Jump to content

Recommended Posts

Posted

Not used them yet, but was reading up on them a few weeks back on Reddit. 

Seems the consensus is "Fairly good but New-kid on block" - Seems to have the basic scanning options, but lack of automated fixing dependant on the CVEs etc even with the paid upgrades. Also really requires the paid for addons for automated frequent scanning etc

Even their own wording is "RoboShadow likely covers around 70-80% of a standard internal and external penetration test, and represents a significant part of the vulnerability assessment process." - So I guess it depends on what you're looking for, a rough idea or a fully compliant scan/test etc

Steve

  • Like 1
Posted

Yea….well we had a meeting with there ceo Tim and was explaining about the products. 
 

He was saying basically that they have alot of customers in the states and have been shifting the focus to the UK they have been going I think he said 5/6 years and they are trying to now align with ncsc and cyber essential plus, he was saying that they working on producing reports to help indicate where this has been met within there product, which i thought was quite good.

 

And they are on the ncsc list for new tech companies 

 

I know there are alot of companies out there but from what he was saying and what other companies I have seen over the year i think these could be pretty good again just my opinion. He has quoted me around 20 pence per Device.

 

Interface is pretty slick esp from a high level overview 

 

 

 

 

Posted (edited)

I use the basic version of the platform. Mainly to keep an eye on all of our external facing systems. 

From school systems, to school websites. 

 

The scheduled alerts show us, if a configuration has been done wrong and a port is open externally that shouldn't be. 

 

Another security layer for us. 

Edited by mdking
  • Like 1
Posted

I have been using the free tier in conjunction with Ping Castle & Action1.  Using it more like Ping Castle, running periodically against the schools domains and public IPs along side the LAN scanner. I just have the client installed on single machine and then use that to scan the network, kind of mimicking what a bad actor would do.

 

Can be quite the eye opener in the same way Ping Castle can.  Only real downside in my usage scenario is it can only scan a /24 subnet at a time.

 

Seems to be another great free way to check your networks security posture.  At the end of the day, you don't know what you don't know.

Posted

@PrimaryNetMan

 

yea I've just downloaded the client and installed it in one of our ICT Rooms, just to test, I'm looking also looking at it from a path management solution.

 

the detail on the patching / cve and the auto healing etc

 

I've yet to try the LAN scanner, I've use ping castle and I like it  but I feel its a bit clunky - great product though 

 

would you say you use roboshaow often? how far are you try using it as like you main soc for example ?

 

Posted
6 hours ago, kevin_lane said:

@mdking thanks for the reply, how long have you  been using the product for ? what systems have you integrated with it? do you have any costings

 

 

Hi, 

 

We have been using for around 6 months. It has helped me out and has provided some good information for senior leadership. 

 

We haven't installed the client as of yet, only the external testing which is scheduled to run once per day. (To test all of our forward facing systems) 

  • Like 1
  • Thanks 1
  • 8 months later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...