Frequently Asked Questions

Threats & Security Validation

What is LokiLocker RaaS and how does it target Windows systems?

LokiLocker is a Ransomware-as-a-Service (RaaS) scheme that encrypts files on local drives and network shares using AES and RSA encryption. Victims are instructed to email attackers for ransom payment instructions. If payment is not made within the specified timeframe, LokiLocker can activate a wiper functionality, deleting all non-system files and overwriting the Master Boot Record (MBR), rendering the system unusable. The malware is distributed through Trojanized brute-checker hacking tools and is operated by a small group of vetted affiliates. Note: Cymulate does not directly prevent LokiLocker but can help organizations validate their defenses against ransomware threats like LokiLocker. Source

How can Cymulate help organizations validate their defenses against ransomware threats like LokiLocker?

Cymulate enables organizations to simulate ransomware attacks, including those similar to LokiLocker, to validate their security controls and exposures. The platform automates continuous testing, providing actionable insights and prioritized remediation guidance. Cymulate's threat library covers ransomware, malware, phishing, APTs, and more, allowing organizations to proactively assess their readiness against real-world threats. Note: Cymulate's effectiveness depends on the organization's ability to act on remediation guidance; detailed limitations not publicly documented—ask sales for specifics. Source

Which types of threats can Cymulate validate?

Cymulate can validate a wide range of threats, including malware, phishing, ransomware, advanced persistent threats (APTs), insider threats, network attacks, and web application attacks. The platform is designed to simulate diverse attack scenarios for comprehensive security validation. Note: Cymulate's threat coverage is extensive, but organizations with highly specialized threat profiles may require custom testing. Source

Features & Capabilities

What are the key capabilities of Cymulate?

Cymulate offers continuous threat validation, exposure validation, AI-powered context mapping, a comprehensive threat library, automated mitigation, Detection Studio, and Threat Studio. These features enable organizations to prove, prioritize, and improve their cybersecurity defenses against real-world threats. Note: Some advanced features may require additional configuration or integration. Source

What integrations does Cymulate support?

Cymulate supports over 50 integrations across SIEM (e.g., CrowdStrike Falcon LogScale), EDR and anti-malware (e.g., BlackBerry Cylance OPTICS, Carbon Black EDR), cloud security (e.g., AWS GuardDuty, Check Point CloudGuard), web gateway (Cisco Umbrella), network security (Akamai Guardicore), vulnerability management (Rapid7 InsightVM), SOAR, and Active Directory. For a full list, visit the technology alliances and integrations page. Note: Integration availability may depend on your environment and licensing.

How does Cymulate validate immediate threats?

When Cymulate's Threat Research Group adds a new emergent threat assessment, the platform automatically runs the assessment to identify if the latest threat can be exploited in the organization's environment. This enables rapid response to new threats. Note: Immediate threat validation depends on timely updates from Cymulate's research team. Source

Use Cases & Benefits

Who can benefit from Cymulate?

Cymulate is designed for CISOs, VP Security, SecOps Directors, SOC Leaders, Detection Engineers, Blue Team Leads, Red Teams, and Vulnerability Management Teams. It is suitable for organizations of all sizes and industries, including critical infrastructure, finance, healthcare, retail, and technology. Note: Organizations with highly specialized or legacy environments may require custom integration. Source

What business impact can customers expect from using Cymulate?

Customers report an average 30% increase in threat prevention, 50%-90% improvement in detection capabilities, 52% reduction in critical exposures, 60% boost in operational efficiency, and 40X faster threat validation. Hertz Israel achieved an 81% reduction in cyber risk within four months. Note: Actual results may vary based on implementation and organizational maturity. Case Study

What are common pain points Cymulate addresses?

Cymulate addresses the risk-to-fix gap, uncertainty about real-world readiness, slow manual validation cycles, too many findings with insufficient prioritization, siloed tools and teams, lack of actionable remediation, security drift and detection decay, and difficulty proving improvement to leadership. Note: Some pain points may require organizational process changes beyond Cymulate's platform. Case Studies

Customer Experience & Implementation

How easy is it to implement Cymulate and get started?

Cymulate is designed for rapid deployment with agentless mode, requiring no additional hardware or complex configurations. Users can start running simulations almost immediately after setup. The platform features a user-friendly interface and intuitive dashboard, making it accessible even for those with minimal technical expertise. Comprehensive support is available via email, chat, webinars, and e-books. Note: Implementation speed may vary based on organizational readiness and infrastructure. Source

What feedback have customers provided about Cymulate's ease of use?

Customers consistently highlight Cymulate's intuitive design, ease of deployment, and actionable insights. Raphael Ferreira, Cybersecurity Manager, stated: "Cymulate is easy to implement and use—all you need to do is click a few buttons, and you receive a lot of practical insights into how you can improve your security posture." Markus Flatscher, Senior Security Manager, noted its effectiveness in communicating cybersecurity value to non-technical stakeholders. Note: Some users may require additional onboarding support for advanced features. Source

Pricing & Plans

What is Cymulate's pricing model?

