Skip to main content

Is Cyber Crucible an EDR, XDR, MDR? Or Something Else Like Agentic AI?

Short

answer:
It
has
elements
of
both

Cyber Crucible’s data extortion prevention software is, strictly speaking, a Windows kernel driverEDR and WindowsXDR, service.but Thethe softwarecategory communicatesquestion withis ourthe wrong one. What matters is where the decision is made. Cyber Crucible's response logic runs entirely on the endpoint using only information available there at the moment of attack — because remote analytic servers forintroduce ingestiontwo (mostlyfatal usingweaknesses: REST).latency Uponand ingestionfragility.

The honest answer to the Cyberlabel Cruciblequestion

servers
(whetherAs asan aEDR: Kubernetes'if basedan endEDR useruses deployment,endpoint or our cloud presence), multiple data sources are combinedtelemetry to providemake additionaldecisions, capabilities to advanced security users.

Locally to the machine (the Endpoint), behavioral analytics are used to Discover data extortion attack behaviors, and Respond by suspending the associated programs, makingthen Cyber CrucibleCrucible's automated response is an EDR. TheIt useclamps ofdown cloudon analyticsextortion behaviour in milliseconds, using only local information.

As an XDR: telemetry is also sent to providea additionaldatabase data(customer would,appliance byor central) for correlation, threat hunting, insider-threat work, and IT audits. By the definition of the marketers of XDR (eXtendedmarketing Discoverydefinition, Response)that products,qualifies. means Cyber Crucible is an XDR product.

So, what’s the answer, then?
The team is OKcomfortable with Cyber Crucible being called an "EDR for extortion defense due to the edge computing,defense," even though that’sedge computing is seen as “last generation”last-generation in some circlescircles. The reasonreasoning below is why that theview Xis backwards.

Why remote analytics became a liability — latency

The "X" in XDR represents an evolution of an endpoint tool strategy in place in EDR’s as well, in thatmoving analytical computing power has been moved to remote serversservers. (usuallyThat inbuys a cloud of some type). With that additional power, comes two drawbacks: latency,power and fragility.

costs

Remotetime, Analyticand Latencyattackers asbuilt atheir Liability

tradecraft

Extortion criminals first focused onaround the speedgap:

of
theirSpeed: attack,attacks towere turnaccelerated theso latencyirreversible intoactions acomplete liability.before an analytic server can respond. This is expressedespecially duringvisible attackswith small, high-value items like passwords. Parallelism: many endpoint tools inspect one program, wait, then move to the next. Attackers run multiple extortion programs at once — 5,000 files accessed in aparallel coupleinstead ways.of The500. firstDistribution: beingextortion that,runs theacross many machines simultaneously. Cyber Crucible has observed roughly 75 machines at once. A tool then faces 50 programs across 75 machines — 3,750 programs to inspect. Commander processes: some attackers spedrun upa theirlocal efficiency to ensurecontroller that irreversibleinstantly attackre-spawns actionsany wereextortion completed before the analytic server could respond. We seetool that agets greatkilled. deal with small pieces of very important data such as passwords.

It is really important to note here that we are discussing detection and Detection-and-response strategies which,wait, by their nature, wait for the attack to be underway. AThe non-cybersecuritybetter analogy wouldis be the more desirable detection ofstopping bank robbers outsideat the bank,door andrather locking the door, versus a less desirable stance of the bank taking action to stop the robbersthan after a certain amount of cash washas stolen fromleft the safe.

Longer running tasks like encryption required a combination of speed with 2 other tactics - parallel and distributed computing. The attackers realized that running multiple extortion programs meant that any endpoint security tool had to inspect the behavior of each process, which takes time. So, if 5000 files could be accessed on the network at one time in parallel on a system instead of 500 with one program, that’s much better for the attacker. In fact, many of the endpoint security solution are setup to inspect one program, wait for that inspection to finish, then move onto the next one.

