Solutions

Conatix cybersecurity software can monitor all of your endpoints and devices – your entire network – in real-time. Giving you unprecedented visibility, security and control.

PREDICTIONPREVENTIONDETECTIONMITIGATIONINVESTIGATIONRETALIATION?

When do we intervene?

Cyber Kill Chain PhaseWhat the APT DoesExample Activity
PRE-INGRESS ACTIVITY
1. ReconnaissanceResearches the target, users, technology, suppliers, and exposed services.Identifies a VPN appliance, executive assistant, cloud tenant, or vulnerable internet-facing server.
2. WeaponizationBuilds an attack package combining an access method with a loader, dropper, or implant.Creates a malicious document, trojanized installer, exploit chain, or customized backdoor.
INGRESS ACTIVITY
3. DeliveryGets the weaponized content to the target environment.Spear-phishing attachment, malicious link, supply-chain update, drive-by download, or remote-service exploit attempt.
PROPAGATE AND LOAD RANSOMWARE
4. ExploitationCauses attacker-controlled code to execute.Exploits a vulnerability, abuses a macro, steals a session, or convinces the user to launch a file.
DETECT MALWARE
5. InstallationDeploys the malware and commonly establishes persistence.A dropper decrypts and writes a payload; a loader downloads an implant; malware creates a service or scheduled task.
ENCRYPT AND LOCK FILES
6. Command and
Control
Establishes a communications channel between the implant and the attacker.Periodic HTTPS/DNS beaconing, cloud-service abuse, tasking commands, or delivery of additional modules.
BLOCK ENCRYPTION
7. Actions on ObjectivesUses the access to accomplish the campaign's purpose.Credential theft, discovery, lateral movement, data collection, exfiltration, espionage, sabotage, or disruption.