Showing posts with label threat detection. Show all posts
Showing posts with label threat detection. Show all posts

Saturday, December 21, 2019

Asigra’s latest program defends public/non-profit organizations against cyber-attacks targeting backup data

Asigra announced a new program focused on defending the backup repositories and data of Canadian public and non-profit organizations against cyber-attacks. The purpose of the program is to ensure the recovery of data that otherwise may have become compromised as a result of malicious malware or ransomware Attack-Loops that prevent the recovery of mission-critical data and often put large volumes of personally identifiable information (PII) at risk.

Cyber-attacks on public/non-profit organizations have put citizen data at risk like never before as new variants of ransomware and other attacks continue to infiltrate and expose sensitive data to unknown and possibly criminal entities.


In a recent attack covered by the Toronto Star, medical test provider LifeLabs agreed to pay the ransom of attackers in order to retrieve millions of customer records. In a statement, the organization said, “The personal information of over 15 million customers was compromised, mostly in British Columbia and Ontario, including name, address, email, login, passwords, date of birth, health card number and lab test results.”

Like many organizations dealing with a cyber-attack, the last resort for recovery relies on a functioning disaster recovery or backup solution in place. Unfortunately, hackers have now designed ransomware and other malware to seek out secondary storage systems (aka: disaster recovery and backup data) in order to compromise a clean retrieval of the information. 


As a result, these organizations no longer have a way to reinstate their data, and therefore are faced with either relinquishing or paying a ransom which can be exceptionally high for public and non-profit entities.

As a Canadian company, Asigra is planning to help protect these organizations by partially donating a large percentage of its cybersecurity-enabled backup technology to Canada’s extensive list of public and non-profit organizations. Those establishments in the country that can issue a tax-deductible receipt may contact Asigra to receive the company's complete anti-ransomware/backup software suite with the cost covered in large part by a donation-in-kind.

Asigra’s cloud-based data recovery platform is unique in the industry for converging data protection and cybersecurity for effective malware/ransomware detection and prevention that ensures safe, secure and reliable data recovery. 


The advanced software includes initial zero-day Attack-Loop preventative technology using bi-directional cyber-threat detection, zero-day exploit protection, variable repository naming, and multi-factor authentication (MFA) for a full defensive suite against aggressive ransomware and other cyber-threats targeting backup data. This is complemented by FIPS 140-2 certification and military-grade data encryption to ensure enterprise-grade data security, making user data unreadable without the proper encryption key.

“The majority of cybersecurity analysts today agree that cyber-attacks are evolving from the perspective of what they target, how they impact organizations and the changing methods of attack,” said David Farajun, CEO, Asigra. “For the past year, we have seen an increasing number of cyberthreats begin to target the number one method of data recovery – the backup repository. As a specialist in this area, we have developed a very effective solution to fight against this and now offer the technology to public and non-profit organizations we share our data with.”

Monday, December 2, 2019

Trend Micro reports on Microsoft discovering polymorphic malware ‘Dexphot’ that affected 80,000 Windows systems

For over a year, Microsoft has been monitoring a malware strain they named “Dexphot” that has been infecting Windows devices since October last year, Trend Micro revealed in a recent post. The malware used computer resources to mine cryptocurrency and profit from the attack. It reached its peak in June 2019, infecting almost 80,000 computers before gradually decreasing over the next months because of Microsoft’s intervention.

Despite the typical malware payload, Microsoft claimed that monitoring the Dexphot gave them insight into not only on how the malware worked but also the techniques that cybercriminals currently use.


This was largely because of the way Dexphot behaved over the course of last year, as noted by Microsoft. The simple payload was delivered through complex techniques that were constantly updated by the malicious actors behind the malware strain.

Microsoft found that the Dexphot malware strain was dropped by another malware known as ICLoader, which is unknowingly installed on a user’s system as part of software bundles. Dexphot was found downloaded and installed in Windows systems that were infected by ICLoader.


While Microsoft Defender Advanced Threat Protection’s pre-execution detection engines blocked Dexphot in most cases, behavior-based machine learning models provided protection for cases where the threat slipped through. Given the threat’s persistence mechanisms, polymorphism, and use of fileless techniques, behavior-based detection was a critical component of the comprehensive protection against this malware and other threats that exhibit similar malicious behaviors.

