CQVista Unveils PacketCYBER 3.0, Claims Edge Over Global NDR Rivals

Photo Image
CQVista's PacketCYBER 3.0

CQVista is targeting the network detection and response (NDR) market with PacketCYBER 3.0, highlighting its threat detection capabilities that the company says surpass those of leading global competitors. A key strength of the platform is its ability to identify anomalous behavior and attack patterns within encrypted traffic without requiring decryption.

Speaking at a partner seminar held in Seoul on June 23, CQVista CEO Jeon Deok-jo said, “PacketCYBER 3.0 supports 14 MITRE ATT&CK tactics and 138 attack techniques, exceeding the 106 techniques supported by major global NDR products.”

He added, “Another key competitive advantage is the ability to detect sophisticated attacks through behavioral analysis without decrypting traffic, even in environments where roughly 90% of communications are encrypted.”

NDR solutions continuously analyze network traffic to identify signs of attacks and suspicious internal activity. PacketCYBER 3.0 classifies detected threats according to the MITRE ATT&CK framework, providing visibility into attackers' objectives, techniques, and stages of operation.

According to CQVista, the rise of AI-powered attack automation and increasingly encrypted or concealed cyberattacks has made traditional prevention-focused security measures insufficient. As a result, the company argues that security strategies should shift from simply blocking threats to continuously monitoring behavior and improving visibility across networks.

PacketCYBER 3.0 distinguishes between different stages of an attack, including initial compromise, lateral movement, command-and-control (C2) activity, and data exfiltration. It also correlates multiple alerts into a single attack chain, helping security teams prioritize their response efforts. CQVista said the platform supports 32 more attack techniques than major global NDR competitors, enabling broader threat coverage.

Rather than decrypting communications, the system analyzes factors such as connection frequency, transmission intervals, certificates, and communication flows between devices. This allows it to identify behavioral traces left by attackers, such as repeated communications with external servers or lateral movement within internal networks. The company positions the solution as a complement to traditional firewalls and signature-based security tools, enhancing the detection of unknown and advanced threats.

CQVista plans to expand support to 142 attack techniques in the next version and add capabilities for detecting the use of public AI services and identifying email spoofing attempts. The number of supported MITRE ATT&CK tactics will also increase from 14 to 15.

“We plan to complete upgrades aligned with the latest MITRE ATT&CK revisions by late autumn and further strengthen our detection capabilities to a global top-tier level,” Jeon said.

· This article was translated using AI and was published after final review by the reporter.