Attivo BoTsink prevents attacks over large attack surfaces
Rating: 8 out of 10
IncentivizedUse Cases and Deployment Scope
Normally any threat in the network persists due to lateral movement and Attivo BoTsink detects exactly that and helps in machine learning based behaviour and blocking of threats. It projects decoys in such a way that it's difficult to distinguish with real assets of enterprise. This deception technique covers wide variety of attack surfaces and configurations for identical appearance
Pros
- Detection of lateral movement
- Deceptive projection of assets identical to production systems
- Blocks threats over large attack surfaces
- It helped reduce efforts of Cyber Security team by 20%
Cons
- More fine tuning of threat detection capabilities needed
- Users should be able to modify AIML configuration
- Improving the display dashboard
Likelihood to Recommend
It is best suited when deployed at perimeter and integrated with SIEM and SOAR solution. It will be able to replicate assets and display realistic configurations making difficult for hackers. We were able to avoid or block 40% of attacks targetted to our critical servers and could easily identify threat actors.