With the proliferation of XDR (specifically managed XDR that includes SIEM and SOAR), has that taken market share from (and replaced) IPS, IDS, HIDS and other tools like Darktrace? I think Carbon Black was not specifically EDR but now they are. I get it that some tools, like running IPS on a firewall natively may perform better than XDR, but would it be "good enough" to have XDR that integrates with a firewall to dynamically modify rules? There is some tradeoff either way, but would having a centralized XDR solution be better than multiple point solutions for a small SOC? One of my core principles is that I rather use a mediocre product well vs having a big, more complex, product that I only use 25% of. Is XDR (if you have a specific one, you can mention it) good enough now to replace the misc point products mentioned? submitted by /u/Adventurous-Dog-6158
[link] [comments]
http://dlvr.it/TC0grP
Post Page Advertisement [Top]
General question about XDR/EDR, IPS, IDS, and HIDS
Hey there,I am a simple blogger who likes to blog to make you uderstand what are the stuff we can learn on the internet and how to learn it.I am here to make you learn and feel the energy of learning by doing.
Subscribe to:
Post Comments (Atom)
';
(function() {
var dsq = document.createElement('script'); dsq.type = 'text/javascript'; dsq.async = true;
dsq.src = '//' + disqus_shortname + '.disqus.com/embed.js';
(document.getElementsByTagName('head')[0] || document.getElementsByTagName('body')[0]).appendChild(dsq);
})();
No comments:
Post a Comment