Automated Forensic Analysis
- No question or IOC needed, hunting from nothing
- Automatically detects all types of threats and the potential risks
- Automatical security posture measurement
- Automatical behavior analysis on suspicious file/URL
- Fully automated with FW/IPS/SIEM/EDR alerting systems
Easy to Understand
- Designed for easy to drill down to the details
- List key indicators (ATT/CK) with link to Mitre's articles
- Executive view with clear priority list from triage result
- Hunting results displayed on AlienVault
- Support on-premise and cloud deployment
Powerful
- Detects APT, ransomware, backdoors, rootkits and hidden downloaders
- Detects unusual network connections
- Uncovers past abnormal activities
- Discovers potential risks from misconfiguration
Easy to Use
- Point and click ad-hoc threat hunting, online/offline
- Input FW/IPS logs to start hunting on all alerted systems
- Script to start hunting from SIEM or EDR (Cylance) events
- Can be scheduled for proactive hunting/health checking periodically