Comodo AEP via Dragon Platform
While the tools discussed in the previous sections provide useful resources for red-teaming and testing your systems, there are also tools that can be used to stop a real attack when it happens. One such tool is Comodo Advanced Endpoint Protection’s Dragon Platform, which brings together an approach to block hackers at each phase of the kill chain.
Comodo has a default deny technology that is particularly useful for thwarting attacks as they are happening as it prevents any unknown files from creating a socket for network communication. It is only after their File Verdict System determines that a file is safe that it is allowed to create sockets and communicate with the network. This eliminates the need for decoding the protocols, identifying non-standard port usage, and protocol tunneling as files are unable to communicate until it is confirmed that they are definitely safe.
This makes Comodo unique as creating a C&C channel is not...