enSilo, a new take on Exfiltration Prevention by Dylan Chatterjee
August 2015 – enSilo is an information security company that focuses solely on exfiltration prevention. They operate under the assumption that your system already is or will be infiltrated and they prevent the attacker from being able to steal any information once they’re inside. Some enterprises get thousands or even tens of thousands of notifications about possible security breaches that must then be gone through to determine what is and isn’t a true threat. enSilo’s real-time exfiltration prevention platform monitors communications and differentiates between legitimate connections and malicious ones. It also only generates a single notification per threat and virtually patches against targeted attacks so an employee can keep working even if they’re infected without risking infecting your whole enterprise. Their approach is unique in that it operates on a whitelist of safe files as opposed to a blacklist of known threats. When something outside of that whitelist is detected it is quarantined and stopped from being able to access any sensitive information until forensics and root cause analysis can be completed.
enSilo Exfiltration Infographic
enSilo’s research revealed that in order for malware to remain hidden it had to alter certain key files in an operating system, enSilo knows what the unaltered files look like and how they behave so any attempt to change them gets flagged and allows them to analyze the communication patterns to determine if it is a malicious attack on the system. This process is done in a deterministic way so that malicious threats can be blocked in real-time without also interrupting legitimate communications on the system.
Once an exfiltration attempt is triggered, enSilo also begins collecting information so a team can create a forensic analysis of the nature and origin of the attack. They describe the threat’s footprint in the system, the potential ramifications of that threat to the enterprise, along with actionable recommendations including pointing to the evidence trail of the exfiltration attempt.
Normally an investigation into a system compromise takes certain programs or communication options out of commission for days or even weeks until the compromise is resolved. enSilo circumvents this need with its virtual patching by only blocking the malicious communication and allowing operations to proceed as normal, in the rest of the system, while the compromise is investigated.
Ransomware is also rendered ineffective by enSilo’s Central Management by denying the malicious threat from being able to modify any files once it is installed so the ransomware won’t be able to lock a device or encrypt sensitive information like it normally would. enSilo was effective in preventing popular ransomwares such as CryptoWall 3.0, CryptoLocker, and TeslaCrypt. By blocking these malicious access attempts, users to continue working as usual while a response team removes the malicious infection.
Due to how enSilo’s software works by gathering OS metadata and analyzing it to determine threats, it uses virtually no CPU usage or memory. It also requires minimal added bandwidth because only connection establishment related data is sent for processing.


