Ransomware Cybersecurity Monitoring and Defense ConsultingProgent's ProSight Active Security Monitoring services feature behavior analysis and AI heuristics by SentinelOne to provide state-of-the-art defense for all endpoints as well as virtual and physical servers. This modern approach to malware protection is designed to meet the new wave of cyber threats, like crypto-ransomware, which routinely avoid filtering by traditional signature-based anti-virus (AV) technology. Progent is a SentinelOne Partner, reseller, and integrator.

Progent's ProSight Active Security Monitoring offers small and mid-sized businesses the advantages of the identical anti-virus technology used by many of the world's biggest enterprises such as Netflix, Visa, and Salesforce. By providing in-line malware filtering, classification, mitigation, restoration and analysis in a single integrated platform, Progent's ProSight Active Security Monitoring cuts TCO, simplifies administration, and promotes rapid recovery. The next-generation endpoint protection (NGEP) built into in Progent's ProSight Active Security Monitoring was ranked by Gartner Group as the "most visionary Endpoint Protection Platform (EPP)."

ProSight ASM online services rely on a low-profile software agent running on each enrolled endpoint and server to create a dynamic security grid that reacts to suspected malware instantly and orchestrates unified protection that includes:

  • Instant protection for Microsoft Windows, macOS, Linux, iOS and Android machines
  • Support for virtual machines powered by Hyper-V, VMware vSphere, and Citrix virtualization platforms
  • Deep OS-level monitoring
  • Signature-independent heuristics and extensive automation
  • Cutting-edge behavioral analysis
  • Ability to spot new generation attacks from all vectors
  • Automated post-attack containment
  • Single-click rollback to most recent safe state after a crypto-ransomware attack including Ryuk, Maze, Sodinokibi, Netwalker, LockBit or Nephilim
  • Immediate and automatic vaccination across the entire matrix of protected machines
  • Immediate visualization of an attack's path through your network
  • Extensive forensics for recognizing vulnerabilities
  • Unified web-accessible management tool
  • Compliant with HIPAA and PCI regulations
Progent's ProSight ASM is provided as an affordable monthly remote service, calls for no extra hardware, and protects local, online, telecommuter, mobile, and cloud devices. If you are a victim of a malware break-in, Progent can provide the services of CISSP-certified cybersecurity experts to serve as your fast-response team to help you to use Progent's ASM's smart tools to mitigate the intrusion, delete the malware from all affected devices, evaluate the impact, restore your network to the last known healthy condition, and document the source of the attack and its progress within your system.

ProSight Active Security Monitoring and the Current Threat Environment
Most ransomware breaches could have been prevented by modern cybersecurity utilities. But inevitably, some attacks will succeed despite the best protective measures. Today's cybersecurity environment is too filled with tireless extortionists, including government-funded adversaries, for any organization to be entirely safe. With this in mind, Progent's ProSight ASM is designed not simply to prevent ransomware from establishing a foothold on your network, but also to react decisively to any breach. This entails immediate quarantine of compromised machines, AI-based threat removal, fast immunization of all machines by means of local agents, one-click restore to a safe state and comprehensive forensic analysis to help you understand how to enhance your security profile to foil future attacks. By delivering advanced protection during all phases of a cyber attack, Progent's ProSight Active Security Monitoring offers a comprehensive solution for surviving the increasingly dangerous security environment and avoiding the financial and reputation loss associated with a serious security breach.

Endpoint devices like desktops, laptops and phones are the most vulnerable and most typically attacked components of a network. Progent's ProSight Active Security Monitoring services offer a unified endpoint protection (EPP) platform to handle the full lifecycle of a cyber assault including blocking, identification, containment, cleanup and analytics. Malware attacks recognized by Progent's Active Security Monitoring include:

