惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

SecWiki News
SecWiki News
N
Netflix TechBlog - Medium
D
Docker
Stack Overflow Blog
Stack Overflow Blog
云风的 BLOG
云风的 BLOG
U
Unit 42
Recorded Future
Recorded Future
G
Google Developers Blog
T
Threatpost
Google DeepMind News
Google DeepMind News
D
DataBreaches.Net
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
T
The Blog of Author Tim Ferriss
C
Cyber Attacks, Cyber Crime and Cyber Security
A
Arctic Wolf
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
GbyAI
GbyAI
V
Vulnerabilities – Threatpost
Project Zero
Project Zero
WordPress大学
WordPress大学
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
M
MIT News - Artificial intelligence
月光博客
月光博客
Spread Privacy
Spread Privacy
Know Your Adversary
Know Your Adversary
人人都是产品经理
人人都是产品经理
D
Darknet – Hacking Tools, Hacker News & Cyber Security
The Hacker News
The Hacker News
K
Kaspersky official blog
Simon Willison's Weblog
Simon Willison's Weblog
MongoDB | Blog
MongoDB | Blog
J
Java Code Geeks
I
Intezer
Y
Y Combinator Blog
P
Proofpoint News Feed
G
GRAHAM CLULEY
L
LINUX DO - 热门话题
Schneier on Security
Schneier on Security
B
Blog
Jina AI
Jina AI
V2EX - 技术
V2EX - 技术
雷峰网
雷峰网
Last Week in AI
Last Week in AI
V
V2EX
Martin Fowler
Martin Fowler
P
Palo Alto Networks Blog
Latest news
Latest news
Google DeepMind News
Google DeepMind News
L
Lohrmann on Cybersecurity
The Last Watchdog
The Last Watchdog

Company Updates Archives - SpecterOps

SpecterOps and OpenAI: Helping to Build a New Security Frontier with Daybreak SpecterOps Selected for OpenAI’s Trusted Access for Cyber Program Introducing BloodHound Scentry: Accelerate Your Identity Attack Path Management Practice with Expert Guidance Fueling the Fight Against Identity Attacks Life at SpecterOps Part II: From Dream to Reality Life at SpecterOps: The Red Team Dream BloodHound Community Edition: A New Era Introducing BloodHound 4.3 — Get Global Admin More Often Introducing BloodHound 4.2 — The Azure Refactor War In Ukraine Announcing Azure in BloodHound Enterprise AWS ReadOnlyAccess: Not Even Once The Attack Path Management Manifesto Introducing BloodHound 4.0: The Azure Update “Voting is not only our right — it is our power.” — Loung Ung SpecterOps Badge Life A Push Toward Transparency Announcing Our Formal Partnership with Palantir Introducing the Adversary Resilience Methodology — Part Two Introducing the Adversary Resilience Methodology — Part One Raphael’s Thoughts: SpecterOps acquires MINIS
Final Steps to BloodHound Enterprise for Government— FedRAMP High Compliance
Justin Kohler · 2024-03-05 · via Company Updates Archives - SpecterOps

Final Steps to BloodHound Enterprise for Government— FedRAMP High Compliance

Ever since SpecterOps first launched BloodHound Enterprise (BHE) in July 2021, one of our team’s biggest frustrations involved a lack of FedRAMP qualifications, which prevented us from supporting a large set of desired users; specifically in the federal space. This is why I am both proud and happy to share that BHE is now in the final stages of the Palantir FedStart program and is expected to be FedRAMP High compliant in April 2024. We are ready to engage with FedRAMP required environments now to show you, our users, how we can help shut down Attack Paths.

BHE is a software-as-a-service (SaaS) Attack Path Management (APM) platform for Active Directory (AD) and Azure. From the beginning, we took the security of the data we held extremely seriously and took steps to segment and secure our infrastructure. This includes a single tenant architecture and adherence to major compliance frameworks like ISO 27001, ISO 27017, and SOC 2 Type 1 & 2. Many of us come from a service background in either the Department of Defense (DOD) or similar agencies and have always wanted to bring our capability to organizations with a requirement for FedRAMP compliance.

Our partnership with Palantir’s FedStart program has streamlined our path to FedRAMP compliance; this begins with Palantir’s SaaS infrastructure platform that is secured for federal clients and is FedRAMP compliant. BHE is deployed as an application on top of this platform to comply with and inherit further security controls FedRAMP requires. We’ve also added additional policy, process, and certification refinements on the SpecterOps side. After several months of working with the Palantir team, we’re excited to detail the final stages:

  • March 2024: FedRAMP High Audit Execution
  • April 2024: FedRAMP High and IL5 Compliant with a High ATO from HHS

This accreditation is through an agency Authority to Operate (ATO) and our progress can be viewed on the FedRAMP Marketplace here.

If you are an agency or an organization that requires FedRAMP compliance and has AD or Azure, we want to talk to you. We have roots in DOD / agency red teams and offensive services and we’re eager to serve again. Request a demo today and let us show you how you can manage your Identity Attack Path risk to remove the adversary’s favorite target.


Final Steps to BloodHound Enterprise for Government— FedRAMP High Compliance was originally published in Posts By SpecterOps Team Members on Medium, where people are continuing the conversation by highlighting and responding to this story.

Post Views: 3,842