Microsoft Defender ATP data shows the effectiveness of behavioral blocking and containment capabilities in stopping the Dexphot campaign. Over time, Dexphot-related malicious behavior reports dropped to a low hum, as the threat lost steam.

Dexphot used legitimate system processes for its malicious activities. It used legitimate Windows apps such as msiexec.exe, unzip.exe, rundll32.exe, schtasks.exe, and powershell.exe to decrypt its data files. Using such tools allows Dexphot to evade detection, as the system would consider its activities as normal processes.

In addition, the decrypted files contained three executable files which are never written on filesystem. They remain on memory. This means Dexphot also used fileless techniques.

Dexphot instead laces the first two executable files into other legitimate system processes like svchost.exe or nslookup.exe. These are monitoring services that maintain Dexphot components. Finally, it replaces setup.exe contents with its third executable, a cryptocurrency miner.

Microsoft saw that Dexphot switched miners throughout their monitoring, using both programs like XMRig and JCE.

Microsoft noted that Dexphot was a malware strain that was not likely to garner much attention for its common payload. However, it does paint a good picture of the techniques that had been pervasive throughout this year, namely living off the land and fileless techniques.

Trend Micro’s most recent security roundup reported that threat actors have been increasingly living off the land. In fact, detections for fileless threats was 18 percent higher during the first half of 2019 compared to the total count for 2018.


Remaining vigilant and wary of similar cases as Dexphot can help in defending against fileless threats moving forward. Organizations would need to consider solutions like behavioral indicators and traffic monitoring to defend against the unique challenges that fileless threats present.

Trend Micro's Smart Protection Suites deliver several capabilities like high-fidelity machine learning and web reputation services that minimize the impact of persistent, fileless threats. 

Trend Micro Apex One protection employs a variety of threat detection capabilities, notably behavioral analysis that protects against malicious scripts, injection, ransomware, memory and browser attacks related to fileless threats. Additionally, the Apex One Endpoint Sensor provides context-aware endpoint investigation and response (EDR) that monitors events and quickly examines what processes or events are triggering malicious activity. 

The Trend Micro Deep Discovery solution has a layer for email inspection that can protect enterprises by detecting malicious attachments and URLs. Deep Discovery can detect remote scripts even if it is not being downloaded in the physical endpoint.

Monday, November 18, 2019

Lacework bring security visibility to cloud monitoring by integrating with Datadog

Lacework announced its integration with Datadog, the monitoring and analytics platform for developers, IT operations teams and business users in the cloud age. The integration unites security and observability data for customers, providing them with a complete cloud security platform, from build-time to run time, Lacework announced on Monday.



The integration between Lacework and Datadog supports two critical shifts in security: the shift from conflict to collaboration, and the shift from centralized to distributed. As more organizations adopt Continuous Integration and Continuous Delivery (CI/CD), the need to move quickly creates security gaps that can lead to data leaks, ransomware, crypto mining, and a variety of other issues that can leave data exposed and vulnerable. 

The Lacework Cloud Security Platform is cloud-native and offered as-a-Service; delivering build-time to run-time threat detection, behavioral anomaly detection, and cloud compliance across multicloud environments, workloads, containers, and Kubernetes. 


Customers significantly drive down costs and risk by freeing themselves from the burden of unnecessary hardware, rule writing, and inaccurate alerts. Lacework is trusted worldwide by enterprise companies at the forefront of embracing the cloud. 


This integration provides significant value to modern architectures that require a unified view of their metrics, logs and performance data with their cloud security findings, thus allowing teams to correlate data across different sources to investigate incidents faster; rehydrate archived logs/events for forensics with Datadog's Logging without Limits; route alerts/escalations through a standard pipeline across engineering; and identify any containers/hosts that are not running Lacework.

Monday, November 4, 2019

CounterFlow AI, CrowdStrike join to help boost network data’s signal-to-noise ratio and expedite incident response

CounterFlow AI announced on Monday an alliance with CrowdStrike to accelerate threat detection and response for enterprise security teams. Through this partnership, CounterFlow AI is enhancing its purpose-built machine learning engine (MLE) with CrowdStrike’s Falcon X, enabling security teams to better prevent future attacks.

Organizations want greater data fidelity from threat insights gained from their networks’ endpoints without creating an unwieldy security stack or larger data storage footprint. 


