share_log

Corelight Integrates SentinelOne Singularity Platform Data to Accelerate SOC Transformation

Corelight Integrates SentinelOne Singularity Platform Data to Accelerate SOC Transformation

Corelight整合SentinelOne Singularity平台數據,加速SOC轉型
PR Newswire ·  10/15 08:00

Company leverages SentinelOne's rich endpoint and vulnerability management telemetry data within Corelight Sensor to find and disrupt attacks

公司利用SentinelOne豐富的端點和漏洞管理遙測數據,在Corelight Sensor內查找並破壞攻擊。

SAN FRANCISCO, Oct. 15, 2024 /PRNewswire/ -- Corelight, the fastest growing provider of network detection and response (NDR) solutions, today announced a partnership with SentinelOne, (NYSE: S), a global leader in AI-powered security, to provide real-time enrichment of Corelight logs. Combining endpoint and vulnerability data at the point of observation in the network sensor will greatly reduce a security team's mean time to detect (MTTD) and mean time to recovery (MTTR). This native integration drives AI-powered SOC transformation and helps customers disrupt future attacks.

舊金山,2024年10月15日 / PRNewswire / -- Corelight,網絡檢測與響應(NDR)解決方案增長最快的提供商,今天宣佈與 SentinelOne,(紐交所:S),一家全球領先的人工智能安全提供商,合作提供Corelight日誌的實時增強。在網絡傳感器的觀測點結合端點和漏洞數據將極大減少安全團隊的發現時間(MTTD)和恢復時間(MTTR)。這種本地集成推動了人工智能SOC轉型,並幫助客戶破壞未來的攻擊。

According to interviews conducted for the Mandiant Global Perspectives on Threat Intelligence report, 84% of respondents said that they are concerned they may be missing out on threats or incidents because of the number of alerts and data they are faced with. The need for analysts to manually integrate data sources and sort through alerts that may not be indicative of malicious activity leads to increased response time, analyst fatigue and staff turnover. By correlating data from Corelight and SentinelOne at the sensor level, Corelight can simplify and streamline alert triage and provide better context for threats that are traversing or hiding in the network.

根據爲 Mandiant全球威脅情報視角 根據報告,84%的受訪者表示,他們擔心由於面臨的警報和數據數量,他們可能會錯過威脅或事件。分析師需要手動整合數據源並篩選可能不表示惡意活動的警報導致反應時間增加、分析師疲勞和員工流失。通過在傳感器級別關聯來自Corelight和SentinelOne的數據,Corelight可以簡化和優化警報分類,併爲正在穿越或隱藏在網絡中的威脅提供更好的上下文。

SOC teams can now control the increasing volume of alerts and confidently reduce dwell time for a more secure posture.

SOC團隊現在可以控制不斷增加的警報數量,並自信地縮短滯留時間,獲得更安全的姿態。

Post this
發佈此貼

"Security teams can become overwhelmed with information across the security stack and as a result can miss the most critical alerts to action immediately," said Todd Wingler, Corelight vice president global alliances and channels. "By combining the insights from both Corelight Open NDR and the SentinelOne Singularity Platform, we're empowering SOC teams to accelerate investigations, reduce false positives, and focus on the most critical indicators of compromise. This means they can finally gain control over the increasing volume of alerts and confidently reduce dwell time for a more secure posture."

"安全團隊可能會因安全堆棧上的信息過載而不堪重負,從而可能錯過立即採取行動的最關鍵警報,"Corelight全球聯盟和渠道副總裁Todd Wingler表示。"通過結合Corelight Open NDR和SentinelOne Singularity平台的見解,我們正在賦予SOC團隊加快調查、減少虛警並專注於最關鍵妥協指標的力量。這意味着他們最終可以控制不斷增加的警報數量,並自信地縮短滯留時間,獲得更安全的姿態。"

By enriching Corelight logs with relevant endpoint data from SentinelOne Singularity Endpoint, SOC analysts have a comprehensive and holistic view of network activity across all connected devices, including unsecured, unsupported, and previously unmanaged endpoints, where EDR cannot be installed. Moreover, by correlating Corelight alerts with endpoint vulnerabilities identified by SentinelOne Singularity Vulnerability Management, mutual customers can more effectively detect and prioritize threats based on current risks to the environment. Pre-correlating data directly in the sensor enhances alerts with additional context that can help accelerate investigations, streamline incident response and reduce the distraction of alerts that can be deprioritized.

