Crypto-Ransomware Cybersecurity Monitoring and Protection ServicesProgent's Active Security Monitoring services include machine learning technology by SentinelOne to offer best-in-class defense for endpoints and servers. This modern approach to malware defense addresses the latest generation of cyber attacks, such as ransomware, which routinely avoid detection by traditional signature-based anti-virus technology. Progent is a SentinelOne Partner, dealer, and integrator.

Progent's Active Security Monitoring gives small and mid-sized businesses the benefits of the same anti-virus tools implemented by some of the world's biggest corporations such as Walmart, Visa, and Salesforce. By providing real-time malware blocking, classification, mitigation, repair and forensics in a single integrated platform, Progent's Active Security Monitoring reduces total cost of ownership, streamlines management, and promotes rapid operational continuity. The next-generation endpoint protection engine built into in ProSight ASM was listed by Gartner Group as the "most visionary Endpoint Protection Platform (EPP)."

Progent's ProSight ASM services rely on a low-profile agent running on each enrolled device in order to form an active security grid that reacts to suspected attacks in real time and orchestrates cohesive protection that includes:

  • Instant protection for Microsoft Windows, Mac, Linux, iOS and Google Android machines
  • Support for VMs powered by Windows Hyper-V, VMware vSphere, and Citrix virtualization platforms
  • In-depth OS-level monitoring
  • Signature-independent heuristics and automation
  • Modern behavioral analysis
  • Ability to spot new generation threats from all vectors
  • Automated post-attack remediation
  • Easy rollback to most recent safe state following a ransomware attack including Ryuk, Maze, Sodinokibi, DopplePaymer, Conti or Nephilim
  • Instant no-touch inoculation across the complete matrix of protected machines
  • Real-time display of an assault's path through your system
  • Comprehensive forensics for recognizing vulnerabilities
  • Unified web-accessible management console
  • Compliant with HIPAA and PCI
Progent's ASM is available as an affordable monthly remote service, requires no extra equipment, and protects onsite, remote, at-home, mobile, and cloud devices. If you experience a cyber break-in, Progent offers the support of CISSP-certified data security consultants to serve as your red team to assist you to utilize Progent's ASM's powerful utilities to contain the attack, remove the malicious software from all affected machines, evaluate the damage, rollback your network to the last known working state, and determine the source of the attack and its storyline across your system.

ProSight Active Security Monitoring and Today's Threat Environment
The vast majority of ransomware break-ins could have been prevented by current cybersecurity tools. But inevitably, some assaults will break through the best protective measures. The modern security environment is too crowded with relentless bad actors, including government-funded cyber criminals, for any enterprise to be impregnable. Given this reality, Progent's ProSight ASM is intended not simply to prevent malware from breaching your network, but also to respond decisively to any detected penetration. This includes instant isolation of infected machines, AI-based threat cleanup, machine-speed inoculation of all machines via embedded agent software, one-click restore to a safe and extensive forensics to show you how to bolster your security defense to foil future attacks. By providing leading-edge protection during all facets of a malware assault, ProSight Active Security Monitoring offers an end-to-end solution for surviving the increasingly dangerous cybersecurity landscape and escaping the economic and public image loss attendant on a major cybersecurity breach.

Endpoints like PCs, laptops and smartphones are the most susceptible and most commonly targeted elements of an information system. Progent's ProSight ASM services provide a unified endpoint protection (EPP) platform to handle the complete lifecycle of a malicious assault including filtering, identification, containment, cleanup and analytics. Malware attacks recognized by Progent's ASM include:

  • File-dependent attacks such as ransomware, trojans, and payload-based assaults
  • File-less and memory-based attacks with no disk-resident indicators
  • Document-carried attacks embedded within malicious macros and Microsoft Office and Adobe files
  • Phishing email-based attacks which are responsible for a large portion of security break-ins
  • Web browser-based assaults embedded in inadvertent downloads, Flash, JavaScript, VBScript, html5, and plug-ins
  • Real-time assaults based on scripts like PowerShell, WMI, and VBScript
  • Credential-oriented assaults including credential-scraping, mimikatz and tokens
Progent's ProSight Active Security Monitoring's Behavior-based Malware Detection
Traditional anti-virus software tools rely on signature recognition as their fundamental means of detecting malware. With this technology, a distinct file hash, called a signature, is generated for every familiar attack. AV software continually compares incoming data against ever-growing signature databases, and stops code with a tell-tale signature. The shortcoming with this strategy is that zero-day malware attacks are currently being generated much faster than AV centers can identify and distribute incriminating digital signatures.

