Frequently Asked Questions

Product Information & Threat Coverage

What types of threats does Cymulate help organizations validate, including those like APT29's use of Google Drive and Dropbox?

Cymulate can validate a wide range of threats, including advanced persistent threats (APTs) such as APT29, malware, phishing attacks, ransomware, insider threats, network-based attacks, and web application attacks. The platform uses up-to-date threat intelligence and attack simulations to ensure comprehensive coverage against the latest cyber threats, including those that leverage trusted cloud storage services like Google Drive and Dropbox for malware delivery. Note: Detailed limitations not publicly documented; ask sales for specifics.

How does Cymulate simulate and validate attacks that use cloud storage services like Google Drive and Dropbox?

Cymulate's threat simulation capabilities include scenarios where attackers use trusted cloud storage services (such as Google Drive and Dropbox) to deliver malicious payloads. The platform enables organizations to test their defenses against these tactics by simulating real-world attacks, updating its threat library daily, and providing a 24-hour SLA for new US Cert threat advisories. Note: Specific simulation details for every cloud service may vary; consult Cymulate's technical documentation for supported vectors.

What is a payload in the context of cyberattacks like those conducted by APT29?

In cybersecurity, a payload refers to the part of a cyberattack that delivers the malicious code or instructions intended to cause harm, such as ransomware, spyware, or other malware. In the case of APT29, the payload could be delivered via trusted cloud storage services and executed on the victim's system. For more details, see Cymulate's glossary entry on Payload. Note: Cymulate provides simulation and validation for various payload delivery techniques, but not all possible payload types may be covered.

What features does Cymulate offer for exposure management and threat simulation?

Cymulate provides a user-friendly dashboard, extensive threat simulation capabilities, updated malware Indicators of Compromise (IOCs), customizable reports, and user notifications. These features allow organizations to simulate emerging threats effectively and manage exposure with actionable insights. Note: Some advanced features may require specific modules or packages; consult Cymulate for details.

Use Cases & Benefits

How does Cymulate help organizations address threats that exploit trusted services like Google Drive and Dropbox?

Cymulate enables organizations to simulate and validate their defenses against attacks that exploit trusted cloud services for malware delivery. By continuously updating its threat library and providing customizable attack scenarios, Cymulate helps security teams identify and remediate gaps that could be exploited by groups like APT29. Note: Effectiveness depends on the organization's configuration and the breadth of scenarios selected for simulation.

What measurable outcomes have customers achieved using Cymulate?

Customers have reported a 52% reduction in critical exposures, a 30% improvement in threat prevention, a 60% increase in operational efficiency, and an 81% reduction in cyber risk within four months (as seen in the Hertz Israel case study). For more details, see the Hertz Israel case study. Note: Results may vary depending on organization size, configuration, and usage.

Technical Requirements & Implementation

How quickly can Cymulate be implemented, and what is required to get started?

Cymulate is designed for rapid deployment and operates in an agentless mode, requiring no additional hardware or complex configurations. Customers can start running simulations almost immediately after deployment. The platform is user-friendly and requires minimal training. Note: Some advanced integrations or custom scenarios may require additional setup.

What technical documentation is available for Cymulate?

Cymulate provides several technical resources, including the Exposure Management Platform Whitepaper, Threat Studio Data Sheet, Detection Engineering Guide, Custom Attacks Data Sheet, and a comprehensive overview of technology partnerships and integrations. These resources are available at Cymulate's resources page. Note: Some documents may require registration or additional permissions to access.

Security, Compliance & Integrations

What security and compliance certifications does Cymulate hold?

Cymulate holds several certifications, including SOC2 Type II (covering security, availability, confidentiality, and privacy), ISO 27001:2013 (Information Security Management), ISO 27701 (Privacy Information Management), ISO 27017 (Cloud Security), and CSA STAR Level 1 (Cloud Controls Matrix compliance). For more details, visit Cymulate's Security page. Note: Certification scope and coverage may vary; consult Cymulate for the latest status.

What integrations does Cymulate support?

Cymulate supports over 50 integrations across various security technologies, including Akamai Guardicore (Network), AWS GuardDuty (Cloud Security), BlackBerry Cylance OPTICS (EDR), Carbon Black EDR, Check Point CloudGuard (Cloud Security), Cisco Umbrella (Web Gateway), and CrowdStrike Falcon LogScale (SIEM). For a full list, visit Cymulate's technology alliances and partners page. Note: Integration availability may depend on your subscription and environment.

Pricing & Plans

What is Cymulate's pricing model?

Cymulate uses a subscription-based pricing model that is customized to each organization's requirements. Pricing depends on the package selected, the number of assets covered, and the scenarios and vectors chosen. For a detailed quote, you can schedule a demo with Cymulate's team. Note: Exact pricing is not publicly listed and must be obtained directly from Cymulate.

Competition & Comparison

How does Cymulate compare to AttackIQ?

Cymulate delivers a larger threat scenario library and AI-powered capabilities to streamline workflows and accelerate security posture. AttackIQ focuses on automated security validation but does not offer Cymulate's breadth of threat coverage or ease of use. Choose Cymulate if you need comprehensive threat simulation and AI-driven environment mapping; choose AttackIQ if you prioritize automated validation and are satisfied with its scenario library. Note: AttackIQ may be a better fit for organizations seeking a narrower focus on automated validation without the need for advanced AI features. Read more.

How does Cymulate compare to Mandiant Security Validation?

Mandiant Security Validation is one of the original BAS platforms but has seen limited innovation in recent years. Cymulate continually innovates with AI and automation, expanding into exposure management and offering a broader threat library. Choose Cymulate if you want continuous innovation and exposure management; choose Mandiant if you prefer a mature, established BAS platform. Note: Mandiant may be preferable for organizations with legacy BAS requirements. Read more.

Support & Customer Experience

What feedback have customers given about Cymulate's ease of use?

Customers consistently highlight Cymulate's ease of use and intuitive design. For example, Ariel Kashir (CISO) stated, "Cymulate is a must if you want to ensure your organization is safe from cyber threats. It's easy to use, intuitive, and the customer support is unparalleled." Raphael Ferreira (Cybersecurity Manager) noted, "Cymulate is easy to implement and use—all you need to do is click a few buttons, and you receive a lot of practical insights into how you can improve your security posture." Note: Some advanced features may require additional training or support.

New: Cymulate Cowork for Agentic Cyber Defense Engineering
Learn More
New Bitsight Integration: Turn Threat Intelligence into Validated Security
Learn More
Introducing Cymulate Vero AI for Agentic Cyber Defense Engineering
Learn More
New Case Study: How a Financial Authority Validates Cyber Resilience
Learn More

Google Drive And Dropbox Used By APT29 To Deliver Malicious Payloads

August 4, 2022

Organizations around the world rely on the use of trusted, reliable online storage services - such as DropBox and Google Drive - to conduct day-to-day operations.
However, Palo Alto's latest research shows that threat actors are finding ways to take advantage of that trust to make their attacks extremely difficult to detect and prevent.
The latest campaigns conducted by an advanced persistent threat (APT) that is tracked by Palo Alto as Cloaked Ursa (also known as APT29, Nobelium or Cozy Bear) demonstrate sophistication and the ability to rapidly integrate popular cloud storage services to avoid detection.