follow

help me to improve quality

donate

Pages

Friday, 10 March 2017

Secure Messaging App 'Confide' Used by White House Staffers Found Vulnerable



The secure messaging app used by staffers in the White House and on Capitol Hill is not as secure as the company claims.

Confide, the secure messaging app reportedly employed by President Donald Trump's aides to speak to each other in secret, promises "military-grade end-to-end encryption" to its users and claims that nobody can intercept and read chats that disappear after they are read.

However, two separate research have raised a red flag about the claims made by the company.

Security researchers at Seattle-based IOActive discovered multiple critical vulnerabilities in Confide after a recent audit of the version 1.4.2 of the app for Windows, Mac OS X, and Android.

Confide Flaws Allow Altering of Secret Messages


The critical flaws allowed attackers to:

  • Impersonate friendly contacts by hijacking an account session or guessing a password, as the app failed to prevent brute-force attacks on account passwords.
  • Spy on contact details of Confide users, including real names, email addresses, and phone numbers.
  • Intercept a conversation and decrypt messages. Since the app's notification system didn't require any valid SSL server certificate to communicate, a man-in-the-middle attacker can potentially grab messages intended for a legitimate recipient.
  • Alter the contents of a message or attachment in transit without first decrypting it.
  • Send malformed messages that can crash, slow, or otherwise disrupt the application.

Exploiting the weaknesses allowed the researchers to gain access to more than 7,000 account records created over the span of two days (between February 22 and 24), out of a database containing between 800,000 and 1 Million records.

Flaw Exposed Details of a Trump Associate and Several DHS Employees


Out of just that 2-day sample, the researchers were even able to find a Donald Trump associate and several employees from the Department of Homeland Security (DHS) who downloaded the Confide app.

IOActive researchers Mike Davis, Ryan O'Horo, and Nick Achatz responsibly disclosed a total 11 separate issues in Confide to the app's developers, who responded immediately by patching the app.

In addition to this, researchers from Quarkslab also showed off Confide exploits Wednesday after analyzing the app's code.

The researchers discovered a series of design vulnerabilities in the Confide for iOS app, which could allow the company to read user messages, adding that the app didn't notify users when encryption keys were changed.

Even, The Company Can Read Your Messages


According to the researchers, "Confide server can read your messages by performing a man-in-the-middle attack," and other security features of the app, such as message deletion and screenshot prevention, can also be defeated.

"The end-to-end encryption used in Confide is far from reaching state of the art," the researchers said. "Building a secure instant messaging app is not easy, but when claiming it, some strong mechanisms should really be enforced since the beginning."

Quarkslab researchers said the company server could generate its own key pair, meaning that the company has the ability to transmit the public key to a client when requesting the public key of a recipient.

"This client then unknowingly encrypts a message that can be decrypted by the server," the researchers added. "Finally, when the server sends the message to the recipient, it is able to re-encrypt the message with its own key for the actual recipient."

In response to Quarkslab's findings, Confide co-founder and president Jon Brod said:

"The researchers intentionally undermined the security of their own system to bypass several layers of Confide's protection, including application signatures, code obfuscation, and certificate pinning. The attack that they claim to be demonstrating does not apply to legitimate users of Confide, who are benefiting from multiple security protections that we have put in place. Undermining your own security or taking complete control of a device makes the entire device vulnerable, not just the Confide app."

Confide has rolled out an updated version of its app which includes fixes for the critical issues, and assured its customers that there wasn't any incident of these flaws being exploited by any other party.

Confide is one of those apps which, unlike other secure messaging apps, keeps its code private and until this time, offered little or no detail about the encryption protocols used in the app.

For more details about the vulnerabilities in Confide, you can head on to IOActive's advisory and Quarkslab's Blog.

New Apache Struts Zero-Day Vulnerability Being Exploited in the Wild



Security researchers have discovered a Zero-Day vulnerability in the popular Apache Struts web application framework, which is being actively exploited in the wild.

Apache Struts is a free, open-source, Model-View-Controller (MVC) framework for creating elegant, modern Java web applications, which supports REST, AJAX, and JSON.

In a blog post published Monday, Cisco's Threat intelligence firm Talos announced the team observed a number of active attacks against the zero-day vulnerability (CVE-2017-5638) in Apache Struts.

