Rapid7 has launched Rapid7 Intelligence to shift enterprise security from reactive alerts to identifying and disrupting attacks before they gain a foothold.
The engine combines threat intelligence, vulnerability research and Rapid7 Labs research, analysing attacker behaviour in real time and feeding insights into Rapid7’s security products.
The company said it tracked 8,539 critical vulnerabilities in the second quarter, while attackers are increasingly automating phishing, reconnaissance and script development.
“Static threat intelligence isn't completely dead – it’s just sitting in standard dashboards doing what it's always done, giving organisations a false sense of security while autonomous threat agents burn down their perimeters,” Christiaan Beek (pictured), vice president of Rapid7 Intelligence, said in a statement.
The launch comes alongside research uncovering a modular Linux malware ecosystem targeting telecommunications and network-edge devices.
Rapid7 researchers identified two campaigns involving new BPFDoor variants, BPF Rekoobe, droppers and AVERAT implants. Behavioural analysis linked the campaigns through their focus on network-edge infrastructure and use of SMTP to blend into victims’ DMZs, target mail security appliances and maintain persistent access.
New BPFDoor variants indicate the malware is evolving into an ecosystem tailored to different telecommunications control, management and data planes, according to Rapid7.
The company said intelligence from the research will feed into its products, managed detection and response and Exposure Management capabilities.
“In a world of infinite telemetry and automated attacks, playing defence with traditional tools is an exercise in futility,” Mel Stone, chief global services officer at Rapid7, said.
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.