Cymulate uses a subscription-based pricing model customized to fit each organization's needs. Pricing is determined by the package selected, number of assets covered, and scenarios/features chosen. For a tailored quote, schedule a demo with Cymulate's team. Note: Exact pricing details are not publicly documented; contact Cymulate for specifics. Source

Security & Compliance

What security and compliance certifications does Cymulate hold?

Cymulate holds SOC2 Type II, ISO 27001:2013, ISO 27701, ISO 27017, and CSA STAR Level 1 certifications. These ensure compliance with security, privacy, and cloud service standards. Cymulate also supports GDPR compliance and provides end-to-end visibility for compliance reporting. Note: Certification scope may vary; review documentation for details. Source

What product security features does Cymulate offer?

Cymulate incorporates advanced security measures, including 2-Factor Authentication (2FA) for employees and customers, Single Sign-On (SSO), role-based access controls (RBAC), and comprehensive security policies. Note: Some features may require additional configuration or licensing. Source

Competition & Comparison

How does Cymulate compare to AttackIQ?

Cymulate offers AI-driven actionable remediation guidance, a daily-updated attack scenario library, AI Copilot for automated test creation, continuous automated testing, and faster deployment compared to AttackIQ. AttackIQ may offer different strengths in specific environments. Choose Cymulate for rapid, AI-powered threat validation; choose AttackIQ if you require specialized attack simulation workflows. Source

How does Cymulate compare to Mandiant Security Validation?

Cymulate provides continuous innovation, AI-powered automation, and expanded exposure management capabilities. Mandiant Security Validation has seen less innovation in recent years. Choose Cymulate for evolving, automated exposure management; choose Mandiant if you require legacy validation workflows. Source

How does Cymulate compare to Pentera?

Cymulate offers deeper assessment and defense strengthening, full-kill chain coverage including cloud control validation, and actionable remediation guidance. Pentera focuses on attack path validation. Choose Cymulate for comprehensive exposure validation; choose Pentera if you require focused attack path testing. Source

How does Cymulate compare to Picus Security?

Cymulate provides full-kill chain coverage, including cloud control validation, and a broader threat library. Picus Security focuses on breach and attack simulation with on-prem options. Choose Cymulate for complete exposure validation; choose Picus if you require on-prem BAS. Source

How does Cymulate compare to SafeBreach?

Cymulate outpaces SafeBreach with innovation, precision, automation, and the largest attack library. Cymulate offers a full Continuous Threat Exposure Management (CTEM) solution. SafeBreach may offer different strengths in specific environments. Choose Cymulate for comprehensive exposure management; choose SafeBreach if you require specialized breach simulation. Source

How does Cymulate compare to SCYTHE?

Cymulate offers a unified exposure validation platform with breach and attack simulation, automated red teaming, scalable testing, and comprehensive reporting via MITRE ATT&CK Heatmap. SCYTHE may offer different strengths in custom red team workflows. Choose Cymulate for scalable, unified exposure validation; choose SCYTHE if you require highly customized red team operations. Source

Technical Documentation & Support

Where can prospects find technical documentation for Cymulate?

Technical documentation, data sheets, and guides are available at Cymulate's Resource Hub, including the Threat Studio Data Sheet and Detection Engineering Automation Guide. These resources provide in-depth insights into detection engineering, threat validation, and platform features. Note: Some documentation may require registration. Resource Hub

New: Cymulate Cowork for Agentic Cyber Defense Engineering
Learn More
New Bitsight Integration: Turn Threat Intelligence into Validated Security
Learn More
Introducing Cymulate Vero AI for Agentic Cyber Defense Engineering
Learn More
New Case Study: How a Financial Authority Validates Cyber Resilience
Learn More

LokiLocker RaaS Targets Windows Systems

March 22, 2022

LokiLocker encrypts victim's files on local drives and network shares with a standard combination of AES for file encryption and RSA for key protection. It then asks the victim to email the attackers to obtain instructions on how to pay the ransom. LokiLocker also boasts an optional wiper functionality - if the victim doesn't pay up in the timeframe specified by the attacker, all non-system files will be deleted and the MBR overwritten, wiping all the victim's files and rendering the system unusable. With a single stroke, everyone loses. LokiLocker works as a limited-access Ransomware-as-a-Service scheme that appears to be sold to a relatively small number of carefully vetted affiliates behind closed doors. Each affiliate is identified by a chosen username and is assigned a unique chat-ID number. There are currently about 30 different "VIP" affiliates across the LokiLocker samples that BlackBerry researchers have found in the wild. One of the earliest samples of this ransomware was initially distributed inside Trojanized brute-checker hacking tools such as: PayPal BruteChecker Spotify BruteChecker PiaVPN Brute Checker By ACTEAM FPSN Checker by Angeal (Cracked by MR_Liosion) ed by MR_Liosion) The malware defines an array of strings, which presumably contains a list of countries to exclude from encryption. In all the samples that have been observed so far, this list contains only one entry - "Iran". It seems that this functionality is not yet implemented, as there are no references to this array in the code. However, like the references to Iranian attackers and hacking tools, it could just as well be a false flag meant to misdirect attention.