Showing posts with label API. Show all posts
Showing posts with label API. Show all posts

Saturday, October 1, 2016

Cyberwatch update

To all who've been using Cyberwatch(R) and provided feedback, thank you!  It's very much appreciated. As a result of some of these feedback,  Cyberwatch API version 1.1 was released last night, and its packed with improvements that you've requested:
  1. 25-35% faster with database clustering improvements
  2. For our automated alerting mechanism, we've built in dynamic notification API keys, which don’t require authenticating! Click through, see everything we know from that 
  3. API key removal from the url on the front end wrapper
  4. Security Updates & bug improvements 
To all who've not yet heard of Cyberwatch, last week we went public with a new application program interface (API), that allows users to run queries against our backend raw intelligence collections.  We knew two things... 

First, many (all?) companies need intelligence --not just information received when they buy that million dollar security tool, but a real understanding of what's going on outside of their border router that will likely affect them. 

Second, many of those companies would prefer to slog through the myriad of google groups, open source lists, and take on the dark web themselves and waste an enormous amount of time chasing things that just don't mean much to the questions they should be asking themselves. 

For example... a RISK focused security pro will always want to know if there's a RISK of something breaching. And if they do, what's the likelihood of loss?

An INTELLIGENCE focused security pro will want to look over the horizon for risks that'll might mean something soon, or they'll want to know that tactical information --what IP blocks should we be monitoring now? Blocking now? Remediating?

At the same time,  our customer base is largely 100,000 computers or bigger... which while good for us, represents a small number of companies who need help... and who may be partnered with or in the supply chain to these larger companies. 

I've talked with dozens of smaller companies. They simply can not, and like will never, spend the money on an intelligence shop.

So what if Wapack Labs could help them? What if we could allow users to query our backend data for say, 30 queries per day (for free), so that these smaller companies could see exactly what they're exposure looks like --and what if Wapack Labs could refer them to a security professional (under NDA of course) to help that smaller company get well? 

Well, that's exactly what we did.
  • Wapack Labs passively collects key logger 'dump' locations at about 1300 locations around the world; 
  • We collect on very specific sinkholes;
  • We collect some specific open source --but not all... we don't want circular reporting;
  • And we collect about a dozen other specific items that can help tell a company when they might have problems. 
And we make that all searchable to anyone who wants to search against it. 

As well, we started (this week) performing automated victim notifications. Our first batch, roughly 5000 of them, went out on Wednesday, with a no-cost, one time link to our databases to show the companies what we found, and why we think they may have been victimized. That email contains a link to our new Partner Exchange Program, and allows the victim to request a referral to one of our trusted, NDA'd,  partners who can assist in the cleanup if needed. 

The Cyberwatch API is available at api.wapacklabs.com.

Need more? We've built an ugly demo front end (we'll make it look nicer soon, I promise) on the API... cyberwatch.wapacklabs.com. Use it to monitor a portfolio of companies. If you're watching your supply chain, or a group of investment companies, you can set up five companies in our Cyberwatch front end, or you can use the API to bring the data into your own environment. Either way... you should be able to pull our data into a usable front end of your choosing or use ours.

So, to those who've provided feedback? We're listening.
To those who've not yet tried it? Try it! 

We're heading into Christmas shopping season. And although much of the work we'd done in the past is APT and Espionage related, we've taken on a second flavor in our analysis --money. So if you're a retailer, financial institution, or a supplier to one of these, as we head into the Christmas shopping season you should be watching our API at least daily, knocking down the threats we identify. 

Give it a try. There's absolutely no reason you shouldn't... it's free and we might know something about you that you don't already know.

Until next time,
Have a great weekend!
Jeff

(CyberWatch(R) is a registered Trademark of Wapack Labs Corporation.)


Monday, September 12, 2016

Wapack Labs Announces Cyberwatch® API for Proactive Cyber Threat Intelligence.

Orlando, FL, September 12, 2016:  Wapack Labs, a cyber threat intelligence company, announced their new Cyberwatch® Application Program Interface (API) today at the Information Security Certification Consortium (ISC2) Congress in Orlando, FL. Companies will now be able to search Wapack Labs’ cyber intelligence collections directly through this bold, new application. That means users can identify and address security threats faster—including before they’re realized.


Wapack Labs recovers information stolen by hackers from keylogger information, sinkholes, the dark web, malicious emails, and more. “With Cyberwatch® API, we’re opening our collections to those not normally privy to high-end cyber threat intelligence,” says Jeff Stutzman, CEO of Wapack Labs. Everything from usernames and passwords to financial transactions and credit card information can indicate previously unknown network breaches. Users can simply enter a company domain into Wapack Labs Cyberwatch® API (api.wapacklabs.com) and find out if it has been compromised. 



What makes Wapack Labs Cyberwatch® API of even greater value, however, is that it enables companies to be proactive. “Because of the sheer volume of our backend collections—which also includes data derived from malicious actors’ activities, and not just the information they steal—results from your search can help you identify if you’re being targeted.” Stutzman explains.  This is revolutionary for an industry where, today, offerings are almost always post-hoc; that is, they are built after a company has already been broken into. Antivirus, sharing intrusion prevention rules, and indicators of compromise all rely on expert analysis after someone has been hacked, and damage is already done. For another company to successfully capitalize on these types of security offerings, they must obtain and incorporate this information into their security tools before the threat evolves.



The Cyberwatch® API enables companies to connect their security tools directly to Wapack Labs’ intelligence backend, giving them direct access to clean, parsed data without requiring additional analysis, thereby prioritizing work for CISOs and their cyber security operations center (SOC) teams. 



These are not credential dumps or aggregated data,” says Stutzman. “This is information stolen by nefarious actors or malware from roughly 15,000 companies and organizations all over the world. If a company or individual finds themselves in a query of our data, if they haven’t been hacked yet, they may be soon, and can get a head-start on precautions.” 



Wapack Labs, located in New Boston, NH is a Cyber Threat Analysis and Intelligence organization supporting the Red Sky Alliance, the FS-ISAC, and individual organizations by offering expert level targeted intelligence analysis answering some of the hardest questions in Cyber. Wapack Labs’ engineers, researchers, and analysts design and deliver transformational cyber-security analysis tools that fuse open source and proprietary information, using deep analysis techniques and visualization. Information derived from these tools and techniques serve as the foundation of Wapack Labs’ information reporting to the cyber-security teams of its customers and industry partners located around the world.



For questions or comments regarding this report, please contact the lab directly by at 603-606-1246, or Chuck Nettleship at cnettleship@wapacklabs.com.