- See why passive defense is dead in modern cybersecurity.
- Learn how to map your attack surface the way hackers do.
- Understand why threat intelligence is imperative for a proactive approach.
- See which ASM and threat intelligence capabilities Censys offers.
- Watch real-world threat hunting and asset discovery in action.
Most security strategies still operate like it’s 2015. They build higher walls, patch faster, and hope attackers lose interest. But today’s adversaries are persistent. They continuously map and aim to exploit your attack surface. If you only play defense, you are letting them dictate the pace. ASM shifts the advantage by proactively discovering, monitoring, and reducing exposures before they can be exploited, forcing attackers to work harder for every inch.
By adopting an attacker’s mindset, you stop waiting for the breach and start finding your own weak spots before they do. Attack Surface Management not only identifies what is exposed but also provides a dynamic and continuously updated view of your digital footprint, highlighting exploitable paths and unknown assets.
Think like the enemy, move like the enemy, and neutralize them before they even find you.
Osman Celik, a Research Analyst at KuppingerCole, is the author of the ASM Leadership Compass. He has been working on why proactive cybersecurity solutions and strategies must replace reactive ones. He will share his insights on how ASM solutions help you stay one step ahead of cybercriminals. He will also explain why threat intelligence is essential to an ASM solution.
Tabatha von Koelichen, Regional Sales Director for DACH and Central Europe and Harald Roeder, Senior Solutions Engineer at Censys and will show exactly how to operationalize attacker-first thinking using Censys’ global Internet intelligence. He will dissect real breaches to reveal where defenders missed their chance, demonstrate live threat hunting techniques, and walk through how Censys uncovers assets you didn’t even know existed because if you don’t know about them, attackers already do.
Who Should Attend
Designed for CISOs, security architects, threat hunters, SOC analysts, and IT leaders responsible for defending complex infrastructures.
Hi everyone, my name is Osman Celik. Today we are going to have a webinar around Outsmarting Cybercriminals by Thinking Like One and I'm joined by two valuable members of Censys today, Tabatha von Koelichen and Harald Roeder.
Hi guys, welcome. How are you guys doing?
Hello, good. Thank you so much, Osman. Great to be here.
Yeah, welcome. Yeah, so before we jump into our webinar directly, let's do some housekeeping first and then I remind you the rules how to use this platform we are using and this Livestorm website. So you are centrally muted so you don't have to worry about controlling your audio and we are going to run some couple of poll questions and then at the end we are going to have also a Q&A session.
So you will be more than happy if we receive your feedback and in today's webinar we will start with my part and then our guests from Censys will do their presentation and at the very end we are going to have a Q&A session. There you can freely ask your questions using the chat button in the right-hand side and also for other purposes you can see that interactive buttons over there for the polls and also for other purposes you can use that interactive section.
And don't worry we are going to record this webinar so if you cannot make it until the end or if you are not joining us today now but you want to watch it later on we are going to make it available for you both the webinar and also the presentations. So here you're going to see again the agenda of our webinar today and our first poll question. I will quickly give you like five seconds for you to see it and then answer it. You can always answer it using the interactive tool right-hand side on your web browser. The question is does your organization have an ASM solution in place today?
Let's begin with my part. So tech service management is an area that I've been working on the last two and a half years and then as Coopinger call we really devoted ourselves to understand the market and then the solutions and then what makes it so unique. So in order to understand why you need a solution you need to also understand the challenges that are making you require one.
So to be honest if you want to get this if you want to understand the position of a cyber criminal and understand their mindset you have to understand their reasons the technology they use and then their ratio analytic. So if you want to take this approach to cyber security you cannot be reactive anymore. So you have to step you have to choose the proactive cyber security strategies and there are tools and technologies for that.
One of them is for me one of the most important one the emerging one is attack surface management and we might list a lot of things why you need an attack surface management but here I quickly list why you need one. Because reactive cyber security solutions are no longer enough because then they are taking actions after you are either if you are already hit by a cyber attack or if you already have downtime in your system or if you already have an operational disruption.
So these are already when these are already done so I mean there is no point to be reactive sometimes because then the harm is already done and your reputation is already gone. So please choose some proactive solutions instead of reactive ones and we have now in our organizations we have a lot we have an attack surface that is extending enormously. So we have interconnected devices like cloud environments in some cases we have IoT and OT sensors and also other smart devices that the list can go on. So ISM provides you a good coverage of these also interconnected devices.
