Cofense Vision stores emails offline and provides threat hunting analytics. Cofense Vision allows the user to search and quarantine emails in minutes — across an entire organization, and is designed to provide threat hunting at speed.
N/A
Microsoft Sentinel
Score 8.5 out of 10
N/A
Microsoft Sentinel (formerly Azure Sentinel) is designed as a birds-eye view across the enterprise. It is presented as a security information and event management (SIEM) solution for proactive threat detection, investigation, and response.
It is well suited in environments where there is a high mail traffic to handle. [Cofense] Vision basically journals the exchange server and keeps a copy of the mail received in the environment. Really beneficial to revoke and quarantine the mail reported by one user, but footprint is there in other mailboxes as well. Less appropriate in the cases where there is no proper segregation of duties within the organization. As it is possible to see contents of the mail. Only authorized personnel should be able to use it.
If you're already a Microsoft shop, it is the option. That's the only one. If you're not a Microsoft shop or not very deep into it, like E5 licenses, I'd say you get much less out of it than you might from some other products.
The visual presentation of data is terrific, so including what we had prior to Microsoft Sentinel, it presents data in a much more usable way, so that's been quite refreshing. It's not quite as complex to understand what you're looking at.
It's hard to pinpoint anything that's wrong with it. It's the only thing is the cost. Everyone wants stuff cheaper, right? Because the product itself is hard to find flaws in, it does exactly what it says it does. I'd love to use it more, but the cost is too expensive, so you have to use it in specific use cases to drive down the cost. If you could open the floodgates, then you would basically use it more.
User interface and overall usability are critical for any security platform, and Microsoft Sentinel performs very well in this area. The UX design makes core functions intuitive and easy to access, which enables analysts to work efficiently and use the platform’s capabilities effectively.
Microsoft support is one of the highest rated on the market. It has global and multilingual support. Calls can be made over the phone and the solution is virtually instantaneous with the help of Microsoft engineers. It's great!
Apple of Discord is the pricing as we were looking for an email security tool in reasonable pricing and Barracuda was undoubtedly efficient in action and was compatible with our business but it was highly expensive and then we made up our mind for another tool and Cofense Vision was offering almost the same as Barracuda but cheaper.
These are all the Microsoft products. We have used Splunk. And again, I would say Microsoft Sentinel stacks up because it's a native tool that is more like an ecosystem. It's not a standalone tool. It's like if you're in the Microsoft stack, Microsoft Sentinel will stack up best to use these things. And of course, Microsoft Sentinel works across clouds as well. So I would recommend Microsoft Sentinel over Splunk or other options.
As any cybersecurity product, this has to be more with risk to avoid loss in case of a ransomware that more than relate to a productivity increase. Maybe the impact could be that instead of having people that are checking 24/7 the dashboard, you could implement Sentinel and have less people checking that or people with less expertise. So the saving will be a minor but will be a saving in the cost of your team.