ESET, a global European leader in the cybersecurity market, announced that it has participated with the solution ESET Inspect (ex ESET Enterprise Inspector) al quarto round delle MITRE Engenuity ATT&CK® Evaluations for Enterprise in which attacks from the Wizard Spider and Sandworm threat groups were simulated, gathering results from 30 participating vendors and highlighting ESET's pioneering research on Sandworm, and, in particular, the discovery of the backdoor Exaramel.
The ATT&CK Evaluations focus on threat groups that can have a significant impact on businesses and governments around the world. Wizard Spider is a financial criminal group that has conducted ransomware campaigns since August 2018 against a substantial number of organizations, ranging from large companies to hospitals. Sandworm is a cyberespionage group known for conducting destructive attacks, such as the 2015 and 2016 outages of Ukraine's power grid and the NotPetya of 2017.
The evaluation detection scenarios consisted of 10 steps for Wizard Spider and 9 for Sandworm. Since Linux support in ESET Inspect was released after the evaluation, four of these steps related to Sandworm were not considered. ESET Inspect detected all 15 applicable steps (100%). The evaluation classified the level of support provided by the vendor's tool and for greater detail you can consult the in-depth analysis of the results at this link.
"ESET believes in taking a multi-layered, high-performance approach to the development of its detection technologies. ESET Inspect is the foundation of our Extended Detection and Response (XDR) solutions and works together with the ESET PROTECT security platform to offer a complete, easy-to-use solution," he explained Roman Kováč, ESET Chief Research Officer. "We have been monitoring Sandworm since its inception, being the first to identify the modus operandi of its BlackEnergy and TeleBots subgroups and discover the source of NotPetya's spread. For us, it is critical to keep pace with our telemetry and test our solutions through the expert lens of the MITER Engenuity team."
"This latest round indicates significant product growth from the vendors participating in the survey. We are seeing an increased emphasis on threat-informed defense capabilities, which in turn has increased the focus of the infosec community on the priority of the ATT&CK Framework," he commented Ashwin Radhakrishnan, General Manager Ad Interim Di Att&ck Evaluations presso Mitre Engenuity.
The ATT&CK Evaluations demonstrate that ESET Inspect it can provide security professionals with excellent visibility and context at all stages of the attack. As an XDR solution, ESET Inspect is a sophisticated tool with advanced threat management and incident response capabilities, and together with ESET PROTECT offers deep network visibility, cloud-based threat defenses and more. ESET and together with ESET PROTECT it offers deep network visibility top player and industry leader for its business solutions.
Read more about ESET's results in the ATT&CK Evaluations, in and together with ESET PROTECT it offers deep network visibility and together with ESET PROTECT it offers deep network visibility and together with ESET PROTECT it offers deep network visibility.