And as your business grow you need some sort of flexibility and scalability and also automation to manage your users your customers and your employees. And infrastructure is also getting more complex like similar to the your attack surface devices and assets in your tech service management. So you might have multi-cloud or hybrid cloud setups modern and legacy systems working together so you need a solution that is able to monitor and identify the assets and vulnerabilities that are taking place in those infrastructures.
And yes every the buzzword AI right so everyone is talking about AI and the machine learning and how they are affecting our daily life. But although it is very nice technology very useful technology we also need to know that cyber criminals are also using it against us. So the emerging attack vectors like for example an efficient attack automated by AI is much more complex and more sophisticated than the efficient attacks that we are used to see in the early years. So the attack services are growing and also attack vectors hitting to that targeting those attack surfaces are also evolving.
So we need some up-to-date solutions. Like always we also need to comply with the regulatory we need to comply with the regulations and then in this case ASM also helps us with the meeting the standards and also the regulations. As I already mentioned the legacy solutions will not be enough they are mostly reactive and then they are going to let you deal with already with the with the incident that you have in your organization. So that's not something we want to see.
And on top of that we are now living in an interconnected world where all the organizations all the companies are kind of needing each other. So we need our supply chain vendors we need other providers we need we have our managed services. So we are heavily relying on third-party organizations and vendors and then our partnerships with them. So there are some tools we might want to take a look at what is going on with them as well in their cyber security landscape. So there are still now tools that are allowing you to scan and monitor even your business partners and their attack surfaces.
So I think that these are the very important reasons and significant causes for our organizations to have one proactive cyber security solution and I think ASM is one of good example for such solutions. So how does it work? In my case in my report I created four subcategories for ASM because depending on how you look at it some organization some some vendors call it exposure management some call it next-gen vulnerability management but let's not get stuck into that but let's focus on the real purpose of it.
So that's why I created this sub categories four subcategories so we can understand without focusing on how vendors name their solution and then we understand the functionality instead.
So the first one is CASM cyber asset attack surface management this is made these solutions mainly look at your inventories and your cyber assets and then they ingest data from your discovery tools your CMDBs or vulnerability scanners or your endpoint agents if you have one and these can operate both on on-premises and in the cloud if you are if you already have this if you have solutions deployed on these environments yes and the second one is external attack surface management this is I would say the most popular solutions in the attack surface management the market and then these solutions identify to aims to identify your internet facing assets so they look at your website your domains your subdomains your subsidiaries your cloud services APIs if you have any shadow of IT risk or not and so on.
The third one is a bit different than these first two because in the first this CASM and ESM we are most most likely focused on your assets in your organization and the possible vulnerabilities that might hit you but in the other ones the DRP and TPRM we are going a bit beyond this level and in the DRP we see solutions offering dark deep web monitoring social media monitoring and brand protection executive protection and also like detection of leak credentials and so on and for the third party risk management like I described in the previous slide these solutions help you monitor your external vendors and your service providers so they can understand the risk arising in your digital supply chain so they are also very unique but four of them could be offered in one single solution by a vendor or we can see one when they're only offering CASM or a combination of all these four and why do we need this is very very I think easy to understand is because once you have these tools you are going to have a better situational awareness of your attack surface and then you are going to understand the risks that might hit your organization and then you can relate it to your departments your regions your subsidiaries and etc and again you need you want to mitigate the risks that are not causing by you but your partners and overall you want to increase your security posture and most importantly maybe here the tech surface management is can be also a complementary tool to your overall cyber security strategy it's not something that you need to use it alone but you can integrate with your ITSM or your SOAR or any other solution cyber security solution you have in place most solutions most vendors in the market provide integration options either out of box or through APIs customized third-party integrations with your other cyber security tool sets you have in your in your organization here you see a workflow of a typical sorry you see the typical capabilities of an ASM the workflow of ASM is discovery assessment prioritization and remediation you see that they are all lining up underneath this four main category I'm repeating again discovery assessment prioritization and remediation so today we are gonna not talk about all these capabilities but we are going to take a look at a bit of attack surface mapping I'm going to talk about it and then we are going to spend some time on cyber threat intelligence and census will provide you also very valuable information regarding that how they combine