
Protecting a large Active Directory Estate against ransomware attacks.
Sophisticated AD ransomware protection that is extensible to the rest of the enterprise.
Broad EDR solutions can’t detect ransomware in AD environments and their ransomware detection in broader enterprise applications isn’t fast enough to protect the enterprise once an attacker moves through AD and targets other critical applications.
So, like many Fortune 500s, REI needed ransomware-specific protection and maintenance of their on-prem AD infrastructure with clear goals:
Mimic’s solution protects REI’s AD estate from ransomware and alerts them to unauthorized changes to their environment that may signal a ransomware attack.
Mimic’s ability to deploy extremely quickly with minimal impact on the REI security team utilized two new technologies:
In collaboration with REI, Mimic can deploy its capability to all REI critical servers at no cost. In this mode, Mimic’s technology just silently watches for an attack, but if a threat actor launches ransomware and tries to encrypt or exfiltrate REI critical data, Mimic can instantly protect the application being attacked. And REI pays only if or when that protection goes live.
Mimic’s Arena technology allowed REI to safely detonate real ransomware strains in an identical mirror of their environment without exposing their network to risk. This provided a unique level of insight, including:
The Mimic delivery team partnered with REI cybersecurity specialists not only in the deployment of the Mimic solution on REI’s critical assets, but all internal testing was done by the REI security team itself, giving them the unique ability to:
1: Mimic immediately was able to warn REI about unauthorized changes going on in their AD environment.
2: REI will be protected on all critical applications but does not have to take the budget expense upfront.
3: Faster, smarter response times with zero excess alert noise to REI’s SOC.
