Contact us: info@tenendo.com
Developer/DevOps adversary simulation
Sometimes, a secured infrastructure can fall to a successful phishing attack or an internal adversary.
Historically, adversary simulations were conducted with employee-level access to the internal on-premise infrastructure. This approach is not adapted to modern development and application deployment processes, causing important access control vulnerabilities to be overlooked, leading to catastrophic effects, as seen in the recent attack on Twitter. During the attack, a successful compromise of a developer account leads to access to the entire authentication mechanism. To combat attacks like these, we have decided to consider a new service — developer/DevOps adversary simulation.
The testing process starts with valid developer credentials for the infrastructure and simulates post-exploitation activities after obtaining access to existing CI/CD, logging, monitoring, and remote access solutions as a generic developer to build a complete threat model, find access control misconfigurations, and help companies ensure no single person can cause a compromise.

If you think this can be useful to you and your partners or consider using this service to secure your development and deployment processes, please contact us for details and delivery process description.
Other services:
-
PCI DSS Penetration Testing Services
What we actually test External testing We attack your internet-facing infrastructure from outside your network, just as an external attacker would. This covers everything in your CDE that’s reachable from the internet. Internal testing We test from inside your network, assuming an attacker has already gained initial access (phishing, compromised vendor, rogue employee). The goal […]
-
Application penetration testing
For all penetration tests, our team collects relevant information about the scope, develops an attack surface, and begins an extensive manual and automated search for vulnerabilities and applicable attacks.
-
Cybersecurity Services
Engage cybersecurity professional services for expert guidance, risk mitigation, and customised solutions to safeguard your organization’s digital assets and operations.