Changelog

These are the latest updates we've made to our platform. If you have any questions about any of the updates you see below, please feel free to contact us!

Date

January 2023

December 2022

  1. We have updated the VPN Profile Page with a much more efficient design. You can start your Internal Assessments faster with the easier deployment of VPN Agents, batch testing multiple VPN Profiles, and having all the details at a glance with the new slide-over (such as assigned Workspaces or OpenVPN Logs).

November 2022

  1. New attack type in Password Auditor: Password Spray

    Copy link to “New attack type in Password Auditor: Password Spray”

    In addition to the existing attack type, Dictionary, we've added a new one. Password Spray will try for every password every username in the wordlist, before moving on to the next password. This helps to avoid account lockouts that would normally occur when brute forcing a single account with many passwords.

  2. You can now use our Sniper tool to create client-side attacks. Generate a 'malicious' file (doc, docm, xls, xlsm) containing obfuscated VBA and send it to your victim user. Once they open and enable the macros, Sniper runs all the extractors on their machine to gather evidence of the successful attack. This approach does not use any exploits.

  3. We've replaced the old Dashboard page with a new, beautiful page. Now you can view the trend of vulnerabilities for the current workspace on the last 14 days, see at a glance the whole picture of the attack surface for the current workspace and more.

October 2022