Ostorlab’s cover photo
Ostorlab

Ostorlab

Computer and Network Security

Middletown, Delaware 18,539 followers

Mobile Security Testing Automation Platform

About us

Ostorlab is a leading Security Testing Automation Platform, trusted by over 18,000 developers and security professionals in more than 80 countries. Our customers choose Ostorlab for its: * Extensive vulnerability knowledge base, the largest on the market. * Advanced detection system that learns from past vulnerabilities to predict and identify new ones. * Easy setup, allowing you to start scanning in seconds and ensuring continuous assessment with every release and commit. Accurate results with zero false positives, thanks to our innovative automated representation of vulnerabilities. Ostorlab is currently available for Mobile Applications on both Android and iOS, and supports scanning Web Applications, Web APIs, and discovering External Attack Surface.

Website
https://www.ostorlab.co
Industry
Computer and Network Security
Company size
11-50 employees
Headquarters
Middletown, Delaware
Type
Privately Held
Founded
2021
Specialties
Mobile Application Security Testing and Web Application Security Testing

Locations

Employees at Ostorlab

Updates

  • Most security teams accept a frustrating compromise: to scan internal assets, you either poke holes in your firewall for a cloud scanner, or you suffer through managing disconnected, legacy on-prem tools. But how do you get the centralized control of a modern cloud platform without exposing your private network to the internet? We realized the answer isn't changing your network. It's moving the scanner. Announcing Ostorlab On-Premises Scanning. We've brought the execution engine securely inside your network, giving you the best of both worlds:   Zero Public Exposure: Test private apps, APIs, and networks directly from your own infrastructure.   Centralized Control: Orchestrate scans and manage remediation for all assets in one unified cloud platform.   Intelligent Scaling: Group multiple scanner nodes for automatic load balancing and capacity management.   Trusted Engine: Get the exact same exploitability testing and safe network throttling, executed locally. Ready to stop compromising between network security and unified management? 📖 Read the full announcement to see how it works: https://lnkd.in/eJ_UevZq

    • No alternative text description for this image
  • View organization page for Ostorlab

    18,539 followers

    A create endpoint should only create a new resource. But in our latest GoPhish source code scan, we found that a create request could update someone else’s resource and transfer its ownership. Three behaviors made this possible: • The request accepted an existing ID. • The application assigned the current user as owner. • The database treated that ID as an update. So when User B submitted User A’s resource ID, the original record could be reassigned to User B. The route said “create.” The database performed an update. Agentic Deep Scan identified the pattern before it was manually validated. Read the full technical breakdown in our latest issue of The Breach Brief. Link in the first comment.

    • No alternative text description for this image
  • Now you can rerun individual risks in Agentic Deep Scan for improved coverage. A risk is a suspected weakness identified during a scan that the agent can investigate further to determine what is actually happening. Select the risk you want to revisit, click 𝗥𝘂𝗻 𝗗𝗲𝗲𝗽 𝗦𝗰𝗮𝗻, and the agent investigates it again within the same scan. Here is how it works: 👇 https://lnkd.in/ewzTXa-7

    • No alternative text description for this image
  • Running a security scan in a large organization often starts with waiting. The security team may be ready, but the credentials, access, and approvals it needs are spread across several other teams. If you work in enterprise security, this will probably sound familiar: You have a mobile application to scan. You need test credentials from the identity team, VPN access from the network team, IP allowlisting from infrastructure, and perhaps help from other teams to adjust the WAF or handle application shielding. What looked like one simple scan already involves several teams, and you have not even clicked “Start scan” yet. When the findings come back, application teams must review and fix them, while security tracks their progress and retests the application. For one application, this is manageable. Across hundreds of applications, it's a full-time coordination job, and that coordination, not the scanning itself, is what actually slows security down. Solving this comes down to two questions: Can the scanner handle restrictions and protections itself, such as bypassing application shielding, so testing can start without waiting for another team? That's the technical half. The other half is organizational: Can the process prevent different team priorities, approval steps, and internal politics from slowing down every scan? We explore how enterprises can solve both challenges in the full Deep Dive. Link in the first comment.

    • No alternative text description for this image
  • Imagine hiring a top-tier human pentester, but every Monday they show up with complete amnesia. They spend three days finding the login screen and mapping basic routes before they ever look at your business logic. You would never accept that level of inefficiency. Yet, security teams accept this exact "Groundhog Day" behavior from automated scanners every single week. Why do we expect our software to evolve continuously, but settle for security tools that reset to zero on every commit? We realized security tools should not act like stateless scripts. Meet Agentic Scan Knowledge, the newest feature we have added to our Deep agentic scan product. Instead of treating every run like a first date, our Deep agentic scan builds a persistent, searchable memory of your application architecture. Here is what changes when your scanner remembers: - Compounding Expertise: Just like a senior pentester who gets to know your app, the scanner builds on past context to probe deeper, complex business logic rather than surface-level routes. - Bypassing the Baseline: The scanner skips repetitive discovery on known endpoints and reallocates its time to testing new code and edge cases. - Visible Chain of Thought: No black boxes. You get a clear, step-by-step paper trail of how the agent used past knowledge to reach a new finding. Stop letting your scanner forget your architecture. Read the full announcement 👇 https://lnkd.in/eeSGRypj

    • No alternative text description for this image
  • 🎣 Is It a Phish? Your inbox has been unusually noisy all morning. Then “IT Helpdesk” messages you on Teams with an update it says will fix the problem. Would you install it? Take a closer look and tell us: legitimate support message or phishing attempt?

    • No alternative text description for this image
  • 👏 Person of the Week: Emanuele Faranda What is an Android app doing after you open it, and where is your data going? Emanuele Faranda built PCAPdroid to make those connections visible. The open-source tool captures and analyzes Android network traffic locally without requiring root access. Users can inspect the servers an app contacts, examine its connections and export captures for further analysis in Wireshark. His work also includes PCAPdroid-mitm for decrypting TLS traffic and zdtun, the networking component that supports PCAPdroid’s no-root capture. For lowering the barrier to Android traffic analysis and continuing to maintain these tools in the open, Emanuele Faranda is our Person of the Week. 👏

  • A new issue of The Breach Brief is live. This week, we look at why enterprise security testing becomes an organizational challenge when every scan depends on several teams before and after it runs. We also break down how a GoPhish create endpoint could allow one user to take ownership of another user’s resources. We spotlight Emanuele Faranda, creator of PCAPdroid, and look ahead to next.app devCon. Plus, your weekly security catch-up and a new Is It a Phish? Read the full issue 👇

Similar pages

Browse jobs