According to the researchers, the issue is a remote code execution vulnerability in the Jakarta Multipart parser of Apache Struts that could allow an attacker to execute malicious commands on the server when uploading files based on the parser.
"It is possible to perform an RCE attack with a malicious Content-Type value," warned Apache. "If the Content-Type value isn't valid an exception is thrown which is then used to display an error message to a user."
The vulnerability, documented at Rapid7's Metasploit Framework GitHub site, has been patched by Apache. So, if you are using the Jakarta-based file upload Multipart parser under Apache Struts 2, you are advised to upgrade to Apache Struts version 2.3.32 or 2.5.10.1 immediately.

Exploit Code Publicly Released


Since the Talos researchers detected public proof-of-concept (PoC) exploit code (which was uploaded to a Chinese site), the vulnerability is quite dangerous.

The researchers even detected "a high number of exploitation events," the majority of which seem to be leveraging the publicly released PoC that is being used to run various malicious commands.



In some cases, the attackers executed simple "whoami" commands to see if the target system is vulnerable, while in others, the malicious attacks turned off firewall processes on the target and dropped payloads.



"Final steps include downloading a malicious payload from a web server and execution of said payload," the researchers say. "The payloads have varied but include an IRC bouncer, a DoS bot, and a sample related to the Bill Gates botnet... A payload is downloaded and executed from a privileged account."
Attackers also attempted to gain persistence on infected hosts by adding a binary to the boot-up routine.

According to the researchers, the attackers tried to copy the file to a benign directory and ensure "that both the executable runs and that the firewall service will be disabled when the system boots."

Both Cisco and Apache researchers urge administrators to upgrade their systems to Apache Struts version 2.3.32 or 2.5.10.1 as soon as possible. Admins can also switch to a different implementation of the Multipart parser.

Wednesday, 8 March 2017

Proposed Bill Would Legally Allow Cyber Crime Victims to Hack Back



Is it wrong to hack back in order to counter hacking attack when you have become a victim? — this has been a long time debate.

While many countries, including the United States, consider hacking back practices as illegal, many security firms and experts believe it as "a terrible idea" and officially "cautions" victims against it, even if they use it as a part of an active defense strategy.

Accessing a system that does not belong to you or distributing code designed to enable unauthorized access to anyone's system is an illegal practice.

However, this doesn't mean that this practice is not at all performed. In some cases, retribution is part of current defense offerings, and many security firms do occasionally hack the infrastructure of threat groups to unmask several high-profile malware campaigns.

But a new proposed bill intended to amend section 1030 of the Computer Fraud and Abuse Act that would allow victims of ongoing cyber-attacks to fight back against hackers by granting victims more powers to engage in active defense measures to identify the hacker and disrupt the attack.

The new bill has been proposed by Representative Tom Graves of Georgia and is named the "Active Cyber Defense Certainty" (ACDC) Act — a term that empowers victims to make use of "limited defensive measures that exceed the boundaries of one's network" in order to stop and identify digital attackers.

However, this new bill allowing hacking back attackers is already stirring up some concerns about potential unintended consequences.

Many argue…When we have legal authority to defend ourselves during a physical assault, then why not during a cyber attack by hacking back the attacker?


First of all, cyberspace doesn't work the way the physical world works, as online life moves at digital speeds. In the cyber world, there is a certain sense of helplessness.

Let's understand this by an example: In a home robbery, it is legal to defend your family from the attackers while waiting for the police authorities, since the robbers are in front of you and if you don't defend, a lot can happen in the several minutes in between.

But, if robbers robbed your house and ran away, you ran behind them and caught a person assuming him one of those, but can not actually identify.

What if he is really an innocent person who accidentally stumbled into your hands?


This is the major concern when hacking back targets innocent people, since attribution or identification of an attacker is tough in this cyber-universe.

But if passed, the ACDC Act will allow hacking victims to "access without authorization the computer of the attacker...to gather information...to establish attribution of criminal activity to share with law enforcement or to disrupt continued unauthorized activity against the victim's own network."

But What if a Botnet Affected System Used to Attack You?


It's important to note that there are some limitations. The proposed bill specifies that victims can access the attacker's computer without authorization, but to only gather information about their attackers and sharing it with law enforcement.

But, the bill doesn't allow hacking victims to perform activities such as destroying any information stored on the attacker's computer, causing physical damage to another person, or creating a threat that can endanger public health or safety. Well, that's commendable.

