Cisco now offers advanced security analytics via the eponymous Cisco Endpoint Security Analytics, a solution that delivers Cisco AnyConnect endpoint data to prebuilt Splunk analytics and dashboards. The vendor states that the service provides deep endpoint insight that even EPP and EDR solutions don't address.
N/A
Cofense Vision
Score 9.2 out of 10
Enterprise companies (1,001+ employees)
Cofense Vision stores emails offline and provides threat hunting analytics. Cofense Vision allows the user to search and quarantine emails in minutes — across an entire organization, and is designed to provide threat hunting at speed.
Cisco Endpoint Security Analytics is best suited for larger environments that need a window into basic logs of what users are experiencing. It provides adequate protection. We have had some issues with false positive detection of apps that are common, especially when downloading program setup files and such. Overall, it is a decent product.
It is well suited in environments where there is a high mail traffic to handle. [Cofense] Vision basically journals the exchange server and keeps a copy of the mail received in the environment. Really beneficial to revoke and quarantine the mail reported by one user, but footprint is there in other mailboxes as well. Less appropriate in the cases where there is no proper segregation of duties within the organization. As it is possible to see contents of the mail. Only authorized personnel should be able to use it.
Cisco Endpoint Security Analytics is semi easy to use. However, the reports are sometimes a bit lacking in detail. We do get alerts when someone encounters something malicious. However, it would be nice to see a bit more detail as to where the malicious file came from so that we can better protect our network.
Cisco Endpoint Security Analytics is easier to use than any of these products and seems to offer a better level of security. Symantec has failed to deliver any kind of support or updates since the Broadcom acquistion. The other products seem to be more geared to home or small office use. We chose Cisco Endpoint Security Analytics because we trust the brand and it seems to offer more features than the competition.
Apple of Discord is the pricing as we were looking for an email security tool in reasonable pricing and Barracuda was undoubtedly efficient in action and was compatible with our business but it was highly expensive and then we made up our mind for another tool and Cofense Vision was offering almost the same as Barracuda but cheaper.