Frequently Asked Questions

Threats & Email Security

What happened in the Ukraine CERT-UA compromised email incident?

An adversary used a compromised email address to send phishing emails with a malicious PDF attachment. The files were protected by VMProtect to hinder analysis. Successful attacks resulted in systems being infected with RomCom, FateGrab, and StealDeal malware variants. Note: This incident highlights the need for continuous validation of email security controls. Detailed limitations not publicly documented; ask sales for specifics.

How does Cymulate help organizations defend against email-borne malware like RomCom, FateGrab, and StealDeal?

Cymulate enables organizations to simulate and validate their exposure to a wide range of email-borne threats, including malware, phishing, and ransomware. The platform can test email gateways and controls against real-world attack techniques, helping identify configuration flaws and gaps that could allow malware to bypass defenses. Note: Cymulate does not replace the need for secure email gateways or endpoint protection; it validates their effectiveness. Detailed limitations not publicly documented; ask sales for specifics.

Why is email security validation important for organizations?

Email remains the number-one attack vector for cyber threats. According to industry sources, 94% of organizations suffered email security incidents, 79% of cyber attacks started with a phishing email, and 69% of ransomware attacks began with an email. Validating email security controls helps organizations reduce the risk of business disruption, data loss, and financial damage. Note: Validation does not guarantee prevention of all attacks; ongoing monitoring and layered defenses are still required.

What types of threats can Cymulate validate?

Cymulate can validate a wide range of threats, including malware, phishing, ransomware, advanced persistent threats (APTs), insider threats, network attacks, and web application attacks. The platform simulates diverse attack scenarios to ensure comprehensive security validation. Note: Cymulate's coverage depends on the scenarios and integrations selected; not all threat types may be available in every package.

Features & Capabilities

What are the key capabilities of Cymulate?

Cymulate offers continuous threat validation, exposure validation, AI-powered context mapping, a comprehensive threat library, automated mitigation, Detection Studio, and Threat Studio. These features enable organizations to automate testing, prioritize remediation, and improve operational efficiency. Note: Some advanced features may require specific packages or integrations; ask sales for details.

What integrations does Cymulate support?

Cymulate supports over 50 integrations across SIEM (e.g., CrowdStrike Falcon LogScale), EDR and anti-malware (e.g., Carbon Black EDR, CrowdStrike Falcon), cloud security (e.g., AWS GuardDuty), web gateways (e.g., Cisco Umbrella), network security (e.g., Akamai Guardicore), vulnerability management (e.g., Rapid7 InsightVM), SOAR, and Active Directory. For a full list, visit the technology alliances and integrations page. Note: Integration availability may depend on your package and environment.

How does Cymulate validate immediate threats?

When Cymulate's Threat Research Group adds a new emergent threat assessment, the platform automatically runs the assessment to identify if the latest threat can be exploited in your environment. This helps organizations respond quickly to new attack techniques. Note: Immediate threat validation depends on timely updates from the research group and customer configuration.

Implementation & Ease of Use

How long does it take to implement Cymulate and how easy is it to start?

Cymulate is designed for rapid deployment, often requiring only a few clicks to get started thanks to its agentless mode. No additional hardware or complex configuration is needed. Customers report that the platform is easy to use and provides actionable insights quickly. Note: Implementation time may vary based on environment complexity and integration needs.

What feedback have customers given about Cymulate's ease of use?

Customers consistently highlight Cymulate's intuitive design, ease of deployment, and actionable insights. For example, Raphael Ferreira, Cybersecurity Manager, stated: "Cymulate is easy to implement and use—all you need to do is click a few buttons, and you receive a lot of practical insights into how you can improve your security posture." Note: User experience may vary depending on organizational requirements and technical expertise.

Pricing & Plans

What is Cymulate's pricing model?

Cymulate uses a subscription-based pricing model that is customized to each organization's needs. Pricing depends on the package selected, number of assets, and chosen scenarios and features. For a tailored quote, you can schedule a demo with the Cymulate team. Note: Exact pricing is not publicly listed and must be requested from sales.

