Detectify’s approach to vulnerability analysis is one of a kind. Find out whether or not it is worthwhile to consider using this vulnerability scanner.
Detectify is a vulnerability scanning system that is offered in two different editions: one for internal scanning, which is ideal for applications that are still in the process of being developed, and one that does external vulnerability scanning and is intended for usage by IT operations teams.
Detectify takes a different strategy than other vulnerability scanners, which search for well-known attacks like SQL injection. This technique is what sets Detectify apart. The corporation has established a new organization in order to capitalize on the study of so-called “white hat hackers” and find new vulnerabilities that may covertly enable hackers to cause damage to systems.
Regarding Detectify
Detectify AB is a Swedish firm that began its business activities in the year 2013. One of the creators of the organization is a “white hat” hacker, and it is based on a tried-and-true technique for doing open-source cybersecurity research known as the bug bounty.
An organization known as Detectify Crowdsource is the driving force behind Detectify. Anyone has the ability to sign up for this system and subsequently disclose a vulnerability in the system’s security. Let’s say that the Detectify library doesn’t already have information on that vulnerability. In that scenario, it will be added, and the contributor will earn a fee each time that weakness is detected in a client system when it is being scanned for vulnerabilities.
The open-source security research process that is the foundation of Detectify serves as the company’s primary point of differentiation. It is continuously adding new vulnerabilities to its list of known flaws, but it does not share these flaws with the wider cybersecurity community. To make matters even better, Detectify does not charge any initial fees to run a research team. Only when they find a new vulnerability are penetration testers compensated for their work.
Finding vulnerabilities that are specific to a product can be a waste of money for cybersecurity businesses. This is because as soon as the producer of the product becomes aware of the problem, the producer publishes a patch, and the vulnerability is no longer a concern. To a large extent, all software manufacturers have access to free system testing services provided by cybersecurity companies that operate research labs. The high cost of research has been eliminated as a result of Detectify’s transformation into a middleman, and the danger of never collecting research costs has been transferred to individual technicians.
Regarding bug bounty programmes
Since quite some time ago, companies in the cybersecurity field have started using bug bounties. This presents an opportunity for a reward to anyone who can identify a flaw in a particular system. In a nutshell, this may work out to be more cost-effective than hiring a penetration testing team due to the fact that the commissioner will only be required to pay a single price and may be able to obtain the services of a large number of ethical hackers.
Anyone who attempts to hack into a system in order to claim a bug reward is, in essence, agreeing to place a wager on the outcome. The efforts of people who don’t give up easily. The few individuals who are successful in discovering an exploit are the only ones who get rewarded monetarily for their efforts.
Companies that offer bug bounties are obviously already familiar with all of the vulnerabilities, such as those listed in the OWASP Top 10. These are the lapses in security that are investigated by each and every vulnerability scanner. Therefore, a corporation that offers a bug bounty will already have closed up all of the vulnerabilities and exploits that were revealed by their vulnerability scans. Because of this, the only hackers who have a possibility of profiting from the challenge are those who find new vulnerabilities that cybersecurity companies are unaware of.
In most cases, a continuing offer of a bug bounty is made, which provides the business that is making the offer with continuous evidence that its security measures are effective. Since they are not required to pay anything for that verification, the cost of paying out when the security is finally breached is a relatively little expense for them to bear.
Detectify now has a bug bounty programme that runs continuously thanks to the establishment of Detectify Crowdsource. Because of this, it will always have a library of exploits that is significantly larger than that of traditional vulnerability scanning services. Due to the fact that the corporation does not pay a flat rate but rather a commission, even the most infrequently occurring exploit does not result in any financial loss for the business.
Because it uses an agency model, Detectify is able to list an endless number of potential vulnerabilities, some of which may be exceptional or very unusual and which, under normal circumstances, would be economically inefficient to investigate. Even if a software manufacturer disables an exploit, the fault in question is still important to look for because there may be a significant number of installations around the world that have not applied the patch that addresses the issue.
Find the hidden plans.
Detectify has three different plans available. Deep Scan, which is used to scan within an organisation, and Asset Monitoring, which is a vulnerability scanner for the outside of the organisation, are the first two of these. The third plan is called Get It All, and it is a combination of the Deep Scan and Asset Monitoring plans, in addition to a variety of individualised recommendations for system security.