The limitation is because today so many compromised computers (botnet) are involved in cyber attacks that a hacking victim could rarely be certain they would be attacking the real attacker rather than an innocent victim.

Even worse, that compromised machine could also belong to a company that stores personal and/or financial information of its customers. So, accessing that data without authorisation would unintentionally compromise the confidentiality of the company's data.
"The first question that comes up with this, assuming you’re able to do it, is ‘Do you know who it is you would hack back against?'" said Ed McAndrew, an attorney with Ballard Spahr in Washington, and former federal cybercrime prosecutor. 
"This is a real concern. You could have people hacking back at pivots (in an attack). Are you hitting back against an attacker or someone accidentally in the middle?"

Hacking Back is legal in your country, but What about Others Where your Attacker Resides?


This bill grants you authority to hack back, but if your attacker resides in the different country, you could face hacking charges in that nation by violating their law.

So, in this case, you inadvertently become a cyber criminal for that country.

What about the cyber crimes that will take place in the name of Hacking Back?


In the whole discussion, one can not neglect sophisticated hackers, who always found some ways to carry out internet crimes.

Today, when hacking back is illegal under the Computer Fraud and Abuse Act, it's quite easy for anyone to judge who is a criminal and who is a victim.

But, if made legal, Hacking back could provide broad affirmative defenses to hackers who get prosecuted, enabling them to use this law to cover their activity conveniently.
"Whatever you can convince a jury of is what truth is; that’s the view of a defense lawyer. The hacker could tell their story that they were doing this activity to aid law enforcement," said McAndrew. "You've got a lot of situations where I could envision a defendant saying they're doing this because they're trying to help law enforcement or assist victims."
Although the ACDC proposed bill is currently undergoing a phase of public discussion, you have a chance to provide your feedback and make recommendations for the draft law before Rep. Graves formally introduce it to the U.S. House of Representatives.

Here's the draft [PDF] of the proposed ACDC act

WikiLeaks Exposed CIA's Hacking Tools And Capabilities Details



WikiLeaks has published a massive trove of confidential documents in what appear to be the biggest ever leak involving the US Central Intelligence Agency (CIA).

WikiLeaks announced series Year Zero, under which the whistleblower organization will reveal details of the CIA's global covert hacking program.

As part of Year Zero, Wikileaks published its first archive, dubbed Vault 7, which includes a total of 8,761 documents of 513 MB (torrent | password) on Tuesday, exposing information about numerous zero-day exploits developed for iOS, Android, and Microsoft's Windows operating system.

WikiLeaks claims that these leaks came from a secure network within the CIA's Center for Cyber Intelligence headquarters at Langley, Virginia.

The authenticity of such dumps can not be verified immediately, but since WikiLeaks has long track record of releasing such top secret government documents, the community and governments should take it very seriously.

CIA's Zero-Day Exploits & Ability to Bypass Encrypted Apps


According to initial analysis and press release, the leak sheds light on the CIA's entire hacking capabilities, including its ability to hack smartphones and popular social media messaging apps including the world's most popular WhatsApp messaging app.
"These techniques permit the CIA to bypass the encryption of WhatsApp, Signal, Telegram, Weibo, Confide and Cloackman by hacking the smartphones that they run on and collecting audio and message traffic before encryption is applied," WikiLeaks said.
The exploits come from a variety of sources, including partner agencies like NSA and GCHQ or private exploit traders, as well as the CIA's specialized unit in its Mobile Development Branch that develops zero-day exploits and malware for hacking smartphones, including iPhones and iPads.
"By the end of 2016, the CIA's hacking division, which formally falls under the agency's Center for Cyber Intelligence (CCI), had over 5000 registered users and had produced more than a thousand hacking systems, trojans, viruses, and other weaponized malware," WikiLeaks said.
The agency can remotely activate smartphones' cameras and microphones at its will, allowing it to hack social media platforms before encryption can be applied, WikiLeaks claims in the statement on their website.

"Weeping Angel" Attack — Hacking Smart TVs to Spy On Users


Vault 7 also details a surveillance technique — codenamed Weeping Angel — used by the agency to infiltrate smart TV's, transforming them into covert microphones.

Samsung smart TVs, which previously drew criticism for their always-on voice command system, are vulnerable to Weeping Angel hacks that place the TVs into a “Fake-Off” mode.

