
  • Paste sites;
  • Social media;
  • Criminal forums;
  • Dark web.

To start with something, you can use free utilities and techniques ranked by difficulty in the guide ‘A Practical Guide to Reducing Digital Risk’.

Step 4: Taking Protective Measures

Upon receiving an alert, specific actions need to be taken. These can be categorized as Tactical, Operational, and Strategic.

In Digital Shadows, each alert includes recommended actions. If it's a phishing domain or social media page, you can track the status of remediation in the “Takedowns” section.

Digital Shadows competently helps reduce digital risks

Access to the demo portal for 7 days

I should clarify right away that this is not a full testing opportunity, but merely temporary access to the demo portal to familiarize yourself with its interface and search for some information. Complete testing will contain up-to-date data relevant to the specific company and is expected to involve an analyst's work.

The demo portal will include:

  • examples of alerts for phishing domains, compromised credentials, and vulnerabilities in the infrastructure;
  • search capabilities for darknet pages, criminal forums, feeds, and more;
  • 200 profiles of cyber threats, tools, and campaigns.

Access can be obtained via this this link.

Weekly Newsletters and Podcast

In the weekly newsletter IntSum you can receive a brief summary of operational information and the latest events from the past week. You can also listen to the podcast ShadowTalk.

To evaluate the source, Digital Shadows employs qualitative assertions from two matrices to assess the credibility of sources and the reliability of the information obtained from them.

Digital Shadows competently helps reduce digital risks
The article is based on 'A Practical Guide to Reducing Digital Risk’.

If you are interested in the solution, you can reach out to us — the company Factor group, a distributor of Digital Shadows_. Just write in a free form to digitalshadows@fgts.ru.

Authors: popov-as and dima_go.

Source: habr.com

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster