AlienVault OSSIM was an open source Security Information and Event Management (SIEM). AlienVault was acquired by AT&T Cybersecurity, now LevelBlue, and OSSIM is no longer available for sale.
N/A
Microsoft Defender for Endpoint
Score 8.8 out of 10
N/A
Microsoft Defender for Endpoint (formerly Microsoft Defender ATP) is a holistic, cloud delivered endpoint security solution that includes risk-based vulnerability management and assessment, attack surface reduction, behavioral based and cloud-powered next generation protection, endpoint detection and response (EDR), automatic investigation and remediation, managed hunting services, rich APIs, and unified security management.
If this is your first experience with a SIEM, this one can get you started. Take the time to learn the ins and outs of the product and you'll most likely be satisfied with it if your company is an SMB. If you need compliance reports, OSSIM is too small for you, you'll need to go with USM or USM Anywhere.
It's well-suited if you're already a Microsoft shop, particularly if there are budgeting concerns or it's a smaller operation where you might not have the finances to have a more diverse toolset. Falling back on something built-in because you're already a Microsoft customer is really helpful. Areas where I would say it's less appropriate are if you're not already a Microsoft customer. If you're a Google shop, then maybe it doesn't make the most sense. And then I'd say if you have large budgets, a wide diversity of systems, or a very large footprint, then having something ancillary, or at least another tool, can be impactful as far as making sure you have better visibility.
Asset discovery. Once installed in a centric, network-accessible server, OSSIM can poll all your endpoints with common protocols (SSH, SNMP, WMI) to detect and discover site-wide assets to monitor. You only need to group them by your own criteria once added to the product.
SIEM Event Correlation. You can define quite complex correlation rules to detect possible suspicious or malicious actions or attempts in your network, in order to categorize them as real threats or as false positives, thus streamlining your risk assessment and management.
Ease of installation. The entire AlienVault OSSIM is self-contained in an ISO file, which can be burned into a DVD or just mounted in your server of choice (physical or virtual) for deployment. The installation process is automated and quote verbosed, with options for static IP, email messaging and others.
Ease of access. Being AlienVault OSSIM a self-contained appliance, it can be accessed via web by any device that supports a web browser, being that desktops, workstation, mobile devices, etc. The OSSIM dashboard and other features are automatically rearranged to adapt to the particular device being in use.
The big thing for us is on endpoint, it kind of integrates with everything else that we already have because we use Microsoft completely. And so that helps us with being able to integrate, and send things over to Azure Sentinel as we need to as well.
Differently. The biggest thing is that if there is a particular update to it that, for whatever reason, is incompatible with, like, an EHR or some software that we have, there is no easy way to roll back. There's not just like a one click rollback or anything like that. So we have to get in and do that. We've actually written a tool ourselves to manage that, so that's something that's missing.
Cost add-ons for Security features is nickel and diming the process to keep pace with cybercrime. Limited Education budgets require us to be more pro-active in finding cost-effective measures to protect our devices, staff and students. Defender is a strong, well-featured product that is pricing itself out of the education market
AlienVault OSSIM is far easy to use and manage - provided you know what you're doing. As any SIEM application, there is some background knowledge required in order to take advantage of the product's functionalities, such as the log correlation and analysis. Other than that, the application is quite usable and robust.
It's fairly good whenever you talk about leveraging it, but your staff just has to go read the tech articles. Microsoft does a great job of producing Microsoft technical articles. And so if you can go out there and take the time to read them, you will learn how to do it. It's just not intuitive from the screen if you're just kind of going through it for the first time.
Microsoft Defender for Endpoint chugs along just fine no matter what we throw at it and what systems it's running on. It doesn't take up a lot of resources either, so that's welcomed.
Everything is done through MSSP and installation pro services. Once those hours are burned up, then you're on your own without a lot of help. Typically the pro services hours aren't enough to get past 60 days and MSSP are hit and miss. We had a miss for installation helpers.
The first time I tried to onboard my macOS endpoints to MDE I struggled for quite a bit. I had to reach out to Microsoft's MDE support team. The tech was very helpful in walking me through the steps during a screen share session
Deployment was handled by our team here and everything went pretty smoothly. We did have a few hiccups in our test group, but that only took a bit to get ironed out.
Originally my organization leveraged alien value due to the lower cost of entry and ability to manage it as a service provider. Unfortunately, after several years of working with this tool, it became unwieldy to use as it felt that almost every useful report had to be created by hand. As other tools have come out with the ability to do automated responses such as Stellar Data processor, we have begun to evaluate alternatives.
I've used Sophos, Bitdefender, SentinelOne, and, of course, Microsoft Defender for Endpoint. We chose this at the time because we were such a Microsoft shop that it just seemed to integrate well with all the other things that we had set up with Microsoft.
I'd probably say improved security outcomes and reduced risks. Vulnerability management has been crazy over these past few years just because of the amount of vulnerabilities that are getting discovered and reported. But Microsoft Defender for Endpoint has given us great visibility around that, even though it's a lot. And from that data, we have used it to help fix vulnerabilities, work with our systems team, and work with the appropriate teams to get those vulnerabilities resolved.