Avanpost SmartPAM Adds 60 MITRE ATT&CK Signatures for Privileged Session Threat Detection
Avanpost has expanded its SmartPAM solution with a new library of 60 signatures aligned to the MITRE ATT&CK matrix. The update, available in version 1.4, enables the Privileged Access Management platform to inspect activities inside privileged sessions instead of limiting itself to access control at the entry point.
The signatures address key stages of attacker behavior after initial compromise, including credential access, persistence mechanisms, lateral movement, and defense evasion techniques. Specific examples include attempts to disable operating system auditing, antivirus software, or firewalls, as well as clearing system logs or obfuscating executed commands.
Session data is processed by an integrated signature analysis engine that normalizes events, correlates them with known attack patterns, and initiates predefined responses. Available actions include blocking individual commands, terminating user sessions, or forwarding alerts to a SIEM platform.
Organizations can extend the supplied rule set with their own custom signatures and tailor detection policies to the specifics of their infrastructure and security requirements. The signature library is distributed via subscription, with free access guaranteed by Avanpost through the end of 2026 and regular updates promised thereafter.
According to the vendor, SmartPAM is the first PAM product to deliver a detection library structured according to the MITRE ATT&CK framework. The enhancement transforms the solution from a simple gateway for privileged accounts into a continuous monitoring system that evaluates every action performed after authentication, addressing the reality that stolen or misused administrator credentials often appear legitimate to basic access controls.
Related articles
Where to Find Scientific Articles and Full Texts in 2026: Russian and International Databases Guide
Finding complete scientific papers often requires navigating multiple platforms because search engines show only titles and abstracts while publishers may demand payment for PDFs. The guide explains the differences between bibliographic databases that help locate publications and full-text repositories that provide actual documents. It covers Russian resources such as CyberLeninka, eLIBRARY.RU with RINC, Math-Net.Ru, and the national platform of scientific journals, along with international tools including Google Scholar, PubMed, arXiv, ACM Digital Library, IEEE Xplore, Scopus, and Web of Science. Additional sections address book catalogs, archives, AI-powered search tools like Consensus, and scientific social networks such as ResearchGate. The material emphasizes that presence in any database does not guarantee quality or validity, urging readers to verify methods, results, and publication status independently. Practical advice is given on locating open-access versions, using library subscriptions, and contacting authors directly.
WAF Connected — What Next? How to Configure Web Application Firewalls for Real Protection Without Disruption
After successful pilot testing, organizations often struggle when scaling WAF protection across dozens or hundreds of applications. Each app brings unique technology stacks, traffic patterns, and legitimate anomalies that can break existing rules. The article stresses starting in monitoring mode rather than blocking to avoid false positives that frustrate users and damage business operations. A structured Risk Score and Priority Score system helps teams prioritize applications based on exposure, business impact, control weaknesses, technical risks, and data sensitivity. Regular tuning, log analysis, and quarterly re-evaluation of the application registry are required because applications evolve constantly. Well-configured WAF solutions must deliver low false-positive rates, rapid exception handling, and resilience under peak loads without creating new operational burdens for security teams.
Positive Technologies Discontinues Active Development of PT AF 3, Shifts Focus to PT AF PRO and PT Cloud AF
Positive Technologies is halting active development of its PT Application Firewall 3 product and redirecting resources toward PT AF PRO and the cloud-based PT Cloud AF. Existing customers of the legacy WAF will continue to receive technical support, though no significant new capabilities are expected. The company cites the dramatic expansion of modern web infrastructure, which now spans hundreds of applications, APIs, and microservices across data centers, clouds, branches, and subsidiaries. Positive Technologies notes that exploitation of internet-facing web application vulnerabilities remains the leading initial access vector, accounting for 36 percent of successful corporate network intrusions. PT AF PRO, developed from the ground up over more than six years, is positioned as the new flagship solution for large-scale, distributed environments. The cloud offering PT Cloud AF provides a hardware-free alternative that organizations can manage themselves or fully outsource to partners. Client adoption of PT AF PRO has doubled over the past year.
StormWall Releases StormWall Appliance for On-Premises DDoS Protection
StormWall has introduced StormWall Appliance, a software solution that filters DDoS attacks inside the customer's own infrastructure rather than routing traffic to an external cloud. The product is aimed primarily at banks, hosting providers, internet service providers, and organizations with strict requirements for infrastructure availability and data control. It supports fully isolated networks through offline licensing with a hardware key and can operate independently or in a hybrid mode with StormWall's cloud platform. The appliance handles attacks at OSI layers L3 through L5, including volumetric floods, TCP stack attacks, reflection and amplification schemes, DNS attacks, and gaming protocols. It also processes TLS and QUIC traffic without decryption using DPDK and proprietary algorithms. Deployment takes as little as one day, with a 30-day free trial available after installation.