Palo Alto Networks launched Unit 42 managed detection and response (MDR), combining its Cortex extended detection and response (XDR) technology with analysis skills from one of the largest threat intelligence research teams to offer continuous threat detection, investigation, and response.
It’s “an extension of the work that our teams are currently delivering in terms of threat hunting with XDR, moving that into a managed detection or response capability, where we'll be offering it 24/7 around the globe,” Wendi Whitmore, SVP of Palo Alto Networks Unit 42, told SDxCentral.
Palo Alto Networks’ Unit 42 team has more than 200 cyberthreat researchers including threat hunters, malware reverse engineers, and threat modeling experts. The MDR service expands the team which previously managed threat hunting capabilities for a subset of Cortex XDR customers under the Unit 42 umbrella, Whitmore added.
This proactive threat hunting capability uses data sources and threat intelligence from the vendor’s Cortex XDR platform and other products.
The MDR team reviews and analyzes the alerts and the most current and relevant threats customers are facing, and leverages Cortex XDR data sources to get the answers, “so that we can really prevent them from being victims to the latest malware campaigns, for example, or the latest vulnerabilities being exploited by threat actors,” Whitmore said.
The Unit 42 experts will also provide periodic cyber health checks and detailed recommendations on policy changes. And the MDR service will offer a dashboard for users to access alerts and events, she added. It’s “one-stop shopping for their organizational health.”
Addressing Alert Fatigue and the Talent GapMany MDR services target small- and medium-sized businesses, but Unit 42’s MDR service benefits companies of all sizes, Whitmore touted.
“There are a lot of pretty large organizations who are really looking to have a partner that can help supplement their existing staff,” she said, adding that a partner such as Unit 42 has unique insights on the XDR technology and a macro picture of the threat actors and landscape.
Based on those insights, the MDR service can not only prioritize alerts but also “clear” those alerts for users.
“We're actually able to resolve much of those situations ourselves, and that enables us to then only escalate a much smaller subset of those alerts to the client where it involves … the business risks or a business operational decision that needs to be made," Whitmore said.
When an alert becomes a significant event that requires an additional level of analysis, the team will escalate and make sure customers are aware of the event, she added.
In addition to alert fatigue, this also addresses the talent gap that the industry is facing. For smaller companies, they can benefit from the management service; and for large companies, the MDR can provide an outside team to supplement their security teams, according to Whitmore.
Comments