AC-Hunter

AC-HunterNetwork Threat Detection Software

AC-Hunter is designed to help security teams quickly identify command-and-control (C2) and other suspicious network behaviors using focused analytics and intuitive dashboards.

 

The AC-Hunter Dashboard above displays the results of its continuous automated hourly threat hunt to identify compromised systems sorted by threat severity. The Dashboard is designed to quickly provide an analyst with the information needed to make an initial decision to prioritize further connection investigations and provide an effective synopsis of the overall health of the network.

Our Core Focus Is Identifying Compromised Systems calling home to their Command and Control servers

We Have Streamlined and Automated the Techniques used by the best pentesters and threat hunters in the industry

Equally Monitor All Network Communications that arrive and depart your network

Advanced Automated Threat Hunting increases your security teams’ success and productivity

We Have Been Awarded 24 Patents for our software formulas and algorithms

  • AC-Hunter can quickly analyze millions of connection requests and identify which systems or IoT devices have been compromised.
  • AC-Hunter continuously threat hunts the previous 24-hours of your network traffic and updates once per hour.
  • AC-Hunter utilizes patented and innovative beacon detection and connection behavior algorithms.
  • AC-Hunter inspects encrypted sessions while maintaining data privacy and integrity.

 

  • No Agents to Install – AC-Hunter identifies compromised hosts on your network regardless of the operating system, hardware, or type.
  • Simple-to-use Graphical User Interface – Designed for everyone from junior analysts to seasoned professionals.
  • Cyber Deception – Lets you plant deception tokens (fake files and user accounts) across your environment and alert when triggered.
  • Safelisting – Safelist communications by source, destination, pairs, single IP address, class A, B or C range, FQDN, Org Name, or ASN.
  • SIEM Alerting – AC-Hunter can notify you of threats via the Syslog protocol to the SIEM of your choice, or a centralized logging server.

 

  • Open Site License – Deploy as many copies of AC-Hunter as you need within your organization’s locations.
  • No Proprietary or Unique Hardware Needed – AC-Hunter installs and operates on a Linux-based server you control (metal or virtual).
  • No Bandwidth Restrictions – Use AC-Hunter to analyze as much network traffic as you wish.

The AC-Hunter connection details screen can be viewed for any connection pair to drill into the details for a deeper investigation, such as the number of connections made, timing and persistency of connections, the amount of data and dispersion, port usage, HTTP & HTTPS header information, User Agent strings, external investigation menus and more.