  • File-dependent attacks such as crypto-ransomware, trojans, and payload-based assaults
  • File-less and memory-based attacks with no disk-resident flags
  • Document-carried attacks incorporated within malicious macros and Office and Adobe files
  • Phishing and spear phishing email attacks which are responsible for a high percentage of security break-ins
  • Web browser-based attacks incorporated in inadvertent downloads, Java, JavaScript, VBS, html5, and malicious plug-ins
  • Live attacks from scripts such as PowerShell, WMI, and VBS
  • Credential-oriented attacks like credential-scraping, and mimikatz
Progent's ASM's Behavior-Analysis Malware Detection
Older-generation anti-virus (AV) software tools use signature matching as their main means of blocking malware attacks. With this technique, a distinct file hash, called a signature, is calculated for every known threat. Anti-virus detection software constantly compares traffic against always-growing signature databases, and stops anything that has a tell-tale digital signature. The problem with this strategy is that new threats are now being developed much faster than anti-virus centers can identify and distribute suspicious signatures.

Modern anti-virus tools supplement conventional signature-based detection with behavior analysis. This technique tracks the activity of a potential attack and decides if the activity is normal and safe or abnormal and potentially threatening. For example, does the code in question impact an unusually large set of processes? Does it alter the registry? Does it save keystrokes? Basically, behavior monitoring concentrates on suspicious actions rather than on a pre-calculated digital signature, which a threat actor can quickly get around simply by changing a few inconsequential bytes of malware code.

Prevention: Before the Break-in
Zero-day threats are being created fast enough to overwhelm the ability of signature-based anti-virus labs. The market began to recognize the limitations of signature-matching EPP about a decade ago. Since then the situation has become more serious.

Progent's <i>ProSight Active Security Monitoring</i>

Threat generation has expanded more rapidly than signature-matching AV technology can respond

Progent's ASM uses modern cloud-based anti-virus centers and whitelisting/blacklisting services from leading providers to block recognized malware attacks. This added to deep file inspection and shared blacklisting and whitelisting give Progent's Active Security Monitoring an advantage over old-school AV solutions. Still, prevention is only the initial phase of modern AV protection. Modern exploits, file-less and script-based malware routinely evade signature-matching defenses. As an example, hackers often employ a so-called packing technique to camouflage a malicious file's format so security labs and AV software can't recognize the threat.

Detection and Mitigation: During the Assault
The next part of the EPP lifecycle involves reacting to a cyber attack while the malware code is executing following a break-in. Progent's ASM utilizes next-generation EPP technology to detect malicious activity caused by any attack that breaks through the first line of protection. In order to modify data, even file-less attacks like memory-resident malware perform identifiable actions such as making an executable file with no permission. ProSight ASM's compact embedded software agent monitors activity in every enrolled device and uses modern behavioral threat analysis and full execution context to detect new assaults as soon as they start. When an assault is identified, Progent's ProSight Active Security Monitoring at once quarantines the affected endpoint from the network to minimize the spread. Since the Progent's ProSight ASM software agent operates independently, endpoints stay secured even if they are disconnected from the Internet.

Restoration: After a Break-in
After containing a malware attack, Progent's ASM starts the remediation process. If Progent's Active Security Monitoring is implemented with Microsoft Windows VSS, changes to data caused by a malware attack can be quickly returned to a safe condition with a single click. ProSight ASM also logs any system-level files and settings that were modified by the assault and what files were recovered. When ProSight Active Security Monitoring detects a recent malicious binary, the malware code is flagged and all machines on the system that are protected by ProSight ASM agents are vaccinated against the new assault. In addition, the Progent's ASM management tool offers extensive forensics like an informative visualization of the attack's storyline throughout the targeted network from start to finish. This history of how an assault travelled through the network helps your IT staff to assess the impact and brings to light gaps in security policies or processes that should be corrected to avoid future break-ins.

Ransomware Forensics Consultants

Progent's ProSight ASM's management console delivers a real-time visualization of a threat's path within the target system

Download the ProSight ASM Datasheet
To download or read a PDF datasheet about the major features of ProSight ASM services, click:
Progent's ASM Ransomware Protection Datasheet. (PDF - 89 KB)

Contact Progent about ProSight ASM Services
To learn more about ways Progent can help you set up an economical and effective crypto-ransomware protection system with Progent's ASM service, call 1-800-462-8800 or see Contact Progent.



An index of content::







  • © 2002-2026 Progent Corporation. All rights reserved.