In Fake-Off mode, the TV owner believes it is off when it is actually on, allowing the CIA to record conversations "in the room and sending them over the Internet to a covert CIA server."

HammerDrill v2.0: A Malware to Steal Data From Air Gapped PCs


The CIA's cyberweapon arsenal also includes a cross-platform malware, dubbed Hammer Drill, that targets Microsoft, Linux, Solaris, MacOS, and other platforms via viruses infecting through CDs/DVDs, USBs, data hidden in images, and other sophisticated malware.

What more interesting? Hammer Drill v2.0 also added air gap jumping ability used to target computers that are isolated from the Internet or other networks and believed to be the most secure computers on the planet.

Besides listing all hacking tools and operations, the documents also include instructions for using those hacking tools, tips on the configuration of Microsoft Visual Studio (which is classified as Secret/NOFORN), as well as testing notes for various hacking tools.

Some of the leaked documents even suggest that the CIA was even developing tools to remotely control certain vehicle software, allowing the agency to cause "accidents" which would effectively be "nearly undetectable assassinations."

For more details on the leak, you can peruse on the WikiLeaks' website.

Tuesday, 7 March 2017

Google Increases Bug Bounty Payouts by 50% and Microsoft Just Doubles It!



Well, there's some good news for hackers and bug bounty hunters!

Both tech giants Google and Microsoft have raised the value of the payouts they offer security researchers, white hat hackers and bug hunters who find high severity flaws in their products.

While Microsoft has just doubled its top reward from $15,000 to $30,000, Google has raised its high reward from $20,000 to $31,337, which is a 50 percent rise plus a bonus $1,337 or 'leet' award.

In past few years, every major company, from Apple to P*rnHub and Netgear, had started Bug Bounty Programs to encourage hackers and security researchers to find and responsibly report bugs in their services and get rewarded.

But since more and more bug hunters participating in bug bounty programs at every big tech company, common and easy-to-spot bugs are hardly left now, and if any, they hardly make any severe impact.

Sophisticated and remotely exploitable vulnerabilities are a thing now, which takes more time and effort than ever to discover.



So, it was needed to encourage researchers in helping companies find high-severity vulnerabilities that have become harder to identify.

Until now, Google offered $20,000 for remote code execution (RCE) flaws and $10,000 for an unrestricted file system or database access bugs. But these rewards have now been increased to $31,337 and $13,337, respectively.

For earning the top notch reward of $31,337 from the tech giant, you need to find command injections, sandbox escapes and deserialization flaws in highly sensitive apps, such as Google Search, Chrome Web Store, Accounts, Wallet, Inbox, Code Hosting, Google Play, App Engine, and Chromium Bug Tracker.

Types of vulnerabilities in the unrestricted file system or database access category that can earn you up to $13,337 if they affect highly sensitive services include unsandboxed XML eXternal Entity (XXE) and SQL injection bugs.

Since the launch of its bug bounty program in 2010, Google has paid out over $9 Million, including $3 Million awarded last year.

Microsoft has also increased its bug bounty payouts from $20,000 to $30,000 for vulnerabilities including cross-site scripting (XSS), cross-site request forgery (CSRF), unauthorized cross-tenant data tampering or access (for multi-tenant services), insecure direct object references injection, server-side code execution, and privilege escalation bugs, in its Outlook and Office services.

Both the tech giants are trying their best to eliminate any lucrative vulnerability or backdoor into their software and products to avoid any hacking attempts and make them more secure.

Hackers will get the payout reward after submitting the vulnerabilities along with a valid working proof-of-concept.

So, what are you waiting for? Go and Grab them all!

Secdo Automates End-to-End Incident Response with Preemptive IR


As vast volumes of digital data are created, consumed and shared by companies, customers, employees, patients, financial institutions, governments and so many other bodies, information protection becomes a growing risk for everyone.

Who wants to see personal customer purchasing data flying into the hands of strangers? What company can tolerate the pilfering of its intellectual property by competitors? What government can stand idly by while its military secrets are made public?

To protect their valuable and private information, organizations purchase numerous cyber security systems – like intrusion detection systems, firewalls, and anti-virus software – and deploy them across their networks and on all their computers.

In fact, a typical bank, manufacturer or government department might have dozens of such products operating at all times.

