This page was machine-translated and may differ from the original. View original

Maestro Forensics Unveils 'Maestro Wisdom' with Enhanced DFIR

Google 우선 소스Published2026.02.10 09:57

Focus on precision, forensic-based responses amid the spread of ransomware, LotL, and fileless attacks.


As cyberattacks, including ransomware, become increasingly sophisticated, incident response capabilities that extend beyond simple detection to encompass root cause identification and response are emerging as critical challenges. In particular, attack techniques exploiting legitimate system tools are proliferating, and concerns are mounting that existing security solutions alone are unable to grasp the full attack flow.

On February 10th in Seoul, Maestro Forensics announced that it has significantly strengthened the breach incident response (DFIR) function of ‘MAESTRO WISDOM,’ an AI-based automated digital forensics and malware analysis integrated platform.

Recently, the Qilin ransomware, LotL (Living off the Land), fileless attacks, and EDR bypass/disable attacks have been rapidly increasing. These attacks are carried out by preemptively disabling security solutions or exploiting basic operating system functions, making existing EDR-centric response systems limited in analyzing breach paths and behaviors.

To address these environmental changes, Maestro Wisdom has strengthened its precision analysis based on digital forensics. Supporting Windows, macOS, Linux, mobile, and cloud environments, it is designed to analyze and correlate over 1,000 digital artifacts to identify attack flows and behavioral chains. Furthermore, its "forensic accelerator" technology improves evidence identification and analysis speed by more than five times compared to previous versions.

Specifically, for LotL and fileless attacks exploiting native Windows tools, the solution comprehensively analyzes memory, processes, registry, event logs, and network evidence to automatically visualize attack tools and execution flow. It can also identify attack traces that bypass, delete, or disable EDR, enabling tracking of later stages undetected by existing security solutions.

According to Maestro Forensics, Client A implemented the platform to respond to a Killin ransomware breach. The platform enabled the initial analysis of a 2TB storage device within four hours, and the identification and blocking of the intrusion path was completed within three days. This demonstrated a significant reduction in the time required for complex analysis, which typically takes one to two weeks.

The platform integrates on-site investigation, remote incident response, and mobile analytics capabilities into a single system and integrates with a threat intelligence platform. This enables comparison of similar attacks, analysis of behavioral patterns, and API integration with external security solutions.

CEO Kim Jong-kwang stated that accurate cause analysis and rapid action are key in responding to recent security breaches, and that the company is enhancing its platform by combining forensic-based analysis and automation to complement the existing EDR system.
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.
배종인 기자
배종인 기자