Case Study: Rubrik assesses a 187-package npm attack in about 30 minutes and holds 24-hour SLAs with Endor Labs
Key results
The challenge
Rubrik's existing SCA tools lacked native Bazel support and integrated poorly, requiring manual triage and deduplication. False positives damaged the security team's credibility, while FedRAMP compliance demanded near-zero vulnerability tolerance and tight remediation timelines.
The solution
Rubrik adopted Endor Labs to consolidate SCA, SAST, container scanning, and secret detection with native Bazel support. Reachability analysis let the team focus on findings that were actually exploitable and defensible with data.
“We have tight remediation SLAs, as short as 24 hours, and Rubrik is consistently hitting them because we don't have to argue over whether a finding is real.”
MGMarty GarvinHead of Security, Rubrik
The results, in context
Following an npm malware disclosure, Rubrik determined within about 30 minutes that it used no affected versions from the 187 compromised packages. With high-fidelity, reachability-backed findings, the team consistently meets remediation SLAs as short as 24 hours required for FedRAMP authorization.