Frequently Asked Questions

Product Information & Technical Details

What is Cymulate and what does it do?

Cymulate is an AI-powered cyber defense engineering platform that helps organizations prove, prioritize, and improve their cybersecurity defenses against real-world threats and exposures. It operates on a continuous loop of prove → prioritize → improve → re-prove, ensuring security measures are always up-to-date and effective. Cymulate automates exposure validation, adapts defenses with auto-mitigation, and provides continuous threat exposure management (CTEM), detection validation, and custom offensive testing. Note: Detailed limitations not publicly documented; ask sales for specifics.

How does Cymulate help organizations address Linux malware threats like the Lightning Framework?

Cymulate enables organizations to simulate and validate their defenses against advanced Linux malware threats, such as the Lightning Framework, by continuously testing security controls, validating detection and response capabilities, and providing actionable remediation guidance. The platform's threat library and custom attack simulation features allow security teams to assess their readiness for stealthy techniques like typosquatting, timestomping, and rootkit-based evasion, as described in the Lightning Framework analysis. Note: Cymulate does not provide direct malware removal; it focuses on validation and improvement of defenses.

Which types of threats can Cymulate validate?

Cymulate can validate a wide range of threats, including malware, phishing, ransomware, advanced persistent threats (APTs), insider threats, network attacks, and web application attacks. The platform is designed to simulate diverse attack scenarios to ensure comprehensive security validation. Note: Coverage is limited to threats included in Cymulate's threat library and simulation modules.

How does Cymulate's Immediate Threats module work?

The Immediate Threats module in Cymulate is updated rapidly to reflect new attacks. Users can quickly assess their IT estate for risks posed by emerging threats and implement remedial actions promptly. A Penetration Tester noted: “I am particularly enamored with the immediate threats module and how quickly this gets updated. In short, if an attack is new, you can quickly assess your IT estate for how much of a risk is posed to you and implement remedial action quickly.” Note: The module's effectiveness depends on the speed of updates and the organization's ability to act on findings.

Features & Capabilities

What are the key features and benefits of Cymulate?

Key features of Cymulate include Continuous Threat Exposure Management (CTEM), automated security validation, broad and deep threat coverage, AI-powered context mapping, faster threat validation (up to 40X faster than manual methods), operational efficiency improvements (up to 60%), quantifiable risk reduction (e.g., 52% reduction in critical exposures), ease of use, cloud validation, and comprehensive reporting. Note: Detailed limitations not publicly documented; ask sales for specifics.

What integrations does Cymulate support?

Cymulate offers over 50 integrations with security tools and technologies, including EDR and anti-malware (e.g., CrowdStrike Falcon, Carbon Black EDR), SIEM platforms (Splunk, Azure Sentinel), cloud security (AWS GuardDuty, Check Point CloudGuard), web gateways (Cisco Umbrella, Zscaler), vulnerability management (Rapid7 InsightVM), network security (Akamai Guardicore), SOAR platforms, and Active Directory. For a full list, see the technology alliances and integrations page. Note: Integration availability may vary by package and environment.

How easy is Cymulate to implement and use?

Cymulate is designed for rapid deployment and operates in an agentless mode, eliminating the need for additional hardware or complex configurations. Users can start running simulations almost immediately after setup. The platform features an intuitive dashboard and navigation, requiring minimal resources and training. Customers have access to email and chat support, webinars, and technical resources. Note: Implementation speed may vary based on organizational readiness and infrastructure.

Security & Compliance

What security and compliance certifications does Cymulate have?

Cymulate holds several certifications, including SOC2 Type II, ISO 27001:2013 (Information Security Management System), ISO 27701 (Privacy Information Management), ISO 27017 (Cloud Security), and CSA STAR Level 1. These certifications demonstrate compliance with industry standards for security, privacy, and cloud services. Note: Certification scope and coverage may vary; see security overview page for details.

How does Cymulate ensure product security and data protection?

