{"id":46596,"date":"2021-02-06T20:46:50","date_gmt":"2021-02-07T01:46:50","guid":{"rendered":"https:\/\/www.opensource.im\/uncategorized\/gurucul-xdr-uses-machine-learning-integration-for-real-time-threat-detection-incident-response-integration-developers.php"},"modified":"2021-02-06T20:46:50","modified_gmt":"2021-02-07T01:46:50","slug":"gurucul-xdr-uses-machine-learning-integration-for-real-time-threat-detection-incident-response-integration-developers","status":"publish","type":"post","link":"https:\/\/euvolution.com\/open-source-convergence\/machine-learning\/gurucul-xdr-uses-machine-learning-integration-for-real-time-threat-detection-incident-response-integration-developers.php","title":{"rendered":"Gurucul XDR Uses Machine Learning &amp; Integration for Real-Time Threat Detection, Incident Response &#8211; Integration Developers"},"content":{"rendered":"<p><p>To improve speed and intelligence of threat detection and response, Guruculs cloud-native XDR platform is adding machine learning, integration risk scoring and more.<\/p>\n<p>by Anne Lessman<\/p>\n<p>Tags:       cloud-native, Gurucul, integration, machine learning, real-time, threat detection,<\/p>\n<p>The latest upgrade to the Gurucul  XDR platform adds  extended detection and response alongside improved risk scoring to strengthen  security operations effectiveness and productivity.<\/p>\n<\/p>\n<p>Improvements to Guruculs cloud-native  solution also sport features to enable intelligent investigations and  risk-based response automation. New features include extended data linking,  additions to its out-of-the-box integrations, contextual machine learning (ML)  analytics and risk-prioritized alerting.<\/p>\n<\/p>\n<p>The driving force behind these updates is to  provide users a single pane of risk, according to Gurucul CEO Saryu Nayyar.<\/p>\n<p>Most XDR products are based on legacy  platforms limited to siloed telemetry and threat detection, which makes it  difficult to provide unified security operations capabilities, Nayyar said.<\/p>\n<\/p>\n<p>Gurucul Cloud-native XDR is vendor-agnostic  and natively built on a Big Data architecture designed to process, contextually  link, analyze, detect, and risk score using data at massive scale. It also uses  contextual Machine Learning models alongside a risk scoring engine to provide  real-time threat detection, prioritize risk-based alerts and support automated  response, Nayyar.added.<\/p>\n<\/p>\n<p>Gurucul XDR provides the following  capabilities that are proven to improve incident response times:<\/p>\n<\/p>\n<p>AI\/ML Suggestive Investigation and Automated  Intelligent Responses: Traditional threat hunting tools and SIEMs focus on a limited number of use  cases since they rely on data and alerts from a narrow set of resources. With  cloud adoption increasing at a record pace, threat hunting must span hybrid  on-premises and cloud environments and ingest data from vulnerability  management, IoT, medical, firewall, network devices and more.<\/p>\n<\/p>\n<p>Guruculs  approach provides agentless, out-of-the-box integrations that support a  comprehensive set of threat hunting applications. These include: Insider threat  detection, Data exfiltration, Phishing, Endpoint forensics, Malicious processes  and Network threat analytics.<\/p>\n<\/p>\n<p>Incident Timeline, Visualizations, and  Reporting: Automated Incident  Timelines create a smart link of the entire attack lifecycle for pre-and  post-incident analysis. Timelines can span days and even years of data in  easy-to-understand visualizations.<\/p>\n<\/p>\n<p>Guruculs  visualization and dashboarding enables analysts to view threats from different  perspectives using several widgets, including TreeMap, Bubble Chart, etc., that  provide full drill-down capabilities into events without leaving the interface.  The unique scorecard widget generates a spider chart representation of cyber  threat hunting outcomes such as impact, sustaining mitigation measures, process  improvements scores, etc.<\/p>\n<\/p>\n<p>Risk Prioritized Automated Response: Integration  with Gurucul SOAR enables analysts to invoke more than 50 actions and 100  playbooks upon detection of a threat to minimize damages.<\/p>\n<\/p>\n<p>Entity Based Threat Hunting: Perform contextual threat hunting or  forensics on entities. Automate and contain any malicious or potential threat  from a single interface.<\/p>\n<\/p>\n<p>Red Team Data Tagging: Teams can leverage red team exercise data  and include supervised learning techniques as part of a continuous AI-based threat  hunting process.<\/p>\n<p>According to Gartner, XDR products aim to  solve the primary challenges with SIEM products, such as effective detection of  and response to targeted attacks, including native support for behavior  analysis, threat intelligence, behavior profiling and analytics.<\/p>\n<\/p>\n<p>Further, the primary value propositions of an  XDR product are to improve security operations productivity and enhance  detection and response capabilities by including more security components into  a unified whole that offers multiple streams of telemetry, Gartner  added.<\/p>\n<\/p>\n<p>The result, the firm said, is to present  options for multiple forms of detection and . . multiple methods of response.<\/p>\n<\/p>\n<p>Gurucul XDR provides the following  capabilities that are proven to improve incident response times by nearly 70%:<\/p>\n<\/p>\n<p>Surgical Response<\/p>\n<p>Intelligent Centralized Investigation<\/p>\n<p>Rapid Incident Correlation and Causation<\/p>\n<\/p>\n<p>Gurucul XDR is available immediately from  Gurucul and its business partners worldwide.<\/p>\n<\/p>\n<p>back<\/p>\n<p><!-- Auto Generated --><\/p>\n<p>Continued here:<br \/>\n<a target=\"_blank\" href=\"https:\/\/www.idevnews.com\/stories\/7421\/Gurucul-XDR-Uses-Machine-Learning-Integration-for-Real-Time-Threat-Detection-Incident-Response\" title=\"Gurucul XDR Uses Machine Learning &amp; Integration for Real-Time Threat Detection, Incident Response - Integration Developers\" rel=\"noopener noreferrer\">Gurucul XDR Uses Machine Learning &amp; Integration for Real-Time Threat Detection, Incident Response - Integration Developers<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> To improve speed and intelligence of threat detection and response, Guruculs cloud-native XDR platform is adding machine learning, integration risk scoring and more. by Anne Lessman Tags: cloud-native, Gurucul, integration, machine learning, real-time, threat detection, The latest upgrade to the Gurucul XDR platform adds extended detection and response alongside improved risk scoring to strengthen security operations effectiveness and productivity. <\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[27373],"tags":[],"class_list":["post-46596","post","type-post","status-publish","format-standard","hentry","category-machine-learning"],"_links":{"self":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts\/46596"}],"collection":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/comments?post=46596"}],"version-history":[{"count":0,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts\/46596\/revisions"}],"wp:attachment":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/media?parent=46596"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/categories?post=46596"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/tags?post=46596"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}