Frequently Asked Questions

Product Information

What is Cymulate and what does it do?

Cymulate is an Exposure Management Platform designed to help organizations proactively validate their security controls, prioritize exposures, and optimize their defenses. It simulates real-world cyber threats, tests security posture, and provides actionable insights to reduce risk and improve resilience. The platform integrates Breach and Attack Simulation (BAS), Continuous Automated Red Teaming (CART), and Exposure Analytics into a unified solution. Learn more.

What sectors does Cymulate help protect?

Cymulate is used across a wide range of industries, including shipping, healthcare, government, energy, financial services, retail, media, and transportation. The platform is particularly effective for organizations facing sophisticated threats, such as those targeting Israeli shipping, healthcare, government, and energy sectors. See case studies.

How does Cymulate address threats like those used by UNC3890?

Cymulate enables organizations to simulate advanced attack techniques, such as those used by UNC3890 (e.g., backdoors, credential stealers, C2 infrastructure, phishing, and watering hole attacks). By running automated, real-world attack scenarios, Cymulate helps organizations validate their defenses against similar tactics and improve their ability to detect and respond to such threats. Learn more about threat validation.

What is the primary purpose of Cymulate's Exposure Management Platform?

The primary purpose of Cymulate's Exposure Management Platform is to help organizations harden their defenses and optimize security controls by proactively validating controls, threats, and response capabilities. It enables organizations to focus on exploitable exposures and strengthen their overall security posture. Learn more.

Who is the target audience for Cymulate?

Cymulate is designed for CISOs, security leaders, SecOps teams, Red Teams, and vulnerability management teams in organizations of all sizes and industries. It is especially valuable for teams responsible for security validation, risk management, and operational efficiency. Learn more about roles.

What types of cyber threats does Cymulate help organizations defend against?

Cymulate helps organizations defend against a wide range of cyber threats, including ransomware, phishing, advanced persistent threats (APTs), credential theft, lateral movement, and cloud-based attacks. The platform simulates these threats to test and validate defenses. Learn more.

What is Cymulate's approach to Continuous Threat Exposure Management (CTEM)?

Cymulate's CTEM approach integrates continuous validation, prioritization, and mobilization of security controls. It enables organizations to evolve from periodic assessments to ongoing, actionable exposure management, ensuring measurable improvements in threat resilience and operational efficiency. Learn more.

How does Cymulate support detection engineering?

Cymulate provides tools for building, tuning, and testing SIEM, EDR, and XDR detection rules. This helps organizations improve their mean time to detect threats and optimize their detection engineering processes. Learn more.

What is Cymulate's mission and vision?

Cymulate's mission is to revolutionize how companies approach cybersecurity by fostering a proactive, collaborative, and resilient security culture. The vision is to empower organizations to effectively manage their security posture and improve resilience against threats. Read more.

What is Cymulate's global presence and customer base?

Cymulate was founded in 2016 and has a global footprint with offices in eight locations, serving customers in 50 countries. Over 1,000 customers trust Cymulate for their cybersecurity needs. Learn more.

Features & Capabilities

What are the key features of Cymulate?

Cymulate offers continuous threat validation, unified exposure management, AI-powered optimization, complete kill chain coverage, attack path discovery, cloud validation, an immediate threats module, and an extensive threat library with daily updates. See all features.

Does Cymulate support integration with other security tools?

Yes, Cymulate integrates with a wide range of security technologies, including EDR (CrowdStrike Falcon, Cisco Secure Endpoint, BlackBerry Cylance PROTECT), SIEM (CrowdStrike Falcon LogScale), cloud security (AWS GuardDuty, Check Point CloudGuard), network security (Akamai Guardicore), and vulnerability management (CrowdStrike Falcon Spotlight). See all integrations.

How does Cymulate's 'Threat (IoC) updates' feature improve threat resilience?

