MENDEL TECHNOLOGY MAXIMIZES SECURITY FOR COST

Cybercrime is evolving at drammatic speed and at every moment, hackers and attackers are figuring out new strategies to compromise organizations and industries. The cybersecurity sector must not fall behind these attackers.
But the number of technologies claiming to create cybersecurity is vast. Organizational spending and reallocating investments to the right network security sector can help reduce cost of cyber breaches. A recent report produced by Accenture, with an independent survey by the Ponemon Institute indicates that among the higher-valued security technologies per cost; machine learning tools and extensive use of cyber analytics and user behavior analytics, have a high return on investment – in other words, they can bring a greater security benefit for a lower cost. Yet, conversely, Accenture reports that these high value technologies are under-deployed compared to other tools in the marketplace.

MENDEL, from GREYCORTEX makes extensive use of machine learning and behavior analytics to identify cyber threats, protecting the network from attacks which would be unknown and unseen by other security tools.

To find out more about MENDEL’s machine learning technology can help you, or to schedule a demonstration, contact your local GREYCORTEX partner, or GREYCORTEX directly.
With this findings comes opportunity to focus on the right technology to protect a company’s assets.

Study and images are found in the following study: https://www.accenture.com/t20170926T072837Z__w__/us-en/_acnmedia/PDF-61/Accenture-2017-CostCyberCrimeStudy.pdf

GREYCORTEX RELEASES MENDEL 2.9

GREYCORTEX is happy to announce the latest version of GREYCORTEX MENDEL; Version 2.9.0. This version includes several new important features: the first is the Flow Exporter, which gives you the possibility to export flows from MENDEL to your SIEM solution. The second important feature is the ability to execute script commands to other devices e.g. a firewall systems in order to block communications. SCADA network protocols Modbus and DNP3 L7 visibility have also been added, as has the ability to audit commands executed from ssh connections.
New Features

  • Added a Flow Export feature, which allows you to export flows from MENDEL to your favorite SIEM tool. This allows you to have the same data detail of a much more expensive SIEM-specific flow export tool, at a fraction of the cost.
  • Added ability to execute and send scripts, e.g. to a firewall – which means you can identify and stop incoming malware at the firewall, without ever leaving MENDEL.
  • Added integrated Modbus and DNP3 SCADA protocol visibility. Think of it as MENDEL for the industrial control systems. GREYCORTEX takes its next steps into protecting not just “traditional” networks, but also SCADA systems as well with these protocols.
  • Added SSH auditing (turn on the SSH audit signature in status monitor signatures)
  • Added possibility to filter by group of entities (subnet, host, mac, user) to extend filtering options using comma “,”, e.g. src:172.16.9.20,172.16.9.21 & dst:1.2.3.4 which shows communication between source IPs 172.16.9.20 or 172.16.9.21 and destination IP 8.8.8.8. In a nutshell: much more efficient filtering capabilities are now yours. Identify communication from not just one source and destination, but several hosts to a single destination, so complicated attacks are now clear.
  • MENDEL is powerful and detailed, but now it works just as well for the T1 Security Analyst. New installations and newly created users will see new default dashboards with Overview, Performance, and Security tabs included, for ease of use by everyone.

Improvements
Several different features of MENDEL were improved. These included improvements to the installation and update process, optimization of flows, and detection features – including the ability to choose your favorite IDS ruleset, or better L7 application service recognition.
Bug Fixes
In general, our development team focused on repairing inconsistencies in user experience and connectivity.

PETR CHALOUPKA NAMED TO NE100

GREYCORTEX is happy to announce that CEO and Co-Owner Petr Chaloupka was named to the New Europe 100 (NE100). The list is made up of individuals selected by the Financial Times, Google, the Visegrad Fund, and Res Publica.

Now in it’s fourth year, the 2017 New Europe 100 “is a list of central and eastern Europe’s brightest and best citizens who are changing the region’s societies, politics, or business environments and displaying fresh approaches to prevailing problems. The aim is to raise the profile of changemakers in emerging Europe and to build connection among those in the vanguard.”
Previous editions of the NE100 have included such well-known business leaders as Vaclav Muchna, CEO of Y Soft.
You can read more about the NE100 here: http://ne100.org/news/show/new-europe-100-challengers-2017,5a166ff03228719568984a76

MENDEL PARTNERS WITH BRNO UNIVERSITY OF TECHNOLOGY (VUT)

GREYCORTEX is happy to announce that our MENDEL network security tool is now part of the Brno University of Technology (VUT) cybersecurity program. MENDEL is used as part of the compulsory Bachelor’s course called “Information and Communication Technologies Security 2”, offered in the Faculty of Electrical Engineering and Communication specifically the Information Security Program.
The course teaches extended information and communication security knowledge of secure network device configuration, secure configuration testing, and penetration testing. MENDEL is used in laboratory exercises as a visualisation tool for various scans, exploits, and other tests practised by students.
VUT is in the top 5 % of world universities, and offers wide range of education programs. The 30 students in the course as well as the Lecturers are happy that MENDEL’s advanced security tools are available to them. They were especially interested in MENDEL’s intuitive filter and full network visualization. GREYCORTEX is happy to work with the next generation of Security Analysts and to provide the right tools to ready them to participate in the future of network security.