Security & Compliance

What security and compliance certifications does Cymulate hold?

Cymulate holds several industry-recognized certifications, including SOC2 Type II, ISO 27001:2013, ISO 27701, ISO 27017, and CSA STAR Level 1. These certifications demonstrate compliance with security, privacy, and cloud service standards. Note: Certification scope and applicability may vary; contact Cymulate for details on coverage for your use case.

How does Cymulate support GDPR compliance?

Cymulate adheres to GDPR requirements through secure development life cycle procedures, data protection by design, and continuous oversight by a Data Protection Officer (DPO) and Chief Information Security Officer (CISO). The platform also provides end-to-end visibility and reporting to help organizations prove compliance. Note: GDPR compliance depends on proper configuration and use; organizations remain responsible for their own regulatory obligations.

Use Cases & Business Impact

What business impact can customers expect from using Cymulate?

Customers report an average 30% increase in threat prevention, 50%-90% improvement in detection, 52% reduction in critical exposures, and a 60% boost in operational efficiency. For example, Hertz Israel achieved an 81% reduction in cyber risk within four months. Note: Results may vary based on organizational maturity and implementation scope.

Who is the target audience for Cymulate?

Cymulate is designed for CISOs, VP Security, SecOps Directors, SOC Leaders, Detection Engineers, Blue Team Leads, Red Teams, and Vulnerability Management Teams in organizations of all sizes and industries. It is especially relevant for companies seeking to proactively manage and validate their cybersecurity posture. Note: Smaller organizations with limited security resources may require additional support for full adoption.

Competition & Comparison

How does Cymulate compare to AttackIQ?

Cymulate offers AI-driven remediation guidance, a daily-updated attack scenario library, and an AI Copilot for automated test creation. It provides continuous, automated testing and faster deployment compared to AttackIQ. AttackIQ may offer different integrations or reporting features. Choose Cymulate for rapid deployment and actionable remediation; choose AttackIQ if you require specific integrations not available in Cymulate. Note: Some advanced features may require additional licensing.

How does Cymulate compare to Mandiant Security Validation?

Cymulate provides continuous innovation, AI-powered automation, and expanded exposure management capabilities. Mandiant Security Validation has seen less innovation in recent years but may offer deeper integration with Mandiant's threat intelligence. Choose Cymulate for automation and rapid updates; choose Mandiant if you need integration with Mandiant's broader security services. Note: Feature availability may depend on package and environment.

How does Cymulate compare to Pentera?

Cymulate provides deeper assessment and defense strengthening, full-kill chain coverage, and actionable remediation guidance. Pentera focuses on attack path validation. Choose Cymulate for comprehensive exposure validation and remediation; choose Pentera if you need focused attack path validation. Note: Cymulate may require additional configuration for certain advanced scenarios.

Technical Documentation & Support

Where can I find technical documentation and resources for Cymulate?

Technical documentation, data sheets, and guides are available at the Cymulate Resource Hub. This includes product whitepapers, case studies, and guides such as the Threat Studio Data Sheet and Detection Engineering Automation Guide. Note: Some resources may require registration or a Cymulate account for access.

New: Cymulate Cowork for Agentic Cyber Defense Engineering
Learn More
New Bitsight Integration: Turn Threat Intelligence into Validated Security
Learn More
Introducing Cymulate Vero AI for Agentic Cyber Defense Engineering
Learn More
New Case Study: How a Financial Authority Validates Cyber Resilience
Learn More

Ukraine CERT-UA: Compromised Email Address Used To Deliver Malware Variants

February 2, 2023

An adversary was discovered using a compromised e-mail address to send phishing emails with a malicious PDF attachment. The files used in the attack were protected by VMProtect to hinder analysis. Successful intrusions resulted in systems infected with variants from the RomCom, FateGrab, and StealDeal malware families.