pwshub.com

New open-source tool from Permiso targets cloud policy obfuscation risks

Identity threat detection and response startup Permiso Security Inc. today released a new open-source tool that helps offensive and defensive security professionals understand how policies could be obfuscated by threat actors to go undetected in an environment.

Called SkyScalpel, the tool has been designed to address issues in cloud environments such as where JSON-based policies, particularly in Amazon Web Services Inc., dictate what resources users and systems can access and the actions they perform. Permiso argues that these policies can be susceptible to obfuscation — where bad actors manipulate the policy’s syntax and semantics to hide their true intentions, making them difficult to detect and prevent.

SkyScalpel addresses obfuscation by providing a solution for scanning, analyzing and normalizing obfuscated policies. The tool ensures that security teams can quickly identify and rectify policies that may compromise the security of their cloud environments.

Given a policy containing some obfuscation, the tool uses a custom tokenizer to parse and decode syntactical obfuscation techniques, allowing access to the underlying values while still preserving the original values for comparison or reassembly of the original input policy.

“SkyScalpel will help teams detect obfuscated JSON documents, with additional rules and de-obfuscation capabilities targeting numerous syntactical and logical evasions that affect IAM policies (and the plethora of runtime events that contain policy statements),” Permiso Principal Threat Researcher Daniel Bohannon explained. “Attackers employing these obfuscation techniques can quite effectively evade traditional string-based detections, with some techniques persisting after JSON deserialization.”

Additionally, SkyScalpel includes a full obfuscation suite of functions that allow red teams to automate the multilayer obfuscation of any input JSON document with additional obfuscation techniques applied to IAM policies. In doing so, red teams can more thoroughly test an organization’s defenses against such evasion techniques.

Permiso is a venture capital-backed startup that has raised about $39.1 million, including a round of $18.5 million in April. Investors include Altimeter Capital Management LP and Point72 Ventures.

The company was previously in the news in September when it announced the launch of its Universal Identity Graph, a service that provides risk and threat visibility for all identities in all environments. The Universal Identity Graph combines identity security posture management with identity threat detection and response to provide a comprehensive identity security solution.

Source: siliconangle.com

Related stories
1 month ago - Artificial intelligence infrastructure is taking really big bucks now to build out, as BlackRock and Microsoft joined this week to invest up to $100 billion in AI data centers and power projects. And that’s not all: Microsoft also teamed...
2 weeks ago - Artificial intelligence startup Hugging Face Inc. is looking to break down barriers to AI development with the launch of Gradio 5, the latest version of its open-source tool for building machine learning applications. The latest version...
22 hours ago - Decentralized social network Bluesky announced today that it has raised $15 million in new funding to expand its user base, enhance its developer ecosystem and continue building out features that prioritize user empowerment and safety....
1 week ago - Startup LatticeFlow AG today released COMPL-AI, a framework that can help companies check whether their large language models comply with the EU AI Act. Zurich-based LatticeFlow is backed by more than $14 million in venture funding. It...
1 month ago - Google LLC today rolled out new features for its artificial intelligence note-taking and research assistant NotebookLM, including the ability to upload videos from YouTube URLs and audio files directly, in addition to text, PDFs, Google...
Other stories
25 minutes ago - Nvidia (NASDAQ: NVDA) has been in scintillating form on the stock market in 2024, reaching gains of nearly 180% as of this writing. This is due to...
25 minutes ago - Two of these AI chips stocks have good reasons to rise today. The third, not so much.
55 minutes ago - Based on the growing demand for systems to perform tasks that typically require human intelligence, such as pattern recognition, data analysis, adapting to new information and real-time decision making, intelligent automation is emerging...
55 minutes ago - The rise of low-code platforms is reshaping the digital landscape, offering businesses a revolutionary way to develop software. Low-code platforms and intelligent automation help businesses handle “heavy lifting” by optimizing software...
1 hour ago - Stocks are reviving somewhat as a pullback in US bond yields lifted some recent pressure on risk appetite.