Exabeam recently became the latest security vendor to pivot to extended detection and response (XDR) with its Fusion XDR product.

The move makes sense for the security analytics vendor that started as next-generation security information and event management (SIEM), with its sights set on taking down Splunk and IBM. It already provided cloud-based analytics and automation across customers’ environments, so, in many ways, adding XDR just puts a new name on what Exabeam already delivers to customers, according to Chief Product Officer Adam Geller.

XDR, while a still newish security segment, combines elements of SIEM; security orchestration, automation, and response (SOAR), endpoint detection and response (EDR); and network traffic analysis (NTA) in a cloud-based platform. This centralizes security data, threat hunting, and incident response.

“What led to Exabeam Fusion XDR: It defines what we’ve been doing for the past several years with our analytics, detection, and response capabilities when we’re not being a full SIEM,” Geller said, adding that Exabeam does this by correlating and analyzing data from third-party vendors’ agents and connectors across endpoints, cloud workloads, and the network.

“We already analyze data from hundreds of vendors in thousands of different formats to synthesize those into security events that can be built together into a story or a timeline that shows what’s happening in an incident across an entire environment,” he explained. “So, when we looked at this emerging world of what is XDR, we have already been moving down that path. So we felt very comfortable being able to stake a claim and say yes, what we’re doing is absolutely XDR.”

Exabeam Fusion XDR Meets Fusion SIEM

In tandem with Fusion XDR, the security analytics vendor also rolled out Fusion SIEM, its cloud-delivered security information and event management product. Exabeam’s Geller says the two products work together to provide threat detection, investigation, and response via an open XDR approach that works with customers’ existing technology stacks.

“There are many customers today who use Exabeam as an augmentation to an existing SIEM,” he said. “So they have a data lake, whether it’s an actual SIEM or just a data lake, they have a place where they store logs and alerts, and they use Exabeam for threat detection, investigation, and response capability — that is our advanced analytics capability — as well as our SOAR capabilities. All of that together is what Fusion XDR is all about.”

Fusion XDR combines Exabeam’s behavior analytics; threat detection, investigation, and response (TDIR) analytics; and “hundreds” of pre-built, third-party security integrations, along with its newer TDIR use-case packages. These provide prescriptive workflows and other content around data sources, detection models, watchlists, investigation checklists, and response playbooks designed to assist security analysts.

“Many of our customer deployments use what we’re now calling Fusion XDR, and they don’t use Exabeam’s data lake,” Geller said. “Early on, they would use us on top of Splunk, or on top of [IBM] QRadar, or on top of ArcSight,” he added, referring to other SIEM and security analytics tools.

“Increasingly now, we get the question of how do you do this on top of data that’s in Snowflake, or Azure Sentinel, or Google Chronicle, or stored in AWS Storage buckets? We can do that, and leverage data stored somewhere else. It’s not required to be in our data lake,” Geller said.

Fusion SIEM, meanwhile, includes all the Fusion XDR capabilities plus access to centralized log storage, search, and compliance reporting.

This two-pronged approach, as Geller calls it, works well for Exabeam and its customers. On one hand, “we replace SIEMs all the time,” he said. “That will continue to happen.”

But on the other hand, cloud providers and top data lake vendors like Snowflake provide cost-effective data management and storage for customers. “We need to make sure that we can integrate with those, and we can’t say that the only way our stuff works is if you bring your data into our data lake,” Geller said.

“There will be one set of customers that do not have a security data lake, and they’re going to look to Exabeam and say, ‘I want Fusion SIEM because I just need all of this together, and you’re a leader in this space,’” he continued. “There’s another set of customers though that will say, ‘I’m already leveraging a cloud data store or the like. Can you integrate with that, and leverage the data that you need out of that, but not have to replace the entire thing or just copy all the data over to your own data lake?’ And in that case, the answer is absolutely yes, that is what we do with Fusion XDR.”