Skip to main content

Randori Recon acts like a hacker to reveal your weaknesses

Randori, a Boston-based start-up from a former Carbon Black executive and a former Red Team consultant, announced its first product today called Randori Recon, a service designed to act with a hacker’s mindset to surface all of your company’s external weaknesses.

Brian Hazzard, co-founder and CEO, says he had worked with his co-founder David Wolpoff when he was running a red team consulting firm. The idea behind a red team is to act as an attacker would and find a company’s weaknesses. The two decided to put Wolpoff’s lucrative consulting firm out of business and develop a tool to put this kind of service in reach of any company.

“The idea is to break out of that defender’s mindset, to stop guessing at what you need to do on the defense side, but rather to inform our strategies and the way we defend our networks from the attacker’s perspective,” Hazzard explained.

Based on just a company email address, Recon begins to build a picture of all the publicly available information about that company, and from that they can find weaknesses and vulnerabilities that a hacker would typically exploit to get inside a company’s defenses.

Wolpoff says that it’s not useful or desirable for a red team to have any knowledge of the target company’s security defenses. He wants to go in there with what he calls “a black box” and discover everything he can find on his own. “We start with basic information, and then we’ll go discover everything that’s discoverable from that and then from each of those individual nuggets that we glean, we chase every thread that we can chase from those,” he said.  They then continually monitor this information, so that if anything changes, they can find new vulnerabilities that could pop up over time.

While the company is starting with external vulnerabilities, the plan is to build out the service to provide internal scans, as well. “As we progress the product, we will be able to do internal reconnaissance inside of an organization as well, but for the Recon product we’re really focusing on an outside-in black box discovery of the publicly visible surface area of an organization,” Wolpoff said.

Wolpoff says the service agency he ran was lucrative, but the sales cycles were long, and because of the cost, it was really only within reach of relatively few organizations who were willing to pay for that kind of service. Over dinner in 2017, Hazzard and Wolpoff hatched the idea of developing his knowledge and expertise and packaging it as an online service.

They started developing the product and opened the company last year. They announced a $9.75 million seed round last October.



from Startups – TechCrunch https://ift.tt/2N2JMEI

Comments

Popular posts from this blog

Axeleo Capital raises $51 million fund

Axeleo Capital has raised a $51 million fund (€45 million). Axeleo first started with an accelerator focused on enterprise startups. The firm is now all grown up with an acceleration program and a full-fledged VC fund. The accelerator is now called Axeleo Scale , while the fund is called Axeleo Capital . And it’s important to mention both parts of the business as they work hand in hand. Axeleo picks up around 10 startups per year and help them reach the Series A stage. If they’re doing well over the 12 to 18 months of the program, Axeleo funds those startups using its VC fund. Limited partners behind the company’s first fund include Bpifrance through the French Tech Accélération program, the Auvergne-Rhône-Alpes region, Vinci Energies, Crédit Agricole, BNP Paribas, Caisse d’Épargne Rhône-Alpes as well as various business angels and family offices. The firm is also partnering with Hi Inov, the holding company of the Dentressangle family. Axeleo will take care of the early stage in...

TikTok’s rivals in India struggle to cash in on its ban

For years, India has served as the largest open battleground for Silicon Valley and Chinese firms searching for their next billion users. With more than 400 million WhatsApp users , India is already the largest market for the Facebook-owned service. The social juggernaut’s big blue app also reaches more than 300 million users in the country. Google is estimated to reach just as many users in India, with YouTube closely rivaling WhatsApp for the most popular smartphone app in the country. Several major giants from China, like Alibaba and Tencent (which a decade ago shut doors for most foreign firms), also count India as their largest overseas market. At its peak, Alibaba’s UC Web gave Google’s Chrome a run for its money. And then there is TikTok, which also identified India as its biggest market outside of China . Though the aggressive arrival of foreign firms in India helped accelerate the growth of the local ecosystem, their capital and expertise also created a level of competit...