Skip to main content

BYOVD Attacks and the Evolving Ransomware Landscape with Jon Miller of Halcyon

N2K NetworksJune 3, 202519 min320 views
24 connections·40 entities in this video

Halcyon's Anti-Ransomware Focus

  • 🎯 Halcyon is positioned as the first company solely focused on anti-ransomware, addressing the perceived generalization in cybersecurity.
  • 💡 The strategy is to build tailored obstacles for ransomware groups by dissecting their specific techniques and tools, rather than trying to defend against all possible threats.
  • 🔑 Key areas of focus include preventing data exfiltration, blocking lateral movement, and ensuring rapid data recovery to minimize the impact of an attack.

Ransomware as a Business

  • 📈 Ransomware groups operate like businesses focused on Return on Investment (ROI), making them susceptible to business-oriented obstacles.
  • ⚠️ By increasing the effort and reducing the gains for attackers, they can be discouraged from continuing an attack, leading them to abandon their efforts.
  • 🚀 The sophistication of ransomware attackers is rapidly increasing, moving beyond simple "low-hanging fruit" targets to complex enterprise environments.

Evolving Ransomware Tactics

  • 📊 The trend is shifting towards double and triple extortion methods, where data exfiltration and leakage are used to pressure victims, with potential for AI to analyze and monetize stolen data.
  • 🔒 Bring Your Own Vulnerable Driver (BYOVD) attacks are a prevalent method for disabling Endpoint Detection and Response (EDR) systems by exploiting signed, but vulnerable, legacy Windows drivers.
  • 🛡️ BYOVD attacks allow attackers to gain kernel privileges, disable security software, and proceed with their objectives, posing a significant challenge to traditional defenses.

Halcyon's Defense and Recovery Approach

  • 💡 Halcyon employs a pre-execution engine using machine learning trained specifically on ransomware, and a behavioral engine that monitors for data exfiltration, EDR attacks, backup tampering, and encryption.
  • 🔑 A unique feature is the capture and tokenization of encryption keys, which can be used for decryption if ransomware is detected and stopped.
  • 🛠️ The Rise team provides 24/7 SOC services to evict attackers in real-time, followed by rapid endpoint recovery and decryption, aiming for resilience within minutes.

The Future of Ransomware

  • 📉 The barrier to entry for ransomware attacks is extremely low, making it accessible even to individuals with basic IT skills.
  • 🌍 Attacks are increasingly originating from countries with lax cybercrime laws, and the targeting of critical infrastructure is a growing concern.
  • ⚠️ The combination of ease of access, potential for high financial gain, and low risk of apprehension suggests a challenging future for cybersecurity.

Innovation and Hope

  • ✨ Despite the grim outlook, innovation in cybersecurity offers hope, with new companies developing novel solutions.
  • 🚀 Emerging areas like AI in security, IoT security, and specialized EDR protection are seen as crucial for combating future threats.
Knowledge graph40 entities · 24 connections

How they connect

An interactive map of every person, idea, and reference from this conversation. Hover to trace connections, click to explore.

Hover · drag to explore
40 entities
Chapters9 moments

Key Moments

Transcript72 segments

Full Transcript

Topics14 themes

What’s Discussed

RansomwareBYOVD AttacksEndpoint Detection and Response (EDR)CybersecurityHalcyonRansomware GroupsData ExfiltrationTriple ExtortionAI in CybersecurityKernel PrivilegesMachine LearningBehavioral AnalysisCritical InfrastructureCybercrime Laws
Smart Objects40 · 24 links
Companies· 7
Concepts· 26
Events· 3
Products· 2
People· 2