Cyber security systems work non-stop to thwart network infiltration and data-theft. Whenever they notice an activity that seems outside the scope of regular use, they issue an alert to notify cyber security personnel who investigate the reason for the alert and take remedial action if necessary.

For example, if someone tries to access a computer and repeatedly enters the wrong password, an alert will be issued. When an email attachment containing a virus is opened, another alarm will be raised.

Despite all of these security systems and their alerts, strong networks are breached, and the information is stolen. Why does this still happen?

Over-Detection and False Positives


Cyber security systems work by noticing unusual activities and behaviors of people and software. But they often get it wrong. Try as they may, in order to be ultra-careful, cyber security systems flag a lot of activities that they determine to be potentially malicious but, in reality, are not.

Yes, you keyed in your password three times until you got it right, but you aren’t a data pirate. That still causes an alert.

From your office computer, you inadvertently accessed a website that is off-limits to your company. Honest mistake, but another alert.

This happens so frequently that, every day, hundreds or even thousands of alerts turn out to be nothing of note.

Can you believe it? The average enterprise in the US receives more than 10,000 alerts every day. Most of them aren’t incidents that should demand attention. But how do you know until you look into them?

This daily load of false positives distracts cyber security professionals from dealing with legitimate security alerts.

As more and more time is wasted chasing after false positives, security staffs have to resort to triage – that is, they try to figure out which alerts are important and require a response, and which ones are false and should be ignored. They aren't always accurate. Sometimes, an analyst spends weeks tracking down an incident that turns out to be irrelevant.

Conversely, sometimes, the alert that is ignored is the real emergency!

Distracted to Ruin


A good example that shows how false positives can be ruinous to an organization is the Target Data Breach.

Target, the second-largest discount-store retailer in the United States, was forced to admit to more than 70 million shoppers that their personal and financial information had been compromised.

With a large cybersecurity team and a significant budget for tools and technologies that protect data, how could this happen to Target? (Or Ebay? Or JP Morgan Chase? Or Yahoo?)

Target's problem wasn't that some sort of hacker had succeeded in bypassing its robust cyber security systems. In fact, the company's detection systems deployed specifically to monitor such intrusion attempts had generated alerts confirming that malicious software was present. So why wasn't it dealt with?

As these important alerts were buried among thousands of daily false positives, they did not achieve high enough attention to warrant the prompt action that they demanded. They were missed. This simple oversight led to one of the largest and most costly data breaches in history, estimated at more than $300 million!

In short, while detecting cyber threats and alerting security personnel is crucial, it is not nearly enough. Organizations must institute an accurate, real-time alert validation methodology that unfailingly determines which of the thousands of daily alerts deserve attention and which are just "noise."

But the devil is in the details.

Secdo Automates the Incident Response Process End to End


Secdo's Preemptive Incident Response platform automatically validates every single alert, distinguishing between false positives and real threats that deserve serious investigation.

Secdo provides all the context – the "who, what, where, when and how" – to help security analysts determine the severity of a real alert. Then, Secdo empowers security teams to respond quickly and precisely to combat the threat.

The Secdo platform comprises three modules:
  1. Observer
  2. Analyzer
  3. Responder

Observer

According to Secdo, effective cyber security begins with preemptive data collection. Like a battery of digital cameras that see and record everything, Observer records and stores every activity that occurs on every endpoint (computer) and server (we call these "hosts") in the network.

Everything on every host, even when they number in the tens of thousands! Observer enables security and IT teams to see how any host, user, or process behaved now or in the past – just like the ability to view any video from any camera now or in the past at the click of a mouse.

Observer enables quick investigations and threat-hunting. It provides facilities for easy ad-hoc inquiries, enabling analysts to investigate any alert and hunt for threats effectively. Security analysts can use the intuitive investigation interface to ask questions about any event and always get a conclusive answer.

For example:
  • Who accessed the website www.youshouldnotgothere.ru on January 24th between 13:31 and 15:09?
  • Which hosts have file iamarealthreat.exe on their hard drive?
  • Which endpoints sent out companyfinancials.xlsx in emails last night?
Answers to these and other questions are displayed promptly and helpfully to the security analyst.



Analyzer

Non-stop, Analyzer correlates the mass of data stored by Observer. If Observer is like thousands of digital cameras recording everything, Analyzer is the intelligence that connects all the individual videos into coherent stories that can be reviewed anytime.

