Endpoint Protection - Screw Gartner, let’s get honest and talk Good, Bad, and Ugly on products and vendors - Who’s the worst, and who’s your favorite?
Which of these EDR solutions would be the best to use?
How do i compare EDR's?
You could check out an evaluation group like SE Labs that focuses on Mitre ATT&CK frameworks like mentioned before and compare some of their more recent reviews for groups like Croudstrike and SentinelOne as well as their 2019-2020 review. These breakdowns are pretty helpful.
SE Labs reports 2020
More on reddit.comWhich EDR to choose?
What is an Endpoint Protection Platform?
Gartner defines an endpoint protection platform (EPP) as security software designed to protect managed endpoints — including desktop PCs, laptop PCs, virtual desktops, mobile devices and, in some cases, servers — against known and unknown malicious attacks. EPPs provide capabilities for security teams to investigate and remediate incidents that evade prevention controls. EPP products are delivered as software agents, deployed to endpoints, and connected to centralized security analytics and management consoles.
EPPs provide a defensive security control to protect end-user endpoints against known and unknown malware infections and file-less attacks using a combination of security techniques (such as static and behavioral analysis) and attack surface reduction capabilities (such as device control, host firewall management and application control). EPP prevention and protection capabilities are deployed as a part of a defense-in-depth strategy to help reduce the endpoint attack surface and minimize the risk of compromise. EPP detection and response capabilities are used to uncover, investigate and respond to endpoint threats that evade security protection, often as a part of broader threat detection, investigation and response (TDIR) capable products.
What is Network Detection and Response?
Network detection and response (NDR) products detect abnormal system behaviors by applying behavioral analytics to network traffic data. They continuously analyze raw network packets or traffic metadata within internal networks (east-west) and between internal and external networks (north-south). NDR products include automated responses, such as host containment or traffic blocking, directly or through integration with other cybersecurity tools. NDR can be delivered as a combination of hardware and software appliances for sensors, some with IaaS support. Management and orchestration consoles can be software or SaaS.
This can be completely subjective, but, share your thoughts and context such as what’s great for massive enterprises and small shops, good budget/no budget, HALO products and vendors, and those to be avoided no matter the org.
For instance, I’ve never had a good experience with Trend or Sentinel… have others? What are your thoughts and experience supporting EDR?
Thanks!