Skip to content

Why runZero is the best way to fulfill CISA BOD 23-01 requirements for asset visibility – Part 1

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recently published the Binding Operational Directive 23-01 for Improving Asset Visibility and Vulnerability Detection on Federal Networks. CISA’s asset visibility requirements are doing a big part in moving the industry forward and evolving our approach to asset inventory while also highlighting the importance of asset inventory in relation to national or organizational security.

The directive covers both vulnerability management and asset inventory. This blog post only focuses on the relevant parts for asset inventory. However, there are some important areas where the two disciplines interact and asset inventory is better suited to fulfill the requirements.

CISA recommends unauthenticated scanning for asset discovery

Many organizations are using data sourced from authenticated vulnerability scans and installed EDR agents to derive asset inventory. CISA’s directive demonstrates that while this is a viable way to augment the data set, it is no longer sufficient:

“Asset discovery is non-intrusive and usually does not require special logical access privileges.”

“No special logical access privileges” translates to either unauthenticated active discovery or passive collection, which is confirmed in the following statement:

“Discovery of assets and vulnerabilities can be achieved through a variety of means, including active scanning, passive flow monitoring, querying logs, or in the case of software defined infrastructure, API query.”

API queries are only recommended for software defined infrastructure, such as cloud-hosting other virtualized environments, but not for your physical network.

Log files can be a helpful way to augment breadth of asset inventory but they do not yield depth. DHCP and DNS logs don’t yield much more information than IP addresses, hostname, and MAC addresses. This misses the essence of what a device is: you know it’s there but you don’t know what hardware and operating system it’s running or what ports and services are active.

CISA directive solves for unmanaged devices

When talking to security teams about challenges with their asset inventory, they frequently cite unmanaged devices as the biggest headache. The CISA directive seems to optimize for unmanaged devices since these are the hardest to cover.

Many asset inventory vendors, particularly those in the CAASM (Cyber Asset Attack Surface Management) space, claim that you can magically solve for unmanaged devices via integrations with existing tooling. That is a great pitch, but it ignores the fact that security teams have tried to use the data from vulnerability scanners and EDR agents for asset inventory for a long time and failed. They do not provide the right data–we’ll get to why in part two of this series.

CISA is well aware of this fact and recently published a binding directive that requires more than just integrations for solving asset inventory.

We’ll take a deeper look into why that is throughout this blog series. Stay tuned for more details and subscribe to our blog so you don’t miss out.

Follow the story

Part two of this story was published on Tuesday, January 18, so be sure to follow the story. Also, don’t forget to subscribe for regular blog notifications.

Try runZero for free

See how you can comply with CISA BOD 23-01 using runZero.

Get started
Learn more about runZero

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About runZero
runZero, a network discovery and asset inventory solution, was founded in 2018 by HD Moore, the creator of Metasploit. HD envisioned a modern active discovery solution that could find and identify everything on a network–without credentials. As a security researcher and penetration tester, he often employed benign ways to get information leaks and piece them together to build device profiles. Eventually, this work led him to leverage applied research and the discovery techniques developed for security and penetration testing to create runZero.

Fostering a culture of kindness at runZero

Our world today is so fast-paced that sometimes kindness can take a back seat. At runZero, kindness is in the front seat, guiding how we work together as a company.

For us, it was really important for kindness to be one of our core values–not only because it aligns with how we work–but because it makes all of us successful as a result of it. We really believe that a kind environment cultivates meaningful work experiences that help drive greater success for our customers, employees, and partners alike.

To really deliver on instilling kindness throughout our company, we really focus on:

  • Always assuming good intentions
  • Being kinder than necessary
  • Working at sustainable levels
  • Hiring based on attitude and aptitude and promote accordingly
  • Being fair and respectful of the candidate and employee experience

Always assume good intentions

When we talk about kindness, we start with a shared understanding that everyone has good intentions. Oftentimes, even when someone makes a decision that seems a bit miscalculated, they do it with good intentions. That’s why we strive to assume kindness before anything else.

Instead of going into a conversation on the defense, it’s more productive to come prepared to have an open discussion. Asking questions demonstrates that you truly want to understand someone. For example, if a teammate has taken a different approach on a project, rather than making a statement, ask, “Can you help me understand why you chose this approach?” This kind of communication helps to build trust and kindness, as well as communication, in the workplace.

