Cyberattacks against critical systems often leave defenders searching for clues outside the machine. Crytica Security wants to change that by monitoring what happens inside the device itself. The cybersecurity company has developed a compact security probe that detects unauthorized changes within embedded systems. Its approach focuses on the instructions a device uses to perform its functions. Crytica says the technology can provide deterministic evidence when those instructions change. That signal could help security teams identify compromises with greater confidence. Inside the device Crytica’s technology uses a probe that occupies less than 100 kilobytes inside a protected device. The lightweight software runs without disrupting normal operations. The probe monitors the device’s instruction set for unauthorized modifications. It can also identify changes involving static data, including configuration files. That distinction matters because many cybersecurity tools observe devices externally. They analyze network traffic, communications, vulnerabilities, and behavior to identify suspicious activity. Those methods can reveal important clues. They cannot always establish whether the device itself still operates from trusted instructions. Crytica calls its internal monitoring technology iNSiM, short for Instruction Set Integrity Monitoring. The system can detect changes quickly and generate alerts for security teams. Faster detection The technology feeds into Crytica’s Rapid Detection, Alert, and Isolation system, known as RDAi. The system aims to give security operations centers a higher-confidence signal. That signal could complement existing security platforms instead of forcing organizations to replace them. Crytica says its technology can work alongside SOC, SIEM, XDR, and AI-assisted security systems. That integration could become increasingly important as cyberattacks accelerate. IBM reported a 56 percent year-over-year increase in AI-driven attacks in its 2026 breach study. The same report found that half of organizations with security operations centers have deployed AI agents. Automated systems now make decisions and respond to threats at increasingly high speeds. Security teams therefore need reliable information to feed those automated workflows. A compromised device could undermine those decisions if its own operating state remains uncertain. Higher stakes The stakes rise considerably when attackers target operational technology. Embedded devices can influence infrastructure that supports essential services and physical processes. Healthcare systems also depend on connected devices that must remain reliable. National security applications face similar concerns, especially where compromised equipment could affect mission readiness. Crytica is pursuing deployments across commercial, utility and federal environments. It also works with security vendors, device manufacturers and systems integrators. CEO C. Kerry Nemovicher said effective detection ultimately needs visibility inside devices. He described the company’s probe as a small software agent designed for that purpose. Executive Chairman C. Lloyd Mahaffey said partnerships around deterministic detection are also emerging. Crytica expects to announce additional technology integrations and collaborations in the coming weeks.The broader idea is straightforward: external monitoring can identify suspicious behavior. Internal integrity monitoring could determine whether the device itself has changed. For defenders protecting critical systems, that difference could provide another layer of confidence when every second matters.Recommended ArticlesGet the latest in engineering, tech, space & science - delivered daily to your inbox.Aamir is a seasoned tech journalist with experience at Exhibit Magazine, Republic World, and PR Newswire. With a deep love for all things tech and science, he has spent years decoding the latest innovations and exploring how they shape industries, lifestyles, and the future of humanity.
Sub-100 KB cyber probe could help military systems expose hidden attacks from within
Full Article
Original Source
Read the full article at Interestingengineering →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.