Frequently Asked Questions

Product Information & Threat Research

What is the attack chain described in the 'Malicious Compiled HTML Help File Delivering Agent Tesla' research?

The attack begins with a 7zip compressed file named ORDER OF CONTRACT-pdf.7z, which contains a malicious compiled HTML help file (ORDER OF CONTRACT-pdf.chm). When opened, the CHM file executes obfuscated JavaScript, which in turn runs obfuscated PowerShell code in the background. This PowerShell payload downloads a second-stage loader from the internet, which then loads Agent Tesla into memory. Note: This research highlights the complexity of multi-stage attacks and the importance of validating defenses against fileless malware and script-based exploits. Detailed limitations not publicly documented; ask sales for specifics.

How does Cymulate help organizations defend against fileless malware and script-based attacks like Agent Tesla?

Cymulate enables organizations to simulate and validate their defenses against fileless malware and script-based attacks by automating continuous testing of threats, security controls, and exposures. The platform's threat library includes scenarios for malware, ransomware, phishing, and advanced persistent threats (APTs), allowing users to assess their readiness against attacks that use obfuscated scripts and in-memory payloads. Note: Cymulate's effectiveness depends on the scenarios selected and the organization's coverage; not all attack variants may be included by default.

Which types of threats can Cymulate validate?

Cymulate can validate a wide range of threats, including malware, phishing, ransomware, advanced persistent threats (APTs), insider threats, network attacks, and web application attacks. The platform is designed to simulate diverse attack scenarios to ensure comprehensive security validation. Note: Coverage is dependent on the scenarios and modules selected; organizations should review the threat library for specific attack types.

What are malware-based attacks and how can organizations defend against them?

Malware-based attacks use payloads like trojans, ransomware, and worms to disrupt or damage networks. Organizations can defend against these attacks by deploying advanced endpoint detection and response (EDR), regularly patching systems, monitoring for anomalies, and validating lateral movement controls. Cymulate's platform can simulate these attack types to test and improve defenses. Note: No single tool can guarantee prevention; layered security and ongoing validation are recommended. Learn more about payloads.

Features & Capabilities

What features does Cymulate offer for threat validation and exposure management?

Cymulate provides automated exposure validation, continuous threat exposure management (CTEM), auto mitigation with trusted integrations, a comprehensive threat library, and modules like Detection Studio and Threat Studio for custom attack simulations. The platform operates in a closed-loop system (prove → prioritize → improve → re-prove) to ensure ongoing improvement. Note: Some advanced features may require specific packages or integrations; check with Cymulate for details.

How does Cymulate's immediate threats module work?

The immediate threats module is updated rapidly to reflect new attacks. Organizations can quickly assess their IT estate for risks posed by emerging threats and implement remedial actions promptly. Users have noted the speed and relevance of these updates. Note: Effectiveness depends on timely updates and scenario selection; not all threats may be covered instantly.

What integrations does Cymulate support?

Cymulate integrates with over 50 security tools, including SIEM platforms (Azure Sentinel, Splunk, CrowdStrike Falcon LogScale), EDR and anti-malware solutions (CrowdStrike Falcon, Carbon Black EDR, Cisco Secure Endpoint), cloud security tools (AWS GuardDuty, Check Point CloudGuard), web gateways (Cisco Umbrella), vulnerability management (Rapid7 InsightVM), and others like Microsoft Defender, Palo Alto Networks, Wiz, and Zscaler. Note: Integration availability may depend on your package and environment; confirm compatibility before deployment.

Use Cases & Benefits

Who can benefit from using Cymulate?

Cymulate is designed for CISOs, VP Security, SecOps Directors, SOC leaders, detection engineers, red teams, vulnerability management teams, GRC/compliance teams, and IT/infrastructure/cloud teams. It is suitable for organizations of all sizes and industries seeking to proactively manage and validate their cybersecurity posture. Note: Organizations with highly specialized or legacy environments may require custom integrations; consult Cymulate for fit.

What business impact can customers expect from using Cymulate?

Customers report an average 30% increase in threat prevention, 90% improvement in threat detection, 52% reduction in critical exposures, and a 60% boost in operational efficiency. Threat validation is up to 40X faster than manual methods, and some organizations, like Hertz Israel, have achieved an 81% reduction in cyber risk within four months. Note: Actual results may vary based on deployment scope and organizational maturity.

Implementation & Ease of Use

How long does it take to implement Cymulate and how easy is it to start?

Cymulate is designed for rapid deployment and operates in agentless mode, requiring no additional hardware or complex configuration. Users can start running simulations with just a few clicks, and the platform is accessible for both technical and non-technical users. Support is available via email and chat, and educational resources are provided. Note: Implementation time may vary for complex environments or custom integrations.

