Talk to a Binalyzer
Get a free trial
Business Email Compromise (BEC) remains one of the most financially damaging cyber threats, with global losses exceeding $50 billion over the past decade (FBI IC3, 2023).
Imagine receiving an email that looks like it's from your CEO, asking for an urgent transfer of funds or confidential information. You follow the instructions, only to realize later that the email was a cleverly disguised fraud.
Incident response teams face an ongoing challenge: how to respond to increasingly sophisticated cyber threats with both speed and precision. The clock starts ticking as soon as an alert is triggered, and every second counts.
Threat hunting has emerged as the ultimate approach for Security Operations Centers (SOCs) to stay ahead of cyber threats. This proactive method involves actively searching for potential threats that might evade standard security tools, ensuring that SOCs can detect and respond to threats before they cause significant damage.
The speed and precision of incident response (IR) can make all the difference between a minor security hiccup and a full-blown crisis. As organizations face increasingly sophisticated threats, traditional, manual approaches to IR are proving inadequate being; slow, expensive, and not deep enough to ultimately strengthen an organization's long-term security posture.
Binalyze is excited to announce that it has successfully achieved SOC 2 Type II compliance, adhering to the stringent standards of the American Institute of Certified Public Accountants (AICPA) for Service Organizations, also known as SSAE 18.
Cyber threat intelligence involves collecting and interpreting real-world threat activity and information about malware and cyber attacks that could lead to data, and money loss.
Cybersecurity breaches have become increasingly common in recent years, with a growing number of employees within organizations falling victim to hackers and cybercriminals. Digital Forensics and Incident Response (DFIR) experts are often called upon to investigate and mitigate the damage caused by these breaches.
Whether you are investigating an endpoint in your corporate environment or you are part of a criminal investigation, you need to investigate the USB device history of an endpoint. Knowing what USB devices were connected to the computer is the essential information and of great importance to a forensic examiner.
In the past month, we released a new version of AIR that includes the new Cases management feature that gives you the ability to manage and create new individual cases for your investigations on a completely self-service basis to increase the speed and efficiency of your investigations
Compromise assessment is an analysis of a network of endpoints or a single endpoint to uncover unknown security breaches, malware, and any sign of unauthorized access. The assessment seeks to discover any present and past attacker traces in the environment.
Microsoft patches actively exploited Exchange, Excel zero-days (CVE-2021-42321). Please refer to their site for more details.
When we plan our incident response strategies and forensic readiness steps, we strongly pay attention to digital evidence acquisition, storage, handling, reporting, and remediation.
The purpose of an investigation is never just to find the source of damage and place a quick repair. An investigation is in place to find out how it happened, document it, and fix those circumstances so they don’t occur again.
Welcome to our monthly product updates roundup! Here’s a rundown of the new features and solutions we released in the past month that you can now take advantage of.
The end goal of this step is to ensure that internal training & awareness programs take place within your organization since your employees may be involved in the process of handling security incidents.
There can be many kinds of suspicious events generated either by the system or by human watchfulness. Every suspicious event (as described in step 6) needs to be checked before launching a full formal investigation.
According to McAfee’s latest report (The Hidden Costs of Cybercrime), the cost and damage of cyber-attacks can rise significantly if not resolved in a fast manner. Therefore, just as businesses and individuals worldwide transform and adapt quickly to new technology evolutions, it’s essential to apply the same mindset to cyber incidents.
Cyber-attacks are on the rise and getting more complex every day. Because of the COVID-19 pandemic and working remotely, security analysts experience new challenges of monitoring, detecting, and responding to cyber-attacks. And current incident response approach falls short.
Binalyze AIR v1.7.50 is now available. You can update directly from your product (shown below) or download it from the product page.
Being agile in dealing with, and handling, digital evidence is of great use when an incident happens. It is helpful to have a document that will clearly state the types of digital evidence required by a court or your internal compliance department, and how to collect them.
Binalyze, the leading provider of advanced Digital Forensics and Incident Response (DFIR) solutions, today announced it has raised €1.5 million in pre-seed funding led by Earlybird Digital East Fund. The funding will be used to accelerate the company’s growth and expansion across the US and Europe.
With the release of Binalyze AIR v1.8.0, we are introducing network capture capabilities to the acquisition profiles so you can capture both Network Flow (TCP/UDP connections) and PCAP IP packet data directly within the AIR platform. This upgrade brings significant advantages by further consolidating all your digital forensics activities into one solution and collaborative platform that delivers automation to save you time, reduce your costs and increase efficiency.
