Cybereason EDR consolidates intelligence about each attack into a Malop (malicious operation), a contextualized view of the full narrative of an attack. Each Malop organizes the relevant attack data into an easy-to-read, interactive graphical interface, providing a complete timeline, the flow of the attack in the network, and any malicious communications. Remediation actions can be automated or accomplished remotely with a click. The Cybereason Defense Platform empowers analysts of all…
N/A
LevelBlue USM Anywhere
Score 7.6 out of 10
N/A
The LevelBlue USM Anywhere XDR platform (replacing the former AlienVault USM) delivers threat detection, incident response, and compliance management.
$1,075
per month
McAfee Total Protection (discontinued)
Score 5.1 out of 10
N/A
McAfee's Total Protection included antivirus and antimalware offerings for home and small businesses or home offices. This product line is not a focus for Trellix, the brand formed from the merger of McAfee and FireEye that offers business grade products. Trellix Endpoint Security is the company's product line for business endpoint security.
It doesn't rely on signatures, most parts of their detection are behavior-based, and their marketing says that they have the lowest false positive rate in the market. It composes our server and notebooks endpoint solutions to protect against external threats and block internal …
I have not personally used McAfee SIEM but have heard of it at MPOWER Cybersecurity summit. They are not as broad and easy to make compatible with other systems, but looks like they have performance and EPS really well done.
AlienVault is cloud based and offers more functionality than OSSIM such as cloud service monitoring like Office 365 and AWS, deployment of sensors for efficient deployment, and event integrations with the MITRE ATT&CK framework. USM also has a much improved GUI and allows for …
AlienVault USM works well for any company size. LogRhythm might be too much if your company is not already big, and the same can be said of McAfee Enterprise Security Manager. If this is your first SIEM, it's a really good choice and has nothing to envy from the others I'm …
AlienVault is generally more affordable than its competitors. It also includes a built-in OpenVAS vulnerability scanner - which most competitors don't have. It is a decent option, but is not as mature of a product as some of the more expensive options like Splunk and LogRhythm.
The AlienVault Unified Security Management is much more affordable than the above mentioned products. Installation and configuration is simplistic and provides much of the same dashboards and raw log viewing. The AlienVault USM does not include extra parts such as specific …
I looked into Splunk, QRadar, but they were way too expensive and the reviews weren't always great. I used McAfee ESM extensively at my prior job and the product is probably the worst in the SIEM space. We moved to AlienVault from ELK which, while a cool product, didn't do any …
It was a pretty even fight between Logrythm and AlienVault. The other two ended up outside our price range. The thing that made the big difference was that AlienVault was supported here in Canberra by a local firm (steadfastinfosec.com). Price wise AlienVault was a bit cheaper.
We are a SMB security firm, so we have a focus on analyzing complex events/ attacks trends, possibily leveraging not-so-expensive security products: AlienVault USM has a perk on that, by delivering an essential but state-of-the-art analysis environment.
AlienVault is way cheaper than the other products for the five capabilities that it provides. However, the market is changing a lot and there are certain features that AlienVault has to think about on their roadmap if they want to stay ahead of competition. Live Response IR …
When comparing the differences between all these programs we noticed that AlienVault Unified Security Managementblew the competitors out of the water not only in pricing but in so much more. The features that they were offering were not only amazing selling points but some of …
AlienVault Unified Security Management solution is extremely flexible and customisable when compared to other SIEM tools such as Splunk, HP ArcSight, LogaRythm etc. The log collectors supported by most of the SIEM tools are mostly limited, and writing new collectors involves a …
I'd recommend Cybereason due to it's efficacy, low TCO, low false/positive rate. The product was easy to implement and maintain. One of the major advantages of using Cybereason is that it requires minimal training for level 1 users to use the tool.
At this point I'm saying a 4. While the marketing material make it appear to be easy to use and it was relatively easy to set up, as previously mentioned, each event description is based upon the individual asset making it nearly impossible for the administrator to be a SME for each asset. For example, if one of the assets reporting is a router, the administrator monitoring alerts would need to know what the various events are that can be triggered as an event for the particular router; however, if the asset is a workstation, the administrator would need to know the various events that are triggered for workstations.