Be kinder than necessary

It’s not always obvious what someone is going through, so we genuinely ask people how they are doing. Whenever I’ve gone into a situation with guns-a-blazing, I’ve always regretted it afterward. It’s better to keep in mind that there might be something more going on. After all, there may be other things going on in their lives, including family, personal, and medical issues.

Compassion has a profound impact on people and can help create a supportive environment for everyone to thrive. For leaders and managers, it’s important to be compassionate and ask questions when an employee is significantly underperforming compared to their baseline. Try something like this: “I’m getting the feeling that I’m not getting your best work lately. Is there something going on in your life that I should be aware of? Is there any way I can help?”

This kind of warmth not only creates goodwill between both parties, it also indicates you are a more attentive leader. One study, which tracked more than 50,000 leaders, found that those in the top-quartile of performance ranked high on levels of warmth. As it turns out, the nice ones do finish first.

Work at sustainable levels

Some people have trouble believing this, but taking time off makes you a good employee. As leaders, it’s important to set this example.

Having down time allows us to take care of ourselves, our loved ones, and our colleagues. I recognize that it can be difficult to do in startup environments when there’s not enough people to go around to handle all the tasks. However, it’s crucial to make rest a priority for all. Otherwise, you may end up with a different set of problems when conflict inevitably arises inside your teams due to stress.

If your company has a PTO policy of “take whatever you need,” it can be helpful to track your days off in a spreadsheet. Research shows people actually take less than they should, so this is a good way to hold yourself accountable. As a leader, check in with your teams and make sure they are taking the time off they need to be productive.

Hire based on attitude and aptitude and promote based on merit and company needs

When it comes to hiring, we focus on more than just experience. We place a high value on attitude and aptitude, so that everyone has an equal opportunity to join our team and grow their career.

Just because someone has been doing their job for a long time doesn’t mean they are the best at it. We are trying to encourage more diversity in the technology sector, and if we rely mainly on years of experience, then we are dipping into the same talent pool as everyone else. We focus more on demonstrable skills and an attitude that is in line with our cultural values as a company.

We also strongly believe in promoting from within where possible, based upon merit and what best aligns with the needs of the company. This helps minimize regrettable attrition and reduces the amount of time onboarding new employees.

In order for our culture to thrive, positivity is essential. Negativity can spread like wildfire, so we take it seriously.

Be honest about the job

As much as we’re screening a candidate, the candidate is screening us as an employer. We are both trying to discover if we’re the right fit, so it’s important for both of us to be honest.

As an employer, we strive to be transparent with our prospective candidates by publishing salary range data so they can make an informed decision. We are also candid about the challenges of the role and our company, which helps build trust in our relationship. We ask all our candidates to be honest in their assessment of their skills, values, and concerns they may have about the role. We want everyone to start off on the right foot.

Another way we demonstrate kindness to employees is by compensating fairly. We pull benchmark data and compensate at the 75th percentile, meaning we pay better than 75% of employers hiring for comparable roles.

Our employees form the backbone of our company and we want to show how much we value their contribution.

Be fair and respectful to candidates and employees

Rejection is tough, no matter the circumstances, but kindness goes a long way in alleviating the sting of rejection. We try to be as empathetic as possible when dealing with departures of any kind–whether they come from a job application or within the company.

When a prospect has been in the late-stages of interview rounds and we feel we have helpful feedback, we offer to share it. We let them know it’s honest, constructive feedback, but we also also give the candidate the option to decline, as we understand that feedback can be hard to receive, depending on what’s going on in their life at the moment.

For outgoing employees, our company culture works hard to ensure kindness and respect during these transitions. Even when legal best practices restrict our ability to share details, we always strive to uphold our reputation of kindness and understanding at all times. We understand that people sometimes just don’t fit into roles and don’t take it as an indication that someone is a bad person or employee.

Why kindness = success

Kindness isn’t just so people feel good about their work. It’s also for the success of your company. A kind, fair, and just culture sets a strong foundation for employees to feel secure in their environment which increases productivity. A healthy company culture reduces conflict amidst employees so they can focus their energy on collaboration and productivity. Hiring is easier because you screen for candidates that share the same values and you create a positive reputation with candidates and recruiters.