THREAT HUNTING WITH MENDEL

“Threat hunting,” or “cyber threat hunting” is the process of proactively and iteratively searching through networks and datasets to detect threats that evade existing automated tools and is done by a threat hunter or security analyst. It is essential for network security because it works to identify hidden threats within an existing set of network data.
Threat hunting utilizes manual techniques from the threat hunter and machine-assisted techniques, the combination of which aims to find Tactics, Techniques, and Procedures (TTPs) of advanced adversaries. While this methodology is both time-tested and effective, it is also time consuming, and can sometimes miss important clues in mountains of network data. In the article below, we will discuss not only what threat hunting is, but also how it can be made more efficient through the use of modern tools.
Download the article here.

GREYCORTEX MENDEL DETECTS BADRABBIT

GREYCORTEX is happy to report that it is able to detect the BadRabbit ransomware. This ransomware appeared in Eastern Europe (Russia, Ukraine) but has begun to spread across several countries including South Korea, Poland, the Baltic, and regions. It uses an NSA-based exploit known as “EternalRomance” to enter networks and spreads by SMB port.
MENDEL is able to detect this ransomware in two different ways:

  • MENDEL’s integrated ruleset includes a rule specifically detecting the BadRabbit ransomware.
  • Independent from this IDS rule, MENDEL’s advanced artificial intelligence and machine learning detects the ransomware’s anomalous port sweep activity.

This detection capability demonstrates that MENDEL can identify unknown threats before rules are created in rules-based security tools. MENDEL provides network security teams vital extra time to protect their networks.

GREYCORTEX WINS IN POLAND

The success continues for GREYCORTEX. This time, the team was first overall at the Pitch Competition at the 3rd Annual European Cybersecurity Forum held in Krakow, Poland on October 10th and 11th, 2017. The event featured cybersecurity-focused speakers from government and industry across Europe, as well as several from North America.
The Pitch Competition, held on Monday afternoon, as part of the Forum, featured 16 companies from Central and Eastern Europe. As winners, GREYCORTEX received the chance to present MENDEL on the main conference stage to a full audience. The pitch presentation itself focused on the overall costs of data breach – not only in data loss – but in lost business reputation, opportunity, and brand value, demonstrating GREYCORTEX MENDEL’s ability to detect advanced persistent threats in the network, as well as it’s founding – with generous support from YSoft Ventures – and its membership in the ESET Technology Alliance.

MENDEL 2.8 RELEASED

We are happy to announce the latest version of GREYCORTEX MENDEL. Version 2.8 includes three new important features: the first is the Event Collector. Released as part of v2.7 (a limited release), the Event Collector offers the opportunity to centrally monitor events from several remote GREYCORTEX MENDEL collectors. The second major new feature is the Correlation Engine. This tool correlates individual, less-serious events – which together may be indicative of attacks within the network, to more effectively alert security analysts. Finally, MENDEL 2.8 includes proxy pairing functionality which identifies source or destination addresses hidden by proxy servers, which will allow security analysts to better identify potential issues on the network and provide even greater visibility.
New Features

  • Added a beta version of the Correlation Engine, including seven tuned rules which further increase security (The feature may be turned on by going to Settings->System Components)
  • Added a proxy pairing feature to display source or destination addresses hidden by a proxy server

Improvements

  • Optimized the display of charts and tables in the Network module
  • Added information about the type of key exchange algorithms in HTTPS and TLS flows
  • Improved the calculation of flow metrics to show values valid for specific parts