通過將來自SentinelOne的相關端點數據豐富化Corelight日誌,SOC分析師可以全面而綜合地查看跨所有連接設備的網絡活動,包括無保護、無支持和以前未受管控的端點,無法安裝EDR。此外,通過將Corelight警報與SentinelOne Singularity漏洞管理識別的端點漏洞相關聯 Singularity Endpoint,SOC分析員對所有已連接設備的網絡活動都擁有全面和整體的視圖,包括無保護、無支持和以前未受管控的端點,在這些端點上無法安裝EDR。此外,通過將Corelight警報與SentinelOne Singularity漏洞管理識別的端點漏洞相關聯 傳感器級別共同客戶可以更有效地根據當前環境風險檢測和優先處理威脅。在傳感器中直接預關聯數據可增強警報的額外上下文,有助於加速調查,簡化事件響應,並減少可以優先處理的警報的干擾。

"For effective enterprise security, comprehensive visibility across the network and each connected device is paramount," said Melissa K. Smith, vice president of Technology Partnerships & Strategic Initiatives, SentinelOne. "As the fastest growing endpoint company and a top choice of customers around the world, SentinelOne sets the standard for endpoint protection. By integrating our AI-powered Singularity Platform with Corelight's industry-leading network intelligence, SOC teams get deeper insights into existing and novel threats with broader detection coverage and faster investigations."

「對於企業安全的有效性,網絡和每個連接設備的全面可見性至關重要,」 SentinelOne的技術合作夥伴和戰略計劃副總裁Melissa k. Smith表示。“作爲增長最快的端點公司,也是全球客戶首選,SentinelOne爲端點保護設定了標準。通過將我們的人工智能驅動的" Singularity Platform 與Corelight行業領先的網絡智能相結合,SOC團隊可以更深入地了解現有和新型威脅,擁有更廣泛的檢測範圍和更快的調查速度。

Learn More about how Corelight and SentinelOne together provide a comprehensive view of enterprise security.

了解更多 關於Corelight和SentinelOne如何共同提供企業安全全面視圖的信息。

Corelight provides security teams with network evidence so they can protect the world's most critical organizations and companies. Corelight's global customers include Fortune 500 companies, major government agencies, and large research universities. Based in San Francisco, Corelight is an open-core security company founded by the creators of Zeek, the widely-used network security technology. For more information, .

Corelight爲安全團隊提供網絡證據,使他們能夠保護全球最重要的組織和公司。Corelight的全球客戶包括財富500強公司、主要政府機構和大型研究高校。總部位於舊金山的Corelight是由Zeek的創始人創建的開放核心安全公司,Zeek是廣泛使用的網絡安全技術。如需更多信息, .

SOURCE Corelight

源自 Corelight

WANT YOUR COMPANY'S NEWS FEATURED ON PRNEWSWIRE.COM?

想要您公司的新聞在PRNEWSWIRE.COM上特色呈現嗎?

440k+
440k+

Newsrooms &
新聞發佈室&

Influencers
影響力
9k+
9k+

Digital Media
數字媒體

Outlets
賣場
270k+
270k+

Journalists
新聞記者

Opted In
已選擇加入
GET STARTED
開始使用
声明:本內容僅用作提供資訊及教育之目的,不構成對任何特定投資或投資策略的推薦或認可。 更多信息
    搶先評論