CrowdStrike expanded its Falcon platform by adding an External Attack Surface Management (EASM) module. The feature is based on capabilities from the vendor’s recent Reposify acquisition.
The vendor nabbed EASM provider Reposify in September to help customers identify exposed external assets. The startup’s core technology is to use one of the largest databases of internet-facing assets to help customers quickly view their external attack surface. CrowdStrike integrated this technology into its Falcon Platform as a standalone module, dubbed Falcon Surface.
The service constantly scans the internet via a proprietary engine to identify users’ known and unknown exposed assets, flags and prioritizes the risks, and automatically suggests remediation steps through its optimizer services.
Additionally, CrowdStrike plans to integrate the EASM capabilities with the other Falcon modules within its Threat Intelligence and Security & IT Operations product suites. The move will unlock more visibility into external adversary activities, CrowdStrike claims.
The Falcon Surface and the integration with Falcon Intelligence Recon are generally available now and the integration with Falcon Spotlight and Falcon Discover is slated to release in the second half of next year.
CrowdStrike Targets to Win EASM MarketGartner identified EASM as one of the top security and risk management trends for this year.
“Digital risk protection services (DRPS), EASM technologies, and cyber asset attack surface management (CAASM) will support CISOs in visualizing internal and external business systems, automating the discovery of security coverage gaps,” the analysis firm wrote.
The demand for attack surface management services is surging. Recent research from Enterprise Strategy Group (ESG) showed only 9% of organizations are monitoring 100% of their attack surface.
To address this need, security vendors have upgraded their attack surface management services, including Palo Alto Networks and Microsoft.
Palo Alto Networks introduced the Active Attack Surface Management to its Xpanse module during this month’s Ignite event. The feature is designed to actively discover and remediate risky exposures for organizations’ internet-facing assets. The Xpanse platform is based on the vendor’s 2020 Expanse acquisition for internal and external digital attack surface management.
Microsoft in August launched its enhanced threat intelligence and external attack surface management services, aiming to track threat actors’ activities and patterns and offer an outside-in view of the user’s attack surface. The Defender Threat Intelligence service is based on technologies from the company’s RiskIQ acquisition.
CrowdStrike CTO Michael Sentonas said the vendor has a unique position in the market.
“First, part of understanding your external attack surface is knowing your adversary. We know more about adversaries than anyone else in the industry," Sentonas explained in a statement. "Second, getting visibility into internet exposures requires both an outside-in and inside-out perspective. We will focus on integrating our IT hygiene, vulnerability management, and EASM modules together so we can deliver deep insights of enterprise risk across all assets. Third and most importantly, we deliver EASM from a unified security platform with a single, lightweight agent. This approach enables us to drive the best outcomes for customers – speed of deployment, ease-of-use, cost efficiencies, and more."
Comments