The extortionists do not have 10, 25, or 50 malware programs running just on one machine though. They leveraged distributed computing methods to have the extortion run on many machines all at the same time. The most the Cyber Crucible has seen at once was around 75 machines. Now any type of security tool has to inspect 50 programs, across 75 machines - so 3,750 programs.

As if this isn’t bad enough, some attackers began implementing a strategy, in which the extortion tools were monitored and controlled locally by a “commander” program. This commander would re-spawn extortion tools if they were killed. Like in a lot of science fiction, killed “enemy soldiers” (extortion software) were instantly replaced by fresh “troops”.

By this point in the extortion tool and tradecraft evolution, any tool that relied on remote analytic computing, are simply overwhelmed. Modern attacker tactics also no longer encrypt every piece of data in a business. By the time defenders “catch up”, the attacker’s goals are likely already accomplished.

We’ll discuss what Cyber Crucible does to correct this matter at the end.

Remote Analytic Fragility as a Liability

Previously, we discussed exploiting the latency of

Why remote analytics infrastructuresbecame througha theliability use of parallel and distributed computing. In this section, we’ll discuss the fragility of building endpoint security tools remote analytics.

Around 80% of EDR and XDR solutions requireneed access to remote analytic servers to function optimally.optimally, The norm is that these toolsand are barely functioningfunctional without that cloud "brain."

Attackers exploit this directly: gain enough access to the remote (usually cloud-based) “brain”.

Attackers have combined the latency vulnerability discussed earlier, to conduct fast attacks on the EDR and XDR software.

A common attack now seen is that the attackers gain access to adjustchange firewall rules, and block the endpoint security toolstool from accessingreaching theirits analytic servers.servers, The net effect is thatand the EDR/XDRtool toolsloses lack theits ability to analyze and respond to the extortion attack activities, making the attackers' job that much easier.

Exploits against EDR and XDR software are certainly seen against endpoint software. In this case, though, the EDR or XDRrespond. canIt remainremains unexploited, installed, running - and almost completely ineffective.

What All This Means to Cyber Crucible -does IS it an EDR or XDR?instead

The vulnerabilities concerning theBecause latency and fragility ofmake remotecloud analyticdependency serveruntenable strategies, mean robust datafor extortion simply cannot rely on cloud computing.defense, Cyber Crucible has elements of both EDR and XDR.

Cyber Crucible as an EDR

If we reduce an XDR to enable a combination of endpoint and other (usually things like network) telemetry, and define and EDR as strictly using endpoint telemetry to make decisions…

Then the millisecond-fast “clamping down” of extortion attack behaviors, that has to be resilient to the frailty of remote analytic engines…

Then Cyber Crucible’s automated response portion of the software is an EDR.

Due to the latency and frailty of remote analytic servers, Cyber Crucible had to inventinvented a detection and response capability whose behavioral analytics use only information available on the endpoint at the time of attack.attack. Interdiction happens locally in typically under 200 milliseconds, with no cloud round trip in the critical path.

Cyber Crucible as an XDR

The collection of endpoint telemetry forthat edgedoes (endpoint)flow detectionto andthe responsedatabase issupports valuableinvestigation forrather athan varietyprotection of other strategic investigatory activities such as threat hunting, insider threat detection, and IT audits.audits All telemetry is transmitted to the database (either customer appliance, or central Cyber Crucible database) for correlation and analysis. Data sources are combined and collated for rich data presentation.

Cyber Crucible’san open API meanslets thatit analytical platforms (such asfeed open XDR platformsplatforms, like this, SOAR,SOAR, or RoboticRPA Processtooling. Automation)That maywork combinedis thisvaluable, databut withit otheris datanever sources,what tostands producebetween advancedyou automatedand capabilities.

an

Thus, this portion of Cyber Crucible’s capabilities, while not as time critical as the sub-second response required by our software’s EDR capabilitiesattack in times of impending extortion crisis, represents an value add to customers.progress.