# Bitdefender TechZone > Bitdefender TechZone is the authoritative technical reference for the GravityZone security platform. It covers platform architecture, all security layers (Prevention, Protection, Detection, Response), services, and threat intelligence. Content is written for security architects, engineers, SOC analysts, and IT managers. All URLs below are canonical TechZone references. Last updated: 2026-09-18 --- ## Platform Overview - [GravityZone Platform](https://techzone.bitdefender.com/en/gravityzone-platform.html): Top-level platform overview. Prevention-first architecture, defense-in-depth philosophy, unified agent and console. - [Why Bitdefender](https://techzone.bitdefender.com/en/why-bitdefender.html): Positioning, independent test results, OEM licensing context. - [Multi-layered Security](https://techzone.bitdefender.com/en/gravityzone-platform/multi-layered-security.html): How the four pillars (Prevention, Protection, Detection, Response) work together. Start here for architecture context. - [The Power of Algorithms and Advanced Machine Learning](https://techzone.bitdefender.com/en/gravityzone-platform/the-power-of-algorithms-and-advanced-machine-learning.html): Deep learning, LLMs in HyperDetect, custom ML models, fileless detection, WannaCry pre-detection case study. - [Minimizing False Positives](https://techzone.bitdefender.com/en/gravityzone-platform/minimizing-false-positives.html): How GravityZone balances detection sensitivity with false positive rates. - [Anti-Tampering and Detection Evasion](https://techzone.bitdefender.com/en/gravityzone-platform/anti-tampering-and-detection-evasion.html): Analysis of EDR bypass techniques (callback evasion, BYOVD), GravityZone anti-tampering protection modules. - [Threat Intelligence](https://techzone.bitdefender.com/en/gravityzone-platform/threat-intelligence.html): Global Protective Network (GPN) processing 50B daily queries. Five products: IP Feed, File Feed, Web Feed, IP Blocklist (enforcement-ready, active C2/malware only), and Threat Intelligence API. Indicators available within 5 minutes of global sensor detection. JSONL/REST delivery. Enrichment includes MITRE ATT&CK mappings, actor profiles, CVE links, TLSH similarity scoring. Integrations for Splunk, Anomali, STIX, MISP. IntelliZone portal for analyst investigation, sandbox detonation, actor profiles, and feed previews. - [Cloud and Virtualization Optimization](https://techzone.bitdefender.com/en/gravityzone-platform/cloud-and-virtualization-optimization.html): Scanning optimization for VDI and cloud workloads, Security Server architecture. --- ## Security Layers Overview - [Security Layers](https://techzone.bitdefender.com/en/security-layers.html): Four-pillar architecture introduction. - [Prevention](https://techzone.bitdefender.com/en/security-layers/prevention.html): Overview of attack surface reduction capabilities, proactive hardening. - [Protection](https://techzone.bitdefender.com/en/security-layers/protection.html): Overview of active threat blocking capabilities. - [Detection](https://techzone.bitdefender.com/en/security-layers/detection.html): Overview of threat detection capabilities, correlation engine, visibility. - [Response](https://techzone.bitdefender.com/en/security-layers/response.html): Overview of incident response capabilities. --- ## Prevention Layer - [Risk Management](https://techzone.bitdefender.com/en/security-layers/prevention/risk-management.html): Endpoint vulnerability assessment, misconfiguration detection, user behavior risk, identity/account risks. Hub page for all risk management sub-features. - [Endpoint Risk Management](https://techzone.bitdefender.com/en/security-layers/prevention/risk-management/endpoint-risk-management.html): Scanning for OS vulnerabilities and misconfigurations, remediation actions. - [PHASR -- Proactive Hardening and Attack Surface Reduction](https://techzone.bitdefender.com/en/security-layers/prevention/proactive-hardening-and-attack-surface-reduction.html): AI-powered behavioral profiles block Living-off-the-Land attacks via PowerShell, WMIC, cryptominers, and tampering tools through action-level blocking via 750+ rules. Prevents attacker tactics while allowing legitimate use without application disruption. Windows, macOS, Linux support; Direct Control or Autopilot modes; separates user and AI agent profiles. Learning phase 30-60 days or minutes with EDR data. Standalone deployment available. - [EASM -- External Attack Surface Management](https://techzone.bitdefender.com/en/security-layers/prevention/risk-management/external-attack-surface-management--easm-.html): Agentless discovery of internet-facing assets (IPs, domains, certificates, open ports, CVEs). Dashboard, assets, artifacts views. Pivot to Risk Management and Incidents. - [Compliance Manager](https://techzone.bitdefender.com/en/security-layers/prevention/risk-management/compliance-manager.html): Maps security controls to GDPR, NIS2, ISO 27001 requirements. Real-time compliance posture. - [KSPM -- Kubernetes Security Posture Management](https://techzone.bitdefender.com/en/security-layers/prevention/risk-management/kubernetes-security-posture-management--kspm----bitdefender-techzone.html): Kubernetes cluster security posture assessment. - [Cloud Security / CSPM](https://techzone.bitdefender.com/en/security-layers/prevention/risk-management/cloud-cspm.html): Cloud Security Posture Management for AWS, Azure, GCP, Alibaba. Misconfiguration detection, compliance, remediation. - [Patch Management](https://techzone.bitdefender.com/en/security-layers/prevention/patch-management.html): OS and third-party application patching for Windows and Linux. On-demand and scheduled scanning, automatic and manual patching. Integrated with Risk Management. - [Content Control](https://techzone.bitdefender.com/en/security-layers/prevention/content-control.html): Web filtering by category/URL, data protection rules, application control enforcement, scheduling, Firewall configuration, endpoint isolation during and incident. - [Device Control](https://techzone.bitdefender.com/en/security-layers/prevention/device-control.html): Policy-based blocking of USB drives, Bluetooth, CD/DVD, and other external devices. - [Full Disk Encryption](https://techzone.bitdefender.com/en/security-layers/prevention/full-disk-encryption.html): BitLocker (Windows) and FileVault/diskutil (macOS) management from GravityZone console. Recovery key storage. --- ## Protection Layer - [Network Protection / NAD -- Network Attack Defense](https://techzone.bitdefender.com/en/security-layers/protection/network-protection.html): Deep-packet inspection on every endpoint. Reputation-based blocking of malicious IPs/URLs/domains, behavioral detection of exploits, brute force, lateral movement, C2 call-home, port scanning. Works regardless of user location. - [Malware Protection](https://techzone.bitdefender.com/en/security-layers/protection/malware-protection.html): Core antimalware scanning (on-access, on-demand), detection profiles (Permissive/Normal/Aggressive), emulation, heuristics, disinfection. Includes HyperDetect subsection. - [HyperDetect](https://techzone.bitdefender.com/en/security-layers/protection/malware-protection.html#UUID-3619efb4-9c78-d641-d4ed-b5bd5fc8e807_section-idm4535424370875233919622308569): Tunable pre-execution ML detection. Detects abused legitimate tools (Rclone, Gsudo, Sysinternals), unknown packers, unusual process relationships, obfuscated malware. Five configurable detection areas with Permissive/Normal/Aggressive thresholds. - [Process Protection / ATC -- Advanced Threat Control](https://techzone.bitdefender.com/en/security-layers/protection/process-protection.html): Zero-trust continuous process scoring. Detects code injection, process hollowing, privilege escalation, unauthorized memory operations. Includes Process Introspection (PI) for memory-level exploit detection. - [Software Exploit Protection / Advanced Anti-Exploit](https://techzone.bitdefender.com/en/security-layers/protection/software-exploit-protection.html): Heuristic exploit detection independent of signatures. Covers ROP, shellcode, LSASS credential dumping, kernel-mode post-exploitation on Linux. Protects browsers, Office, Adobe Reader, and custom applications. - [Fileless