the attack surface management and CTI so this was my evaluation criteria we call it spider chart at Copenhagen call so these are we could say eight main pillars of attack surface management and this is this image actually is retrieved by my report so this is actually this actually belongs to a vendor I cannot name the vendor but as you see we score their eight main capabilities in the ASM market and one of them is cyber threat intelligence so let's understand why CTI matters for ASM because to be honest yes CITM matters for ASM but it's not only a key capability that ASM is leveraging it is a capability that so many different cyber security tools are leveraging also for example web application firewalls or network detection and response tools or other extended detection and response tool are mainly using cyber threat intelligence to enrich and contextualize the risk that might hit their organization yeah on I can also think about like SOAR and SIEM also using it so ASM is not the only solution but it is a critical part of ASM because it enriches your understanding of your attack surface and another thing here is I could talk about is that the MITRE ATT&CK it's a non-profit organization actually I would like to share with you but at the time because of the time limitations I'm going to briefly talk about it so the MITRE ATT&CK mapping is basically is it's a globally accessible knowledge base of adversary tactics and techniques based on real world observations and then they have categories like let me tell you like reconnaissance the initial access executions like privilege escalation discovery lateral movement collection etc they have techniques that are mapped to to different use cases and then the how attackers actually utilize this so you might want to have a solution that is able to do that because then you don't have to go and try to understand every threat every CVE that you receive and then you don't really need to go and have a full understanding of and then you know where to begin as well because one of the most important point of ASM is prioritizing and then getting rid of false positives so you know where to start and what to remediate so of course we need a better management of CTI data now and then we are using tools like AI and ML because the volume of the CTI is a lot large and then you cannot really analyze it and also spend hours on it to manage and I would say that especially if you are if you have like NLP in your workflows if you need to deal with like road threats and then NLP extraction and then if you need to correlate and reach something then you need a CTI tool that can actually utilize AI and ML and make useful and it's a beneficial outcomes out of the threat intelligence that you are either receiving or generating.
Yeah and nowadays we also hear a lot about the agentic AI and here what matters for me I have I haven't seen that much of solutions that are utilizing agentic AI but this could be something innovative for the market that I realize that most solutions are using gen AI but this is a technology that's acting upon your request so that is not taking autonomous decisions and they are not able to minimize the human supervision so agentic AI use of agentic AI could really empower the CTI and but for now I know that this is not something really super realistic to expect from vendors to invest in it's because your resources and also you might need to wait if there is anything violating the regulations as well So to wrap up my points I would like to share with you the main use cases of CTI in ASM.
You have better threat detection response and then you can prioritize the vulnerabilities that might that you have or that that you might have you know as your organization so you need to prioritize them and then you need to see if there is anything that you need to fix first so ASM combined with CTI will help you that same goes for alert prioritization these two can be actually relevant so you need to find out what is most relevant to you you have a better understanding of your supply chain actors and then you have also your subsidiaries so you have a better risk management arising from your partners you have the control of your users your customers and then your employees and then if in case if your brand is in danger if some brand impersonation or impersonation attacks are happening in social media or if your employees credentials are leaked on dark and deep web and you can also understand the the threat actors where they are from what are their aims if they are actually coming from another country if there's any other political reasons behind or such attacks and finally you also have easier operations I guess for getting complied by regulations and by standards so here is our second poll question has how has your has your organization organization cyber security budget changed this year compared to last year so you can answer this question I'll give you five seconds please use again the the interactive tool we have in the right hand side and then I think that from here on I'm gonna leave it to Tabata and Harald for for doing their part very good thank you so much Osman you know good afternoon to everyone it's really a pleasure to be here with you today and we'd like to thank the team from coping our call for the invitation to participate in this webinar and also for the very professional organization so thanks Osman to you and and your colleagues my name is Tabata von Kurlichen and I'm the regional sales director at census and joining me today is my technical colleague Harald Rueda who is our senior solutions engineer and we are the local census team responsible for supporting both our customers and our systems integrators in the Dach and central eastern regions in addition we also cover off Israel and Turkey next slide please at census we like to say that we are the experts in threat hunting and cyber intelligence and thanks to our global scanning infrastructure we have access to the latest and really the most detailed data that you can use for proactive cyber defense with our CTI and the information that we provide you about exposures threats threat actors and threat groups