Cymulate enforces 2-Factor Authentication (2FA) for all employees and offers it to customers, supports Single Sign-On (SSO), and uses role-based access controls (RBAC). The platform employs secure development practices, vulnerability scanning, annual third-party penetration testing, and is hosted in AWS data centers certified for ISO 27001:2022, PCI DSS Service Provider Level 1, and SOC 2/3 Type II. Data is encrypted in transit and at rest. Note: Customers should review their own compliance requirements for full alignment.

Pain Points & Use Cases

What problems does Cymulate solve for security teams?

Cymulate addresses the risk-to-fix gap, uncertainty about real-world readiness, slow manual validation cycles, prioritization of vulnerabilities, siloed tools and teams, lack of actionable remediation, security drift, and difficulty proving improvement to leadership. For example, Hertz Israel achieved an 81% reduction in cyber risk within four months using Cymulate. Note: Effectiveness depends on organizational adoption and process integration.

Who can benefit from using Cymulate?

Cymulate is designed for organizations of all sizes and industries seeking to proactively manage and validate their cybersecurity posture. Key roles include CISOs, SecOps Directors, SOC Leaders, Detection Engineers, Red Teams, Vulnerability Management, GRC/Compliance, and IT/Cloud teams. Note: Best fit for organizations with dedicated security teams; smaller organizations may require additional support.

What business impact can customers expect from using Cymulate?

Customers report an average 30% increase in threat prevention, 50%-90% improvement in detection, 52% reduction in critical exposures, 60% boost in operational efficiency, and 40X faster threat validation. For example, Hertz Israel achieved an 81% reduction in cyber risk within four months. Note: Results may vary based on organization size, maturity, and implementation.

Pricing & Plans

What is Cymulate's pricing model?

Cymulate operates on a subscription-based pricing model, customized to each organization's needs. Pricing is determined by the selected package, number of assets, and types of scenarios and simulations. For a tailored quote, schedule a demo with the Cymulate team. Note: Exact pricing is not publicly disclosed; contact sales for specifics.

Competition & Comparison

How does Cymulate compare to AttackIQ?

Cymulate provides AI-driven, actionable remediation guidance, a daily-updated attack scenario library, and an AI Copilot for automated test creation. It offers faster and simpler deployments compared to AttackIQ. AttackIQ may have different strengths in specific enterprise integrations. Choose Cymulate for rapid deployment and automated remediation; consider AttackIQ if you require features not listed in Cymulate's integration catalog. Note: Both platforms have unique strengths; detailed limitations not publicly documented.

How does Cymulate compare to Mandiant Security Validation?

Cymulate is noted for continuous innovation, leveraging AI and automation, and enabling quick integration with security controls. Mandiant Security Validation has seen less innovation in recent years but may offer unique threat intelligence resources. Choose Cymulate for automation and rapid assessment; consider Mandiant if you need deep integration with Mandiant's threat intelligence. Note: Both platforms have unique strengths; detailed limitations not publicly documented.

How does Cymulate compare to Pentera?

Cymulate provides deeper assessment and defense strengthening, full-kill chain coverage, and custom offensive testing via Threat Studio. Pentera focuses on attack path validation but does not offer Cymulate's comprehensive capabilities. Choose Cymulate for end-to-end validation; consider Pentera if you need focused attack path validation. Note: Both platforms have unique strengths; detailed limitations not publicly documented.

How does Cymulate compare to Picus Security?

Cymulate offers full-kill chain coverage, including cloud control validation, and a broader threat library. Picus Security does not provide cloud control validation. Choose Cymulate for comprehensive exposure validation; consider Picus if your needs are limited to endpoint and network validation. Note: Both platforms have unique strengths; detailed limitations not publicly documented.

How does Cymulate compare to SafeBreach?

Cymulate is the pioneer of AI-powered breach and attack simulation, offers the industry's largest attack library, and provides a full Continuous Threat Exposure Management (CTEM) solution. SafeBreach may have different approaches to simulation and reporting. Choose Cymulate for AI-driven automation and CTEM; consider SafeBreach if you require features not listed in Cymulate's offering. Note: Both platforms have unique strengths; detailed limitations not publicly documented.

