Could your SOC tell you which of these ten adversaries would get furthest in your network? Scattered Spider. RomCom. Everest. Sandworm. Qilin. NightSpire. SideWinder. DragonBreath. The Gentlemen. Nova. For Cybersecurity Awareness Month, our research team is opening the case files on all ten, active adversaries tracked over the past year across telecom, government, healthcare, energy, and manufacturing targets. Each one links to an assessment or emulation built from its real techniques, so you can run your own environment against the actual playbook instead of guessing. 🗂️ Open the watchlist: https://lnkd.in/epUazskV
AttackIQ
Computer and Network Security
Los Altos, California 51,746 followers
CTEM Runs on AVA Agentic OS
About us
AttackIQ is the leader in threat-informed Continuous Threat Exposure Management (CTEM), helping organizations continuously validate defenses, break attack paths, and reduce threat debt through evidence-based security operations. Through AVA Agentic OS, AttackIQ introduces the industry’s first agentic operating system for CTEM, enabling organizations to execute it autonomously at scale. By orchestrating specialized AI agents across threat intelligence, security validation, detection engineering, control optimization, threat debt reduction, and AI security validation, AttackIQ transforms fragmented security activities into continuous cyber resilience. Trusted by the world’s largest enterprises, government agencies, and managed security providers, AttackIQ empowers organizations to continuously discover, validate, and reduce cyber risk with confidence. CTEM Runs on AVA.
- Website
-
https://attackiq.com
External link for AttackIQ
- Industry
- Computer and Network Security
- Company size
- 51-200 employees
- Headquarters
- Los Altos, California
- Type
- Privately Held
- Founded
- 2013
- Specialties
- Continuous Security Controls Validation, Breach and Attack Simulation, Red and Blue Team Testing, Cybersecurity, Purple Teaming, Information Security, Adversarial Exposure Validation , CTEM, MITRE ATT&CK®, Threat-Informed Defense, and Continuous Threat Exposure Management
Employees at AttackIQ
Locations
-
Primary
Get directions
171 Main St
Suite 656
Los Altos, California 94022, US
-
Get directions
Placa Del Gas, 2
3rd Floor
Barcelona, 08003, ES
-
Get directions
One Kingdom Street
Paddington Central
London, W2 6BD, GB
Updates
-
If you have 47 security tools, this is a safe space. 💜 Buying a tool is only the first step. Nobody tells you step two is proving the tool actually catches an attack. Our CTEM Maturity Playbook covers step two. See where your program stands: https://lnkd.in/ebdSYjdb
-
📸 Some of our favorite moments from the CyberOne x AttackIQ wine dinner at the Cowboys Club. Thanks to everyone who came out, and to the CyberOne Security team. Carl Wright Jose Barajas Cameron LaFond Kes Nelson Joseph C. Chase Hanna
-
-
-
-
-
+7
-
-
One cybercrime group allegedly hacking another makes for a good headline. But Jonathan Baker (VP of Threat-Informed Defense, AttackIQ) sees a more important issue underneath it: what happens to the victim data those groups accumulate? Ransomware gang, ShinyHunters claims it breached rival Cl0p’s infrastructure and has threatened to release information about companies that allegedly paid the ransomware group. So far, there’s no proof it actually obtained those victim files. But as Jon told Dark Reading, “stolen information doesn’t retire.” Once data leaves an organization, copies can remain across infrastructure controlled by threat actors, affiliates, and other third parties, creating opportunities for that information to resurface long after the original incident. Dark Reading digs into what the ShinyHunters–Cl0p feud could mean for Cl0p’s previous victims. See how this could create new risk for past victims: https://lnkd.in/e3KPzKrd
-
-
The AI agents you deployed to move faster are privileged insiders now too. They hold credentials. They hold permissions. Give one a goal and a poorly enforced boundary, and it can pursue that goal through a path no one intended, without malicious intent required. Derek A Whigham breaks down the second front security programs now have to defend: not just the adversary on the outside, but the automation running inside with the access we gave it. His answer isn't more audits. It's control verification, threat debt, and continuous compliance validation, used together to prove your defenses hold against both. 📖 Read Derek's latest: https://lnkd.in/er5uGHdQ
-
-
"Agentic AI should be judged by the security outcomes it produces, not simply the number of tasks it automates," says Carl Wright, AttackIQ's Chief Commercial Officer. That's the standard AVA Agentic OS runs on: coordinated agents executing the full CTEM cycle, from exposure prioritization to confirmed fixes. AVA just earned the 2026 Tech Ascension Award for AI-Powered Enterprise Agent Solution of the Year. Learn more: https://lnkd.in/efCep8wi Tech Ascension Awards
-
-
18 years at DISA. More than 12 of them as Chief Technology Officer, the agency's senior authority on the engineering behind the Department of War's IT and cybersecurity mission. David Mihelcic spent that time representing DISA on engineering matters with Combatant Commands, Military Services, Defense Agencies, the Intelligence Community, and industry. He's now AttackIQ's Field CTO – Federal, responsible for program management of DISA's enterprise Adversarial Exposure Validation program, helping the Department move from periodic assessments to continuous, evidence-based validation of its defenses. 📖 Read Dave’s take: https://lnkd.in/eXzz-83w 🔗 Read the full announcement: https://lnkd.in/e-kCTQxp
-
-
What happens if one of the latest payloads tied to an Iranian adversary hits your environment today? You shouldn’t have to wait for an incident to find out. AttackIQ Flex includes assessments built around Iranian threat actors and malware families including: 🔸 MuddyWater 🔸 APT35 / Charming Kitten 🔸 OilRig / APT34 🔸 RustyWater 🔸 WezRAT Security teams can use the package to test how their existing controls respond to real-world payloads associated with adversaries that have targeted government, energy, financial services, telecommunications, technology, and other critical sectors. Threat intelligence can tell you what adversaries are using. Security validation tells you whether your defenses are ready for it. Explore the latest Iranian adversary assessment in AttackIQ Flex for free: https://lnkd.in/eh-VMeEF
-
-
Level 1 Maturity: We think we're covered. Level 5 Maturity: We operate with confidence, not hope. Most security programs sit somewhere in between and have no reliable way to prove which end they're closer to. CTEM + MITRE INFORM For Dummies pairs CTEM's five-stage validation cycle with MITRE INFORM's maturity model, so that answer comes from real information instead of a guess. 📘 Download the guide today: https://lnkd.in/eTq5QFBm
-
-
AttackIQ reposted this
Your environment and the behaviors any attacker must run to cross it have not changed. That is where defense must focus. https://hubs.li/Q04xtNj20 Written by Jonathan Baker of AttackIQ