Avantec AG
Zug
How HP wants to kill the Kill Chain with a new old approach – Tec-Bite
- 08 August 2026
- 100%
- Permanent position
- Zug
Job summary
HP Sure Click, part of HP Security Solutions, enhances device security.
Tasks
- It isolates potentially dangerous files in a Micro-VM.
- Offers strong protection for various file types and sources.
- Ensures compatibility with other hardware and provides new features.
Skills
- Experience in cybersecurity and familiarity with virtual environments.
- Knowledge of malware detection and prevention techniques.
- Understanding of endpoint security solutions and cloud technology.
Is this helpful?
About the job
Bromium was acquired by HP Inc. in autumn 2019 and is now part of HP Security Solutions under the somewhat unusual name "HP Sure Click". Some may now ask: What does HP have to do with security? Well, I felt the same way, to be honest, and was rather sceptical. However, if you take a closer look at HP devices, or rather the security solutions HP offers for its device fleet, the acquisition of Bromium makes quite a bit of sense. More on that later.Kill Chain – where does Sure Click come in?Common AV solutions try to prevent infection or exploitation of an open security vulnerability by recognising known IOCs or unusual behaviour through behavioural analysis. In the Kill Chain model, we intervene between Deliver and Exploit. The catch is simply that such solutions need to recognise something in order to protect against it. And however you want to do that, whether with or without patterns, with behavioural analysis, machine learning and AI: if you cannot recognise something, it becomes difficult.An EDR system often comes in as an additional defence layer. This operates either between Install and C2 (C&C), or between C2 and Actions. This is intended to detect an attack at the latest when, for example, unusual processes are started on endpoints or lateral movements occur between hosts. Like AV solutions, EDR systems rely on detection. Detection is even more difficult with EDR because you cannot rely solely on known IOCs but must actually search for the unknown. Which brings us to threat intelligence. For those interested: www.tec-bite.ch/endpoint-detection-and-response-wer-richtig-sucht-der-findet/HP Sure Click also operates between Deliver and Exploit but foregoes detection for protection. Regardless of the potential danger of a file or website, everything is simply isolated in a micro-VM. Detection then occurs in a second step through analysis of the operations taking place in the micro-VM. In the case of, for example, ransomware hidden in a Word file, you would thus have an autopsy report without a corpse. The ransomware can be executed without affecting my host and thus my backend systems in the slightest.Kill Chain model from HP Sure Click Enterprise webinarWhat is protected?HP Sure Click offers strong protection for Office files, PDFs, image and video files, as well as archives. Supported data sources include Outlook mail attachments, browser downloads and USB sticks.The file to be protected is not altered by Sure Click. The file hash of the file is identical with and without Sure Click installed. This is important, among other things, when sharing a document with an external recipient. Even if the file is isolated on an internal computer, an external recipient can open the file without Sure Click without any problems.From Bromium to HP Sure Click – what changes?In terms of general product functionality, nothing changes at all. Those familiar with Bromium will only have to get used to the new design. Bromium orange is replaced by HP blue. This applies both to the visible part on the endpoint, desktop console icon and untrusted files icons, as well as the GUI of the controller.Even though "HP" is in the name, the software naturally also runs on hardware from other manufacturers. However, there are customised versions or bundle solutions that only run on HP devices. For example, HP Sure Click Pro is pre-installed on EliteBooks and can thus also be used by private users. A really great thing, I can confirm from my own experience. Of course, the functionality is limited and does not offer the same possibilities as Sure Click Enterprise. However, for the security-conscious private user, it is tip top.New features from version 4.2The new version not only looks new but also delivers interesting new features.Identity Protection:With Identity Protection enabled, the URL is checked using the Web Reputation Service. If the URL has a poor or unknown reputation, the configurable policy decides whether the user is allowed to enter credentials on the website or not. The reputation service can be supplemented with its own white or black list. This feature is not only available in isolated browsers but also works in Microsoft Edge or Firefox thanks to a plugin.Protected App:Protected App is not exactly a new feature. From a licensing perspective, it is even considered a standalone product. However, management is done via the same HP Sure Click Enterprise controller. From version 4.2, the solution has made a big leap forward and is now really a cool thing!Protected App is essentially about securely running a PAW (Privileged Access Workstation) virtually on your own computer. The target group for PA is therefore not the large mass of "normal" users but primarily admins. The RDP or HTTPS connections of admins to target systems are to be secured. With PA in use, keylogging or spying on the desktop via screenshots is no longer possible. Similar to HP Sure Click's micro-virtualisation, connections run via their own hypervisor and are thus separated from the host.HP Security Solutions – an overviewThe functions of Bromium are offered by HP in various bundles, sometimes with more, sometimes with less functionality. In addition to Sure Click, the bundles also include Sure Sense as an AV solution, Sure View as a privacy shield and Sure Start as a BIOS check.In the following table, you can see which HP Security Solutions version covers which functions. Regarding Sure Click, since this is not an HP blog, I will leave the rest aside.ConclusionAs you can see, the full package is only available with HP Sure Click Enterprise. In conversations with customers, it has often emerged that companies using HP hardware thought they would no longer need Sure Click Enterprise. As the table shows, this is only partly true.Once you have come to terms with the name and the new design, Bromium runs as you know and appreciate it. It is and remains a very cool solution that I can recommend to pretty much everyone as a techie. Of course, there are some points that need to be looked at in detail to keep the noticeable impact on end users as low as possible. And in my opinion, this is also the biggest risk for HP: if you search the web for HP Sure Click, you will find some forums with quite negative entries. Sure Click disrupts normal operation, makes everything slow and generally HP should keep its security solutions where the pepper grows. The criticised version is always HP Sure Click Pro, the "free" version pre-installed when buying an HP computer. However, if the solution is professionally installed and configured, the impact on the user is very low.Linkswww.avantec.ch/loesungen/hp-sure-click-enterprise/The article How HP wants to kill the Kill Chain with a new old approach first appeared on Tec-Bite.