What are your thoughts on Sentinel One?
Best Corporate Anti-Virus/Endpoint Protection
What Endpoint Protection do you use? About to replace my existing vendor.
Any Experience on Crowdstrike by Falcon?
I loved Crowdstrike while I had it at a previous job, dead easy to configure and setup, not that hard to understand detection events and their support and documentation were good too (the one time I had to speak to support about a false positive they were already aware of, had a temporary workaround documented and confirmed a fix was due to be deployed the next day).
I wouldn't say Crowdstrike is unique, but it is among the top "new" breed of AV's that have almost totally moved away from old style file signature based detections and rely more on behaviour to decide if a process is good or bad.
Depending on the license type you get they also have a bunch of other handy tools based on the data that the CS agent is able to pull from clients, one big one is being able to query things like processes or DNS lookups across every client even if a detection hasn't been triggered which is good for threat hunting or just general investigation of something suspicious.
If you have the budget for it they also have some fancy tiers that involve their staff either being on hand to assist with detection events and/or taking over and doing active threat hunting on your devices proactively for you.
More on reddit.comWhat is an Endpoint Protection Platform?
Gartner defines an endpoint protection platform (EPP) as security software designed to protect managed endpoints — including desktop PCs, laptop PCs, virtual desktops, mobile devices and, in some cases, servers — against known and unknown malicious attacks. EPPs provide capabilities for security teams to investigate and remediate incidents that evade prevention controls. EPP products are delivered as software agents, deployed to endpoints, and connected to centralized security analytics and management consoles.
EPPs provide a defensive security control to protect end-user endpoints against known and unknown malware infections and file-less attacks using a combination of security techniques (such as static and behavioral analysis) and attack surface reduction capabilities (such as device control, host firewall management and application control). EPP prevention and protection capabilities are deployed as a part of a defense-in-depth strategy to help reduce the endpoint attack surface and minimize the risk of compromise. EPP detection and response capabilities are used to uncover, investigate and respond to endpoint threats that evade security protection, often as a part of broader threat detection, investigation and response (TDIR) capable products.
What Core EDR Technology Does SentinelOne Use?
What Types of Threats Can SentinelOne EDR Detect and Respond To?
Videos
Hi,
What you guys think of Sentinel One? Is it good and worth the money? Does it work well on macOS and Windows? Is it resource intensive? Has anyone used the on-premises version?