Sophos to bring OpenAI cyber models into its Managed Risk offering
Sophos has announced Exploit Path Verification (EPV), a new capability being developed for its Sophos Managed Risk service to help security teams determine which vulnerabilities are actually exploitable in their environments.
EPV will use OpenAI’s GPT cyber models through the OpenAI Daybreak Defense Network to assess factors including asset and patch status, endpoint protection policies, network reachability, identity and privilege information, and known exploit availability. It will classify findings as Confirmed Exploitable, Blocked by a Control, Not Reachable, or Insufficient Evidence.
The capability is also being designed to identify attack paths where multiple lower-severity vulnerabilities can be chained together, and provide remediation recommendations. Sophos said each verdict will include supporting evidence and will be reviewed by its security analysts.
“Exploit Path Verification is being built to make it clear what in their environment is reachable by an attacker, with the evidence to prove it, so they fix what counts first,”...
Copyright of this story solely belongs to www.expresscomputer.in. To see the full text click HERE