Kevin Mandia, founder of Mandiant and co-founder and general partner at Ballistic Ventures, has joined SpecterOps, a Virginia-based startup focused on attack path management, as the chair of its board of directors.Â
Founded in 2017, SpecterOps offers software that allows companies to better defend identities, particularly those used in conjunction with Microsoft Active Directory, Azure AD, Entra ID and hybrid environments. Started by three red-teamers â David McGuire, Jason Frank, and Raphael Mudge â the company also offers penetration testing and security maturity assessments.Â
In an interview with CyberScoop, Mandia said he is excited to join the board and sees a lot of similarities between where SpecterOps is now and his early days at Mandiant. He hopes to use that expertise to help McGuire â the SpecterOps CEO â avoid potential land mines.
âI was unfunded [at Mandiant], so I didnât have an institutional investor saying, âYou need to do this, you need to look this way,ââ Mandia said. âI was doing whatever I wanted for seven years. So I think some of the things I learned along the way, the hard way, can maybe save David a few months of decision-making.â
A good portion of that further decision-making will be in relation to SpecterOpsâ BloodHound Enterprise, a software tool that allows organizations to map and predict how an attacker can move through a system based on a hypothetical credential theft. McGuire told CyberScoop his company built the tool for its own pen-testing engagements, and then released an open-source version that has been well-received among practitioners. The paid version of the software has also been popular for the company, with SpecterOps saying that new customer acquisition grew more than 125% year-over-year in the second quarter of 2024.
âWhere we focus is, âLetâs sever lateral movement escalationâ specifically, and no real product out there does that,â McGuire told CyberScoop. âWe feel the most excited when weâre removing the adversary and their ability to attack enterprises.â
Mandia has first-hand knowledge of how identity-based attacks can get through the toughest security setups. In 2021, Russiaâs foreign intelligence service (SVR) leveraged specific username and passwords to breach FireEye as part of the SolarWinds incident, rather than using a single software backdoor akin to a master key that would unlock all of the necessary data.
âIt is a frustrating position to be in,â Mandia told CyberScoop. Organizations âneed to understand identity architecture and the risk it presents to your organization. I think thatâs an enormous blind spot. Weâve got public companies that help us shut the front door [with vulnerability management]. It is time for a company to help us shut the back door [with identity management] and thatâs SpecterOps.â
McGuire believes in BloodHound because the company partly developed it as a way to raise the quality of its pen-testing work.Â
âNot to throw shade on anybody, but EDRs (Endpoint Detection and Response software) donât stop usâ in pen-testing engagements, McGuire said. âWe can bypass almost every security technology from an apex attacker perspective. Itâs a little egotistical, but we built the tool to stop ourselves.âÂ
Bravado aside, the work is paying off. SpecterOps has grown significantly over the past year; with employee headcount climbing 40%. Mandia says he will primarily help SpecterOps scale its business as growth continues.Â
âI learned every lesson on scale the hard way, from a guy in a basement to a CEO of a public company with 3,700-plus employees,â he told CyberScoop. âI look at David, and I see a lot of pattern recognition at a technical practitionerâ who Mandia can help guide.Â
Even with the new role, Mandia says he will continue his work with Ballistic Ventures and his advisory work with Google Cloud.Â
âIâm a 30-year cybersecurity person,â Mandia said. âThis is all Iâm good at. Iâm not going to start a bakery.âÂ
The post Exclusive: Kevin Mandia joins SpecterOps as chair of the board appeared first on CyberScoop.