I think McAfee is great to have whether it's for work or for personal use. While it has some drawbacks, I like the peace of mind of feeling safe when I'm browsing the web/email, especially when my computer has sensitive/confidential information, knowing that McAfee will immediately detect any threats. The UI is extremely easy to navigate, which makes it easy for users regardless of how tech-savvy they are.
AlienVault USM is simple and easy to deploy. Sensors can be deployed in as little as 15 minutes through the setup wizard.
The USM UI is easy to understand. I've trained multiple analysts who are able to perform their duties on their first day, in part because of USM Anywhere's ease of use.
Top-notch built-in compliance templates and reporting features.
Personally, I've wished I could purchase a service that would configure AV for my environment. I get a lot of traffic on a daily basis and I almost need to hire an analyst that just works on AV.
Some of the filters when looking for a specific alert aren't that easy to use.
The centralized logging and retention for PCI compliance was our main driver, and it is meeting that need. Otherwise there has been enough frustration with the lack of documentation and the need to customize through the CLI that I would be open to alternatives.
McAfee has consistently delivered on its stated goals of providing comprehensive protection for our networks and systems. Due to their excellent work and follow through I have been, and will continue to be a loyal customer.
Once you are able to navigate the different panels, finding what you need is quite easily. Before getting used it it can be a bit of challenge . Each panel is quite well laid out and the filtering search capabilities are quite strong.
We do have issues with maintenance on the AlienVault USM as the disk fills up from time to time with other data sources. Sources for scanning logs and net flow data isn't calculated in regular disk maintenance and can easily fill up our disk if we do not keep an eye on it with some custom Nagios plugins. The system does properly trim logging data from logging sources properly.
With the latest release of AlienVault USM overall performance has not been an issue. We have noticed single source events per second does not scale well with the overall system. 2,000eps on a vmware system with a single source produces delays of up to an hour for us. Pages, reporting and even raw log searches are rather quick though.
The support we received from alienvault was excellent. They went above and beyond in making sure everything was working as it needed to be. They REALLY want their product implementation to be a success and our security goals be achieved. They are like a member of our security team.
I did not have any experience with "in person" training directly. The free online classes offered for a half a day are based on the actual training offered. These little teasers are very good and well worth your time to learn a few quick and dirty ways of getting more information from your SIEM
It was very well organized and helpful in using the product to the fullest extent. The instructor allowed time for folks who were involved with managed services to receive tuning tips in order to better support their customers. In addition, the course materials were automatically updated when the new version came out.
AlienVault USM was a very simple to implement and get up and running. We started with a trial version and had that up and going within an hour of receiving email instructions from the sales engineer. We never had to contact support to get the system up and going. It was extremely easy to convert over to a full license once we started with a paid version.
Cybereason provides superior protection than either Microsoft or CrowdStrike and a better TCO. We receive less false positives than with Microsoft Defender and Cybereason is easier for level 1 users to use.
Splunk's ES is a paid add-on on top of an already pricey product. Finding a MSSP that supports Splunk and isn't a 6 figure annual commitment seems unlikely. LogRhythm did not have a cloud-based solution when we were considering SIEMs. Fantastic product though and have a good MSSP base. Devo did not have a MSSP partner base when we looked. Their product is fantastic too. AlienVault USM has good partners to choose from as well as an affordable cloud model, that's why we chose it.
I haven't used Norton for a while, but when I did use it I felt that it slowed down my computer and had constant pop-ups, which were both equally frustrating and annoying. It was also very difficult to remove from my computer. Malwarebytes is a great, straightforward program I've used for virus scanning. It's pretty bare bones but I think if you just want something to scan for viruses it gets the job done quickly and reliably. In my opinion McAfee offers similar benefits as Norton but its more intuitive and doesn't impact system performance.
The AlienVault USM is not very scalable. Some scalability can be achieved by installing additional sensors, but this only offers 500eps per sensor and is still overall limited by the installation type of VM or physical. We have also noticed the EPS (events per second) is rated overall and not towards a single source. A single source on a very healthy VMware partition tops out at 2,000eps for us, no matter how we configure it. Maybe this is a problem of the 5.2 release?
Once you hit the 150 asset mark, you have to jump to their unlimited license. There is no middle ground. We were only 10 or so assets above the 150 so we had to chose to either not monitor those assets or pay the price of the upgrade.
AlienVault brings all the information to one place which makes it much quicker to track down problems.