Categories: Wire Stories

Endace Integrates with Palo Alto Networks Cortex XSOAR to Deliver Forensics for Accelerated Response to Cyberthreats

Integration combines EndaceProbe Analytics Platform with Cortex XSOAR to simplify and accelerate cybersecurity investigations with definitive, network-wide packet history

AUSTIN, Texas & AUCKLAND NEW ZEALAND–(BUSINESS WIRE)–Endace, a world leader in high-speed network recording, playback and analytics hosting, today announced that the EndaceProbe Analytics Platform is now integrated with Palo Alto Networks Cortex XSOAR (previously Demisto), the industry’s first extended security, orchestration, automation and response platform with native threat intel management that empowers security leaders with instant capabilities against threats across their entire enterprise. Through this integration, Endace and Cortex XSOAR provide customers with network packet capture from within Cortex XSOAR playbooks to enable accelerated, evidence-led, forensic investigation of cyberthreats.

The integration leverages Endace’s rapid-search and data-mining APIs to integrate network history into Cortex XSOAR. Using Cortex XSOAR’s powerful automation capabilities, the full packet history relating to specific security incidents is automatically retrieved from one or more EndaceProbes and provided back to analysts as definitive forensic evidence.

Analysts can leverage Cortex XSOAR’s integration with Endace’s InvestigationManager™ and EndaceVision™ for detailed packet level investigations across global EndaceProbe estates. This lets them pivot from an investigation in Cortex XSOAR directly to the global packet history related to that incident to extend their investigation and drill down to investigate associated network activity such as lateral movement, data exfiltration or command-and-control (C2) traffic.

“Endace’s scalable, network-wide full packet capture is a powerful addition to the Cortex XSOAR ecosystem,” said Rishi Bhargava, vice president of product strategy, Cortex XSOAR at Palo Alto Networks. “It provides customers with rapid access to rich forensic evidence for investigating security incidents and the ability to include packet history into Cortex XSOAR use cases and playbooks to put definitive evidence at analysts’ fingertips.”

“Security teams are desperate to combat alert fatigue, streamline workflows and accelerate investigations to provide certainty when responding to network threats,” says Cary Wright, VP of Product Management at Endace. “The combination of Cortex XSOAR’s powerful orchestration and automation capabilities with the rich network history recorded by the EndaceProbe Analytics Platform gives security operations access to the conclusive forensic evidence they need to respond quickly and accurately to threats.”

Cortex XSOAR is an extended security orchestration, automation and response platform that unifies case management, automation, real-time collaboration and threat intel management to transform every stage of the incident lifecycle. Teams can manage alerts across all sources, standardize processes with playbooks, take action on threat intel and automate response for any security use case – resulting in significantly faster responses that require less manual review.

The EndaceProbe Analytics Platform combines 100% accurate, network-wide packet capture with the ability to host and integrate with a wide range of commercial and open source network security and performance solutions to deliver definitive evidence for troubleshooting network and application performance issues and responding to cyberthreats.

About Endace

Endace specializes in high-speed, scalable packet capture for cybersecurity, network and application performance.

The open, EndaceProbe Analytics Platform lets customers record a 100% accurate history of activity on their network and integrates with a range of security tools for fast, accurate incident investigation and resolution. Endace’s Fusion Partners – including Cisco, Darktrace, IBM, Micro Focus, Palo Alto Networks, Plixer, Splunk and others – offer pre-built integration with the EndaceProbe platform to accelerate and streamline incident investigation and resolution.

EndaceProbes can also host network security and performance monitoring tools that need to analyze real-time or historical traffic. This hosting capability enables agile deployment and reduces cost by consolidating analytics solutions on a common hardware platform.

Endace’s global customers include banks, healthcare, telcos, broadcasters, retailers, web giants, governments and military. Follow Endace on Twitter and LinkedIn. For more information see www.endace.com.

Contacts

USA: Kelly Dorsey

mobile +1-818-436 9646

EMEA: Leah Jones (CommsCo)

+44 203 697 6680

Asia Pacific: Mark Evans

mobile +64-21-494 850

Alex

Recent Posts

Solera Announces Strategic Partnership with Axalta, a Leading Global Supplier of Liquid and Powder Coatings

Solera and Axalta partner together to accurately calculate CO2 emissions per vehicle repair. WEST LAKE,…

1 min ago

Lenovo Supercharges Next Gen Copilot+ PCs with Latest Yoga Slim 7x and ThinkPad T14s Gen 6

HONG KONG SAR - Media OutReach Newswire - 21 May 2024 - Today, Lenovo™ launched…

47 mins ago

Arizona Sonoran Continues to Define Near Surface Mineralization at MainSpring

CASA GRANDE, Ariz. & TORONTO--(BUSINESS WIRE)--$ASCU #Arizona--Arizona Sonoran Copper Company Inc. (TSX:ASCU | OTCQX:ASCUF) (“ASCU”…

2 hours ago

KAYTUS Introduces KR1280V2 – a 1U Server with 32 E1.S SSDs, Boosting I/O Performance for LLM Training

The KR1280V2, a 1U 2-socket high-density server, is ideal for compute-intensive applications like high-performance computing…

2 hours ago

Ooredoo Qatar Extends Partnership With Netcracker for Revenue Management and Managed Services Across All Lines of Business

Middle Eastern Operator Will Continue Leveraging Netcracker’s Digital BSS Product Suite and Managed Services to…

2 hours ago

SCG International Partners with Buna Al Mamlaka to Propel Sustainable Construction Innovations in Saudi Arabia

BANGKOK, THAILAND - Media OutReach Newswire - 21 May 2024 - SCG International Corporation Co.,…

2 hours ago