Live data from Hacker News

Just launched our web-based spear phishing attack simulator app

threatsim.com

1–10 of 21 posts

Re: Just launched our web-based spear phishing attack simulator app

#4
post #2

I wonder how many companies are currently running tests like this in the enterprise. Anyone have an idea of what people currently use?

This is a consulting offering at several low-end app sec firms (if you're a high-end appsec firm that does this stuff, sorry, I didn't know). It's one of those attractive "scales across every employee of the company" services consultants love. Happy to see it productized.

Re: Just launched our web-based spear phishing attack simulator app

#6

1. I have no idea what this website does, but it sounds like it is web based security checking. 2. The web site is down. Potential Delicious Irony: Somebody took down ThreatSim with ThreatSim.

Irony is that we're under a lot of traffic right now and moving to EC2 as I type this. Site is back up btw :)

Re: Just launched our web-based spear phishing attack simulator app

#7

I can't wait to see stats from this! Hoping when you license it to companies, you collect anonymous but public stats.

Yes, one of our goals is to collect industry-wide metrics that will help everyone figure out what the best approach to tackling this difficult problem.

Re: Just launched our web-based spear phishing attack simulator app

#8
post #4
post #2

I wonder how many companies are currently running tests like this in the enterprise. Anyone have an idea of what people currently use?

This is a consulting offering at several low-end app sec firms (if you're a high-end appsec firm that does this stuff, sorry, I didn't know). It's one of those attractive "scales across every employee of the company" services consultants love. Happy to see it productized.

We're a mid-level appsec firm, how's that? :) The problem is that high, med, and low end attackers are using spear phishing to get a foothold inside many organizations. This is testing that everyone should be doing today. Read any recent mainstream media article about any breach and Cmd-F "phish".

Re: Just launched our web-based spear phishing attack simulator app

#9
Little background here: We're a security consulting company. We do a ton of web app security assessments, network vuln/pen testing, etc. A while back one of our clients (large financial) hired us to do a spear phishing simulation. "Show us how people are still able to get in and show us how they are able to get out". So we did it all manually both the phishing as well as going on site to to data exfiltration to see how we could get around their outbound firewall rules, IDS/IPS, DLP, proxies, sniffers, etc. We figured out how to do all of these successfully and were able to "steal" some fake credit card numbers.

We lost a lot of money on that engagement. :) We went waaay over margin. So we started thinking how can we automate this and make it a repeatable process that customers can run on an on-demand and on-going basis. Security is who we are and in our blood. We we started coding...

And here we are.

So there are two sides:

1. Web based spear phishing engine that sends out "malicious" emails with all kinds of different options (e.g. malicious attachments, links to malicious web sites, 'your pass expired, enter it here!' sites, etc.) We track who clicked on what, who has out of date Acrobat, Flash, Java, etc.

2. Bottom line is that phishers will ALWAYS get people to click on something. No matter what. And the attacker only needs 1 person to do it. Just 1. So let's assume that we're going to eventually get in. We have an on-demand executable that mimics attacker malware complete with ninja-sneaky network tricks that phones home fake credit card numbers, .rar files, all kinds of cool network trickery.

All of the above is run by the end user and presented in a nice web UI so a security guy/gal can make intelligent decisions on where their security is good and where it sucks.

We're super excited about our new service and we hope everyone else is too. Would love to hear more feedback.

Re: Just launched our web-based spear phishing attack simulator app

#10

Little background here: We're a security consulting company. We do a ton of web app security assessments, network vuln/pen testing, etc. A while back one of our clients (large financial) hired us to do a spear phishing simulation. "Show us how people are still able to get in and show us how they are able to get out". So we did it all manually both the phishing as well as going on site to to data exfiltration to see h…

Awesome - I'll be contacting you. This is great, for the typical over-worked but security conscious IT guy (me).
Post reply on HN