Showing posts with label forensics. Show all posts
Showing posts with label forensics. Show all posts

Thursday, November 28, 2019

Kaspersky data finds suspicious objects are malicious in close to three-quarters of investigated cases

Following Kaspersky’s analysis of anonymized and aggregated statistics of requests to the Kaspersky Threat Intelligence Portal, research showed that when security researchers requested additional details of a suspicious object, 72 percent of cases turned out to be malicious and could put corporate security at risk.

On average, 44 percent of security alerts are not investigated, likely due to the vast volume of incoming warning signals that security teams are challenged with. As a result, analysts must carefully choose which alerts need investigating versus those that do not justify further attention.


Of the 72 percent of cases that are found to be malicious after undergoing additional research, the share of such objects is especially high for web-related items including domains (86 percent), IP addresses (75 percent) and URLs (73 percent). This figure slightly drops for files, as 61 percent of hashes were categorized as dangerous. These statistics imply that it is more difficult for researchers to distinguish legitimate files from malicious ones without consulting with the appropriate threat intelligence.

The Kaspersky Threat Intelligence Portal is a web service which provides customers with knowledge about cyber threats gathered by Kaspersky. The company provides free access to basic information about suspicions files, hashes, IP addresses and others.

Global cybersecurity company Kaspersky offers deep threat intelligence and security expertise is constantly transforming into security solutions and services to protect businesses, critical infrastructure, governments and consumers around the globe. The company’s comprehensive security portfolio includes endpoint protection and a number of specialized security solutions and services to fight sophisticated and evolving digital threats. 

Overall, researchers are most interested to learn about which resources the endpoints in their network are communicating with, as shown by 41 percent of total requests falling under this category. With information on IP address reputation and associated web sites and files, security teams can make a decision if they should deny access to this resource or block any communication with it. 

In addition, a third (31 percent) of requests were about a file hash category, meaning analysts are looking for additional information about the file (i.e. geographical distribution, popularity and connections with other objects) during their investigations.

“As our statistics show, security analysts in organizations rarely make mistakes when they suspect that an alert poses a security risk and might need further investigation,” said Anatoly Simonenko, group manager for technology solutions product management at Kaspersky. “However, it’s not all about checking the hypotheses. To be able to accelerate their incident response and forensic capabilities, analysts need to see the bigger picture on a threat, quickly. Access to threat intelligence provides just that, ultimately saving time and effort for typically understaffed security teams.”

Monday, November 18, 2019

Lacework bring security visibility to cloud monitoring by integrating with Datadog

Lacework announced its integration with Datadog, the monitoring and analytics platform for developers, IT operations teams and business users in the cloud age. The integration unites security and observability data for customers, providing them with a complete cloud security platform, from build-time to run time, Lacework announced on Monday.



The integration between Lacework and Datadog supports two critical shifts in security: the shift from conflict to collaboration, and the shift from centralized to distributed. As more organizations adopt Continuous Integration and Continuous Delivery (CI/CD), the need to move quickly creates security gaps that can lead to data leaks, ransomware, crypto mining, and a variety of other issues that can leave data exposed and vulnerable. 

The Lacework Cloud Security Platform is cloud-native and offered as-a-Service; delivering build-time to run-time threat detection, behavioral anomaly detection, and cloud compliance across multicloud environments, workloads, containers, and Kubernetes. 


Customers significantly drive down costs and risk by freeing themselves from the burden of unnecessary hardware, rule writing, and inaccurate alerts. Lacework is trusted worldwide by enterprise companies at the forefront of embracing the cloud. 


This integration provides significant value to modern architectures that require a unified view of their metrics, logs and performance data with their cloud security findings, thus allowing teams to correlate data across different sources to investigate incidents faster; rehydrate archived logs/events for forensics with Datadog's Logging without Limits; route alerts/escalations through a standard pipeline across engineering; and identify any containers/hosts that are not running Lacework.

Tuesday, October 22, 2019

Guardonix USB3.0 Writeblocker assists forensic examiners to capture lost evidence from damaged/degraded data storage devices

A new device from DeepSpar Data Recovery Systems is making it possible for digital forensic examiners to capture lost evidence from malfunctioning hard drives (HDDs), solid state drives (SSDs), and other data storage devices.

To perform forensic analysis, storage devices are commonly connected to a forensic workstation through the USB interface. A writeblocker is required to ensure that evidence is not altered during analysis. 


A unique advantage of Guardonix is that in addition to writeblocking, it also stabilizes the USB connection – if a storage device is malfunctioning and intermittently goes offline, Guardonix hardware handles the issue, allowing data acquisition to succeed.

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...