Is Cyber Crucible an EDR, XDR, MDR? Or Something Else Like Agentic AI?
Short
Cyber Crucible’s data extortion prevention software is, strictly speaking, a Windows kernel driverEDR and WindowsXDR, service.but Thethe softwarecategory communicatesquestion withis ourthe wrong one. What matters is where the decision is made. Cyber Crucible's response logic runs entirely on the endpoint using only information available there at the moment of attack — because remote analytic servers forintroduce ingestiontwo (mostlyfatal usingweaknesses: REST).latency Uponand ingestionfragility.
The honest answer to the Cyberlabel Cruciblequestion
Locally to the machine (the Endpoint), behavioral analytics are used to Discover data extortion attack behaviors, and Respond by suspending the associated programs, makingthen Cyber CrucibleCrucible's automated response is an EDR. TheIt useclamps ofdown cloudon analyticsextortion behaviour in milliseconds, using only local information.
So, what’s the answer, then?
The team is OKcomfortable with Cyber Crucible being called an "EDR for extortion defense due to the edge computing,defense," even though that’sedge computing is seen as “last generation”last-generation in some circlescircles. The reasonreasoning below is why that theview Xis backwards.
Why remote analytics became a liability — latency
The "X" in XDR represents an evolution of an endpoint tool strategy in place in EDR’s as well, in thatmoving analytical computing power has been moved to remote serversservers. (usuallyThat inbuys a cloud of some type). With that additional power, comes two drawbacks: latency,power and fragility.
Remotetime, Analyticand Latencyattackers asbuilt atheir Liability
tradecraft Extortion criminals first focused onaround the speedgap:
It is really important to note here that we are discussing detection and Detection-and-response strategies which,wait, by their nature, wait for the attack to be underway. AThe non-cybersecuritybetter analogy wouldis be the more desirable detection ofstopping bank robbers outsideat the bank,door andrather locking the door, versus a less desirable stance of the bank taking action to stop the robbersthan after a certain amount of cash washas stolen fromleft the safe.
Longer running tasks like encryption required a combination of speed with 2 other tactics - parallel and distributed computing. The attackers realized that running multiple extortion programs meant that any endpoint security tool had to inspect the behavior of each process, which takes time. So, if 5000 files could be accessed on the network at one time in parallel on a system instead of 500 with one program, that’s much better for the attacker. In fact, many of the endpoint security solution are setup to inspect one program, wait for that inspection to finish, then move onto the next one.
The extortionists do not have 10, 25, or 50 malware programs running just on one machine though. They leveraged distributed computing methods to have the extortion run on many machines all at the same time. The most the Cyber Crucible has seen at once was around 75 machines. Now any type of security tool has to inspect 50 programs, across 75 machines - so 3,750 programs.
As if this isn’t bad enough, some attackers began implementing a strategy, in which the extortion tools were monitored and controlled locally by a “commander” program. This commander would re-spawn extortion tools if they were killed. Like in a lot of science fiction, killed “enemy soldiers” (extortion software) were instantly replaced by fresh “troops”.
By this point in the extortion tool and tradecraft evolution, any tool that relied on remote analytic computing, are simply overwhelmed. Modern attacker tactics also no longer encrypt every piece of data in a business. By the time defenders “catch up”, the attacker’s goals are likely already accomplished.
We’ll discuss what Cyber Crucible does to correct this matter at the end.
Remote Analytic Fragility as a Liability
Previously, we discussed exploiting the latency of
Why remote analytics infrastructuresbecame througha theliability use of parallel and distributed computing. In this section, we’ll discuss the— fragility of building endpoint security tools remote analytics.
Around 80% of EDR and XDR solutions requireneed access to remote analytic servers to function optimally.optimally, The norm is that these toolsand are barely functioningfunctional without that cloud "brain."
Attackers exploit this directly: gain enough access to the remote (usually cloud-based) “brain”.
Attackers have combined the latency vulnerability discussed earlier, to conduct fast attacks on the EDR and XDR software.
A common attack now seen is that the attackers gain access to adjustchange firewall rules, and block the endpoint security toolstool from accessingreaching theirits analytic servers.servers, The net effect is thatand the EDR/XDRtool toolsloses lack theits ability to analyze and respond to the extortion attack activities, making the attackers' job that much easier.
Exploits against EDR and XDR software are certainly seen against endpoint software. In this case, though, the EDR or XDRrespond. canIt remainremains unexploited, installed, running -— and almost completely ineffective.
What All This Means to Cyber Crucible -does IS it an EDR or XDR?instead
The vulnerabilities concerning theBecause latency and fragility ofmake remotecloud analyticdependency serveruntenable strategies, mean robust datafor extortion simply cannot rely on cloud computing.defense, Cyber Crucible has elements of both EDR and XDR.
Cyber Crucible as an EDR
If we reduce an XDR to enable a combination of endpoint and other (usually things like network) telemetry, and define and EDR as strictly using endpoint telemetry to make decisions…
Then the millisecond-fast “clamping down” of extortion attack behaviors, that has to be resilient to the frailty of remote analytic engines…
Then Cyber Crucible’s automated response portion of the software is an EDR.
Due to the latency and frailty of remote analytic servers, Cyber Crucible had to inventinvented a detection and response capability whose behavioral analytics use only information available on the endpoint at the time of attack.attack. Interdiction happens locally in typically under 200 milliseconds, with no cloud round trip in the critical path.
Cyber Crucible as an XDR
The collection of endpoint telemetry forthat edgedoes (endpoint)flow detectionto andthe responsedatabase issupports valuableinvestigation forrather athan varietyprotection of other strategic investigatory activities such as— threat hunting, insider threat detection, and IT audits.audits All telemetry is transmitted to the database (either customer appliance, or central Cyber Crucible database) for correlation— and analysis. Data sources are combined and collated for rich data presentation.
Cyber Crucible’san open API meanslets thatit analytical platforms (such asfeed open XDR platformsplatforms, like this, SOAR,SOAR, or RoboticRPA Processtooling. Automation)That maywork combinedis thisvaluable, databut withit otheris datanever sources,what tostands producebetween advancedyou automatedand capabilities.
Thus, this portion of Cyber Crucible’s capabilities, while not as time critical as the sub-second response required by our software’s EDR capabilitiesattack in times of impending extortion crisis, represents an value add to customers.progress.