The 'Threat (IoC) updates' feature provides recommended Indicators of Compromise (IoCs) that can be exported and applied directly to security controls. This helps control owners quickly build defenses against new threats, improving overall threat resilience. Learn more.

What technical documentation and resources are available for Cymulate?

Cymulate provides whitepapers, guides, solution briefs, data sheets, and industry reports covering topics like CTEM, exposure validation, detection engineering, and vulnerability management. Browse resources.

How often is Cymulate updated with new features or threat intelligence?

Cymulate updates its SaaS platform every two weeks with new features, such as AI-powered SIEM rule mapping and advanced exposure prioritization. The threat library receives daily updates to keep customers ahead of emerging threats. Learn more.

What is Cymulate's approach to cloud security validation?

Cymulate provides dedicated validation features for hybrid and cloud environments, helping organizations address new attack surfaces and compliance requirements introduced by cloud adoption. Learn more.

How does Cymulate help with attack path discovery?

Cymulate automates offensive testing to identify and mitigate threats related to privilege escalation and lateral movement, providing visibility into potential attack paths within the organization. Learn more.

What is the Immediate Threats module in Cymulate?

The Immediate Threats module assesses environments against new attacks as they emerge, enabling organizations to respond quickly and proactively to the latest threats. Learn more.

Use Cases & Benefits

What business impact can customers expect from using Cymulate?

Customers can expect an 81% reduction in cyber risk within four months, a 60% increase in operational efficiency, 40X faster threat validation, a 30% improvement in threat prevention, and a 52% reduction in critical exposures. These outcomes are supported by case studies such as Hertz Israel and others. Read the Hertz Israel case study.

How does Cymulate help organizations overwhelmed by the volume of threats?

Cymulate provides continuous threat validation, simulating real-world attacks to help organizations focus on the most critical exposures and validate their defenses efficiently. Learn more.

How does Cymulate improve visibility into security posture?

Cymulate offers tools to identify exploitable vulnerabilities and assess resilience against current threats, providing actionable insights and clear metrics for security teams. See the Nemours Children's Health case study.

How does Cymulate help with vulnerability prioritization?

Cymulate ranks vulnerabilities based on exploitability, business context, and threat intelligence, enabling organizations to focus remediation efforts on the most critical exposures. Learn more.

How does Cymulate address operational inefficiencies?

Cymulate automates threat validation and vulnerability management processes, reducing manual tasks and improving operational efficiency. See the credit union case study.

How does Cymulate help organizations with fragmented security tools?

Cymulate consolidates Breach and Attack Simulation, Continuous Automated Red Teaming, and Exposure Analytics into a single platform, reducing complexity and improving visibility and control. See the IT services case study.

How does Cymulate support cloud security and compliance?

Cymulate provides cloud validation features and has helped organizations automate compliance and regulatory testing requirements, as demonstrated in the sustainable energy company case study. Read the case study.

How does Cymulate help CISOs communicate risk to stakeholders?

Cymulate provides validated exposure scoring and quantifiable metrics tailored to CISOs, enabling clear communication of risk and justification of security investments. See the UK bank case study.

How does Cymulate tailor its solutions for different security personas?

Cymulate addresses the unique pain points of CISOs, SecOps teams, Red Teams, and vulnerability management teams by providing tailored metrics, automation, offensive testing, and exposure prioritization. Learn more about personas.

Pricing & Plans

What is Cymulate's pricing model?

Cymulate operates on a subscription-based pricing model tailored to each organization's needs. Pricing depends on the package, number of assets, and scenarios selected. For a detailed quote, schedule a demo.

How can I get a Cymulate pricing quote?

You can request a customized pricing quote by scheduling a demo with the Cymulate team. They will assess your organization's requirements and provide a tailored proposal. Book a demo.

Implementation & Ease of Use

How long does it take to implement Cymulate?

Cymulate is known for its quick and straightforward implementation. It operates in agentless mode, requiring no additional hardware or complex configurations. Customers can start running simulations almost immediately after deployment. Read a customer story.