we can really help you to stay one step ahead of the hackers and the attackers which is ultimately where you want to be we've got an exciting agenda so we've got about 20 minutes to cover off all of these topics we're going to start with a brief summary of our findings from the new census state of the internet report we bring one of these out every year afterwards Harald is going to give us a short live demo he's going to give you a quick tour of our census platform and threat hunting module and show you how you can use it to search for exposures today we're not going to be showing you a full demo of attack surface management because it is a tailor-made risk analysis of your assets so it's much more relevant for us to provide you with a personal demo which we'd like to invite you to ask us for we can provide the possibility to build you an attack surface management workspace and then discuss in detail your specific project look at your assets in detail and see the associated risks so today we're going to be focusing more on our flexible solution we are then going to present some very concrete examples of how census can be used to uncover exposures and vulnerabilities in your infrastructure and help you to of course discover those find them and fix them before they are that you really have an up-to-date view of your attack surface and that you take a proactive approach to detecting and preventing cyber attacks and we're going to discuss that a little bit more in detail and show you how census can really help you in achieving that goal and finally we're going to introduce census as a company to you and explain how our scanning infrastructure works because that's kind of interesting to know and finally we'll also show you how you can sign up for the next slide please at census i think you might have to oh there we go the graphics have just shown up okay perfect at census we have a pretty large research team that produces a report every year last year they focused on industrial control solutions and systems this year the brand new state of the internet report focuses on our analysis of c2 infrastructure so this year we also looked in detail at some more well in more detail at some recent incidents and we're going to talk a little bit about that and how specific threat actors are using exposures maliciously so our report and i've put in a link here at the bottom was recently published as a six-part blog series so there's a lot to read through but i invite you to take take the time to do that later we're just going to summarize the main findings for you here so c2 infrastructure as you know are servers and networks used by hackers and attackers to control and coordinate cyber attacks and with census scanning infrastructure we can identify these so our research team was looking at a specific c2 infrastructure between december 2024 and may 2025 so over a six-month period and on average we found about 3 000 malware detections worldwide threat actors as i explained rely heavily on c2 infrastructure and we could see that the most common type of c2 infrastructures were cobalt strike with 34 then we have viper sliver and rem costs and we found malicious infrastructure really spread out across the world to be specific in 62 different countries so you can see that china and the usa made up the majority with 55 of the global malware activity but you can also see we've got some european countries up there the netherlands germany as well as the uk the high concentration in china in the us can definitely in our opinion be linked back to the wide availability of hosting providers in those countries so we discovered that networks belonging to alibaba and tencent in china as well as cologics in the usa were particularly impacted and we also saw some uh well some very well-known global players like amazon and microsoft so next slide please harold our research shows also that c2 infrastructure is very short-lived cobalt strike typically has a ttl or a time to live of about 11 days viper 17 days both can be tracked through unique watermarks so we look at that we observe very frequent changes in both their network and content behavior and this rapid turnover or a lot of changes really highlights the need to have continuous monitoring and a solution that gives you a real-time view of what's going on out there we also know that malicious well malicious actors are using open directories to often expose payloads web shells and malicious tools and with our scanning infrastructure we can also recognize these we can even tag specific uh open directories that meet certain criteria as suspicious directories and harold's going to show you that in a minute um again we found here that the median ttl is really short between one and three days so across both the network and content so it really shows you just how fast this kind of malicious infrastructure is being modified and why you need to have a real-time perspective our research team as i explained looked at a number of recent incidents so they looked in detail at threat groups and threats and um and and attacks like beaver tail clop secret blizzards um yeah dragon force and polar edge to name a few and what we're seeing a few trends we're saying that attackers are getting very creative they're often exploiting cves they're looking at iot devices as a as a vector to penetrate and um we even saw an increased use of home routers as well for specific attacks double extortion is the standard right so they make you pay twice not only just to de-encrypt your data but also to avoid your data which is sensitive of course being leaked and um since these threat actors and groups are extremely well organized and extremely well financed uh often better than the the corporates that are are fighting against them um it's sure that ransomware malware which is the main problem will continue to just evolve develop they're using ai as well and that the number of incidents is going to continue to rise so understanding being able to track and disrupt adversary infrastructure can only be really done with real-time accurate internet-wide visibility and historical context so census can help you with all