$4.99/mo - Save 61% With Exclusive 2-Year Plan + 4 Months Free!Claim Now

Permiso Launches Open-Source Tools to Enhance Cloud Security Detection

  • Last updated November 8, 2024
  • written by
    Writer

City, November 8, 2024 – Permiso, a leader in real-time identity security, has unveiled a suite of three open-source tools aimed at enhancing security teams’ detection capabilities against various cyber threats.

Founded by former FireEye/Mandiant staff, Permiso’s P0 Labs team has been developing tools based on ongoing threat research and real-world attack observations. To date, they have launched a total of ten open-source tools, including YetiHunter and CloudGrappler, earlier this year.

YetiHunter is designed to detect indicators of compromise specifically within Snowflake environments, while CloudGrappler queries high-fidelity detections related to known threat actors in popular cloud platforms like AWS and Azure. The company has also developed over 1,400 detection rules that have been integrated into various open-source projects, allowing security teams to enhance their detection capabilities across diverse environments.

Co-Founder and Co-CEO Jason Martin emphasized the steep learning curve for cloud detection, stating, “Our goal is to help security teams bolster their detections across their cloud environments without having to purchase commercial software solutions like a SIEM.” He further noted the company’s commitment to providing resources to aid the broader security community in defending against modern threat tactics.

The suite includes DetentionDodger, which identifies identities with leaked credentials and assesses their potential impact, and BucketShield, a monitoring system for AWS S3 buckets that ensures the continuous flow of logs and mitigates misconfigurations. Additionally, the CAPICHE Detection Framework simplifies the cloud API detection process, allowing defenders to create various detection rules even with incomplete API names.

Principal Threat Researcher Daniel Bohannon stated, “The collection of these three tools helps security teams immediately hone their detections and bolster their defences against a variety of cloud-based attacks,” highlighting that these tools not only prepare for future threats but also address existing vulnerabilities.

Permiso’s latest offerings signify a proactive approach to cloud security, empowering organizations to better defend against evolving cyber threats.