Tecninf Security Smart Tool

OUR PRODUCTS – cybersecurity, BEFORE YOU NEED IT.

TssT

The TssT Tecninf Security Smart Tool was created under the growing pressure of the worldwide diffusion of the cyber attack surface, as well as the urgent need to have an Italian IT security product, completely created and developed by a team of Italian cybersecurity experts.

In addition, the TssT gives maximum capacity for action to CISOs in their daily activity of repression of cybercrime and to security analysts, by enhancing analysis skills. Furthermore, it supports SOCs (Security Operation Centers) in the daily monitoring of the cybersecurity landscape.

01

Dashboard / Agent infrastructure

Dashboard / Agent infrastructure
  • TssT is a specialised product designed to work in complete affinity with SIEM systems and to perform SOAR automation functions. It is composed of a set of vertical cybersecurity features, able to protect an infrastructure no longer passively or reactively, but actively.
  • The TssT is based on a Dashboard / Agent infrastructure system, developed using the Java Spring Boot and React frameworks; it uses an API layer and a set of open-source and paid sources to intercept global attacks.
  • The base system is a customised Debian distribution, protected by a software IPS and by a very dense mesh of ACLs on IP tables that open and close autonomously according to the configuration applied.
  • The application core resides in a customised Docker container, which gives extreme dynamism and portability: it is the heart of the TssT and is portable even on Windows systems, regardless of the base system.
  • A very low computational-impact agent allows interaction with the Dashboard, while the Linux system offers extreme versatility in enriching it with proprietary pentest and hacking tools.
02

Modular cybersecurity

Modular cybersecurity

The TssT is made up of the modules listed below, all related to each other in a perpetual and functional cycle:

  • Threat News: detects news about cyber attacks worldwide, reporting the description of the indicators of compromise (IOC), with a filter to highlight only the news detected by the TIG.
  • Threat Map: displays world attacks, indicating the progress of the cyber attack on the world map and geolocating the event path from source to destination.
  • Hack Back: the core module of TssT, it actively defends the infrastructure by counterattacking the targets detected as attackers.
  • Sandbox: runs Malware Analysis in two ways, a hybrid version using the hybrid sandbox and a manual mode making use of the intelligence team analysis.
  • Rogue Device: intercepts anomalous devices in the protected infrastructure, blacklisting and blocking them on perimeter firewalls and IPS probes.
  • Remote Installation: remotely installs the TssT agent directly from the agent dashboard repository, without manual intervention.
  • Vulnerability Scanner: uses the OpenVAS open source framework to scan targets for known vulnerabilities.
  • Performance Monitor: uses the open source Zabbix framework to detect the performance of the bandwidth used in the network or by individual clients.
  • Trouble Ticket: allows a support TT to be opened directly from the dashboard, automatically taken over by the Tecninf assistance technicians.