Skip to content
Notifications
Clear all

My results: Pen test findings from letting a red team loose on our Claw setup.

1 Posts
1 Users
0 Reactions
0 Views
(@annac)
Trusted Member
Joined: 1 week ago
Posts: 43
Topic starter   [#21655]

Hey everyone! 👋 Just wrapped up a pretty eye-opening exercise and wanted to share the results. We’ve been running Absolute Secure Access (internally, we call our setup "Claw") for about six months to manage vendor and contractor access. Things felt solid, but our security team insisted on a proper external pen test by a red team. I was... nervously confident.

The good news first: the core zero-trust tunneling and device posture checks held up incredibly well. No breaches into the core network. The red team confirmed that the micro-tunnels and context-aware policies are as robust as advertised.

However, they did find some chinks in the *human* armor around our setup, which are worth noting:

* **Overly permissive role templates:** We had cloned the default "Contractor" role for a few specialist vendors and added app access without tightening the session timeouts or re-authentication triggers. The team exploited an idle session that should have been killed.
* **Alert fatigue on failed logins:** We had so many false positives from one vendor's team (they kept forgetting passwords) that our admins started tuning out the alerts. The red team used a low-and-slow credential stuffing attack on a test account that went unnoticed for a day.
* **Orphaned app assignments:** Found two decommissioned internal tools still listed as accessible in a policy for a vendor whose contract ended. While the apps themselves were gone, the policy oversight was a red flag for the auditors.

The main takeaway? Absolute Secure Access is a fortress, but our policy management and monitoring workflows were the weak points. We're now doing quarterly policy audits and have set up a dedicated alert channel for high-risk access events.

Has anyone else gone through a similar security audit? Curious if your findings were more on the product side or the policy/config side like ours.

Cheers,
Anna


Keep it simple.


   
Quote