What Active Focus monitors

Identity and Cyber Threat Intelligence

The easiest way into an organisation is rarely an exploit — it is a valid password. Organisations are compromised every day because a user's credentials let an attacker simply log in, using techniques like credential stuffing and password spraying. If we want to protect you, we have to operate as close as possible to the threat actors who do this for a living — from script kiddies to cyber criminals to nation states. The simple techniques work, so River Security uses them too, first.

Credential stuffing

Hacking doesn’t have to be complex, and credential stuffing proves it. Attackers take credentials leaked from other sites and systems and try them against yours — because people reuse passwords, often tied to their company email address, across third-party services. When one of those third parties is breached, River Security procures the leaked credentials the same way threat actors do and tests them across your infrastructure.

We buy and collect cyber threat intelligence from multiple sources to stay on top of this on your behalf. We also receive passwords harvested from malware-infected machines — often devices belonging to your own user base — which lets us protect not just your organisation’s accounts, but frequently your customers’ too.

Password spraying

With lists of usernames and a carefully chosen set of likely passwords, attackers target logins at scale — email, SaaS providers, VPN concentrators and more — using automation to find any account with a weak password. It is called spraying because a small, crafted password list is tried broadly across many accounts, and it can run quietly for a long time.

Using all the attack surface we’ve mapped for you, River Security sprays specially crafted password lists across your user base. The difference from a criminal is simple: the moment we succeed, we tell you immediately.

Procuring cyber threat intelligence

Producing, procuring and consuming intelligence on the latest attack vectors, credentials and current status quo is essential for an offensive team. River Security gathers this intelligence through partner networks and our own investigative work, and puts it straight to use in our operations.

Cyber threat intelligence feeding River Security’s continuous offensive operations

Any penetration test will try to use current threat intelligence — but because Active Focus is continuous and always-on, customers benefit on a far more proactive basis. Turning raw CTI into actionable value is hard for many organisations; for offensive engineers, it is second nature.

Applying credentials and breach data continuously

Employee credentials feed our credential-stuffing process — but there is more. Stealer logs — data harvested by malware from infected machines — are part of our team’s arsenal too. From them we recover credentials, active sessions and more: passwords from password managers, sessions from browsers, values from web forms. We hunt this data for anything pointing at your systems, because each piece is a live risk to you and to the people who use your services.

When we recover a working credential, we test it everywhere we can attribute to you — mail and Microsoft 365, social accounts, and third-party, cloud and DNS providers — because an attacker won’t stop at your main system, and neither do we. That is also the advice we give back to you: when a credential is exposed, reset it everywhere that username and password combination is used, not just on the obvious system.

See how Active Focus works Talk to an expert