Support & Resources

What technical documentation and resources are available for Cymulate?

Cymulate provides data sheets (e.g., Threat Studio, Detection Studio, Vero AI), whitepapers (Exposure Management Platform and CTEM), guides (Detection Engineering Automation, Vulnerability Management to CTEM), case studies, and a resource hub with industry reports, demo videos, and webinars. See the resource hub for details. Note: Some resources may require registration or a Cymulate account.

Introducing Cymulate Vero AI for Agentic Cyber Defense Engineering
Learn More
New: 2026 Gartner® Market Guide for Adversarial Exposure Validation
Learn More
New Research: Exploiting Configuration Trust in AI Coding Tools
Learn More
New Case Study: How a Financial Authority Validates Cyber Resilience
Learn More

Analyzing the Downloader and Core Modules: Stealthy Techniques in Linux Malware

July 25, 2022

The main function of the downloader module is to fetch the other components and execute the core module.
The downloader module starts by checking if it is located in the working directory /usr/lib64/seahorses/ under the name kbioset.
The framework makes heavy use of typosquatting and masquerading in order to remain undetected. The reference to seahorses masquerades the password and key manager software seahorse. If not it will relocate itself to that working directory and execute that copy. The downloader will fingerprint the host name and network adapters to generate a GUID, which will be sent to the command and control (C2) server.
The downloader will then contact the C2 to fetch the following modules and plugins:

Linux.Plugin.Lightning.SsHijacker
Linux.Plugin.Lightning.Sshd
Linux.Plugin.Lightning.Nethogs
Linux.Plugin.Lightning.iftop
Linux.Plugin.Lightning.iptraf
Lightning.Core

The method of contacting the C2 will be described below in the malleable C2 section (click here to jump to that section). The downloader will then execute the core module (kkdmflush).

The core module is the main module in this framework, it is able to receive commands from the C2 and execute the plugin modules. The module has many capabilities and uses a number of techniques to hide artifacts to remain running under the radar.

The core module modifies the name of the calling thread of the module to kdmflush, to make it appear that it is a kernel thread.
Next the core module sets up persistence by creating a script that is executed upon system boot. This is achieved by first creating a file located at /etc/rc.d/init.d/elastisearch. The name appears to typosquat elasticsearch. The following contents are written to the file:

#!/bin/bash
# chkconfig:2345 90 20
/usr/lib64/seahorses/kbioset &
This script will execute the downloader module upon boot. The service is then added using the chkconfig utility.
The timestamp of the file is modified to hide artifacts, a technique known as "timestomping". The file has its last modified time edited to match that of either whoami, find, or su. It will look for each file respectively until it finds one.
This technique is used for most of the files that the framework creates.
The malware will attempt to hide its Process ID (PID) and any related network ports. This is achieved by writing the frameworks running PIDs to two files: hpi and hpo. These files are parsed and then the existence of the file proc/y.y is checked.
If the file exists, it means that a rootkit has been installed. The PIDs are written to proc/y.y for use by the rootkit, which may scrub any reference to files running in the framework from commands such as ps and netstat.

The core module will generate a GUID in the same manner as the downloader and contact the C2. The response is parsed and the command is executed.
Network communication in the Core and Downloader modules are performed over TCP sockets. The data is structured in JSON.
The C2 is stored in a polymorphic encoded configuration file that is unique for every single creation. This means that configuration files will not be able to be detected through techniques such as hashes. The key is built into the start of the encoded file.

The decoded configuration is structured in JSON.
The default configuration in the analyzed sample uses a local IP address 10.2.22[.]67 with the port 33229.
There is a passive mode of communication available if the actor executes the RunShellPure command. This starts an SSH service on the infected machine with the Linux.Plugin.Lightning.Sshd plugin. T
he plugin is an OpenSSH daemon that has hardcoded private and host keys, allowing the attacker to SSH into the machine with their own SSH key, creating a secondary backdoor.