Perfectly solved cloud/native east-west attack detection (lateral movement attack detection) from an industry perspective.

2. Functional characteristics

TiFlow Microprobe + TiCommander/TiDetector can perfectly solve this problem; Its functional characteristics are as follows:

Feature 1: no intrusion, no blind spot detection capability

TiFlow can quickly deploy to each workload without intrusion, and return the session data of each workload to the TiCommander in real time with refined JSON messages. The TiCommander risk detection engine TiDetector will detect attack risks in real time and form alarms and dashboards;

Feature 2: detailed contextual backtracking analysis ability

For alarms issued by any TiDetector and most alarms issued by border security products (WAF/IDS/Firewall), TiCommander can provide detailed alarm risk context content for in-depth analysis and judgment;

Feature 3: Attack Chain and Discovery of Infected Hosts

TiCommander provides a tracking topology for various attack features. Users only need to enter attack features, and the TiCommander can automatically help users sort out related attack chains. In the event of a security incident, it is very helpful to find all infected workloads in time.