of these things and next slide please i'll just very quickly explain a little bit about our solution so census um has built and operates the world's largest global scanning infrastructure and it allows us to scan the entire internet and all connected devices multiple times per day so we scan not only standard ports but we also scan the non-standard ports which are really important to look at when you're looking at attack vectors and we provide our customers with very up-to-date very accurate and detailed internet intelligence so um our data is what we call the census internet map and we offer three different user interfaces to access our data um if we start here in the middle we've got our enterprise platform license and this option includes our worldwide data set and allows you really almost like a search engine to flexibly search for anything that's of interest for you um you know you can just put in a top domain or an ip address and off you go you can search for hosts web entities and certificates and you can get back detailed information that provides your SOC team with insights into what's going on right now uh as well as what happened in the past so um the previous version of our uh solution was called search and in that version you lean based query language now with our new user interface the platform we've integrated ai and um actually our uh our user interface speaks many different languages so um the ai is used to convert natural language into um our senql which is our new language and we've tested it out with many different languages and our ui seems to understand pretty much all of them um and what's also very cool and harold's going to show this is that you can even do an on-demand rescan if you want to check if something has changed uh if we move to the right we have our threat hunting module which is an add-on license specifically built for threat hunting teams and at census right now we're tracking about 125 individual threats and um you can see these in our threat dashboard uh we currently know that about 15 000 hosts worldwide are being used by these different threats and threat groups um and uh you can use this module of course to help you better track c2 infrastructure so the heat map that we provide you with is it's dynamic it's continuously being updated it can be used for something as simple as using it to um you know update your firewall block lists and to you know to ensure that you're not communicating with any of these infected hosts and it really helps threat hunters and threat hunting teams to save time because they can very easily pivot down and look for similar infrastructure they can do on-demand port scans and even view timeline of specific certificates so um finally on the left hand side and uh again we prefer to do a a tailor-made demo for you and look at your assets in a in a kind of more of a is focusing down on your assets and the risk associated with assets so basically we do an attribution based upon your seed data and this solution provides you with a daily updated risk dashboard shows you the holes in your perimeter gives you the external perspective and shows you kind of how a cyber criminal would look at your security posture from the outside in and we have a lot of customers that are also using it to monitor the risk associated with their third-party suppliers now we all know what happened at the airports last weekend right so third-party supplier security is a big issue at the moment we have some customers who even look at look at it during the due diligence phase of when they're doing an acquisition and we have also some mssps service providers that are using our solution to monitor services and and security of their customers so at this point um yeah we've just sort of given you an overview of the different options and i'm going to pass it over to harold and we're going to show you a live demo of how it really looks like in in uh in real time yeah many thanks top and many thanks osman also a warm welcome from my side to the audience so i will now try to give you a sort of a live demo and if all works well we should be able to see the platform so that's the flexible tool what top mentioned before um as we have not a lot of time today i will go very quickly and i'm more than happy if you reach uh after the webinar out to us and we can do in a in a more uh depth manner let's say so that's the platform you just can very easily look for an ip address and i use now google you get the latest candida where the host is located all open ports and protocols um we have also the the possibility to look um at let's say a company and i have prepared prepared something for a fictional company called acme.com and what i am doing here is when i look to the to the query i look for any host names are associated with acme.com any certificates any certificate names where is acme inside the certificate name for any hdp headers with acme or third past subject organizations or even where i have in the whois organization contact email anything with acme.com that brings me to 408 000 hosts today we do not see any certificates and any web properties because that is just a fictional company which does not really exist but there are a lot of admins or or tech guys or nerds out in the out in the world using this fictional organization in the certificate when they set up test systems and stuff like that yeah there you get then threats where we detect a threat on different threats on different hosts cves you can also look what software we can uncover software products we have service labels so where is a login page behind remote access look to the the protocols and the transport protocols and even show you on which network these hosts are running and where are the geolocation you can with the a feature called collection monitor this infrastructure collection build let's say monitors your search query and keeps you informed if any hosts have been added to that hit list or removed from the hit list i have here one collection quickly prepared for um a different a different search so in this search i'm looking for iot devices with a login pages in germany so everything with modbus bugnet