Exclusive: Terra Security’s Prevention writes the firewall rules to block proven exploits
Offensive security startup Terra Security Inc. today launched Prevention, a feature that writes the firewall rules needed to block an attack its artificial intelligence agents have already proven works. Prevention is available now. Terra built it for the gap between a confirmed finding and a deployed code fix, a stretch that can run for weeks […] The post Exclusive: Terra Security’s Prevention…
Terra Security Inc., an offensive security startup, has introduced Prevention, a feature that automatically generates firewall rules to block exploits that its AI agents have already confirmed as effective. This tool addresses the gap between discovering a vulnerability and deploying a code fix, a period that can last for weeks due to release cycles and change-management approval processes. Cyber attackers, however, do not wait that long, often weaponizing known vulnerabilities within minutes of their disclosure.
Traditional remediation advice, such as updating a web application firewall, tuning a firewall, adjusting segmentation, or changing configurations, is rarely followed because it does not specify the exact rule to implement or whether that rule would effectively stop the exploit mentioned in the report. When Prevention identifies an exploitable risk, its AI agents test the customer's existing compensating controls against that specific attack path.
If these controls are insufficient, Prevention creates a targeted WAF or firewall rule and validates it against the exploit itself. The security team then deploys the generated rule, with any sensitive changes requiring human sign-off.
According to Gal Malachi, Terra Security's co-founder and Chief Technology Officer, "Finding an exploitable risk is only half the job. The hardest part is the stretch between proving it and fixing it, and adversaries can now exploit vulnerabilities in minutes. Defenders get time to remediate properly without leaving the door open."
The rules created by Prevention undergo the same exploit, guidance, and retest cycle that the company applies across its platform. Terra claims that no other agentic offensive security platform takes action on the risks it proves exploitable.
Founded in 2024, Terra sells an AI-native offensive security platform, with its AI agents probing customer environments under human supervision. The platform ranks findings based on their exploitable potential rather than just severity scores. Terra's services cover web applications, APIs, mobile and internal applications, AI systems, networks, and cloud environments, with Fortune 500 organizations among its customers.
The startup expanded its capabilities in May by adding continuous exploitation validation for network gear to its existing web application and AI system testing. Terra also won CrowdStrike Holdings Inc.'s Cybersecurity Startup Accelerator prize in September. Backed by venture capital, including a $30 million Series A round led by Felicis Ventures Management Company, Terra continues to leverage agentic AI to identify risks before attackers do.
Written by urgent.news from SiliconANGLE's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.