Modern AV platforms reinforce conventional signature-based detection with behavior analysis. This approach examines the actions of a possible attack and decides if the activity is normal and safe or unusual and possibly threatening. For example, does the code under observation affect an unusually large number of processes? Does it alter the registry? Does it copy keystrokes? Essentially, behavior monitoring concentrates on potentially dangerous activities instead of on a fixed digital signature, which an adversary can quickly nullify just by changing a few inconsequential bytes of malware code.

Prevention: Before the Breach
New threats are being created quickly enough to overwhelm the ability of signature-based AV software vendors. The market began to recognize the limitations of signature-matching endpoint protection around 2012. Since then the situation has become more serious.

Progent's <i>ProSight Active Security Monitoring</i>

Malware generation has increased faster than signature-based anti-virus technology can keep up

Progent's ASM utilizes intelligent cloud-based AV centers and reputation services from leading vendors to block recognized threats. This added to deep file analysis and shared blacklisting and whitelisting give Progent's ASM an advantage over old-school anti-virus solutions. Still, prevention is only the first line of modern AV defense. Modern attacks, file-less and script-based assaults easily slip by signature-matching systems. As an example, threat actors often employ a so-called packing technique to camouflage malware code so security labs and AV software can't recognize the attack.

Recognition and Reaction: During the Assault
The next part of the endpoint protection process involves responding to a cyber attack while the malware code is executing after a break-in. Progent's Active Security Monitoring utilizes next-generation endpoint protection technology to detect malware activity caused by any attack that penetrates the initial line of defense. In order to compromise information, even file-less attacks like memory-resident assaults carry out recognizable actions such as making an executable file without authorization. Progent's Active Security Monitoring's compact embedded software agent monitors activity in each enrolled endpoint and uses modern behavioral threat analysis and full execution background to recognize new attacks as soon as they start. After an attack is identified, Progent's ProSight Active Security Monitoring immediately quarantines the affected endpoint device from the network to contain the damage. Because the ProSight ASM software agent operates independently, endpoint devices stay protectedd even when they are not connected to the Internet.

Cleanup: After a Break-in
After isolating a malware attack, ProSight ASM starts the cleanup process. When ProSight ASM is implemented with Windows Volume Shadow Copy Service, modifications to data caused by a malware assault can be quickly returned to a safe condition with a single click. Progent's ASM also logs any system-level files and settings that were modified by the attack and what files were fixed. When Progent's ASM uncovers a recent malicious binary, the code is tagged and all devices on the grid that are secured by agents are immunized against the latest attack. Also, the ProSight ASM management tool offers comprehensive forensics such as an intuitive display of the assault's progress across the targeted network from beginning to end. This history of how an assault travelled through the network helps you to evaluate the damage and brings to light gaps in security policies or processes that need to be corrected to prevent future breaches.

Ransomware Forensics Consulting

Progent's ASM's management tool delivers a real-time visualization of an attack's path within the network

Download the ProSight Active Security Monitoring Datasheet
To download or read a PDF datasheet describing the key features of Progent's ProSight Active Security Monitoring services, click:
Progent's ProSight Active Security Monitoring Ransomware Protection Services Datasheet. (PDF - 89 KB)

Contact Progent about ProSight Active Security Monitoring Services
To find out more information about how Progent can assist you create an economical and efficient ransomware protection system with Progent's ASM service, call 1-800-462-8800 or visit Contact Progent.



An index of content::



  • © 2002-2026 Progent Corporation. All rights reserved.