This is the stable release of the previous RC version (v.1.7.45)
A couple of weeks ago, we released our new DRONE solution, which is set to transform remote digital forensics investigation by giving you the capability to quickly understand your network by acquiring and analyzing data across all endpoints in minutes.
The first innovation of Binalyze was decreasing the evidence collection time to minutes from hours, if not days. The second one was making the overall acquisition process a fully automated workflow.
Proven strategy to defend an organization from the risk of cyber attacks has for so long been proved to be prevention.
It’s 4 AM, and you’re in the midst of a blissful dream, sipping sangrias on a sun-kissed beach along the South coast. Everything is perfect until your phone erupts with a critical alert.
Since efficiency and simplicity are at the core of Binalyze solutions, in this product release we incorporated the compression and encryption feature.
Once you complete a risk assessment of all your business operations, you can proceed to the second step of the forensic readiness plan which is identifying all types and sources of digital evidence in your organization.
In the past month we released two new products to our lineup to cover all your evidence collection needs; ACQUIRE, a forever free digital evidence acquisition tool, and TACTICAL, the ultimate upgrade of IREC.
Binalyze AIR v1.7.40 is now available. You can update directly from your product (shown below) or download it from the website.
Binalyze AIR v1.8.0 RC is now available. The full production version of AIR 1.8.0 will be available on 18th August. You can update directly from your product (shown below) or download it from the website here.
Ransomware is not new but it continues to be one of the biggest challenges for every kind of organization in recent years. There were a total of 308 million ransomware attacks in 2020. This means a 62 percent increase from 2019. At the same time, ransom payments are also increasing. In the first quarter of 2021, the average of ransom payments was over $220,000.
Finalizing the first two steps of the forensic readiness plan brings you to a position where it is possible to decide which types and sources of evidence collection (Step 2) can help you in dealing with business risk situations (Step 1).
Before we dive into how to use the Webshell Detection feature in DRONE here is a quick reminder on what a web shell malicious attack is capable of.
Binalyze, the developer of the fastest and most comprehensive digital forensics solutions, has completed a rebranding effort in response to accelerated company growth. At the heart of this rebranding is customer-centricity.
The first step in achieving forensic readiness is to do a complete risk-assessment analysis of all your business operations. The main goal is to identify any potential risk and vulnerabilities in your business processes so you can understand and define where digital evidence may be required and may benefit the organization.
Covid-19 pandemic has become the most important topic in cyber security as in many other areas. The pandemic has affected people’s lives and caused significant changes in working procedures of organizations. Many organizations including public institutions activated remote working procedures hastily.
In the current cases in the DFIR world, there is a lot of confusion about which steps to take decisively and quickly at the endpoint side when something suspicious is found from the moment the investigation started, or from the moment the evidence is found.
A couple of months ago we released our new DRONE solution, which is set to transform remote digital forensics investigation by giving you the capability to quickly understand your network by acquiring and analyzing data across all endpoints in minutes.
Binalyze, the leading provider of advanced Digital Forensics and Incident Response (DFIR) solutions, today announced it has partnered with AHAD as a channel distribution partner for the GCC region (United Arab Emirates, Saudi Arabia, Qatar, Oman, Kuwait, and Bahrain).
In a collaboration with our partner OnRetrieval, we are organizing a webinar where we will showcase the main features of Binalyze AIR and how to achieve cyber resilience with its capabilities.
Throughout the digital evidence collection process all actions have to be taken in a secure manner. In the previous step we covered how to ensure that digital evidence is collected in a secure way, using appropriate tools, so the authenticity of the digital record is not compromised.
We’re excited to announce the launch of Binalyze DRONE, a transformation to remote digital forensics investigations. This innovative new approach is built for organizations that need to perform agile, efficient, and remote digital forensics investigations.
Binalyze AIR release notes Version 1.7.45 (RC)
New feature: AIR-QRadar integration. Now, an acquisition can be started by triggering AIR via QRadar (credits: Esra Kulüp)
SFTP home run. This Friday we will release the latest version of Binalyze AIR [1.7.35] which will include a number of powerful new features that will be announced individually in the run up to the launch.
The outstanding coverage of Binalyze DFIR platforms for Windows clients is now also available for Linux. This was a popular request from a large number of our users and customers so we incorporated the feature into our roadmap right away. This Friday we will officially launch it.
Binalyze AIR v1.8.0 RC is now available. The full production version of AIR 1.8.0 will be available on 18th August.
Being agile in dealing with, and handling, digital evidence is of great use when an incident happens. However, applying system monitoring in your organizational network to achieve forensic readiness shows that an organization has the initiative and ability to manage risks effectively in real-time.