Protection](https://techzone.bitdefender.com/en/security-layers/protection/fileless-protection.html): Command-Line Scanner for PowerShell, WMI, wscript, cscript, rundll32. AMSI integration. Blocks malicious PowerShell commands and reflective code injection at pre-execution stage. - [Ransomware Protection](https://techzone.bitdefender.com/en/security-layers/protection/ransomware-protection.html): Multi-layered defense (OS-level mini-filters, file monitoring, cloud support for heuristic tuning, False Positive/Negative Mitigation). that correlates intelligence from several modules like ATC, Integrity Monitoring and Anomaly Detection, triggers a real-time backup process (independent of VSS) for the immediate restoration of any affected files. - [Sandbox Analyzer](https://techzone.bitdefender.com/en/security-layers/protection/sandbox-analyzer.html): Cloud-based detonation of suspicious file. ML and heuristic prefiltering, behavioral monitoring, zero-days, ransomware detection, report with MITRE ATT&CK mapping. - [Email Protection](https://techzone.bitdefender.com/en/security-layers/protection/email-protection.html): Integrated security for cloud (Microsoft 365) and on-premises Exchange. Blocks phishing, BEC, and zero-day malware. Includes cloud-native Security with gateway and API capabilities and endpoint-level Email Protection via the BEST agent. - [Mobile Security / MTD](https://techzone.bitdefender.com/en/security-layers/protection/mobile-security.html): Mobile Threat Defense for Android, iOS, Chromebook. OS vulnerability assessment, app vetting (180+ detection points), phishing/network attack detection, threat hunting, forensics, MDM integration. --- ## Detection Layer - [EDR, XDR, and MDR Overview](https://techzone.bitdefender.com/en/security-layers/detection/edr-xdr-and-mdr-overview.html): EPP vs EDR vs XDR vs MDR explained. Correlation engine, lateral movement detection, incident visualization. - [Incident Investigation and Forensics](https://techzone.bitdefender.com/en/security-layers/detection/incident-investigation-and-forensics.html): Root Cause Analysis (RCA), Incident Advisor, kill chain visualization, critical path, guided response actions, pivot to Live Search and IntelliZone. - [Sensors](https://techzone.bitdefender.com/en/security-layers/detection/sensors.html): XDR sensor types -- Network, Office 365, Active Directory, Azure AD, AWS, Azure, GCP, Intune, Google Workspace, Atlassian, CSPM, Mobile, correlation engine. - [Incidents Sensor](https://techzone.bitdefender.com/en/security-layers/detection/sensors/incidents-sensor.html): Incidents Sensor detects across the attack lifecycle—network discovery, persistence, Living off the Land (ProcDump dumping LSASS), credential theft, ransomware staging, all mapped to MITRE ATT&CK. Feeds Correlation Engine, PHASR, custom detection rules, threat hunting, EDR and XDR. Enables automated response actions (Prevent/Terminate process) and osquery-based Live/Historical Search. - [Network Sensor](https://techzone.bitdefender.com/en/security-layers/detection/sensors/network-sensor.html): Network Sensor Virtual Appliance (NSVA), TAP mode via SPAN port. Makes unmanaged devices (printers, IoT, BYOD, NAS) visible; detects port scanning, RDP brute-force, C2 channels, ZeroLogon (CVE-2020-1472). MITRE ATT&CK mapping, feeds XDR Correlation Engine. Images for vSphere, Hyper-V, Proxmox, Azure vTAP. - [Office 365 Sensor](https://techzone.bitdefender.com/en/security-layers/detection/sensors/office-365-sensor.html): Office 365 Sensor monitors Microsoft 365 mailboxes (Exchange Online, SharePoint, OneDrive) for phishing campaigns, compromised account abuse, configuration exposure, and data exfiltration, all mapped to MITRE ATT&CK. Requires no appliance or agent—direct cloud connection. Feeds Correlation Engine for XDR incident assembly, tying email/account activity to endpoint and network telemetry. Response actions: delete malicious campaigns from all mailboxes, disable/reset compromised accounts, delete exfiltrated files. Detects account compromise and post-access abuse invisible to endpoint monitoring. - [Google Workspace Sensor](https://techzone.bitdefender.com/en/security-layers/detection/sensors/google-workspace-sensor.html): Google