Stellar Cyber updated its extended detection and response (XDR) platform with a new XDR Kill Chain that the security vendor says stop attacks quicker.

The new version builds on the MITRE ATT&CK framework, but is purpose built for XDR, according to Sam Jones, VP of product management at Stellar Cyber.

“It became clear to us that the kill chains on the market today were not sufficient for XDR,” which Stellar Cyber defines as “everything detection and response,” because the promise of XDR is to protect the entire attack surface, Jones said.

An XDR kill chain “really requires full attack characterization, and it needs to be simple enough to be widely adopted in an industry that we know has huge talent and training shortages,” he added.

Stellar Cyber previously used the decade-old Lockheed Martin Cyber Kill Chain, but Jones said it hasn’t kept up with the way attacks have evolved. Plus, the Lockheed Martin version isn’t compatible with the MITRE ATT&CK framework.

“So we developed our own kill chain that’s fully compatible with MITRE ATT&CK, but also extends it, so it can better differentiate between things like internal and external attacks and lateral movement,” Jones explained.

Stellar Cyber added the XDR Kill Chain into the new version 4.0 of its Open XDR platform. It features a loop that prioritizes detections into five phases: initial attempts, persistent foothold, exploration, propagation, and exfiltration/impact. The model captures the progression of complex attacks so that incidents appear in the context of the five-phase kill chain to help security analysts more easily understand their priority and respond to the most critical threats first.

What Makes Stellar Cyber XDR Stellar

Stellar Cyber’s updated Open XDR platform comes as security vendors compete to differentiate themselves in the hot, newish sector.

XDR combines elements of security information and event management (SIEM); security orchestration, automation, and response (SOAR); endpoint detection and response (EDR); and network traffic analysis (NTA) in a software-as-a-service (SaaS) platform. This centralizes security data, threat hunting, and incident response.

Stellar Cyber, which started as an artificial intelligence (AI) based security analytics and threat detection vendor, calls its platform Open XDR because it integrates with customers’ existing third-party EDR, SIEM, NTA, and user and entity behavior analytics tools. Additionally, Stellar Cyber’s platform aggregates and correlates their data, applied AI-based analytics to inspect it, and automatically responds to threats through a single console.

“What we built as a vision never changed,” Stellar Cyber founder and VP of engineering Aimei Wei said. “At the beginning, we called it a security analytics platform, and the core of that was the need to progressively collect the data from all the attack surfaces: on prem, in the cloud, endpoint, user, network — all of the data. And then normalize it.”

The updated kill chain is an extension of this evolution, and both the new kill chain plus Stellar Cyber’s “open” platform, give it a competitive advantage, Wei added.

“If you look at the Gartner description of XDR, it’s exactly what we are doing, except they define it as everything has to come from one vendor. Our idea is it doesn’t have to be all from single vender,” she said. “And the fact that we do integrate with all the different types of security tools means that our customers do not have to rip and replace. We can work with what they have.”