Solutions
Conatix cybersecurity software can monitor all of your endpoints and devices – your entire network – in real-time. Giving you unprecedented visibility, security and control.
When do we intervene?
| Cyber Kill Chain Phase | What the APT Does | Example Activity | |
|---|---|---|---|
PRE-INGRESS
ACTIVITY | 1. Reconnaissance | Researches the target, users, technology, suppliers, and exposed services. | Identifies a VPN appliance, executive assistant, cloud tenant, or vulnerable internet-facing server. |
| 2. Weaponization | Builds an attack package combining an access method with a loader, dropper, or implant. | Creates a malicious document, trojanized installer, exploit chain, or customized backdoor. | |
INGRESS
ACTIVITY | 3. Delivery | Gets the weaponized content to the target environment. | Spear-phishing attachment, malicious link, supply-chain update, drive-by download, or remote-service exploit attempt. |
PROPAGATE
AND LOAD
RANSOMWARE | 4. Exploitation | Causes attacker-controlled code to execute. | Exploits a vulnerability, abuses a macro, steals a session, or convinces the user to launch a file. |
DETECT
MALWARE | 5. Installation | Deploys the malware and commonly establishes persistence. | A dropper decrypts and writes a payload; a loader downloads an implant; malware creates a service or scheduled task. |
ENCRYPT AND
LOCK FILES | 6. Command and Control | Establishes a communications channel between the implant and the attacker. | Periodic HTTPS/DNS beaconing, cloud-service abuse, tasking commands, or delivery of additional modules. |
BLOCK
ENCRYPTION | 7. Actions on Objectives | Uses the access to accomplish the campaign's purpose. | Credential theft, discovery, lateral movement, data collection, exfiltration, espionage, sabotage, or disruption. |