praetorian-inc / chariot-ui

Chariot Offensive Security Platform
https://preview.chariot.praetorian.com
MIT License
15 stars 6 forks source link

Real-time cloud attribution for assets #123

Closed privateducky closed 1 week ago

privateducky commented 1 week ago

A detection, such as SSH, might be detected on an AWS IP, the host goes down, and a new owner picks up that IP. Next, the new owner enables SSH on the machine. After this, MSP goes to triage the SSH exposure. We'd like a way to verify that a cloud asset still exists within a customer's environment at the time of triage.

Edit: I acknowledge this may not be necessary in the long-term when the scan frequency is increased to 5-10 minutes or we automatically close risks when we detect that an IP is decommissioned.