Mark joined Bishop Fox in March 2020 to work on the Cosmos platform, which focuses on continuous offensive security at scale, aligning with his interest in staying ahead of nation-state actors and emerging threats.
The Cosmos platform aims to provide continuous offensive security testing at scale, helping customers identify and address vulnerabilities before malicious actors can exploit them.
Red teaming involves high-stakes, stealthy operations where the goal is to avoid detection, while continuous external pen testing aims to be detected as a positive sign of effective security measures.
Cosmos includes automated attack surface discovery, continuous web application pen testing, and prioritization of vulnerabilities, with plans to expand into internal pen testing.
Subdomain takeover vulnerabilities can lead to phishing attacks, credential harvesting, and damage to customer trust, making them a high-priority issue for Cosmos to address.
Cosmos uses a breadth-first approach to identify subsidiaries and domains, leveraging tools and open-source intelligence to build a comprehensive attack surface before conducting depth-first vulnerability assessments.
AI and LLMs are being explored to enhance attack surface discovery, improve vulnerability prioritization, and streamline processes like parsing SEC filings and other data sources for faster, more accurate insights.
Cosmos automates low-level, repetitive tasks like identifying directory listings or subdomain takeovers, while reserving more complex, creative exploits for human operators to ensure validated, high-quality findings.
The main challenges include prioritizing vulnerabilities across large attack surfaces, ensuring continuous scanning without overwhelming customers, and staying ahead of emerging threats to maintain high signal-to-noise ratios.
SOC 2 compliance has helped Bishop Fox ensure internal processes align with best practices, but it hasn't directly driven new business. Customers typically handle SOC 2 compliance internally based on findings provided by Bishop Fox.
Offensive penetration testing, or offensive pentesting, involves actively probing a system, network, or application to identify and exploit vulnerabilities, mimicking the tactics of real-world attackers. The goal is to assess security weaknesses and provide actionable insights to strengthen defenses before malicious actors can exploit them.
Bishop Fox) is a private professional services firm focused on offensive security testing. Mark Goodwin) is the Director of Operations at Bishop Fox and he was previously an officer in the U.S. Air Force where he did cyberspace operations. Mark joins the podcast with Gregor Vand to talk about Bishop Fox and the future of offensive pentesting.
)Gregor Vand is a security-focused technologist, and is the founder and CTO of Mailpass. Previously, Gregor was a CTO across cybersecurity, cyber insurance and general software engineering companies. He has been based in Asia Pacific for almost a decade and can be found via his profile at vand.hk.
Please click here to see the transcript of this episode.)
Sponsorship inquiries: [email protected])
The post The Future of Offensive Pentesting with Mark Goodwin) appeared first on Software Engineering Daily).