Positive Technologies has updated MaxPatrol Carbon to version 26.2 and focused on faster modeling of attacks in corporate infrastructures. The system now calculates the possible routes of the attacker 20 times faster and covers 81% of the technique of the MITRE ATT&CK matrix of version 15.1. For security professionals, such a calculation helps not just to see individual vulnerabilities, but to understand which chains of action can lead to critical consequences for the company.
MaxPatrol Carbon is used to proactively assess cyber resilience: the system builds an attack graph, shows possible paths of the attacker inside the infrastructure and helps to identify routes to unacceptable events. In the release of 26.2, the developers optimized the construction of the graph and changed the calculation algorithms, due to which the analysis of large and complex IT environments became faster.
In the updated version, the set of actions of intruders was expanded, which the system takes into account when modeling. MaxPatrol Carbon now shows how the attack can develop after the compromising Active Directory, capture the certificate management center, the abuse of Kerberos delegation, the use of group policies after taking a domain controller, get rights through Microsoft Exchange Server or select credentials with weak password policy.
A separate unit of change is associated with centralized end-to-devices control systems. MaxPatrol Carbon 26.2 simulates compromising vectors through the Kaspersky Security Center and Microsoft SCCM. This analysis shows how service station administration servers can turn into a point for remote code execution and further movement through the infrastructure.
According to the leader of the food practice Positive Technologies Konstantin Manyakov, the safety of the infrastructure depends not only on the number of shortcomings found, but also on the understanding of the ways in which an attacker can use vulnerabilities to achieve goals. In the new version, the team focused on the realism of modeling routes to unacceptable events, as well as on accelerating the analysis of large infrastructures.
The developers also simplified the primary configuration of the entry points into the infrastructure. Operators no longer need to know the syntax of the query language to search for data: it is enough to enter a query in the field and choose the necessary pre-requires. This approach should lower the entry threshold for specialists who are just starting to work with the system.
The interface updated the recommendation page and scenarios for working with it. The changes are aimed at more convenient prioritization of protective measures, elimination of sources of threats and the introduction of compensating mechanisms. In addition, MaxPatrol Carbon has upgraded the dashboard Infrastructure: in one window, it is now possible to assess the coverage, the quality of the audit and the completeness of the asset data.
MaxPatrol Carbon is used to proactively assess cyber resilience: the system builds an attack graph, shows possible paths of the attacker inside the infrastructure and helps to identify routes to unacceptable events. In the release of 26.2, the developers optimized the construction of the graph and changed the calculation algorithms, due to which the analysis of large and complex IT environments became faster.
In the updated version, the set of actions of intruders was expanded, which the system takes into account when modeling. MaxPatrol Carbon now shows how the attack can develop after the compromising Active Directory, capture the certificate management center, the abuse of Kerberos delegation, the use of group policies after taking a domain controller, get rights through Microsoft Exchange Server or select credentials with weak password policy.
A separate unit of change is associated with centralized end-to-devices control systems. MaxPatrol Carbon 26.2 simulates compromising vectors through the Kaspersky Security Center and Microsoft SCCM. This analysis shows how service station administration servers can turn into a point for remote code execution and further movement through the infrastructure.
According to the leader of the food practice Positive Technologies Konstantin Manyakov, the safety of the infrastructure depends not only on the number of shortcomings found, but also on the understanding of the ways in which an attacker can use vulnerabilities to achieve goals. In the new version, the team focused on the realism of modeling routes to unacceptable events, as well as on accelerating the analysis of large infrastructures.
The developers also simplified the primary configuration of the entry points into the infrastructure. Operators no longer need to know the syntax of the query language to search for data: it is enough to enter a query in the field and choose the necessary pre-requires. This approach should lower the entry threshold for specialists who are just starting to work with the system.
The interface updated the recommendation page and scenarios for working with it. The changes are aimed at more convenient prioritization of protective measures, elimination of sources of threats and the introduction of compensating mechanisms. In addition, MaxPatrol Carbon has upgraded the dashboard Infrastructure: in one window, it is now possible to assess the coverage, the quality of the audit and the completeness of the asset data.