CounterFlow AI’s integration with CrowdStrike gives security teams an automated way to assess streaming network data with real-time contextualized threat intelligence and the assurance they record only the data with high investigative value. It alerts customers with detailed Indicators of Compromise (IoCs), such as domain and IP information, to help security teams more quickly detect existing threats and perform incident investigations more effectively.


CounterFlow AI’s ThreatEye AIOps platform for network forensics enables intelligent packet capture and network intelligence. Designed for hybrid cloud deployments, ThreatEye brings together full packet capture, machine learning, and visualization to provide timely and actionable insights. 

The ThreatEye Network Forensics platform incorporates machine learning and artificial intelligence to enable intelligent packet capture, which allows security teams to keep high-fidelity data and eliminate extraneous data by up to 80 percent. 

Unlike many network traffic analysis (NTA) solutions built on proprietary, black-box architecture, ThreatEye is an open, scalable, platform designed for SOC analysts who want the flexibility to create a customized packet capture and more intelligent foundation for incident response and threat hunting, easy integration with existing workflows and the explainability to keep the “human-in-the-loop”. 


CounterFlow AI’s open platform integrates seamlessly with the cloud-native intelligent, single-agent platform that is CrowdStrike Falcon®. CrowdStrike’s unique approach enables frictionless deployment at scale to stream high-fidelity data to the cloud, equipping customers with prioritized threat analysis and response.

CrowdStrike’s Threat Graph technology processes, correlates, and analyzes over two trillion endpoint-related events per week and continuously looks for malicious activity with graph analytics powered by cloud-scale AI. This creates a powerful network of crowdsourced intelligence that provides actionable insights to customers. The platform enables intelligent, dynamic automation at scale to detect threats and stop breaches.


“We’re thrilled to partner with a firm like CounterFlow AI, who is introducing a more intuitive way to approach packet capture and eliminate the time-consuming activities that have historically been associated with it,” said Amol Kulkarni, chief product officer, CrowdStrike. “By integrating the benefits of CrowdStrike Falcon with CounterFlow AI ThreatEye, we are offering customers contextualized threat intelligence to help enable security teams to move from a reactive state to a proactive one. This powerful combination delivers a more efficient way to help organizations conduct investigations, including the critical intelligence necessary to get ahead of known and unknown threats.”

Friday, November 1, 2019

Cisco joins with Perch Security to help MSPs protect, detect and respond to an increasing threat landscape

Cisco partnered with Perch Security to deliver a new security solution for managed service providers (MSPs) who are challenged by an evolving threat landscape. MSPs are on the front lines of protecting their clients against data breaches, malware, ransomware and other attacks for which they are often unprepared. 

To address these threats, Cisco is applying its security expertise and portfolio to MSPs in partnership with Perch to bring them the tools that will strengthen their security posture and better protect both themselves and their clients.


The combined technology solution offers clear benefits for Cisco partners and their customers by correlating events from both the endpoint and network, reducing ticket counts and lowering labor costs. 

Perch has integrated with Cisco Advanced Malware Protection (AMP) for Endpoints and Cisco Umbrella, ingesting their logs and feeding them into Perch’s security information and event management (SIEM) solution.

Its features include Perch’s Security Operations Center (SOC) that provides event correlation, alert review, and custom alert options; and Perch’s Duo integration correlates Duo Multi-Factor Authentication and endpoint visibility with data from other Perch-connected cloud services, such as Office 365, Cisco Umbrella and Cisco AMP. 


By combining these solutions into a single pane of glass, alerts are correlated and consolidated to reduce tool sprawl. Perch feeds data from cloud services and security products into a single data lake that is monitored by Perch SOC.

This announcement ties into the newly created Cisco Secured MSP offer, which includes a free, internal use license program and gives MSPs the ability to elevate their internal security and protect themselves from attack. This works by using DNS solution from Cisco Umbrella for MSP, next-generation endpoint detection and response with Cisco Advanced Malware Protection (AMP) and cloud-based threat detection from Cisco Stealthwatch Cloud. 


The Cisco secured MSP offer brings the best of security to every MSP and the knowledge and training to get it right the first time through the Protect Your House course on ConnectWise MSP University. Cisco helps partners grow managed service revenue with incentives, promotions and market development funds (MDF). 

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...