Arctic Wolf - Another Layer of Protection
Rating: 8 out of 10
IncentivizedUse Cases and Deployment Scope
Agents installed on all end points and servers. Monitoring location, logins and potential malicious file and scripts running. Email alerts sent to specified contacts and phone call if issue severity is high. Location based alerts for 365 accounts will trigger when a user account is accessed outside of whitelisted countries.
Pros
- Monitoring 365 logins
- Monitoring Windows processes
- Active Directory monitoring
Cons
- Some erroneous 365 alerts about failed logins
- Need an easier method to suppress alerts (outside of email)
- Too many places to look for info in console
Likelihood to Recommend
Arctic Wolf is a great tool to run in parallel with end point protection. It gives you some good weekly reports on locations, IP addresses, traffic, Active Directory and can be run on demand to categories specified. The quarterly meetings cover quite a bit of information and their support team is always there to assist.
