Cybercrime driven by malware is projected to cost $6 trillion globally by 2021, and the threat landscape has expanded from fewer than 2,000 known threats in the early 1990s to hundreds of millions today. Malware now spans many categories—ransomware, botnets, fileless attacks, crypto-miners, and multi-stage toolchains—often combining credential theft, privilege escalation, and stealth techniques such as hiding code in “code caves.” Volume and complexity are rising simultaneously, with hundreds of thousands of new variants detected daily and examples like NotPetya demonstrating multiple propagation methods. NotPetya also illustrates a shift toward destructive “wiper” attacks and a broader trend of state-sponsored campaigns that can be more damaging than profit-motivated crime and may achieve very high penetration due to heavy investment.
Attack channels have widened from email to social media, compromised websites, and compromised applications (including browsers and plugins). Fileless techniques and use of legitimate tools such as PowerShell undermine signature-based defenses, making layered security essential—especially capabilities to detect and respond when prevention fails. This has accelerated adoption of Endpoint Detection and Response (EDR) and the newer Network Detection and Response (NDR), which monitors network behaviors, supports forensics, and can automate mitigation while centrally logging activity.
Vectra’s Cognito NDR platform applies AI (supervised/unsupervised ML and deep learning) and behavioral analytics to detect malicious activity across data centers, cloud, mobile, IoT, and OT/SCADA environments. It integrates with common security ecosystems (SIEM, firewalls, NAC, endpoint tools) and supports three options: Stream (enriched metadata to SIEM/data lakes in Zeek format), Recall (cloud-based historical metadata search for investigations), and Detect (real-time adversary detection). Strengths include behavior-focused detection, prioritization via severity/certainty scoring, and usability features that reduce repeated false alerts. Challenges include two-week default metadata retention, lack of decryption/sandboxing, and limited built-in MFA (RADIUS today).
See All Locations
See All Locations