Open-Source Detector of CISA's Known Exploitable Vulnerabilities
github.com
github.com
apologies for hijacking your post OP but I am curious if people flocking to such a post would be interested in being beta users for us too
It’s what happens after.
More scanners aren’t what we need because vendors still can’t meaningfully answer the most important questions:
- Is the vulnerability valid based on the environment it was found in? Solve this and you’ll reduce enterprise vulnerabilities by probably 30-40%.
- What are the compensating controls? Identify these automagically and reduce the vuln risk scores based on what controls are found, you will remove another 30% of vuln work for engineering teams
We don’t need any more scanners. We need better asset and vuln management.
Sifting through that and writing up why that vulnerability doesn’t actually apply to your environment and showing evidence of such is an incredibly time consuming process. It’s honestly easier to just patch it, a lot of times.
My role, and others like me, need to get that critical vuln number down. Meaning yes, upgrading libs was enough.
Approaching vulnerability management from a developers view is a very narrow scope.
Paying a managed service to advise is also an option. I have heard Huntress is pretty good. I am sure there are others out there.
Complete support is provided through Slack to (or however you wish), so you know you don't have to wait for any kind of support.
We know there are plenty of scanners out there. Hence we are using an open-source one and working on how we can improve the 'what happens after' part by using human-led expertise to save others their time
- Is the vulnerability valid based on the environment it was found in? Solve this and you’ll reduce enterprise vulnerabilities by probably 30-40%. --> Having a human expert confirm and filter the list is what we are offering to our closed beta users for now so yes that is what we are targeting to solve!
- What are the compensating controls? Identify these automagically and reduce the vuln risk scores based on what controls are found, you will remove another 30% of vuln work for engineering teams --> We have a list of controls we've identified, but we know each environment is different, hence looking for users we can tune our controls to
We are particularly looking for users who are in small organizations looking to grow rapidly. Ultimately, we are looking to save other devs time by taking over the cumbersome work.
Please sign up and let me know when you do so we can share more?
The more toned down version is I find the whole thing suspect. It costs someone time to do this, so "free" doesn't scale. That someone would want to Trivy install, tuning, monitoring for "free" in return for remote access seems like a big red flag.
And yes, the current model cannot scale for sure as there's a human piece at the end. We aren't looking to scale at the moment, just exploring if there can be a solution to this space we can come up with.
Again, like I mentioned above, just looking for users we can actually help as this is a common problem many face if they aren't at a big organization.
Also mentioned this isn't our main business, something we are experimenting with hence we are in closed beta and offering to do it for free for only a few. We have human labour costs to lol
We offer to install it for you for ease or can guide you on installing it yourself, and we will obviously be signing NDAs and whatever a user would like to build trust. We are literally in the business of DevOps..nothing malicious my man, just exploring a different kind of MVP but I understand the distrust
I also get that products, and people, have to get a start somewhere - unfortunately scammers and mal actors look similar. I figured it was worth raising for others to consider, but did so near the bottom on the comment chain rather than top level so as to not derail discussion.
Edit: fighting autocorrect, detail -> derail
Yeah a possible upsell or doesn't have to be if this service is actually useful to anyone out there. We will potentially start charging a small fee (dependent on so many other factors, but hey you'll be getting an actual human expert in this age of automation to speak to eitherways) on this months from now - we haven't decided or thought of anything further as we don't know yet if people feel this is enough of a pain to be open to solutions, as obviously one can do it themselves to but at what cost of time?
any other feedback you may have on such a service or legitimate places to find users this can help would also be appreciated!
it's 'free' only for the closed beta as duh we are clearly stating there's a human expert at the end who will be reviewing and going through with it.
We also know this model is not going to scale because of the human aspect, but we know this is a problem most people face if they are from small organizations, so we are looking to see how we can solve for steps AFTER the scan. This is just our first step as we try to learn more.
Trivy was the choice of scanner for now, but we don't tend to stick with it as there can be better scanners out there depending on the environment- it's just what we chose for the start, open to discussions if a user has a preference for a different scanner
We are not going to be acquired or disappear as we have been in this business for over 20+ years and we plan to stay independent.
We also won't have cash flow problems as like I mentioned, this is a side project for us at the moment and not our main source of income.
We are just looking to test if this would be useful to anyone out there, hence it's free for the people that join our closed beta.
Happy to chat more if you more questions
www.example.com is not a domain name, and AFAICT there is no attempt to enumerate hosts in a domain and scan them all.
You can do so by adding your domain name generation tool of your choice, or all. The ones supported for now are `subfinder` and `amass`.
Agent Subfinder: https://github.com/Ostorlab/agent_subfinder Agent Amass: https://github.com/Ostorlab/agent_amass
I think the confusion still remains. Scanning "domain-name www.example.com" will not scan a domain. (And www.example.com is not a domain name, but maybe I'm being prescriptivist here? Have we colloquially abandoned the distinction between hosts and domains? Even if so, I'd argue that a network tool should not use the colloquial sense, but I can go check for kids on my lawn if that would be more fruitful...)
Be sure to let us know how we can help, and you are welcome to open issues on GitHub or join our Discord if you have questions.
Usage Instructions seem lacking.
Updated the readme with the basic commands and referenced another tutorial with in-depth info: https://docs.ostorlab.co/tutorials/run-your-first-scan.html
I like the idea for personal use. I was just looking for something similar the other day and for once I'm happy I don't need to build it.