Google Cloud and CrowdStrike today said they extended their partnership beyond its primarily endpoint focus to now span customers’ hybrid cloud environments. Through a series of product integrations, the companies say that customers can now share telemetry and data between Google Cloud’s security products and CrowdStrike’s Falcon platform. This, they add, provides better visibility, workload protection, and defense-in-depth security across customers’ entire environments.
It sounds a lot like extended detection and response (XDR). But Google Cloud VP of Cloud Security Sunil Potti says it’s beyond XDR.
“Is this directionally aligned with where things are going with XDR? Probably,” Potti said. “If there was a market to align with, that’s probably the market. But on the flip side, this does many other things.”
Under the new partnership, Google Cloud’s Chronicle security analytics engine will integrate with CrowdStrike’s Falcon security platform, which is says processes more than 5 trillion endpoint-related events per week. The companies say this integration will help security teams analyze endpoint and workload telemetry to find threats more quickly, and correlate petabytes of data from Chronicle with datasets from Falcon to better investigate long-term attacks and stop new ones.
VirusTotal, Google Cloud’s crowdsourced malware collection platform, will also integrate with Falcon and be available through the CrowdStrike Store. This will allow teams to search for and identify files or URLs that are relevant to an investigation, uncover previously unknown threats, track adversaries, and generate detection rules that can eliminate blind spots in their hybrid infrastructure.
Google Cloud Security Command Center will aggregate alerts and events from the CrowdStrike Falcon platform to provide a single view of security and compliance across a customers’ cloud environment.
And finally, Google Cloud’s BeyondCorp Enterprise and Google Workspace will also integrate with Falcon Zero Trust Assessment to allow joint customers to create and enforce granular access policies to applications using CrowdStrike’s risk signals. Additionally, CrowdStrike will offer integrations with Google Cloud’s Security Agent Deployment, which uses Operating System Configuration Management for automated and scalable sensor deployment.
If It Walks Like a Duck …XDR combines elements of security information and event management (SIEM); security orchestration, automation, and response (SOAR); endpoint detection and response (EDR); and network traffic analysis (NTA) in a software-as-a-service (SaaS) platform. This centralizes security data, threat hunting, and incident response.
The Google Cloud and CrowdStrike integrations check all of the XDR boxes. “But this does many other things,” Potti said. “For example, bringing the [VirusTotal] malware pieces much more tightly coupled in the context of a CrowdStrike detection and response workflow is less about being an XDR, it’s more about what I call using data, just at your fingertips.”
Potti describes this approach as a “Google Assistant for security. It’s this background layer of intelligence that’s in the background collecting and synthesizing and bringing some coherence, but in the foreground, you still use your primary app. And when you’re using your primary app, there’s a bunch of this contextual intelligence being provided,” which makes the security teams’ jobs easier.
“I don’t want to hold ourselves back from this vision by just saying it’s XDR,” Potti continued. XDR collects and analyzes all of these network and endpoint events, and for these capabilities, Chronicle plays a major role in the CrowdStrike integrations. “And then you provide some nice detection response workflows” from CrowdStrike’s workload protection and threat response.
“But there is a bigger opportunity, in our opinion, of having this invisible app, which is the equivalent of Google Assistant for security,” he said. “It is essentially an intentional way to track data across all these silos and derive intelligence from it, but then also bring it right in context of the jobs to be done.”
Comments