Skip to content

Solutions

Ransomware readiness: close entry points early

Ransomware readiness means closing entry points before encryption and extortion begin. blacklens.io finds them from the attacker's perspective and warns you of leak site matches.

Attack surface of beispiel-gmbh.at

47

Assets

112

Services

6

critical

Criticalvpn.beispiel-gmbh.atFortiGate SSL-VPN 7.0.12
Highmail.beispiel-gmbh.atExchange 2019 CU12
Highdev-old.beispiel-gmbh.atGitLab 15.2, Shadow IT
Mediumshop.beispiel-gmbh.atnginx 1.24, TLS 1.2
Highbeispiel-gmbh-login.comLookalike, registered 3 days ago

Dark web: compromised identities

m.huber@beispiel-gmbh.atStealer-Log (RedLine), 2 h ago
Session-Cookie M365Combolist, yesterday

Sample data. Get your own view with the exposure check.

How a ransomware attack unfolds

Ransomware rarely starts with ransomware. Days to weeks often lie between the sale of the access and the attack.

  1. 1

    Initial access

    Access brokers use exposed services, leaked credentials or fresh vulnerabilities.

  2. 2

    Sale in the underground

    The finished access is sold to ransomware groups in underground forums.

  3. 3

    Attack and data theft

    The group uses the access and exfiltrates data, often days to weeks after the purchase.

  4. 4

    Extortion via leak site

    The victim is listed on a leak site and extorted with the publication of data.

Entry points blacklens.io finds

Prioritised by what ransomware groups actually exploit.

Newly discovered assets+4 since yesterday
beispiel-gmbh.atRoot domain
vpn.beispiel-gmbh.atFortiGate SSL-VPN 7.0.12Critical
dev-old.beispiel-gmbh.atGitLab 15.2Shadow ITHigh
mail.beispiel-gmbh.atExchange Server 2019Medium
203.0.113.24OpenSSH 8.9NewInfo

Visuals show sample data.

Results from practice

Early warning works when it comes before the attack. Alerts are collected every five minutes and sent by email, push, Teams, Slack, Jira, ServiceNow or to your SIEM.

Early warning47 min ago
CVE-2024-21762FortiOS SSL-VPNCritical
  1. CVE published08:12
  2. 2 assets in your inventory affected09:00
  3. Confirmed by PoC scan09:26
  4. Alert sent to Microsoft Teams09:27

Visuals show sample data.

  • Login subdomain on a leak site

    A SaaS provider found a subdomain considered inactive internally in a ransomware group's leak.

  • ProxyShell, 48 hours before the attack

    A manufacturer patched after the alert, 48 hours before an automated attack.

  • Partner access visible for the first time

    An IT service provider saw all exposed services including partner access and hardened them.

Frequently asked questions

Ransomware readiness describes how well an organisation knows and has closed the typical entry points of a ransomware attack, and how early it detects warning signals before encryption and extortion begin. It is not about recovery after the incident but about the phase before it. Typical entry points are exposed remote access, unpatched perimeter systems, stolen credentials and session cookies, forgotten systems, misconfigured cloud and backup systems, and compromised service providers.

Do you know what an access broker finds about you?

Start with your domains. Within 24 hours you see exposed access, vulnerable systems and traded credentials.

  • 14 days free, all features
  • No credit card required
  • We walk you through your first findings