Uncover attackers hiding on your network
Use Cases and Deployment Scope
Extrahop has been an integral piece in our Security Operations Centre and has repeatedly uncovered suspicious activity earlier in the attack kill-chain than other tooling.
We purchased ExtraHop to enhance our network based detections and for their complimentary approach to Crowdstrike as an EDR. Crowdstrike provides strong visibility at the endpoint level; however, that assumes it is installed on all devices. ExtraHop analyzes all network traffic regardless if the device is corporate managed or what technologies exist on the endpoint. This results in clear visibility into what is actually occurring on the network.
Furthermore, we also have utilized ExtraHop quite extensively for other projects including mapping out network communication flows, and gaining insight into system dependencies through network communications prior to deccomissioning assets.
Overall, it has been a great purchase and become fundamental to our information security program.
We purchased ExtraHop to enhance our network based detections and for their complimentary approach to Crowdstrike as an EDR. Crowdstrike provides strong visibility at the endpoint level; however, that assumes it is installed on all devices. ExtraHop analyzes all network traffic regardless if the device is corporate managed or what technologies exist on the endpoint. This results in clear visibility into what is actually occurring on the network.
Furthermore, we also have utilized ExtraHop quite extensively for other projects including mapping out network communication flows, and gaining insight into system dependencies through network communications prior to deccomissioning assets.
Overall, it has been a great purchase and become fundamental to our information security program.
Pros
- Network discovery
- Network based detections for suspicious/malicious activity and behaviour
- Insight into data flow between systems
- Visibility into network errors
Cons
- Reporting
- Prevention
Return on Investment
- Increased visibility into network based attacks
- Increase visibility into data flows aiding in data loss prevention capabilities
- Assisting network infrastructure teams with visibility into network based performance metrics
Usability
Alternatives Considered
Netskope CASB, Palo Alto Panorama, Palo Alto Networks Virtualized Next-Generation Firewalls - VM Series, Palo Alto Networks Prisma Cloud, Zscaler Internet Access, Zscaler Private Access, Darktrace and Varonis Data Security Platform
Other Software Used
Netskope CASB, Zscaler Internet Access, Zscaler Private Access, Palo Alto Panorama, Palo Alto Networks Prisma Cloud, Palo Alto Networks Next-Generation Firewalls - PA Series, Microsoft Defender for Cloud Apps, Tenable Lumin, Tenable Cloud Security, Tenable Attack Surface Management, Tenable Vulnerability Management, Tenable Web App Scanning, Tenable Nessus, Snyk, Veracode, Microsoft Sentinel, Exabeam Fusion, ZeroFOX