For example, malicious software from my boss’s computer is trying to send data out to a foreign website, an event that triggers an alert. It sounds like a simple case, but the full story might read like this:
"Yesterday, I received an email from a particular address. I clicked on the attachment, looked at it, and thought about it no more. However, unbeknownst to me, the attachment wrote a bit of malware on my hard drive. Two hours later, it started to search my computer until it found a password file that enabled it to jump to my boss’s computer. There, at midnight, the malware woke up, searched my boss’s hard drive until it found a file called secretcompanyplans.docx. It connected to a website in Ukraine and attempted to send the file. This is what triggered the alert."
The security analyst will see the limited information in the alert which says: "The boss’s endpoint attempted to connect to www.ohnodontgothere.ua."

How can the analyst know the entire story of the alert in order to understand that there is an attachment to an email on my computer that started the whole incident?

Merely preventing access to the bad website will not eradicate the danger. Perhaps this piece of malware is so smart that it will wake up again and try some other tricks like sending another file to a different website. That will just trigger another alert and require another security analyst to fix the same problem tomorrow.

The full story is necessary to fix the entire problem once and for all..

Secdo's Analyzer helps analysts get to the root of every problem and understand its full scope so they can remediate it at its root cause.

Analyzer's Causality Engine places all events received from the Observer data into causality chains (the story) in anticipation of alerts, preparing the forensics that will be necessary for any future security investigation.

As alerts are triggered from any source (any of the many cyber security systems that the organization has deployed), Analyzer automatically correlates the alerts with their appropriate causality chains, placing them into their full context. IT and security teams are able to see the chain of events (the entire story) of exactly what happened from this moment backward into the past.

With the full context, Analyzer can accurately distinguish false alerts so that analysts don’t have to endure unnecessary distractions. It accurately priorities and presents each genuine alert, displaying the entire context including the attack chain starting from root cause (how did this incident start?), all entities involved (where has it spread?) and damage assessment (what did the bad guys do to us so far?) – the entire story.

With all this information presented graphically before their very eyes, security analysts can properly analyze real alerts and respond correctly in seconds.



In our example, Secdo would enable the analyst to see that the malicious attachment on my computer started the entire chain of events, that it jumped to my boss's computer and that both malicious processes must be cleaned as well as other files or commands they might have written and anything else that is pertinent to this incident.


Responder


So, what do you do once you have found an actual cyber breach that requires a firm and accurate response?

Before Secdo, IT personnel usually had to confiscate your computer, wipe it clean and reinstall Windows and all your applications and data files. Everything. This could take hours or even days. What an interruption to your productivity and what a cost to the company!

With Secdo, the process is a lot faster and smarter, and doesn't interfere with your work. Responder gives security and IT people the ability to remotely access and surgically resolve any threat on any host without impacting productivity.

Responder provides numerous powerful containment and remediation capabilities including patented ICEBlock™ that safely freezes a process in memory while the endpoint remains on the network. You can keep working securely while all this takes place.



Responder even takes security a step further. Its plentiful and powerful response capabilities can be fully automated adding protection to the organization into the future.

Conclusion


Digital data is an attractive target for cyber attackers who would steal it for nefarious purposes. Organizations employ security analysts and deploy numerous security products to help them defend against cyber attacks.

These products may generate thousands of alerts every day, and most of these are false positives. Due to the overwhelming daily volume, security teams cannot deal with all alerts and must triage them.

Analysts need an automatic, accurate way to separate out the false positives and prioritize the real ones so that they can focus on real threats. They need to see the entire scope of incidents in order to determine the proper course of remediation. They require remote, surgical response tools that enable them to accurately eradicate threats while maintaining business productivity.

Secdo's Preemptive Incident Response (PIR) transforms the traditional IR process from reactive to proactive by continuously collecting and storing all host activity data – BEFORE an incident occurs.

All activity data from all endpoints and servers (hosts) is automatically correlated in causality chains (context) in anticipation of future incidents. As alerts are ingested from detection systems, they are connected with their appropriate causality chains, preparing full forensic evidence even before Incident Response teams get involved.

With full context, false positives can be eliminated accurately, and real alerts can be prioritized correctly. Security analysts can quickly investigate each alert, already observing its root cause, full activity, entities involved and damage assessment.

With this level of visibility and context, accompanied by a suite of advanced surgical remediation tools, analysts can respond remotely, promptly and precisely to threats while maintaining business productivity.