{"id":23373,"date":"2023-11-14T11:27:54","date_gmt":"2023-11-14T19:27:54","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2023\/11\/14\/news-17103\/"},"modified":"2023-11-14T11:27:54","modified_gmt":"2023-11-14T19:27:54","slug":"news-17103","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2023\/11\/14\/news-17103\/","title":{"rendered":"New Active Adversary Defense capabilities with Sophos Firewall, Sophos XDR, and Sophos NDR"},"content":{"rendered":"<p><strong>Credit to Author: Doug Aamoth| Date: Tue, 14 Nov 2023 10:59:29 +0000<\/strong><\/p>\n<div class=\"entry-content lg:prose-lg mx-auto prose max-w-4xl\">\n<p>Active adversaries are now a major threat to organizations of all sizes. These highly skilled cybercriminals continue to develop and evolve their techniques in response to superior defenses, executing attacks at scale and employing sophisticated techniques specifically designed to avoid triggering preventative security solutions.<\/p>\n<p>We are excited to announce the addition of new capabilities to Sophos Firewall, Sophos XDR, and Sophos NDR solutions to further enable organizations to defend against these active adversaries.<\/p>\n<h2>What are active adversaries and how do they operate?<\/h2>\n<p><em><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-952232 alignleft\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2023\/11\/quotes.png\" alt=\"\" width=\"99\" height=\"84\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2023\/11\/quotes.png 1547w, https:\/\/news.sophos.com\/wp-content\/uploads\/2023\/11\/quotes.png?resize=300,254 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2023\/11\/quotes.png?resize=768,649 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2023\/11\/quotes.png?resize=1024,866 1024w, https:\/\/news.sophos.com\/wp-content\/uploads\/2023\/11\/quotes.png?resize=1536,1299 1536w\" sizes=\"auto, (max-width: 99px) 100vw, 99px\" \/>Active adversaries are highly skilled cybercriminals, often equipped with sophisticated software and networking skills, who gain entry into an organization&#8217;s systems, evade detection and <strong>continuously adapt their techniques<\/strong>, using hands-on keyboard and AI-assisted methods to circumvent preventative security controls and execute their attacks.<\/em><\/p>\n<p>Organizations need adaptive security controls designed to detect and respond to the approaches commonly used by active adversaries:<\/p>\n<p><strong>Multi-stage attacks<\/strong><br \/> <strong><img loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-952237\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2023\/11\/multi-stage.png?w=61\" alt=\"\" width=\"70\" height=\"70\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2023\/11\/multi-stage.png 61w, https:\/\/news.sophos.com\/wp-content\/uploads\/2023\/11\/multi-stage.png?resize=32,32 32w, https:\/\/news.sophos.com\/wp-content\/uploads\/2023\/11\/multi-stage.png?resize=50,50 50w\" sizes=\"auto, (max-width: 70px) 100vw, 70px\" \/><\/strong><em>Attacks that end in a different place than they started<\/em><br \/> Active adversaries execute attacks that cross multiple domains across the victim\u2019s environment. The full scope of these attacks cannot be detected by a single point product. Organizations need visibility across their entire ecosystems.<\/p>\n<p><strong>Living off the land attacks<br \/> <\/strong><strong><img loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-952238\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2023\/11\/live-off-land.png?w=46\" alt=\"\" width=\"70\" height=\"70\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2023\/11\/live-off-land.png 46w, https:\/\/news.sophos.com\/wp-content\/uploads\/2023\/11\/live-off-land.png?resize=32,32 32w\" sizes=\"auto, (max-width: 70px) 100vw, 70px\" \/><\/strong><em>Attacks that use legitimate tools in malicious ways<br \/> <\/em>Preventative security tools are unable to block the use of legitimate IT tools without the risk of causing significant operational disruption. Attackers take advantage of this by using legitimate IT tools like RDP and PowerShell to blend into the background.<\/p>\n<p><strong>Unknown vulnerabilities<br \/> <\/strong><strong><img loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-952239\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2023\/11\/vulns.png?w=42\" alt=\"\" width=\"71\" height=\"71\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2023\/11\/vulns.png 42w, https:\/\/news.sophos.com\/wp-content\/uploads\/2023\/11\/vulns.png?resize=32,32 32w\" sizes=\"auto, (max-width: 71px) 100vw, 71px\" \/><\/strong><em>Attacks that leverage a weakness, flaw, or error in software<br \/> <\/em>Attackers exploit zero-day and unpatched vulnerabilities to execute attacks: 65% of ransomware attacks start with an attacker exploiting an unknown vulnerability or logging in using legitimate credentials.<\/p>\n<p><strong>Credential abuse<br \/> <\/strong><strong><img loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-952240\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2023\/11\/creds.png?w=177\" alt=\"\" width=\"75\" height=\"56\" \/><\/strong><em>Attacks that start with an adversary logging in instead of breaking in<br \/> <\/em>Active adversaries use compromised legitimate user credentials to log in and execute their attacks. Preventative security tools are unable to block or detect until the &#8220;user&#8221; demonstrates suspicious or malicious behavior.<\/p>\n<p><a style=\"color: #004991\" href=\"https:\/\/news.sophos.com\/en-us\/2023\/11\/14\/active-adversary-for-security-practitioners\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-952257 size-medium\" style=\"border: 3px solid #999999\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2023\/11\/Report.png?w=224\" alt=\"\" width=\"224\" height=\"300\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2023\/11\/Report.png 1323w, https:\/\/news.sophos.com\/wp-content\/uploads\/2023\/11\/Report.png?resize=224,300 224w, https:\/\/news.sophos.com\/wp-content\/uploads\/2023\/11\/Report.png?resize=768,1029 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2023\/11\/Report.png?resize=765,1024 765w, https:\/\/news.sophos.com\/wp-content\/uploads\/2023\/11\/Report.png?resize=1147,1536 1147w\" sizes=\"auto, (max-width: 224px) 100vw, 224px\" \/><\/a>Our new <a href=\"https:\/\/news.sophos.com\/en-us\/2023\/11\/14\/active-adversary-for-security-practitioners\" target=\"_blank\" rel=\"noopener\">Active Adversary Report for Security Practitioners<\/a> highlights key changes in adversary behavior over the last year, including:<\/p>\n<ul>\n<li>Attackers are speeding up. Dwell time in ransomware is rapidly decreasing, down from nine days in 2022 to five days in the first half of 2023.