How easy is Cymulate to use?

Cymulate is praised for its intuitive and user-friendly interface. Customers report that the platform is easy to implement, navigate, and provides actionable insights with just a few clicks. See customer feedback.

What support options are available for Cymulate customers?

Cymulate provides comprehensive support, including email and chat support, to ensure a smooth onboarding and ongoing experience for customers. Contact support.

Security & Compliance

What security and compliance certifications does Cymulate have?

Cymulate is certified for SOC2 Type II, ISO 27001:2013, ISO 27701, ISO 27017, and CSA STAR Level 1. These certifications demonstrate Cymulate's commitment to security, privacy, and cloud compliance. See all certifications.

How does Cymulate ensure data security and privacy?

Cymulate's services are hosted in secure AWS data centers with strong physical security, encryption for data in transit (TLS 1.2+) and at rest (AES-256), and high availability through redundancy and disaster recovery. The platform follows a strict Secure Development Lifecycle and ongoing employee security training. Learn more.

Is Cymulate GDPR compliant?

Yes, Cymulate adopts a holistic approach to GDPR, incorporating data protection by design and maintaining a dedicated privacy and security team, including a Data Protection Officer (DPO) and Chief Information Security Officer (CISO). Read more.

Competition & Comparison

How does Cymulate compare to AttackIQ?

AttackIQ provides automated security validation but lacks Cymulate's innovation, threat coverage, and ease of use. Cymulate offers a more comprehensive threat scenario library and advanced AI-powered features. Read more.

How does Cymulate compare to Mandiant Security Validation?

Mandiant is an original BAS platform but has seen less innovation in recent years. Cymulate continually innovates with AI and automation and has expanded into exposure management as a market leader. Read more.

How does Cymulate compare to Pentera?

Pentera focuses on attack path validation but lacks the depth Cymulate provides for full exposure validation and defense strengthening. Cymulate covers the full kill chain and provides cloud control validation. Read more.

How does Cymulate compare to Picus Security?

Picus is suitable for those seeking a BAS vendor with on-prem options but lacks Cymulate's comprehensive exposure validation, full kill chain coverage, and cloud control validation. Read more.

How does Cymulate compare to SafeBreach?

SafeBreach offers breach and attack simulation but lacks Cymulate's innovation, precision, and automation. Cymulate provides a full CTEM solution, comprehensive exposure validation, and advanced automation. Read more.

How does Cymulate compare to Scythe?

Scythe is built for advanced red teams to build custom attack campaigns but lacks Cymulate's ease of use, continuous validation, and actionable remediation guidance. Cymulate offers automated, no-code workflows, daily threat updates, and specific mitigation guidance. Read more.

Introducing Cymulate Vero AI for Agentic Cyber Defense Engineering
Learn More
New: 2026 Gartner® Market Guide for Adversarial Exposure Validation
Learn More
New Research: Exploiting Configuration Trust in AI Coding Tools
Learn More
New Case Study: How a Financial Authority Validates Cyber Resilience
Learn More

Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors

August 18, 2022

UNC3890 uses at least two unique tools: a backdoor which Mandiant named SUGARUSH, and a browser credential stealer, which exfiltrates stolen data via Gmail, Yahoo and Yandex email services that we've named SUGARDUMP. UNC3890 also uses multiple publicly available tools, such as the METASPLOIT framework and NorthStar C2. In addition, Mandiant discovered UNC3890 operates an inter-connected network of Command-and-Control (C2) servers. The C2 servers host domains and fake login pages spoofing legitimate services such as Office 365, social networks such as LinkedIn and Facebook, as well as fake job offers and fake commercials for AI-based robotic dolls. Mandiant observed the C2 servers communicating with multiple targets, as well as with a watering hole that Mandiant believes was targeting the Israeli shipping sector, in particular entities that handle and ship sensitive components.