Our product is not a CTF! It inserts honeypots in our customer's infrastructure (through WAF and/or DNS configuration) to categorize attacks (manual vs. automated, targeted vs. random, persistent vs. changing) and attackers (profile creation, activity tracking despite IP rotation, skill assessment).
We then produce Threat Intel data feeds, instrument scenario seen on the honeypots and automatically replay them against our customer's assets, etc.
I will try to rephrase to make sure I understand correctly: the idea would be to have checkpoints at strategically placed locations allowing the attacker to offer their services to the targeted organization? Since we have developed the maze ourselves, this allows us to augment the attacker's application with its profile (e.g., has the ability to break passwords). Where I am less sure is what the discount would be for? Or are you suggesting this as an alternative to bug bounty platforms? In any case, thank you for your suggestion :)
Our product is not a CTF! It inserts honeypots in our customer's infrastructure (through WAF and/or DNS configuration) to categorize attacks (manual vs. automated, targeted vs. random, persistent vs. changing) and attackers (profile creation, activity tracking despite IP rotation, skill assessment).
We then produce Threat Intel data feeds, instrument scenario seen on the honeypots and automatically replay them against our customer's assets, etc.