Authored by: PlexTrac Author Posted on: February 15, 2023 OnDefend Integrates with PlexTrac to Deliver Threat-Informed Penetration Testing Use OnDefend Powered by PlexTrac to Leverage Global Threat Intelligence in Your Pentests JACKSONVILLE, FLORIDA and BOISE, IDAHO — February 15, 2023 — OnDefend, a critical partner of security service firms and corporations throughout the US and around the world, using the power of PlexTrac, the premier cybersecurity reporting and collaboration platform, presents a groundbreaking security offering to customers and partners through threat-informed penetration testing (TIP). TIP is the next generation in penetration testing that leverages global threat intelligence about specific emerging adversaries targeting your industry to provide valuable insight on how your environment will respond. TIP safely tests the exact tactics and techniques of the threats your leadership and organization are concerned about. Through an in-depth API integration, OnDefend can now offer customers their automated breach and attack simulation (BAS) solution, BlindSPOT, with seamless remediation management and retesting through PlexTrac Runbooks. OnDefend’s BlindSPOT enables you to execute attack activity on your client’s production network environments for more consistent and real-world practice against adversaries. PlexTrac’s Runbooks supports the planning, execution, reporting, and remediation tracking of your red teaming, purple teaming, or adversary emulation activities. Using OnDefend and PlexTrac together make TIP actionable for your team by Leveraging OnDefend’s seasoned red team to emulate the specific threats actors of your company’s choosing Automatically delivering results via API to PlexTrac for comprehensive reporting and remediation management Performing remediation retesting via PlexTrac Runbooks, selecting BlindSPOT, OnDefend’s Breach and Attack Simulation solution, to guide the testing Watch an on-demand webinar from OnDefend and PlexTrac to learn more about the value of threat-informed pentesting and see the BlindSPOT/Runbooks integration in action. Watch Threat-Informed Pentesting: The First Step to Continuous Assessment About OnDefend OnDefend empowers the information security industry through its cutting-edge technological innovations and battle tested professional services team. By solving the problems that the cyber security industry has not solved, OnDefend has become a critical partner of security service firms and corporations throughout the US and around the world. Whether it’s their next generation SaaS offerings of BlindSPOT and Confirm4Me or their seasoned security team leveraged by partners to meet market service demand, OnDefend has enabled cyber security firms to extend their capacities and corporations to secure their future. To learn more, visit ondefend.com. About PlexTrac PlexTrac, Inc. is the premier penetration test reporting and proactive cybersecurity management platform driven by a mission to help teams win the right cybersecurity battles. PlexTrac makes security data aggregation, red and blue team reporting, purple team collaboration, and remediation tracking more effective and efficient so security teams can become more proactive and demonstrably improve security posture. To learn more, visit plextrac.com. PlexTrac Author At PlexTrac, we bring together insights from a diverse range of voices. Our blog features contributions from industry experts, ethical hackers, CTOs, influencers, and PlexTrac team members—all sharing valuable perspectives on cybersecurity, pentesting, and risk management.
From Friends Friday to Black Hat Europe: What Security Teams Should Focus on Next Software supply chain vulnerabilities are becoming one of the most unsettling challenges in modern cybersecurity with increasingly creative attackers. To explore these issues, our founder, Daniel DeCloss, sat down with Jonathan Leitschuh, an open source security researcher known for uncovering high-impact vulnerabilities, advancing responsible disclosure practices, and pushing the industry toward more secure-by-default software. READ ARTICLE
The Missing Link Between Pentest Findings and Fixes Why Every Security Program Needs a Mobilization Coordinator Pentests rarely fail because testers miss something critical. In fact, that part usually goes pretty well. The breakdown almost always happens after the report is delivered. Findings sit untouched. Some get half-fixed. Others disappear under the weight of sprint deadlines, operational noise, or the vague hope that... READ ARTICLE
The Automation Imperative: Why Pentest Delivery Must Catch Up With Continuous Testing Security feels a lot like Whac-A-Mole these days. Between cloud-native architectures, microservices, APIs, and rapid deployment cycles, cybersecurity threats are constantly popping up and redefining how software is built and delivered. Yet penetration testing, which is a proven method for identifying exploitable weaknesses, remains a point-in-time snapshot.In some cases, annual penetration tests don’t even happen.... READ ARTICLE