Cyber risk and advisory programs that identify security gaps and build strategies to address them.
MDR that provides improved detection, 24/7 threat hunting, end-to-end coverage and most of all, complete Response.
Our team delivers the fastest response time in the industry. Threat suppression within just 4 hours of being engaged.
Be protected by the best from Day 1.
24/7 Threat Investigation and Response.
Expert hunting, research and content.
Defend brute force attacks, active intrusions and unauthorized scans.
Safeguard endpoints 24/7 by isolating and remediating threats to prevent lateral spread.
Investigation and enhanced threat detection across multi-cloud or hybrid environments.
Configuration escalations, policy and posture management.
Detects malicious insider behavior leveraging Machine Learning models.
Customer testimonials and case studies.
Stories on cyberattacks, customers, employees, and more.
Cyber incident, analyst, and thought leadership reports.
Demonstrations, seminars and presentations on cybersecurity topics.
Information and solution briefs for our services.
MITRE ATT&CK Framework, Cybersecurity Assessment, SOC Calculator & more
eSentire will be a Sponsor at the NetDeligence Cyber Risk Summit in Fort…
eSentire will be a Sponsor at the NetDeligence Cyber Risk Summit in…
eSentire is an exhibitor at RSAC 2023. Visit us at Booth 0535.
In a joint report, the FBI and CISA have disclosed recent Russian state-sponsored APT activity. An unspecified Russian APT group was observed abusing misconfigured Multi-Factor Authentication (MFA) and the PrintNightmare vulnerability (CVE-2021-34527) in a recent attack against a Non-Government Organization (NGO). The attack resulted in the theft of sensitive data.
Organizations are strongly recommended to ensure that the use of MFA is enforced and reviewed for proper implementation. Additionally, all devices impacted by PrintNightmare need to be up to date on security patches in order to prevent abuse.
The recent campaign impacted a Non-Government Organization (NGO). In the attack, initial access was gained via a bruteforce attack. The compromised account was then used to enroll a new device in the company’s MFA platform. After persistent access was achieved, the threat actors exploited the PrintNightmare vulnerability to allow for lateral movement and the eventual theft of information.
CVE-2021-34527 was disclosed in July 2021. It is a Remote Code Execution vulnerability in the Windows Print Spooler service. Initial recommendations related to PrintNightware were to ensure that Internet-facing devices were patched. As widespread exploitation has been ongoing for months and exploits have been widely adopted by multiple threat actor groups, organizations need to ensure that all devices, including internal, are up to date on relevant patches.