How Cylance Endpoint Security uses advanced technology to protect users and devices
Cylance Endpoint Securityuses advanced technology to protect users and devices
CylancePROTECT Mobileleverage cutting-edge cloud services to determine whether software, files, and websites are potentially malicious and a threat to the security of a device. The
CylancePROTECTcloud services use sophisticated AI, machine learning, and efficient mathematical models to process large volumes of data from global sources, retain and continuously learn from the patterns and properties of that data, and use that data to make intelligent predictions and decisions about the risk potential of software, files, and Internet destinations in near-real time. The
CylancePROTECTservices constantly evolve to address new cyber threats, providing an aggressive and proactive security strategy that identifies malicious software and websites before they can have any impact on your organization's infrastructure or device users.
CylancePROTECTservices provide the threat analysis for files that are scanned by the
CylancePROTECT Desktopagent. If a file is identified as malicious, the
CylancePROTECT Desktopagent will perform any mitigation actions that you configured (for example, alert or quarantine). The agent includes a local
CylancePROTECTservice model, so if the agent cannot communicate with the cloud, the agent will use the local model to score a file.
CylanceGATEWAYprovides machine learning models (for example, Signature detection and DNS Tunneling detections) and continuous monitoring and dynamic application of IP reputation databases to monitor network traffic and identify destinations that might contain potentially malicious threats. If a destination is identified as containing potential threats,
CylanceGATEWAYwill perform any the actions that you have configured (for example, alert or block the connection to the destinations).
CylanceGATEWAYprovides two modes of operation, Work Mode and Safe Mode, to protect users' devices and your network from threats.
CylancePROTECTservices are a core component of several
CylancePROTECT Mobilefeatures, including malware detection, SMS message scanning, and secure network checks. If
CylanceGATEWAYis enabled, the
CylancePROTECT Mobileapp also uses machine learning to continuously monitor network traffic and can block a user’s access to a destination.
CylanceOPTICSagent on desktop devices sends the data that it collects to the
CylanceOPTICScloud services. The data is aggregated and stored in the secure
CylanceOPTICScloud database. The
CylanceOPTICSdata analytics services offer rich interpretations of device data that you can access in the management console.
CylanceOPTICSuses a Context Analysis Engine (CAE) to analyze and correlate events as they occur on devices. You can configure
CylanceOPTICSto take automated response actions when the CAE identifies certain artifacts of interest (for example, display a notification or log off the current user), providing an additional layer of threat detection and prevention to complement the capabilities of
CylanceGATEWAYagent on desktop devices uses machine learning and static reputation databases to identify destinations that might contain potentially malicious threats. If the agent is also enabled for and using Safe Mode,
CylanceGATEWAYwill enforce an acceptable use policy (UAP) by intercepting each DNS query to determine if connection can proceed or is blocked.
CylanceAVERTagent identifies the sensitive files on an endpoint and notifies the administrator of any attempt to exfiltrate those files through email, browser uploads, network drives, or USB devices. If a sensitive file is involved in an exfiltration event,
CylanceAVERTwill perform the mitigation action that the administrator specified in the information protection settings.
CylanceAVERTuses keyword matching and regex validation to identify the sensitive data types that trigger an exfiltration event.