dnp3 and a valid let's say a web page with the status code 200 so and also a label login page and we monitor this infrastructure now since four weeks and we have 997 assets right now and you can see that 66 assets have been added during the last 24 hours and then you can look to the assets and have a deeper look what is exposed and what's running on it so but today we want also to do to concentrate on our threat hunting model and it will take a little bit and that's the the threats explore page let's say and there you can filter down for for different threats for different threat names or even for different threat actor groups and we will not do today a for command and control we look to suspicious open directory and filter it out here and you can see we detected 4917 hosts of a suspicious open directory and and what tab mentioned you can even say okay i want to filter it more down to let's say a location to a to a country and i can do it in german maybe or you can put any any other language and therefore you get the query and then it will be filtered down to germany and then we have a hit of 294 so as in this demo we are also looking to to the remote access and i want to have a look into to rdp so we're also not only an open directory is exposed and i have also remote desktop protocol running on it so i will filter it down also to rdp and then i get around my my hit list gets smaller and smaller 28 hosts and i have uncovered one host which looks quite interesting it's this one because at top mentioned this infrastructure and which hosts are having threats and adversary infrastructure is changing very very quickly and when you do a demo you have to to check it let's say at least four hours before because it the host could be already in a in a different state so we see here we have a suspicious open directory also label remote access we scanned this host today about lunchtime we have a lot of different open ports here you can also look also look to the threats you get a threat description of it and then we can look to the services we could even go to the to the event history and look over time what has changed on the host if some ports have been not opened or different ports had been open before but as we do not have a lot of time we we keep this part of the demo out and therefore you see we have also screenshots now you see here what's in the open directory you get a password zip file then if we go down to the different open ports you get snb is open and you see also the remote desktop protocol from a windows 2012 server which is already end of life and to to find let's say similar infrastructure we have a large pivoting function in our tool let's say we are interested in a special file name this looks some like some video stuff in it ffmpeg and therefore I can go into the tool and look for files with the same name or files with the same name and size or with the same extension and then I get a new pop-up a new window and I'm getting different hosts here and you see already two there are located from amazon web services in in Oregon in the US and if I look inside the the open directory here again the screenshot I can see that the same file name with a different size is also in another host and I think from a time-wise perspective tap we are have to move very fast so indeed yes so that was a a quick demo how you can our threat hunting tool to uncover threats and adversary infrastructure I move back to the presentation mode and just going ahead there are a few other examples where we uncovered go to RTC servers that are let's say cameras connected to a web service or very often you can go to the live stream without any authentication so very very weird and another one where we uncovered VNC is also an open and remote desktop protocol very often used in the IoT world and therefore we can also find infrastructure very directly can go to the to the remote access host and go to the to the heating panel and let's say adjust some temperatures and do weird stuff on this heating system one thing I want to to cover and it is quite important that we recently introduced our model context protocol service for all of our products and what that means that is a middleware and you use a software like cursor and connect it to a LLM module like Claude as an example and then you can ask questions to the MCP server to get a threat report to do let's say also what we have done ISM style attack surface management report style and the MCP server is asking our APIs and getting all the data and pulling it back to the to the LLM module and what we have done for our own paperdown.cloud demo asset is here a risk dashboard and uncover how many assets we can find how many exposures where are the hosts located what is running on an unusual port and we also can in the in the whole report we can show you all the CVEs and vulnerabilities and that's let's say the art of the possible what we can do with artificial intelligence and all of the AI stuff.
Great thank you Harold so I hope it's very clear to everyone that we are the one place to really understand everything on the internet and that we've established ourselves as the authority for internet intelligence and insights. Next slide please. I see that we we don't have too much time left but it's all about visibility it's all about providing you with the capability of proactively protecting yourself. We have very flexible solutions that provide you with real-time information they can also go back into the past and provide you with historical insights.
We fit seamlessly with our attack surface management into your security stack and whether you're a large corporate customer or an MSSP or a government agency or intelligence or military whatever it's all really about providing you with the visibility of your attack surface and making sure that you are proactively taking care of your vulnerabilities and exposures before the hackers and cyber criminals find those.
So I think at that point we're gonna go to the next slide and Harold do you want to just very quickly explain our scanning infrastructure because I think it's important for everybody to understand that. We'll do it in two minutes.