Workspace Sensor monitors Gmail, Drive, and administrative console for credential attacks, persistence, defense evasion, malware staging, and exfiltration. Requires no appliance or agent—direct cloud connection. Licensed via Bitdefender XDR Sensor - Productivity add-on (shared with Office 365 Sensor). Feeds Correlation Engine for XDR incident assembly and Incident Advisor for guided response. Response actions: disable/reset compromised accounts, delete phishing emails. Detects account compromise and post-access abuse invisible to endpoint monitoring. - [Atlassian Cloud Sensor](https://techzone.bitdefender.com/en/security-layers/detection/sensors/atlassian-cloud-sensor.html): Atlassian Cloud Sensor monitors Atlassian Admin, Jira Cloud, Confluence Cloud audit events for account and permission abuse, no agents or appliances required. Detects brute force, impossible travel, malicious IPs, API token creation, administrative anomalies, and permission tampering. Integrates with XDR Correlation Engine for cloud-SaaS-endpoint incident consolidation. Response actions disable compromised users; artifacts (tokens, guest accounts, public links, exports) require cleanup in Atlassian Admin. - [Active Directory Sensor](https://techzone.bitdefender.com/en/security-layers/detection/sensors/active-directory-sensor.html): Monitors on-premises domain authentication to detect credential attacks, reconnaissance, lateral movement, and log evasion — feeding these signals to the Correlation Engine to correlate domain events with endpoint and network telemetry, trace the identity thread of attacks through XDR incidents, and enable rapid response actions from the incident console. - [Microsoft Intune Sensor](https://techzone.bitdefender.com/en/security-layers/detection/sensors/microsoft-intune-sensor.html): Monitors device management via Graph API, detecting malicious app deployment, policy tampering, root certificate planting, and BitLocker ransom encryption. No agent deployment. Correlates Intune changes with endpoint, network, and identity telemetry for XDR-driven response. - [AWS Sensor](https://techzone.bitdefender.com/en/security-layers/detection/sensors/aws-sensor.html): AWS Sensor monitors CloudTrail and AWS Config from single accounts or Control Tower organizations, detecting compromised access keys, privilege escalation, logging evasion, and data exfiltration, all mapped to MITRE ATT&CK. No appliance or agent; direct cloud connection. Feeds Correlation Engine for XDR, correlating control-plane activity with endpoint, network, and identity telemetry. Response actions: Disable AWS IAM account. Detects account compromise invisible to endpoint and network monitoring. - [Azure Sensor](https://techzone.bitdefender.com/en/security-layers/detection/sensors/azure-sensor.html): Azure Sensor monitors activity logs from Azure subscriptions, detecting credential attacks, privilege escalation, data exfiltration, and logging evasion, all mapped to MITRE ATT&CK. No appliance or agent—direct connection via service principal. Feeds Correlation Engine for XDR, correlating Azure activity with endpoint, network, and identity telemetry. Response actions: Disable compromised Azure accounts. - [Google Cloud Platform Sensor](https://techzone.bitdefender.com/en/security-layers/detection/sensors/google-cloud-platform-sensor.html): Google Cloud Platform Sensor monitors GCP resources via Cloud Audit Logs and Pub/Sub for credential attacks, privilege escalation, persistence, data exfiltration, and defense evasion, all mapped to MITRE ATT&CK. Covers single projects or entire GCP organizations. Requires no appliance or agent—direct cloud connection. Feeds Correlation Engine for XDR incident assembly, tying cloud activity to endpoint, network, and identity telemetry. Response actions: disable Google user, reset password. Detects account compromise and cloud-native attacks invisible to endpoint security. - [Anomaly Detection](https://techzone.bitdefender.com/en/security-layers/detection/anomaly-detection.html): Per-device behavioral baseline modeling. Detects deviations from normal activity patterns. Seasonal Auto-Regressive