You are able to sign up for subscriptions to both Deep Scan and Asset Monitoring if you so desire. Despite this, the Get It All plan won’t be completely modelled using this approach because the top system is a unique concept that also incorporates additional consultation services.
Deep Scan
The Deep Scan method works well in environments that utilise DevOps. It provides on-demand, scheduled, and continuous scanning, making it an excellent candidate for incorporation into a CI/CD pipeline.
Invoking the scanner for an on-demand run or going via the autodiscovery procedure are both viable options for how to utilise this tool. Loading a list or obtaining a feed from a platform such as AWS Route 53 or Google Analytics are both viable options for getting the system up and running, allowing for the possibility of either identifying all assets or scanning them.
Regardless of how the system is operated, the results of the scan will provide you with a list of assets found (although it is possible that there will only be one) along with an evaluation of the safety of each. The instructions that are included with the report on the results might be used to improve upon any areas of weakness.
The information contained inside the Deep Scan knowledge base is continually improved thanks to the contributions made by the Detectify Crowdsource system. In addition to that, the service makes use of the fuzzing methodology, which examines how an application responds to a variety of different input possibilities.
The capacity of the Deep Scan system to function as a component of a DevOps project system is the primary advantage offered by this software. The ability to automate test launches and feedback pathways is made feasible via integrations with Jira, Slack, Trello, OpsGenie, and Splunk. Because of this, the application security testing may now be started in an automated fashion.
Keeping an eye on the assets
Detectify Asset Monitoring is an external scanning service that does not rely on dynamic testing methodologies. In fact, that system markets itself as a service that discovers vulnerabilities that a DAST method would miss in order to attract customers.
The dashboard of the Detectify SaaS platform is where this service is managed and operated. After entering a URL into the corresponding field in the dashboard, the user activates the automatic scanning feature. A discovery service will be initiated by the vulnerability manager. This service will chain through all of the pages on a specific website and identify all of the components. After that, it searches for the location of such services and examines them to look for lower layers of support functions. This iterative procedure will continue until all of the infrastructure that is enabling the investigation has been located.
In the same way that Deep Scan can be linked to project management platforms like Jira and Slack, Asset Monitoring can do the same. The results of the scan can also be distributed to key individuals, who can be given recommendations for how to address any issues that were found.
The research gathered from the Detectify Crowdsource platform is incorporated into the vulnerability scanner that the Asset Monitoring service employs. A scan will investigate all of the auxiliary and supporting services, such as DNS records, containers, and management systems for containers. The system is also able to identify channels for the inadvertent leak of information as well as values that were carelessly hardcoded.
How much does it cost to use Detectify?
Detectify’s two more affordable options are available for purchase on a monthly subscription basis. The Enterprise package is more of a negotiated service that may entail one-time fees in addition to continuous subscriptions. Depending on the terms of the agreement, these fees and subscriptions may be ongoing or periodic.
The following is a list of the starting costs for Detectify’s services:
• Deep Scan costs $85 per month when paid annually and $105 per month when paid monthly.
• Asset Monitoring costs $420 per month when paid annually, but $570 per month when paid monthly.
A two-week trial period is available for either of the two programmes to be tried out.
Detectify deployment options
Detectify is exclusively offered as a software as a service (SaaS) platform. This indicates that you gain access to the service by utilising a dashboard that is housed on the Detectify server, and that all of the service’s processing operations are executed on that server.
The service is able to communicate with various different tools thanks to a number of integrations. This is of utmost significance in the Continuous Integration and Continuous Delivery pipeline deployment options for Deep Scan. It is possible to communicate with applications such as Jira, OpsGenie, and Splunk by downloading and installing free plug-ins for the system.
Determine the benefits and drawbacks.
The following is a rundown of the advantages and disadvantages of having a Detectify subscription.
Pros:
• An exclusive compilation of vulnerabilities gleaned from the hacking community
• A cost that is significantly lower than that of competing CI/CD testing services or vulnerability scanners
• A user-friendly service that only requires the input of an asset’s address into the dashboard in order to function.
• There is no requirement to host any software, as the cost of the service includes all software maintenance on the cloud server.
• A selection of scanning strategies for both the inside and the outside
Cons:
• There is a possibility that the novel approach to vulnerability identification offered by Detectify Crowdsource will not be very successful.
