The newly combined security giant McAfee Enterprise and FireEye joined forces with Amazon Web Services (AWS) to add extended detection and response (XDR) capabilities to the vulnerability management service Amazon Inspector. 

The new XDR offering incorporates the FireEye Helix platform with Amazon Inspector, aiming to offer better visibility and protection for applications and data in the cloud. The Helix platform is a software-as-a-service (SaaS)-based security operation platform that provides threat detection and response capabilities including security orchestration, automation and response (SOAR), and security incident and event management (SIEM). 

Amazon Inspector is an automated security assessment service installed in the operating system of customers’ AWS Elastic Compute Cloud (EC2) instances to improve application security and compliance.

“Threats in the cloud are unique because data is stored with a third-party provider and accessed over the internet, this means visibility and control over that data is limited,” Michelle Salvado, SVP of engineering at McAfee Enterprise and FireEye, said in a statement. “The combined technology and intelligence of McAfee Enterprise and FireEye protect AWS customers by providing that additional visibility and control, reducing overall risk while also allowing for faster migration to the cloud and easier, more streamlined interoperability.” 

In addition, the Amazon Inspector integration extends Amazon Cloudwatch, Amazon VPC Flow logs, AWS Network Firewall, AWS CloudTrail, Amazon GuardDuty, AWS Security Hub, Amazon Simple Storage Service (Amazon S3), and Amazon Route 53 services to existing FireEye AWS offerings. Around 600 different security and business applications supported by the Helix platform can now share data. 

The integration announcement came after the completion of the McAfee and FireEye combination.

Private equity firm Symphony Technology Group (STG) acquired both vendors earlier this year. STG paid $4 billion for McAfee’s enterprise security business in March, and closed its sponsored acquisition of FireEye in an all-cash deal totaling $1.2 billion in October, which completed the merger.

McAfee Enterprise and FireEye Join AWS ISV WMP

McAfee Enterprise and FireEye also announced plans to join the AWS ISV Workload Migration Program (AWS ISV WMP). The company intends to provide a repeatable blueprint to migrate on-premise security services to AWS SaaS, platform-as-a-service (PaaS), and infrastructure-as-a-service (IaaS) security products. 

Under the program, McAfee Enterprise and FireEye will offer cloud migrations; cloud governance and compliance; threat protection for endpoint, network, and email; cloud access security broker (CASB); and cloud security operations services, the company claims.

McAfee Platform Supports AWS Detective

In addition to Amazon Inspector, McAfee’s Mvision Cloud for AWS platform already supported Amazon Detective, which is a service that helps customers conduct large-scale investigations. 

The integration was designed to detect misconfigurations and other cloud risks using McAfee’s cloud security platform, and then move into the investigation phase with Amazon Detective. McAfee’s platform also provides integrated CASB functionality such as data loss prevention and malware detection, as well as user behavior and threat analytics that go beyond detecting basic configuration issues.