Integrated Moving Average (SARIMA), Seasonal and Trend decomposition using Loess (STL), and Moving Average algorithms. - [Live Search](https://techzone.bitdefender.com/en/security-layers/detection/live-search.html): Osquery-based real-time endpoint querying across Windows, Linux, macOS. threat hunting, 340+ predefined queries. Historical data retention. - [YARA Rules](https://techzone.bitdefender.com/en/security-layers/detection/yara-rules.html): Custom pattern-matching detection rules. On-access and on-demand scan modes. Automatic response actions (isolate, kill, quarantine, sandbox). Results in Incidents and Historical Search. - [Integrity Monitoring](https://techzone.bitdefender.com/en/security-layers/detection/integrity-monitoring.html): File, directory, registry, service, user, and installed software change monitoring on Windows and Linux. Default and custom rules. Automatic remediation. Three performance modes. PCI DSS, HIPAA, SOX, GDPR compliance use cases. - [Security Data Lake](https://techzone.bitdefender.com/en/security-layers/detection/security-data-lake.html): Unified SIEM and scalable data lake storage. Centralizes and normalizes telemetry from 100+ inputs like firewalls (Palo Alto, Fortinet, Check Point, Cisco ASA, etc.), cloud, identity, SaaS. Streams, Pipelines, Illuminate Packs, Sigma Rules, Anomaly Detection, Correlation Engine, Investigations. MITRE ATT&CK coverage mapping. --- ## Response Layer - [Threat Response](https://techzone.bitdefender.com/en/security-layers/response/threat-response.html): GravityZone incident response action: endpoint isolation, process kill, quarantine, remote shell, patch deployment, account disable, password reset, delete email, Collect investigation pkg, exclusion list, add to sandbox, Search with VirusTotal. - [Managed Detection and Response (MDR)](https://techzone.bitdefender.com/en/security-layers/response/managed-detection-and-response.html): 24/7 analyst-led monitoring. Threat modeling, CTI team, SOC team, pre-approved response actions, brand/IP reputation monitoring, MDR portal. --- ## Services - [Cybersecurity Advisory Services](https://techzone.bitdefender.com/en/services/cybersecurity-advisory-services.html): Security architecture alignment, services across three main pillars: Strategy and Leadership, Risk and Compliance, and Event Preparedness. - [Professional Services](https://techzone.bitdefender.com/en/services/professional-services.html): GravityZone deployment and optimization. - [Offensive Services](https://techzone.bitdefender.com/en/services/offensive-services.html): Penetration testing and red teaming. --- ## Tech Explainers Evergreen articles explaining attacker techniques and how GravityZone detects them. - [What Is BYOVD -- Bring Your Own Vulnerable Driver](https://techzone.bitdefender.com/en/tech-explainers/what-is-bring-your-own-vulnerable-driver--byovd-.html): Attacker technique that loads legitimate signed drivers to reach kernel (Ring 0) from user-mode, enabling EDR bypass, memory manipulation, and security agent termination. Covers escalation chain, IOCTL abuse, vulnerable vs. permissive drivers, and GravityZone ELAM and Callback Evasion (CBE) defenses. - [What Is DLL Sideloading](https://techzone.bitdefender.com/en/tech-explainers/what-is-dll-sideloading.html): Technique where attackers place a malicious DLL alongside a legitimate executable, causing the application to load the attacker's library instead of the intended one. Covers search-order hijacking, vulnerable application patterns, and GravityZone detection via HyperDetect and Process Protection. - [Living off the Land Attacks (LOL, LOTL, LOLbin, LOLBAS)](https://techzone.bitdefender.com/en/tech-explainers/living-of-the-land-attacks.html):How attackers abuse legitimate, pre-installed system tools (PowerShell, WMI, certutil, RDP, and others) to blend with normal activity across the full attack lifecycle - from privilege escalation and lateral movement to data exfiltration and ransomware deployment. Covers attack categories, top 10 abused Windows utilities, and defense strategy combining PHASR, Process Protection, Fileless Protection. - [What is