Bug Fixes

  • Fixed issues with disabling deep packet inspection and enabling rules in IDS
  • Fixed an issue with updates to older installations
  • Fixed issues with MS-SQL protocol parsing at higher speeds
  • Fixed an issue with displaying current values on the Network Services tab
  • Fixed an issue with displaying multiple VLAN IDs in a single flow
  • Fixed issues with parsing SMB flows
  • Fixed issues with editing export definitions
  • Fixed an issue with pagination results in the Peers graph
  • Fixed issues with restarting services
  • Fixed an issue with filtering by protocol type
  • Fixed an issue with deleting user-defined filters
  • Fixed an issue with saving user-created or user-defined filters
  • Fixed an issue with displaying VLAN statistics in the Analysis module
  • Fixed an issue with exporting records in CEF and Syslog formats
  • Fixed an issue with long hostnames
  • Fixed issues with calculating the minimum and maximum duration of flows
  • Fixed link formatting in Exports
  • Fixed an issue with displaying ASN names in flows
  • Fixed an issue with displaying host information in the Analysis module
  • Fixed the calculation of RTT and ART metrics in long term flows with unfinished communication
  • Fixed an issue with the validation of row counts in Column Manager

GREYCORTEX WINS AGAIN AT CESA 2017

GREYCORTEX took home the top prize in its category at the Czech Finals of the 2017 Central European Startup Awards (CESA). The Czech final,  held on September 25th in Prague, recognized GREYCORTEX as the Best AI Startup in the country.
The Central European Startup Awards is a series of national events in the CEE countries, recognizing and celebrating the entrepreneurial spirit and startup ecosystems of the region. Having been successful in the AI Startup category in the Czech Republic, GREYCORTEX now competes in the Regional Finals, to be held in Sofia Bulgaria on November 23rd. GREYCORTEX was successful at least year’s Regional Final, winning “Best Newcomer” in Ljubljana, Slovenia.
A list of CESA Czech Winners in 2017 may be found at: http://centraleuropeanstartupawards.com/season-2017/czech-republic-national-winners

GREYCORTEX JOINS ESET TECHNOLOGY ALLIANCE

Excellent news from Brno!
GREYCORTEX is proud to announce that we have been named as part of the ESET Technology Alliance. In addition to complimenting ESET’s existing endpoint security solutions – by addressing traffic within the network, this relationship means that GREYCORTEX MENDEL is now available through all ESET partners, worldwide. You can read our full press release below:

GREYCORTEX Joins ESET Technology Alliance

Brno, Czech Republic – GREYCORTEX, advanced network security solutions provider, is happy to announce that it has been named as a part of the ESET Technology Alliance which provides holistic protection against advanced cyber threats. Launched in 2013, the ESET Technology Alliance is an integration partnership that aims to better protect businesses by offering a range of complementary IT security solutions. All members of the ESET Technology Alliance are carefully vetted against a set of established criteria to extend “best-in-class” business protection across IT environments.
Through the ESET Technology Alliance partnership, MENDEL, GREYCORTEX’s network traffic analysis solution, is now available to enterprise customers through all ESET partners. MENDEL uses advanced artificial intelligence, machine learning, and data analysis to detect threats to enterprise, government, and critical infrastructure networks that other network security solutions miss. It is able to offer rapid detection and response to network security teams, but also gives them the security to know that they can efficiently monitor network performance and visualize the entire network up to, and including the application layer.
Providing effective network security is continually evolving. Security analysts need to be able to identify not just threats like viruses, but also advanced persistent threats like malware, RATs, Trojans, and Zero-day attacks. Analysts also need to know that they have full network visibility on every device and application in the network. MENDEL provides complete network visibility and detailed insight into application and network performance, so that security teams can identify threats before they do damage,” said Petr Chaloupka, CEO, GREYCORTEX.
GREYCORTEX compliments ESET’s existing endpoint security solutions, by addressing traffic within the network. “There are never enough layers of security for one’s network infrastructure,” said Jeronimo Varela, Director of Global Sales at ESET. “The GREYCORTEX solution provides an analysis of any behavioral anomalies that may go unnoticed. Moreover, the solution is easily integrated into the infrastructure of businesses of any size and can work not only as a detection or monitoring tool, but also to provide visibility into the  functionality of additional security components.”
For more details about GREYCORTEX’s solution MENDEL, please click here.
More information about the ESET Technology Alliance can be found here.
About GREYCORTEX
Built on a decade of extensive industry and academic experience, GREYCORTEX uses advanced machine learning and data analysis to help protect sensitive data, networks, trade secrets, and reputations. In addition to the ESET Technology Alliance, serves customers in over 14 countries through its own distributor network. In 2016 GREYCORTEX received an investment of 1.3 million USD from Y Soft Ventures, a venture capital arm of leading enterprise office solution provider Y Soft.
About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint and mobile security, to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give consumers and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real-time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D centers worldwide, ESET becomes the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003. For more information visit www.eset.com or follow us on LinkedInFacebook and Twitter.