Stellar Cyber integrated third-party threat intelligence feeds into its extended detection and response (XDR) platform, which the security vendor says means customers don’t have to subscribe to and manage third-party feeds.
The move natively integrates Stellar Cyber’s Threat Intelligence Platform (TIP) with its Open XDR platform.
TIP is a cloud-based platform that automatically collects and aggregates feeds from many different sources. These include commercial and non-commercial threat intelligence from organizations such as Proofpoint, DHS, OTX, Openphish, and PhishBank, as well as Stellar Cyber’s internal research data collected from its deployments. Customers can also integrate other third-party threat feeds into Stellar Cyber’s Open XDR platform.
TIP supplies threat information to the XDR platform’s analytical engines. The engines then process and analyze this data, and, if needed, the platform then remediates the threats.
XDR is a newish and very hot cybersecurity buzzword at the moment that combines elements of security information and event management (SIEM); security orchestration, automation, and response (SOAR); endpoint detection and response (EDR); and network traffic analysis (NTA) in a software-as-a-service (SaaS) platform. This centralizes security data, threat hunting, and incident response.
Stellar Cyber calls its platform Open XDR because it integrates with customers’ existing third-party EDR, SIEM, NTA, and user and entity behavior analytics (UEBA) tools. Additionally, Stellar Cyber’s platform aggregates and correlates their data, applies artificial intelligence (AI) based analytics to inspect it, and automatically responds to threats through a single console.
The new TIP integration amplifies the XDR platform’s threat detection, investigation, hunting, and response capabilities, and it also delivers bi-directional feeds so that the Open XDR platform grows smarter over time. TIP sends feeds down to the Open XDR platform’s analytical engine, and customers can send new threats up to the TIP, which provides additional information and benefits all Stellar Cyber customers.
“Threat intelligence feeds are critical to effective cybersecurity defense, but subscribing to and integrating them into a disjointed security infrastructure is problematic,” IT-Harvest analyst Richard Stiennon said in a statement. “Integrated TIP eliminates this issue for the security operations team.”
Comments