Frankly, it’s also just the right thing to do. Companies are made up of people who deserve kindness from others.

Want to join our team?

Explore our open positions and find the perfect fit for you. Discover why runZero is the best place to build your career.

View open roles
Join our team

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About runZero
runZero, a network discovery and asset inventory solution, was founded in 2018 by HD Moore, the creator of Metasploit. HD envisioned a modern active discovery solution that could find and identify everything on a network–without credentials. As a security researcher and penetration tester, he often employed benign ways to get information leaks and piece them together to build device profiles. Eventually, this work led him to leverage applied research and the discovery techniques developed for security and penetration testing to create runZero.

4 Keys to Consider When Evaluating Cloud Data Protection Tools

External Article by Keepit Staff

Keepit’s Chief Customer Officer (and frequent contributing author to the Keepit blog) Niels van Ingen has been featured in Solutions Review as part of their “Premium Content Series” written by industry experts. 

As a true veteran in the data protection and management space — not only from a product point of view but also from a customer and business development one — Niels covers what he finds are the most important elements to consider when evaluating cloud data protection offerings.

Those who work in IT disaster recovery understand that data is perhaps a business’ most valuable asset that needs protection all day, every day. Implementing a SaaS backup and recovery plan is essential for nearly every aspect of business operations, and those who have not made it a top priority are literally flirting with disaster.

To read the full article entitled ‘4 Keys to Consider When Evaluating Cloud Data Protection Tools’ on Solutions Review, click here.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Keepit
At Keepit, we believe in a digital future where all software is delivered as a service. Keepit’s mission is to protect data in the cloud Keepit is a software company specializing in Cloud-to-Cloud data backup and recovery. Deriving from +20 year experience in building best-in-class data protection and hosting services, Keepit is pioneering the way to secure and protect cloud data at scale.

ESET Research discovers StrongPity APT group’s espionage campaign targeting Android users with trojanized Telegram app

  • ESET researchers identified an active StrongPity campaign distributing a fully functional but trojanized version of the legitimate Telegram app.
  • This is the first time that the described modules and their functionality have been documented publicly.
  • StrongPity’s backdoor is modular and has various spying features, such as recording phone calls, collecting SMS messages, collecting lists of call logs and contact lists, and much more.
  • If the victim grants the malicious StrongPity app notification access and accessibility services, the malware is able to exfiltrate communication from messaging apps such as Viber, Skype, Gmail, Messenger, and Tinder.
  • A copycat website mimicking Shagle, an adult video-chat service, is used to distribute StrongPity’s mobile backdoor app.
  • The app is a modified version of the open-source Telegram app, repackaged with StrongPity backdoor code.
  • Based on similarities with previous StrongPity backdoor code and the app being signed with a certificate from an earlier StrongPity campaign, we attribute this threat to the StrongPity APT group.

BRATISLAVA, KOŠICE— January 10, 2023 — ESET researchers identified an active StrongPity APT group campaign leveraging a fully functional but trojanized version of the legitimate Telegram app, which despite being non-existent, has been repackaged as „the“ Shagle app. This StrongPity backdoor has various spying features: its 11 dynamically triggered modules are responsible for recording phone calls, collecting SMS messages, collecting lists of call logs, and contact lists, and much more. These modules are being documented publicly for the very first time. If the victim grants the malicious StrongPity app notification access and accessibility services, the app will also have access to incoming notifications from 17 apps such as Viber, Skype, Gmail, Messenger, and Tinder, and will be able to exfiltrate chat communication from other apps. The campaign is likely very narrowly targeted, since ESET telemetry still hasn’t identify any victims.

Unlike the entirely web-based, genuine Shagle site, which doesn’t offer an official mobile app to access its services, the copycat site only provides an Android app to download, with no web-based streaming possible. This trojanized Telegram app has never been made available from the Google Play store.

The malicious code, its functionality, class names, and the certificate used to sign the APK file, are the identical to the previous campaign; thus ESET believes with high confidence that this operation belongs to the StrongPity group. Code analysis revealed that the backdoor is modular and additional binary modules are downloaded from the C&C server. This means that the number and type of modules used can be changed at any time to fit the campaign requests when operated by the StrongPity group.

