With the proliferation of XDR (specifically managed XDR that includes SIEM and SOAR), has that taken market share from (and replaced) IPS, IDS, HIDS and other tools like Darktrace? I think Carbon Black was not specifically EDR but now they are. I get it that some tools, like running IPS on a firewall natively may perform better than XDR, but would it be "good enough" to have XDR that integrates with a firewall to dynamically modify rules? There is some tradeoff either way, but would having a centralized XDR solution be better than multiple point solutions for a small SOC? One of my core principles is that I rather use a mediocre product well vs having a big, more complex, product that I only use 25% of. Is XDR (if you have a specific one, you can mention it) good enough now to replace the misc point products mentioned? submitted by /u/Adventurous-Dog-6158
[link] [comments]
http://dlvr.it/TC0grP
Post Page Advertisement [Top]
Subscribe to:
Post Comments (Atom)
';
(function() {
var dsq = document.createElement('script'); dsq.type = 'text/javascript'; dsq.async = true;
dsq.src = '//' + disqus_shortname + '.disqus.com/embed.js';
(document.getElementsByTagName('head')[0] || document.getElementsByTagName('body')[0]).appendChild(dsq);
})();
No comments:
Post a Comment