So what we believe what we have done the last couple of years we have set up the world's largest internet scanning infrastructure and what that means we currently installed at seven different tier one ISPs across three continents and installed means really that we not just rent there a virtual host or a host at the ISP we have a full rack space in all of these seven locations and also the hardware inside the racks is our own hardware where we have full access to it and what on the hardware what is running on the hardware is our protocol and deep protocol scanners for now we have around 210 protocol and deep protocol scanners we're all developing these scanners also ourselves so our engineering and engineering and development department is around 50 people strong and we write the scanners ourselves and also maintain the hardware and the infrastructure ourselves so we concentrate very very hardly on the full 65 000 port range so we very often uncover ports where let's say ssh rdp telnet services are hidden between a weird high port number and we have also a large certificate database where we can look for certificates also from a historical perspective and also from a from an internet history perspective we have available 20 petabytes of data and with this set as top mentioned we offer let's say two two modules the platform the flexible tool and the tailor-made solution our asm solution great so there are two ways to try out our solution completely free of charge actually i'll change that there are three ways so this is the first one we recently launched a chrome plugin for your browser and you can just and you get 50 free ip lookups per day the other way which is on the next slide and you can take a picture of the qr code is to sign up for the free version of the census platform with limited features but it will really give you a good idea of the quality of our data and the third way is you give us the chance to build for you an attack surface management workspace and that we show you our results for your organization and present that to you in a presentation so we look forward to hearing from you last slide is our european team at census and as i said harold and i are responsible for central eastern europe we have colleagues in the nordics and benelux as well as the uk ireland and africa so looking forward to hearing from you with your more details about your projects and how we can work together perfect thank you very much it was a great presentation and also a live demo i would say all right so before we actually jump into our q a session let's give some time to our audience as well to also collect their thoughts and also answer our last final poll question what is the biggest challenge when implementing cyber security budget skills shortage wrong tool choice stakeholder management take maybe five ten seconds to answer that and also i would also like to receive your questions because now we have like around 12 minutes to discuss your questions it was great actually actually i wanted to start with the last slide you uh showed us so where do you actually operate do you are you like available in the all regions or like you focused in north america and europe only our headquarters are in north america but we have teams really deployed across the world with a strong presence in europe as well as in asia pack yeah so because uh i i thought that you are more active only in europe that was that was interesting no yeah no we are definitely well our headquarters is in ann arbor michigan so that's where we have offices around the us and we're covering off canada and and um well basically the americas from from uh different different points and different teams we usually have teams deployed with a salesperson and a technical technical um solution engineer all right so we have one question from uh alfred does census have the ability to uncover unidentified services good question okay well take it up yeah sure i can i mean we're we're a lot of different protocols i believe it's over 200 protocols at the moment but our research team is constantly updating the the different types of services that are out there and putting it into our solution so that we can recognize through our scanning infrastructure whatever new services um are are out there so yeah i mean the big the big focus of of census is really on ports and that's what we do um that's our that's our sweet spot and so of course we're constantly updating the different types of new services that are coming and it's publicly available so everyone can go to uh our release notes and read a weekly update where we uh tell uh tell you what we recently have added which scanners we have added uh which type of protocols we can uncover yeah as far as i remember it also stretches to ics protocols right or iot and ot if you would like to elaborate on this absolutely yeah we can recognize all types of iot um you know things associated with cameras things associated with industrial controls medical devices mot yeah yeah so you are then then working with these verticals as well that using critical infrastructure and so on right then that's a big focus for us in europe definitely so we work with all kinds of uh you know everything from telcos to energy providers to transportation organizations so yeah we have a big focus on that and of course because of compliance reasons at the moment with the this too they have to really step up and they're particularly concerned about the third party suppliers which is again what we saw with the you know exactly yeah all right the second question is but if you have if you're collecting data publicly sorry is the data census collecting publicly accessible or is it proprietary harold do you want to take that i can i can tell you the non non-technical uh which i think is a very i'll say that first yeah uh so we have a passive scanning infrastructure implemented so we knock on the door but we do not go through it and the data is absolutely public available and we doing so our scanners what we are how our scanners are written and what we can to uncover is of course propriety but the information is uh let's say publicly accessible absolutely absolutely and um just to let you know i mean we talked about the two different interfaces we have the flexible solution the census platform and the asm there's another option that we do offer specifically for those organizations that are very sensitive um to uh yeah i mean they want to have an offline version of our data and that is possible so that's usually military or intelligence or insurance that are asking for that and we can provide up to four years of historical data which then gets updated either on a daily weekly or monthly basis and um and that is uh yeah something that that contains petabytes of information so it contains