As all cybersecurity defenders know, visibility into the network is the key to understanding what is really happening at your organization. In order to protect a corporate network, cybersecurity teams must be aware of the complete attack surface. In order to achieve this, Stamus Security Platform (SSP) u40 has introduced a new feature: the Attack Surface Inventory. This new feature makes it incredibly easy for a security team to quickly see and understand exactly where an attack could happen.
As the Stamus Security Platform probes capture traffic in key parts of the network, they are able to see all the hosts actively communicating over, and thus create a list of all active servers and endpoints on the network. Prior to SSP u40, only the hosts that had a detection method trigger were listed on the “Host” page. Now, as of the release of SSP u40, all active hosts communicating over the network are listed, providing users with a complete attack surface inventory.
The Stamus Security Platform is able to capture a broad range of data points which are made available in the inventory, such as:
The information above is then displayed in a user friendly and easily readable way:
Stamus Security Platform probes capture traffic in real time. As a result, they are capable of updating the attack surface inventory host data points in real time. This mechanism allows SSP users to always have the most current information possible about the hosts in the network they are protecting.
The Attack Surface Inventory feature is crucial for cybersecurity defenders as it allows them to have a complete view of the network, thus enabling them to:
The Attack Surface Inventory is a native feature to Stamus Security Platform u40. All new customers will automatically benefit from it and see the Inventory option in their sidebar. For existing customers, upgrading from your current release to SSP u40 is the only way to benefit from the Attack Surface Inventory. After installing SSP or upgrading from a previous version, you can navigate to the Inventory page to see the list of all actively communicating assets in your network:
The more you can see, the more you will know. The more you know, the more you can do. The Attack Surface Inventory gives security teams a clear picture of the assets communicating on their network, in turn allowing them to have greater visibility, improved incident response, and proactively identify possible weaknesses. If you have not yet upgraded to Stamus Security Platform U40, then we strongly encourage you to do so to get the most out of the new features.
To stay updated with new blog posts from Stamus Networks, make sure to subscribe to the Stamus Networks blog, follow us on Twitter, LinkedIn, and Facebook, or join our Discord.