Exploit Public-Facing Application

Description

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.

Products, Sensors, and Dependencies

ProductDependenciesData sourceAccess requiredProtocolData CollectedNotes
Tenable Web App ScanningWeb ApplicationsRead-onlyAnyInjection OR XXE Vulnerabilities
Tenable Vulnerability ManagementCloud instancesRead-onlyAnyVulnerabilities
Tenable Cloud SecurityIaaSRead-onlyAnySecurity Groups
Tenable Vulnerability ManagementComputersRead-onlyAnyVulnerabilities
Tenable Attack Surface ManagementExternal AssetsRead-onlyAnyExternal Assets
Tenable Web App ScanningWeb ApplicationsRead-onlyAnyInjection OR XXE Vulnerabilities
Tenable Cloud SecurityIaaSRead-onlyAnyCloud Network data
Tenable Web App ScanningWeb ApplicationsRead-onlyAnyInjection OR XXE Vulnerabilities
Tenable Cloud SecurityIaaSRead-onlyAnyCloud Network data