10-14+ Days This item will be shipped directly from the manufacturer. Leadtime to shipment will be a minimum of 10-14 working days. Call for further shipping details.
-
(888) 912-3151
or
E-Mail
With the XDR Cloud Sensor, GravityZone XDR monitors activity that may indicate whether the security of cloud environments, such as Amazon Web Services (AWS), has been compromised. The sensor monitors for multiple indicators of attack.The Cloud Sensor recognizes anomalies by, first, establishing a baseline of normal behavior and then identifies when detected actifities deviate from the baseline. GravityZone detects when a user performs an action outside of the baseline, when a file with a suspicious extension has been uploaded and deviates from the baseline behavior, when a cloud function performs an action outside of the usual scope of activity, and other cloud-specific detections.In addition, the Cloud Sensor identifies suspicious activity associated with many granular cloud service functions such as AWS Lambda. The sensor detects when an attacker has executed a Lambda function that triggers a suspicious action. For example, it can distinguish when suspicious automatic code execution has been performed, such as using a Lambda function to create an access key to backdoor an AWS Identity and Access Management (IAM) user. As another example, when a Lambda function is used to update a security group to allow ingress on a port, GravityZone XDR will identify this as a maneuver that may allow an attacker to access the cloud instance.The GravityZone XDR Cloud Sensor detects other suspicious behavior such as when an unfamiliar user or host removes the default encryption from an AWS Simple Cloud Storage (S3) bucket. By performing this action, the attacker exposes all encrypted objects (using server-side encryption) in that S3 bucket. XDR detects when an attacker disables or removes monitoring services such as stopping Amazon's logging service, CloudTrail, or deleting logs from the AWS monitoring service, CloudWatch. It also identifies when an attacker has performed reconnaissance events against an S3 bucket. GravityZone XDR can also reveal when a user has logged in from multiple regions simultaneously, a typical indicator of a compromised account.
Security applications - content filtering, security suite
Product Type:
Subscription license renewal - 1 year
Licensing
License Qty:
1 license
License Pricing:
Academic, volume / 100-149 licenses
Unified visibility Leverage access to multiple sensors for automated incident assembly across endpoints, identity, network, cloud and productivity applications. Turn siloed data into actionable insights and get a view across your entire organization, as well as individual endpoints, enabling seamless detection and response.
Detection, response, prevention Understand an incident with a graphical, intuitive view of the entire attack lifecycle, the impact on the organization, and any correlated incidents. Quickly determine root cause with analysis to define security protocols and prevent similar attacks in the future.
Single-click response Turn insights into action across your environment. The response framework delivers guided response actions to quickly execute intelligent incident response.