As a network-based threat detection solution, Attivo BOTsink stands guard inside the business network, using high-interaction deception and decoy technology to lure attackers into engaging and revealing themselves. Through misdirection of the attack, the vendor states organizations gain the advantage of time to detect, analyze, and stop an attacker.
N/A
FortiDeceptor
Score 10.0 out of 10
N/A
FortiDeceptor is a deception-based breach protection that helps users deceive, expose and eliminate external and internal threats.
It is best suited when deployed at perimeter and integrated with SIEM and SOAR solution. It will be able to replicate assets and display realistic configurations making difficult for hackers. We were able to avoid or block 40% of attacks targetted to our critical servers and could easily identify threat actors.
To help the Infosec Team Scale & create a seamless consolidated threat response. FortiDeceptor all the Security analysts to manually investigate & manual remediation or automatically block these attacks based on severity before actual damage occurs via integration with Fortigate to quarantine the IP address of the threat actor, FortiNAC to isolate devices within an organization with FortiSOAR to trigger appropriate playbooks for an orchestrated response and with 3rd party solutions to trigger a response action via built-in fabric connector API. FortiDeceptor needs other FortiFabric Devices to respond well, however, FortiDeceptor also connects with other solutions via built-in fabric connector API, but you may miss the real-time data flow or may be delayed in response.
Attivo BoTsink was selected based on cost price and wide coverage of detection capabilities. Our decision was primarily based on reducing efforts to identify and mitigation of attacks. The ease of deployment was additional factor in decision making. As compared to Zscaler Deception and SentinelOne Singularity I found Attivo BoTsink detects more threats
Since we have other Fortinet solutions like Fortigate NGFW & FortiSIEM in place, they share the threat intelligence with each other, and FortiDeceptor works very well in FortiFabric environments, We decided to go with FortiDeceptor for Deception technology. In the case of Rapid7 & Smokescreen, we had to counter the integration issue with existing IT infra, Security solutions should not work in silos, they need to share intelligence with each other to get the best from the existing Solution & to get the best ROI.
Internet security is a gamble. It's hard to know the cost of a "would-be" attack. FortiDeceptor is basically an insurance policy and for that, it is a great investment.