Not yet another Death Note caused by the Ryuk Ransomware

enSilo Corporate and Product, cybersecurity

SUMMARY

Your network has been penetrated, your valuable files have been encrypted and the only way to decrypt your data is by paying an unknown entity a ransom via Bitcoins. This is not the beginning of a science fiction story as many of us would think. In recent years, organizations have been facing this harsh reality due to ransomware

Read More

The Gartner Market Guide for Endpoint Detection and Response Solutions Validates the enSilo Approach to Protecting Endpoints

enSilo Corporate and Product, cybersecurity

The latest version of the Gartner Market Guide for Endpoint Detection and Response Solutions validates the need for real-time prevention and why the detect-then-decide approach simply can’t keep up with today’s threats. 

Read More

City of Atlanta Ransomware Attack

cybersecurity, enSilo Corporate and Product

Overview

On March 22 of this year, the City of Atlanta experienced one of the most devasting and costly ransomware attacks to date in the US. For one week, the city floundered while five of its thirteen local government departments were held hostage, unable to perform their functions. For city employees logging-in to their devices that morning,

Read More

Exactis Data Breach: The Risk of Data Exposure Without Endpoint Protection

cybersecurity, enSilo Corporate and Product

Earlier this year Exactis, a Florida-based marketing data broker, had their database (close to 340 million individual records) exposed on a public server. Though hacking efforts didn't expose the data, the personally identifiable information was inexplicably left on an unsecured server without basic security safeguards. 
Read More

Melting Down PatchGuard: Leveraging KPTI to Bypass Kernel Patch Protection

enSilo Breaking Malware, cybersecurity, Windows, meltdown, KPTI, PatchGuard

The mitigation for Meltdown created a new part in the kernel which PatchGuard left unprotected, making hooking of system calls and interrupts possible, even with HVCI enabled.

Read More

enSilo Blocks LokiBot Infostealer

cybersecurity, enSilo Corporate and Product

enSilo’s Endpoint Security Platform detected and blocked a new variant of the LokiBot malware in July, 2018. During that time, VirusTotal exhibited only twelve commercial Anti-Virus (AV) applications having a virus definition for this malware, which indicates a low detection rate:

Read More

Turning (Page) Tables: Bypassing Kernel Mitigations to Successfully Escalate Privileges

enSilo Breaking Malware, cybersecurity, enSilo Corporate and Product

On August 8th, at the BSides Conference in Las Vegas, we unveiled a new exploitation technique against the Microsoft Windows operating system. It's a general technique to leverage with kernel vulnerabilities and make privilege escalation easier.

Read More

Supporting the Growth of Managed Detection and Response Services

enSilo Corporate and Product, cybersecurity

Gartner says it best in its most recent Market Guide for Managed Detection and Response (MDR) Services: “Managed detection and response improves threat detection monitoring and incident response capabilities via a turnkey approach to detecting threats that have bypassed other controls. Security and risk management leaders need to understand

Read More

enSilo Terminates DLL Search Order Hijacking

enSilo Corporate and Product, cybersecurity

In June 2018, Cybereason posted a blog about a malicious Dynamic-Link Library (DLL) file exhibiting a behavior associated with credential theft. Their analysis discovered that the malicious DLL MSVCR100.dll was leveraging the DLL search-order hijacking technique to load itself during the execution of unpack200.exe – an Oracle verified Portable

Read More

enSilo Blocks Hidden Cobras Latest Attack Tool

enSilo Corporate and Product, cybersecurity

Hidden Cobra’s latest attack tool

Read More