Optional Substitutes for Detectify
It is difficult to find an alternative to Detectify’s one-of-a-kind approach to gathering more intel on system security through its Detectify Crowdsource solution. Because of this service, the Detectify vulnerability scanner will always have access to information concerning security flaws that have not yet been found by any other research laboratories. Additionally, the system discovers new opportunities for damaging web applications without requiring the company to make any financial investment in the funding of a research team. As a result, the company is able to keep its costs low and undercut other providers of vulnerability scanners that are similarly thorough.
It’s possible that other new ways currently available for finding zero-day exploits and other security testing services could offer better strategies than those that Detectify currently provides.
The following is a list that we have compiled of the five most viable alternatives to Detectify:
1. Get a free trial of Invicti Access. This service can be utilised either as a vulnerability scanner for IT operations or as a continuity tester for CI/CD pipelines. Both of these functions are possible. Even though the dynamic and interactive application security testing systems included in this package are effective, Invicti’s competitive advantage comes from its Hawk detector system. This system runs through extended scenarios to identify out-of-band vulnerabilities, which are flaws that aren’t counted as errors in testing systems offered by other companies but which could easily compromise a system. It can either be installed on Windows or Windows Server, or it can be used as a cloud service. You are able to obtain a free trial.
2. Acunetix ACCESS FREE DEMO Both an external vulnerability scanner and an internal network scanner are included in this service. The external vulnerability scanner checks for 7,000 exploits, and the internal network scanner checks for 50,000 network-based vulnerabilities. This system is suitable for either testing performed by DevOps or IT operations. The scanning of assets that are more likely to be vulnerable to attack is given higher priority by the service. Acunetix is offered in three different plans, each of which is tailored to a specific kind and size of organisation. The service consists of a software package that may be installed locally and is compatible with Windows, macOS, and Linux. Register for a free demo.
3. GitLab Ultimate GitLab is an industry-leading environment for DevOps project management, and this is the most advanced edition available. GitLab’s most basic edition is available without charge, however the Ultimate plan is the only one that offers built-in security scanning using a DAST system. This product is in direct competition with Detectify’s Deep Scan option, and it is not appropriate for individuals who are primarily interested in a vulnerability scanner for IT operations. This application runs on a cloud-based platform, and you have the option of either hosting it on your own cloud account or subscribing to the SaaS version of the software. Get your hands dirty with the hosted version with a free trial.
4. Rapid7 InsightAppSec (pronounced: The sponsors of Metasploit provide users with access to this system. Since it can function as a vulnerability scanner for already existing live assets as well as be integrated into a development environment, it serves as a model for both essential editions of Detectify. The reports that are generated by this system for detected exploits include demonstrations of the code. This provides developers with the ability to comprehend how the problem can be fixed through a re-write. This cloud-based solution is available at no cost for the first thirty days.
5. HCL AppScan (in IPA) This service provides dynamic security scanning, static security scanning, and interactive security scanning for Web applications that are still in the development phase. As a result of the fact that the technology can also be used for external vulnerability scanning for established Web services, it is a good contender for Detectify’s Deep Scan and Asset Monitoring. This technique can also be used to test mobile applications to determine whether or not they contain vulnerabilities. In addition to being able to be installed on Windows and Windows Server, the package is also recognised as being in the category of SaaS platforms. A free demo version of AppScan can be downloaded and used.
Taking into consideration Detectify
The Detectify bug bounty technique might have several problems that could arise from it. The fact that there is not an immediate incentive means that the relatively small reward that is being offered by the business does not necessarily entice all of the information that is being acquired by its registered researchers. While a white-hat hacker may potentially make money through Detectify’s commissions structure over time, doing so might not be as immediately fulfilling as, say, selling a novel attack plan on the Dark Web in exchange for an advance payment.
In a nutshell, despite the fact that Detectify’s Crowdsource method appears to be successful on paper, it may simply be picking up low-value exploits that are discovered by hackers all over the world. Instead, it provides a clearance section for hackers who have realised that they cannot make a significant amount of money from some of the vulnerabilities that they discover.
Before making a purchase decision, it is important to evaluate Detectify in comparison to other Web application security testers. It is well worth your time to investigate the features that Detectify has to offer.