A tool meant for the front lines and more.
Use Cases and Deployment Scope
Phishing is the number one attack vector and certain SOC tools require persistent tools to provide intelligence and actionable features. Agari Active Defense addresses business problem by providing and easy to use interface, metrics, and customizable lists that filter through many of the day to day emails and attacks. The scope covers the entire organizations mail flow.
Pros
- Phishing detection
- VIP or HVT alerts
- Tactics and Intel
Cons
- Raw data extraction
- Reporting for Executives
- Clustering
Most Important Features
- Purging threats in the organization.
- Blocking known bad senders and Ad-Hoc lists.
- Shared intelligence of known IOCs
- Journaling
Return on Investment
- Mitigation of risk in regards to Phishing
- Cost of maintenance on SOC tool
- Features are easy and training is acceptable
Alternatives Considered
ServiceNow Now Platform and KnowBe4 Security Awareness Training
Other Software Used
Cofense PhishMe, KnowBe4 Security Awareness Training, Microsoft Sentinel (formerly Azure Sentinel)