-
Notifications
You must be signed in to change notification settings - Fork 0
Blog: PTaaS is BS #119
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Draft
GlitchWitch
wants to merge
2
commits into
main
Choose a base branch
from
ptaas-is-bs
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Draft
Blog: PTaaS is BS #119
Changes from all commits
Commits
Show all changes
2 commits
Select commit
Hold shift + click to select a range
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,80 @@ | ||
| --- | ||
| layout: post | ||
| # The filename will be used for URL slug generation, try to keep it to 1-3 words | ||
| title: "PTaaS is BS" | ||
| # Keep the title short, does not need to match the filename | ||
| subtitle: "Why (we think) Penetration Testing as a Service is bullshit." | ||
| # Subtitles should be 90-120 characters | ||
| date: 2024-02-10 | ||
| # Date in YYYY-MM-DD Format, should match date used in the filename | ||
| date-updated: | ||
| # Date in YYYY-MM-DD Format. Add this if a change is made after the date above | ||
| author: Jade Null | ||
| # Use "GlitchSecure" if no author | ||
| coauthor: | ||
| # Coauthor or optionally the editors name | ||
| category: updates | ||
| # Use either updates, resources, guides as the category | ||
|
|
||
| image: | ||
| # Images are stored in the assets/img/ folder. | ||
| # Create a new subfolder within assets/img/blog/ for each post new. | ||
| hero: blog/10/header.jpg | ||
| # Upload a 1920x1008 image, replace 10 with the post slug or number | ||
| # This is used for the background on the post | ||
| feature: blog/10/feature.jpg | ||
| # Upload a 1200x630px image, replace 10 with the post slug or number | ||
| # This is used for the preview of the post | ||
| credit: Vladimir Srajber | ||
| # Include the feature photo authors name | ||
| creditlink: https://www.pexels.com/photo/horse-poop-on-ground-15671402/ | ||
| # Include link to original photo source | ||
| hero-vertical: true | ||
| # Whether to use a vertical layout. Default is true for blog posts. | ||
| hero-wrapper-padding: "pb-24" | ||
| # This must be set to "pb-24" when using a vertical layout and removed when not. | ||
| comments: true | ||
| # Whether or not comments are enabled. This hasn't been implemented yet, but generally we can leave them enabled for anything that's not an update. | ||
| --- | ||
|
|
||
| Recently a redditor asked ["What the hell is PTaaS?"](https://old.reddit.com/r/cybersecurity/comments/1acpbmi/what_the_hell_is_ptaas/) | ||
|
|
||
| This is a really good question. While every vendor has a different spin on what they call Penetraion Testing as a Service, the term is often assoiated with one or both of the following: | ||
|
|
||
| - Providing Penetration Testing services in a more real-time manner utilising a custom built dashboard or off the shelf software like Plextrac instead of forcing you to wait for some consultant to craft a PDF in word. | ||
| - Using crowd-sourced gig-workers to more quickly spin up a penetration test at a lower cost. | ||
|
|
||
| In this article, we'll dive into why we think the PTaaS model is marketing bullshit, and why we actively avoid using it. | ||
|
|
||
| # Traditional Penetration Testing | ||
|
|
||
| Before we dive into PTaaS, it's important to look at how Penetration Testing has historically been performed. | ||
|
|
||
| Usually the process looks a little something like: | ||
|
|
||
| 1. Find a reputable security consultancy and work with them to scope out a test | ||
| 2. Get a quote and set a time on the calendar for the test to begin | ||
| 3. Anxiously wait for the testing period to come and go, get a fancy PDF report some time later | ||
| 4. ~Argue~ work with the consultants to ensure your patches actually fix the flaws. | ||
|
|
||
| This process often involved a lot of spreadsheets, emails, and meetings. While some consultancies figured this out better than others, it's a process just dieing for a software solution. | ||
|
|
||
| # -aaS All The Things | ||
|
|
||
| Efforts to streamline parts of the traditional penetration testing process with a software platform have always been a thing. But where there is software, there are people looking to turn that into a subscription. | ||
|
|
||
| # Uber for Pentesting | ||
|
|
||
| One of the most infamous users of the term, the ~dingleberries~* lovely folks at Cobalt, [once described PTaaS](https://resource.cobalt.io/hubfs/Pentest_as_a_Service_Impact_Report_2020.pdf) as the following: | ||
|
|
||
| > We define Pentest as a Service (PtaaS) as a service that utilizes a global talent pool of certified | ||
| pentesters and a data-centric platform to deliver pentests. | ||
|
|
||
| <small>* Cobalt once spent 6 months trying to bully GlitchSecure and a friend of the company with legal threats, but that's a story for another time! Don't waste everyones time again Chris ;)</small> | ||
|
|
||
| Building on the backs of commerical and open source penetration testing platforms alike, | ||
|
|
||
|
|
||
| # It's all BS | ||
|
|
||
| # Other Options | ||
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Since I made this repo public today...
For legal purposes, my official stance is; fuck bullies we will fight back AGAIN and we will win AGAIN for needless bullshit threats.
You can screenshot this if y'all ever want to threaten us again, we will happily humiliate you all over. Let's be honest, we're better at "making security dance" 😝 .
p.s if you ever need a good tech lawyer with a sense of humour in your corner, Ranish Raveendrabose is your man.