Much more room available for product improvement!
Use Cases and Deployment Scope
We barely got this functional. Implementation itself did not go as expected. Unstable and many false positives were provided as observations. Might have been better if we used this further. But the organization was not in a position to spend further time observing and rectifying the errors and issues. Therefore, we had to move out to another tool unfortunately.
Pros
- Complex attacks are identified frequently.
- Advanced thread intelligence.
- Privacy of all data is very well maintained.
Cons
- False positives were identified frequently.
- Implementing rules are a very complex process.
- UI crashes were spotted randomly.
- Deployment needs to be much smoother.
Most Important Features
- Advanced Threat Defense
- Modern Endpoint Security
Return on Investment
- Implementation did not go as planned. Therefore, time consumption was increased.
- Since we moved out of the tool, we had to consider another which costed time.
Alternatives Considered
IBM Security QRadar
Other Software Used
IBM Security QRadar, Wireshark, Microsoft Teams