four four years of yeah all right and can you also use it for forensic purposes sure that's what it's often used for or calculating risk models etc for in the case of insurance companies yeah perfect and one last question from our audience is there any upcoming features related to ai or machine learning and i can actually add to that like so many solutions it's also related to the last part of my presentation i see lots of efforts coming from some vendors trying to embed the agentic ai to their asm or cti solutions like cti feeds let's say so i would like to also hear what are your efforts on this or something in your roadmap yeah well um you know we we've we've built in the simple ai support with the you know language recognition to make our query language simpler we've also harold showed that the mcp server which is um you know something that we can use to filter down or make it easier to get through all of the data that we are collecting right so it's it's um i guess in that case it is agentic so it is really helping you to analyze those massive amounts of data and really ask specific questions in a in a structured manner and a manner that's easier to do without having to put in a specific query um so yeah there are lots of plans moving forward i don't know if we can talk about them all with without an nda in place but if you if you want to discuss with us our our development team is uh very open to having discussions and to uh we often talk to customers about what they are looking for um you know it's we have to fit into the jungle of security stack that's existing already right so we have lots of integrations we have lots of ways to help our take feeds from different sources add in our source and then um we have to be open to any kind of of ai uh you know solution at this point through through i would say um integration options yeah carol would you like to add anything to that no uh absolutely right so we have let's say absolutely uh with our cto a clear ai mission and we will we started building tools and we also will build new tools and also use ai to enrich our data set and be more flexible and be faster yeah and from my point of view i can tell you this when i was doing the research i also come came across with also some end user uh feedback and then for them what matters the most is remediation so especially in terms of attack service manager but i'm specifically talking about it now and when you hear their concerns then then you understand that they don't want to deal with lots of alerts coming up lots of risks hitting their uh firewall and so on so they just want to prioritize what is relevant to them so i think that ai or ml in this in this case is very useful to to to automate things and then make the analyst job easier and then so that they they know what is the context of the the potential trend or the vulnerability they have or what is relevant to them so in in some cases i see some context score risk scores relevancy score so on like they are all like at one point they are their purposes only to find out what is most important for an organization and what to prioritize what to remediate first so i think that could be taking more serious tasks tasks there and especially if we are jumping into a gigantic ai realm i think that's really exciting for me to see as well what our tools the technology embedded them can independently do in the future that's interesting for me and maybe i can connect it to one of our poll question here so i only see that only 20 percent of our audience today have actively deployed asm i think that is also applicable for cti use of cti here so only 40 percent of them are evaluating evaluation and the proof of concept phase and 40 percent of uh of them has no solutions yet no solution yet so if you would like to maybe wrap up in one two minute what would you like to suggest them why asm empowered with cti is so important nowadays i already shaped my point maybe you would also like to tell because you have these two modules in your solution both asm and very powerful cti especially you call it internet scans i know but maybe you would like to summarize why they should really consider now and because the 20 percent is really low for me now yeah i'm i'm in shock i think i need to yeah no uh guys please uh contact us let us know how we can assist you um it's absolutely essential to have a view of your external attack surface we do meetings every day with customers we build workspaces for customers we have projects asm projects where we're finding all not so pretty things out there shadow it cloud resources that were spun up without the it departments um you know visibility uh things that are vulnerable it's hard when you're a large organization to have a complete view of of all of these you know everything from certificate to web entities to hosts and things get forgotten things sometimes are not patched as they should be and you really need to have an overview like you said cutting through all the noise all of those alerts okay making sure that your attack surface management is identified the things that you feel are risky for your organization right so you can adjust the risk level in our solution you can remove resources or let's say assets that you don't think are associated with you we have a very flexible solution so that it helps you to really filter down on what's important to you and um i can only uh tell you you know the the attackers are getting very very sophisticated you absolutely have to have an external vision of what's going on out there and we can assist you with that visibility is key yeah and one one thing to add from my point um what uh what is what is very very flexible our solution is about is to kind of build multiple workspaces and we have companies having 60 different workspaces maybe sometimes i want to being responsible for different parts of the world or they have different organizations daughter companies or even use it for mergers and acquisitions and recently we just had the request that they want to have the cloud world in an extra workspace to just to have one workspace which is purely concentrating on on cloud assets and cloud exposures perfect yeah just to wrap it up one one last final uh verdict from me let's say because now i work in this market so much so for me asset and vulnerability monitoring or identification tools are like kind of the fuel the gasoline of a car but cti is like the nitrogen that like steps it up so i think that that kind of sums it up why you need cti if you want to be proactive today and yeah i think that should kind of be the motto and the final word of our webinar thank you so much for joining us and then i'm looking forward to see you guys again in another webinar thank you so much thank you very much
See All Locations
See All Locations