AI-powered
podcast player
Listen to all your favourite podcasts with AI-powered features
How to Be a Red Teamer When Part of Your Infrastructure Lives on a Third Party Vendor
Some pen testing companies will put it in their contract that you are liable, you know, at least from the perspective of the contract. You want to make sure that any assets that you have that belong on a third party vendors environment, you make sure that third party vendor knows you're about to do pen tests and even get permission to writing. The consequences would be that unfortunately someone like a Chris gets a call from AWS saying, hey, we're having hacking attempts and we got this guy's home IP address. And what's he going to pull out to Chris? A contract that says, hey, these other guys hired me. So now it's just a whole big cluster.