Cofense Triage accelerates phishing qualification, investigation, and response by automating standard responses to suspicious emails to make analysts more efficient and driving out actionable intelligence, and providing incident response playbook.
N/A
FireMon
Score 7.9 out of 10
Enterprise companies (1,001+ employees)
FireMon is a real-time security policy management solution built for today’s complex multi-vendor, enterprise environments. Supporting the latest firewall and policy enforcement technologies spanning on-premises networks to the cloud, FireMon delivers visibility and control across the entire IT landscape to automate policy changes, meet compliance standards, to minimize policy-related risk. Since creating their policy management solution in 2004, FireMon states they've helped…
Triage is an excellent solution for analysing and triaging emails. It has a set of rules which can be used to rate the risk of meaages, these rules are updated on a daily basis to keep up with known IOCs of attackers. The support from Cofense is also excellent and reaching out …
Cofense Triage is the product that has been used in the organization for almost 3 years now the overall performance triage shows is always good and never disappointing with every new release of the version they come up with the features which customers tell them as feedback or …
The main purpose we [chose] Cofense Triage [is to] secure our environment from phishing emails. The phrasing of reported emails is accurate. It has abundant information about reported emails.
Cofense Triage has a much better GUI and rate of understanding the mails when reported by the user. The overall setup with other Cofense products gives an excellent opportunity to complete the email security suite of the organization. The info and intel provided within Cofense …
The other product had a lot of fails on the auto-processing and did not integrate well with our current environment. One issue had to do with the way it sends the submissions to its processing engine—our email gateway configuration would have blocked this traffic. I also did …
I was not involved on the decision but having multiple brands in the company make sense to use a tool such as Firemon because it integrates easily with multiple vendors.
The Dell product ran on its own hardware, which failed often. The reports were not available to us in real-time, we had to request them. Many false detections of issues.
Both perform admirably with regards to providing that single pane of glass and visibility in a normalized view. They both provide great insight into where your organization stands in terms of compliance controls. In terms of upgrading and scalability, I would have to give the …
I has worked with Algosec and while they are very similar product, I find the FireMon is easier to understand and get rolling with. While both require some learning, FireMon is by far the easier one. Once you have an understanding of how things are arranged and labeled you can …
FireMon has the most supported devices. The UI is easy to use and intuitive. There is a comprehensive list of built in compliance controls that are missing in the competition.
To be blunt, at the time of purchase most of these products appeared to do the same things in the same ways. What really brought us to the table with FireMon six years ago was their willingness to earn our business, and to this day they remain just as committed to keeping our …
They are two very well done tools, FireMon is better suited for firewall rules evaluation, configuration and review, Tenable.io is better suited for CIS benchmarking. We ended up using both of them in the end, it really depends of your needs and what you are looking for, the …
We performed a head-to-head PoC between FireMon and AlgoSec several years ago. Both platforms were well developed, but FireMon had the upper hand in three areas:
Its UI was more unified and intuitive across the different components and products
AlgoSec and Tufin both have initial issues during the POC stage, and FireMon even though with the changes they have made still works better and is more user friendly.
The tool is very helpful in improving Phishing detection capabilities as it streamlines the process of analyzing user reports a lot. Besides it has a built-in mechanism of rating reporters(end-users) based on their historical performance. Downside - tool requires continuous resource investment to deliver best result. Tool is not helping too much in improving user-education, because automated response process is not immediate and is prone to errors
FireMon is best used in a large environment (for example, I have >100 firewalls in my environment). It's best used when trying to improve security posture and showing changes in firewall security over time. It might not be the best choice for smaller environments or those that aren't concerned about security management.
PCI Reporting - After identifying which firewalls and rulesets are in scope, producing a report artifact to satisfy PCI requirements on Firewall reviews is literally a two-click operation.
Storing Rule Metadata - FireMon stores metadata (prefilled fields, standard fields, and custom fields) for each rule in each policy which is valuable for context during firewall reviews in particular
API - FireMon exposes most if not all of its functionality via REST API
YARA rules, while the functionality is fantastic I've found that the documentation can be a bit confusing. Although, that might just be my personal experience.
Rare glitches make the send notification button unusable. This can be remediated by navigating to a different report, but [it] is a bit of a pain in the moment.
I would like to see a dark mode get added as well, but that's obviously a tertiary concern.
Once all the customization has been completed, the business is starting to see the return on investment. The visibility it provides into the network gear that is owned by other IT groups is immeasurable and has allowed us to apply standards across the board. The only thing I have concern with is their support documentation.
FireMon has been relatively stable overall. However, there have been a handful of times where we had issues with the console. For example, we couldn't update which devices to include in a security assessment. The initial suggestion from support was to just reboot it. It seems like there weren't many other options available such as to restart services before going to the extreme of a complete reboot.
I'm not sure we have the largest implementation of FireMon out there but we do have a few 1000 devices being probed by FireMon. Overall, the system's performance has been rock solid. The console refreshes quickly and reports are generated within an expected timeframe.
FireMon technical support is awesome! They respond quickly to our requests and they are well trained and very knowledgeable about the tool. Some issues have to be referred to the development team, but technical support largely provides solutions for any issues that we may have.
The other product had a lot of fails on the auto-processing and did not integrate well with our current environment. One issue had to do with the way it sends the submissions to its processing engine—our email gateway configuration would have blocked this traffic. I also did not like the user interface.
I has worked with AlgoSec and while they are very similar product, I find the FireMon is easier to understand and get rolling with. While both require some learning, FireMon is by far the easier one. Once you have an understanding of how things are arranged and labeled you can easily import firewalls and begin to work on them to improve them
Firemon Is easily scalable and maintainable with any size team. Although it requires some tech debt, it is well worth the time to invest to ensure compliance is visible and reports are accurate. Although our environment is very large we do not fully utilize the scalability of the Firemon product.
My company had nothing of this sort previously and we were stuck trying to make use of free resources and doing things very manually. Triage was a huge life saver in this area.
The ability to quickly respond to several users at once has been a great help.
It helps us save us time in determining what change was made and by whom.
Real time alerting is a great convenience in helping us know if something went wrong, we can immediately review the last report to determine what has changed.
Allows us to determine what rules are not used and if said rules are still required.