“During our research, the analyzed version of malware available from the copycat website was not active anymore and it was no longer possible to successfully install and trigger its backdoor functionality. This is because StrongPity hasn’t obtained its own API ID for its trojanized Telegram app. But that might change at any time should the threat actor decide to update the malicious app,” says Lukáš Štefanko, the ESET researcher who analyzed the trojanized Telegram app.

The repackaged version of Telegram uses the same package name as the legitimate Telegram app. Package names are supposed to be unique IDs for each Android app and must be unique on any given device. This means that if the official Telegram app is already installed on the device of a potential victim, then this backdoored version can’t be installed. “This might mean one of two things – either the threat actor first communicates with potential victims and pushes them to uninstall Telegram from their devices if it is installed, or the campaign focuses on countries where Telegram usage is rare for communication,” adds Štefanko.

StrongPity’s app should have worked just as the official version does for communication, using standard APIs that are well documented on the Telegram website, but it no longer does. Compared to the first StrongPity malware discovered for mobile, this StrongPity backdoor has extended spying features, being able to spy on incoming notifications and exfiltrate chat communication, if the victim grants the app notification access and activates accessibility services.

For more technical information about the latest StrongPity app, check out the blogpost “StrongPity espionage campaign targeting Android users” on WeLiveSecurity. Make sure to follow ESET Research on Twitter for the latest news from ESET Research.


Comparing the legitimate website on the left and the copycat on the right

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

2022 年全球最常用的 20 個密碼 + 附解決方法

密碼是我們日常生活中不可式缺的一環,但您有留意它們的安全性嗎?以下列出 2022 年最常用的 20 個密碼,如果您正在使用這些密碼,強烈建議您立即更換它。

排名 密碼
1 password
2 123456
3 12123456789
4 guest
5 qwerty
6 12345678
7 111111
8 12345
9 col123456
10 123123
11 1234567
12 1234
13 1234567890
14 000000
15 555555
16 666666
17 123321
18 654321
19 7777777
20 123

參考 ESET 網絡安全專家的建議,提升密碼安全強度並非難事,也可以為我們的數位生活帶來一些立竿見影的好處。

1) 儘量使用複雜且獨特的密碼或短句
2) 永遠不要重複使用密碼
3) 不要共享您的密碼
4) 關閉所有未使用的帳戶,避免潛在的安全風險
5) 考慮使用密碼管理器和生成器,密碼庫將自動建議並儲存任何長度、強度和唯一的密碼
6) 定期檢查密碼強度並更新任何太弱或過時的密碼
7) 儘可能加入雙重身份驗證(MFA)
8) 不要登錄公共 Wi-Fi,因為同一網絡上的黑客可能會盜取您的密碼
9) 使用信譽良好的安全解決方案來防範信息竊取程式和其他惡意軟件
10) 考慮為您的手提電腦使用屏幕防窺貼
11) 不要點擊未經請求的電子郵件和文本中的可疑鏈接
12) 僅使用 HTTPS 登錄網站
13) 使用第三方服務,檢查您的密碼是否已被洩露

About Version 2

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products. Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

關於ESET
ESET成立於1992年,是一家面向企業與個人用戶的全球性的電腦安全軟件提供商,其獲獎產品 — NOD32防病毒軟件系統,能夠針對各種已知或未知病毒、間諜軟件 (spyware)、rootkits和其他惡意軟件為電腦系統提供實時保護。ESET NOD32佔用 系統資源最少,偵測速度最快,可以提供最有效的保護,並且比其他任何防病毒產品獲得了更多的Virus Bulletin 100獎項。ESET連續五年被評為“德勤高科技快速成長500 強”(Deloitte’s Technology Fast 500)公司,擁有廣泛的合作夥伴網絡,包括佳能、戴爾、微軟等國際知名公司,在布拉迪斯拉發(斯洛伐克)、布裏斯托爾(英國 )、布宜諾斯艾利斯(阿根廷)、布拉格(捷克)、聖地亞哥(美國)等地均設有辦事處,代理機構覆蓋全球超過100個國家。