Adlumin is a great service and well worth the cost
Use Cases and Deployment Scope
We use Adlumin as an automated log review, monitoring, and protection system that scans for anomolies in our technology stack that could potentially be a problem. It then emails us and/or takes action depending on the settings we've configured and/or the defaults configured by the company.
The most obvious business use case is account compromise alerting and protection, but depending on your specific technology stack, it can also protect against phishing attacks, ransomware, and a number of other malicious scenarios.
Pros
- Malicious actor detection through log analysis
- Randomware protection through agent and canary files
- Single pane of glass monitoring and visibility
- Automated responses to malicious actions
Cons
- Reducing extra noise - specifically, having the ability to mark certain accounts as "safe" so that we're not alerted whenever an admin installs an app
- Clearer setup instructions - the initial setup call was good, but having knowledge base articles / self-help processes are always good
- More integrations
Return on Investment
- There's no way to accurately calculate the return on investment for preventing an attack, but the average cost of a business email compromise (from quick Google searching) is 135K. If we use that number, for us it's at least a 5x ROI even if it catches only one such attack (and it has caught more and other attacks besides)
- It does take some managing (getting an AI alert for nothing late at night is not awesome) but that's far better than ignoring an attack.
- It's not the cheapest tool, but it's a necessary one, especially in today's age of constant data breaches and password leaks.
Usability
Other Software Used
N-able N-central, N-able Take Control, Cove Data Protection