What do customers say about Cymulate's ease of use?

Customers consistently praise Cymulate for its intuitive design and ease of use. For example, Raphael Ferreira, Cybersecurity Manager, stated: "Cymulate is easy to implement and use—all you need to do is click a few buttons, and you receive a lot of practical insights into how you can improve your security posture." Other users highlight its value for communicating risks to management and its accessibility for both technical and non-technical stakeholders. Note: User experience may vary based on organizational needs and platform familiarity. Read more reviews.

Security, Compliance & Documentation

What security and compliance certifications does Cymulate have?

Cymulate is SOC2 Type II certified and holds ISO 27001:2013, ISO 27701, ISO 27017, and CSA STAR Level 1 certifications. These attest to compliance with security, privacy, and cloud service standards. Note: Certification scope and coverage may vary; review official documentation for details. Learn more.

What technical documentation is available for Cymulate?

Cymulate provides a resource hub with industry reports, whitepapers, case studies, and technical guides. Notable resources include the Threat Studio data sheet and the Detection Engineering Automation Guide. These materials offer in-depth insights into detection engineering, threat validation, and platform capabilities. Note: Some resources may require registration. Access the resource hub.

Pricing & Plans

What is Cymulate's pricing model?

Cymulate uses a subscription-based pricing model tailored to each organization's needs. Pricing depends on the package selected, number of assets covered, and chosen scenarios and features. For a personalized quote, organizations can schedule a demo with the Cymulate team. Note: Exact pricing is not publicly listed; contact Cymulate for details. Schedule a demo.

Competition & Comparison

How does Cymulate compare to AttackIQ?

Cymulate offers AI-driven remediation guidance, a daily-updated attack scenario library, and an AI Copilot for automated test creation. Cymulate is recognized as a Momentum Leader by G2 and a Customer’s Choice in the 2025 Gartner Peer Insights Voice of the Customer for Adversarial Exposure Validation. AttackIQ may offer different integrations or workflows; choose Cymulate for rapid, AI-powered validation and AttackIQ if you require their specific integrations. Note: Cymulate may not cover all AttackIQ-specific features; review both platforms for fit. Read more.

How does Cymulate compare to Mandiant Security Validation?

Cymulate emphasizes continuous innovation with AI and automation, rapid deployment, and an intuitive dashboard. It provides a comprehensive attack library with daily updates and actionable remediation guidance. Mandiant Security Validation may offer different threat intelligence or integration options; choose Cymulate for ease of use and automation, and Mandiant for their threat intelligence network. Note: Cymulate may not replicate all Mandiant-specific features. Read more.

How does Cymulate compare to Pentera?

Cymulate combines breach simulation, automated red teaming, and deep security control integrations. It allows custom attack chains from a library of over 100,000 actions and delivers daily threat updates. Pentera may focus more on automated penetration testing; choose Cymulate for continuous exposure validation and Pentera for periodic pen testing automation. Note: Cymulate may not cover all Pentera-specific workflows. Read more.

How does Cymulate compare to Picus Security?

Cymulate delivers full kill-chain coverage, including cloud control validation, and features no-code workflows with a library of over 100,000 attack actions. Picus Security may offer different reporting or integration options; choose Cymulate for cloud validation and Picus for their specific integrations. Note: Cymulate may not include all Picus-specific features. Read more.

How does Cymulate compare to SafeBreach?

Cymulate leverages AI and automation for exposure validation, offers the largest attack library updated daily, and provides intuitive dashboards and centralized validation. SafeBreach may focus on different validation workflows; choose Cymulate for AI-driven automation and SafeBreach for their specific integrations. Note: Cymulate may not cover all SafeBreach-specific features. Read more.

Introducing Cymulate Vero AI for Agentic Cyber Defense Engineering
Learn More
New: 2026 Gartner® Market Guide for Adversarial Exposure Validation
Learn More
New Research: Exploiting Configuration Trust in AI Coding Tools
Learn More
New Case Study: How a Financial Authority Validates Cyber Resilience
Learn More

Malicious Compiled HTML Help File Delivering Agent Tesla

May 19, 2022

The initial attack sent a 7zip compressed file named ORDER OF CONTRACT-pdf.7z, which contained the single malicious compiled HTML help file ORDER OF CONTRACT-pdf.chm (SHA256: 081fd54d8d4731bbea9a2588ca53672feef0b835dc9fa9855b020a352819feaa). The file contains obfuscated JavaScript that is executed when the file is opened. When the Javascript code in turn executes obfuscated PowerShell code which is executed in the background when the file is opened. The powershell payload downloads a second stage payload from the internet, which is a powershell loader. When the powershell loader is run, it in turn loads Agent Tesla to memory.