Quick Summary
- ▸ In this project, the CodeBranch team conducted a final audit of the work of the core IT security team at Fluid Attacks, a company that helps organizations strengthen their security posture.
- A significant improvement in the quality of security testing was achieved by adding an extra audit step to the assessment process.
- CodeBranch was able to help security analysts identify issues that were not visible during their previous review rounds.
Overview
Fluid Attacks is a cybersecurity company that focuses on identifying and remediating vulnerabilities in software and IT infrastructure. They provide a wide range of security services and aim to help companies strengthen their security posture by proactively identifying risks and helping them build secure software systems. In this project, the CodeBranch team conducted a final audit of the work of the core IT security team at Fluid Attacks. Based on a series of static and dynamic tests, CodeBranch checked for possible false negatives that may have been overlooked in the previous security phases — both the human testing team and the machine-based automated tests.
Industries
Services Provided
- InfoSec
- Dynamic Analysis
- Static Analysis
Approach
The CodeBranch team employed a comprehensive set of security assessment methodologies: SAST (Static Application Security Testing), DAST (Dynamic Application Security Testing), MPT (Manual Pentesting), MAST (Mobile Application Security Testing), SCA (Software Composition Analysis), CSPM (Cloud Security Posture Management), PTaaS (Penetration Testing as a Service), RE (Reverse Engineering), ASPM (Application Security Posture Management), and SCR (Secure Code Review). This project lasted two years with two dedicated Cybersecurity Experts serving as an independent final audit layer on top of Fluid Attacks' existing assessment pipeline.
Results
- A significant improvement in the quality of security testing was achieved by adding an extra audit step to the assessment process.
- CodeBranch was able to help security analysts identify issues that were not visible during their previous review rounds.