Email to schedule an appointment: contact@abatis.ch
How Abatis Prevents Cyber Attacks
Cyber-attacks may begin in many different ways, including phishing emails, stolen credentials, compromised maintenance laptops, supply chain attacks or remote access. Although the initial point of entry varies, almost every successful attack ultimately depends upon one common requirement:
Unauthorised software must execute on the protected device.
Abatis implements Deterministic eXecution Integrity (DXI) by authorising software before it executes, rather than attempting to detect malicious behaviour afterwards. If software is authorised, execution proceeds normally. If it is not authorised, execution is prevented before Windows completes the request.
Cyber attackers continually develop new methods to gain access to systems. These may include phishing, credential theft, trusted maintenance laptops, supply chain compromise or remote access. Although the attack vectors continually evolve, the attack itself ultimately depends upon one critical event: Unauthorised software must execute.
Traditional cybersecurity attempts to determine whether that software appears malicious using signatures, heuristics, behavioural analysis or artificial intelligence. DXI takes a fundamentally different approach.
Instead of asking:
"Does this software look malicious?"
DXI asks a much simpler question:
"Is this software authorised to execute?"
If the answer is No, execution is denied before the operating system completes the request.
Without unauthorised execution, ransomware cannot encrypt files, malware cannot establish persistence, attackers cannot move laterally and data theft tools cannot operate.
Abatis operates as a native Windows Ring 0 File System Filter Driver, loading during the operating system boot process before users or applications begin execution.
Every executable write and execution request passes through the Windows Kernel I/O Manager. Before Windows permits the operation, Abatis evaluates the request against a deterministic execution policy.
This policy validates whether the executable is authorised according to organisational policy.
If authorised, Windows completes the operation normally.
If not authorised, the request is denied before execution occurs.
Unlike traditional endpoint protection products, this decision does not depend upon malware signatures, behavioural analysis, cloud lookups or artificial intelligence.
The decision is deterministic, consistent and immediate.
Abatis implements Deterministic eXecution Integrity through four simple but highly effective operating principles.
Freeze Executable Storage
Abatis prevents unauthorised executable files from being written to protected storage. If malicious software cannot establish itself on the device, it cannot execute or persist.
Control Where Software Executes
Only software residing in authorised storage locations may execute. Attempts to execute software from removable media, network shares or unauthorised locations are denied.
Prevent Fileless Attacks
Modern attacks increasingly abuse trusted operating system tools using techniques known as Living off the Land (LotL). Abatis prevents execution of unauthorised interpreters and LotL binaries, disrupting fileless attack techniques before they become operational.
Protect the Protection
Abatis includes anti tamper capabilities that prevent attackers, malicious software and privileged users from disabling or bypassing the protection itself.
Traditional cybersecurity products attempt to identify malicious software after it reaches the endpoint.
DXI changes the security model entirely.
Instead of attempting to determine whether software is malicious, DXI simply determines whether it is authorised to execute.
This deterministic approach reduces complexity, removes dependence upon continuously updated threat intelligence and provides effective protection against ransomware, malware, zero day attacks, fileless attacks and many other modern attack techniques.
The result is a trusted execution environment in which only authorised software is permitted to run.
Cybersecurity has spent decades attempting to identify malicious software with increasingly sophisticated detection technologies. DXI replaces that uncertainty with deterministic policy enforcement.
Rather than attempting to determine what software might do, DXI simply determines whether it is authorised to execute.
Execution is authorised before it occurs, not detected afterwards.
See how Abatis authorises execution before software becomes operational.
Additional technical resources are available.
This site uses cookies to provide you with the best experience on our website. Please, accept cookies for optimal performance. For full details, see our Privacy Policy