Impacket](https://techzone.bitdefender.com/en/tech-explainers/what-is-impacket.html): How Impacket atexec, smbexec, wmiexec, and psexec abuse SMB, RPC, and DCOM to move laterally with stolen credentials - forensic artifacts per tool, common misconceptions (fileless, LOTL, malware), and behavioral detection strategies. - [What Is Process Impersonation](https://techzone.bitdefender.com/en/tech-explainers/what-is-process-impersonation.html): How attackers split a process's visible identity (name, path, parent, hash) from its security identity (token, SIDs, privileges). Covers nine variants — name spoofing, hollowing, doppelganging, ghosting, herpaderping, thread injection, PPID/command-line spoofing, bind-link path spoofing, and token theft — plus Windows internals (EPROCESS vs. PEB), signal reliability ratings, and GravityZone defenses via Process Protection, ATC, and memory scanning. - [What is User Execution](https://techzone.bitdefender.com/en/tech-explainers/what-is-user-execution.html): MITRE T1204 User Execution exploits expected user behavior (malicious links, files, clipboard paste) rather than vulnerabilities. Attackers pivot file types faster than signatures adapt (macros → LNK → ISO → OneNote → ClickFix fileless attacks). User training and macro blocks fail; detection requires behavioral process monitoring (Office spawning cmd.exe, explorer.exe launching PowerShell with execution-policy bypass, LNK files with extended arguments). GravityZone response via Extended Email Security, PHASR, Fileless Protection, Advanced Threat Control, and EDR Correlation Engine. - [What Is Credential Dumping](https://techzone.bitdefender.com/en/tech-explainers/what-is-credential-dumping.html): MITRE T1003.001 post-exploitation technique for extracting password hashes, Kerberos tickets, and plaintext credentials from LSASS memory, the SAM and SECURITY hives, and NTDS.dit. Covers LOTL dumping via ProcDump, comsvcs.dll through rundll32.exe, createdump.exe, and MiniDumpWriteDump; DCSync replication impersonation over MS-DRSR and krbtgt Golden Ticket forgery. Detection signals (Sysmon Event ID 10, Event ID 4662, non-standard .dmp paths). Bitdefender GravityZone protection through ATC, Fileless Protection, PHASR, EDR Sensor, Integrity Monitoring. - [What is Email Bombing](https://techzone.bitdefender.com/en/tech-explainers/what-is-email-bombing.html): Volume-based attack where adversaries flood a target's inbox with hundreds or thousands of clean emails from legitimate services or attacker-controlled servers to bury malicious messages and enable vishing attacks. Attackers layer the flood with fraud like credential phishing emails. Detection requires per-recipient inbound rate limiting and temporal correlation—volume spike alongside password reset, MFA prompt, financial approval, or inbound call. GravityZone Extended Email Security enforces rate limiting; XDR Correlation Engine links email telemetry with endpoint authentication events. --- ## Tech Papers and White Papers - [Threat Hunting](https://techzone.bitdefender.com/en/tech-papers/threat-hunting.html): Proactive threat hunting methodology, GravityZone tools (Live Search, Security Data Lake, Sigma Rules), MDR threat hunting. - [GravityZone Best Practices](https://techzone.bitdefender.com/en/tech-papers/gravityzone-best-practices.html): Policy configuration guidance, module-by-module recommended settings. - [Preventing Security Incidents from Escalating into Breaches](https://techzone.bitdefender.com/en/white-papers/preventing-security-incidents-from-escalating-into-breaches.html): Post-compromise attack path, detection and containment strategy. - [A Guide to Effective Cybersecurity Risk Management](https://techzone.bitdefender.com/en/white-papers/a-guide-to-effective-cybersecurity-risk-management.html): Risk assessment methodology, likelihood/impact matrix, framework selection. - [Mitigating Supply Chain Attacks](https://techzone.bitdefender.com/en/white-papers/mitigating-supply-chain-attacks.html): Supply chain attacks, dual role: victim or entry point, supply chain risk assessment,safeguarding upstream integrity, securing the connected business ecosystem and Third-Party interactions. ---