<\/li>\n<li>Adversaries frequently abuse legitimate IT tools. The LOLBins (Living-off-the-Land Binaries) and techniques being used by active adversaries do not vary substantially between fast (&lt; five days dwell time) and slow (&gt; five days dwell time) attacks.<\/li>\n<li>Active adversaries will innovate when they must, and only to the extent that it gets them to their target.<\/li>\n<\/ul>\n<p>The report highlights the need for organizations to understand how active adversaries behave and to have visibility across their security ecosystems to detect quickly and respond even faster.<\/p>\n<h2>What\u2019s new?<\/h2>\n<p>We\u2019re adding new capabilities to the Sophos platform across Sophos XDR, Sophos Firewall, and Sophos NDR that give organizations even greater power to defend against active adversaries:<\/p>\n<p><strong>Sophos Firewall \u2013 now with Active Threat Response<br \/> <\/strong><strong><img loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-952241\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2023\/11\/FW.png?w=108\" alt=\"\" width=\"75\" height=\"65\" \/><\/strong><em>Now available!<\/em><br \/> The new Active Threat Response feature in Sophos Firewall v20 provides instant and automated response to active adversaries. Sophos XDR and MDR analysts can push threat intel to firewalls directly from Sophos Central, enabling the firewalls to coordinate defenses immediately without the need for manual intervention or new firewall rules.<\/p>\n<p><strong>Sophos NDR &#8211; now available for XDR<br \/> <\/strong><strong><img loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-952242\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2023\/11\/NDR.png?w=108\" alt=\"\" width=\"75\" height=\"65\" \/><\/strong><em>Available November 20, 2023<\/em><br \/> Sophos Network Detection and Response (NDR) detects active adversaries moving across an organization\u2019s network between devices. Previously available only as an add-on to Sophos MDR, Sophos NDR is now available as an add-on to Sophos XDR, for organizations who manage their own detection and response activities.<\/p>\n<p><strong>Sophos XDR &#8211; now with expanded third-party compatibility and optimized UX<br \/> <\/strong><strong><img loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-952243\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2023\/11\/XDR.png?w=108\" alt=\"\" width=\"76\" height=\"66\" \/><\/strong><em>Available November 20, 2023<\/em><strong><br \/> <\/strong>We\u2019re significantly expanding the range of third-party tools and products that customers can integrate with Sophos XDR, across endpoint, firewall, cloud, identity, network, email, and productivity categories. Sophos XDR consolidates security data and provides a single console for customers to work from, with optimized workflows that reduce their investigation workloads.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-952244 size-full\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2023\/11\/3P.png\" alt=\"\" width=\"1577\" height=\"917\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2023\/11\/3P.png 1577w, https:\/\/news.sophos.com\/wp-content\/uploads\/2023\/11\/3P.png?resize=300,174 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2023\/11\/3P.png?resize=768,447 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2023\/11\/3P.png?resize=1024,595 1024w, https:\/\/news.sophos.com\/wp-content\/uploads\/2023\/11\/3P.png?resize=1536,893 1536w\" sizes=\"auto, (max-width: 1577px) 100vw, 1577px\" \/><\/p>\n<h2>Point products vs. connected products and services that work together<\/h2>\n<p>Attackers continuously adapt their techniques, resulting in the introduction of new point products to defend against these new approaches. Disparate tools, however, typically do not communicate well together. Sophos provides a <strong>unified platform<\/strong> that incorporates a broad portfolio of cyber security products and services that has been engineered to work together seamlessly. Plus, compatible with third-party technologies, <strong>Sophos\u2019 connected ecosystem provides automated actions and correlated data, allowing organizations to detect, investigate, and respond to active adversaries faster, across all key attack surfaces.<\/strong><\/p>\n<h2>Elevate your defenses against active adversaries<\/h2>\n<p>To learn more and explore how Sophos solutions can help your organization better defend against active adversaries, speak with a Sophos adviser or your Sophos partner today.<\/p>\n<\/p><\/div>\n<p><a href=\"https:\/\/news.sophos.com\/en-us\/2023\/11\/14\/new-active-adversary-defense-capabilities-with-sophos-firewall-sophos-xdr-and-sophos-ndr\/\" target=\"bwo\" >http:\/\/feeds.feedburner.com\/sophos\/dgdY<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2023\/11\/shutterstock_1862077075.jpg\"\/><\/p>\n<p><strong>Credit to Author: Doug Aamoth| Date: Tue, 14 Nov 2023 10:59:29 +0000<\/strong><\/p>\n<p>New capabilities to further enable organizations to defend against active adversaries.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10377],"tags":[11179,129,10405,10384,24562,24552,19056,24567,28404,22487],"class_list":["post-23373","post","type-post","status-publish","format-standard","hentry","category-security","category-sophos","tag-endpoint","tag-featured","tag-intercept-x","tag-network","tag-products-services","tag-security-operations","tag-sophos-endpoint","tag-sophos-firewall","tag-sophos-ndr","tag-xdr"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/23373","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=23373"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/23373\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=23373"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=23373"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=23373"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}