Agentless network miracles and magic - Armis is king!
Use Cases and Deployment Scope
Tracking rogue devices - analyzing traffic activity - blocking devices from the network with a click of a button - yes, please! Armis is a fantastic tool with more features than I know what to do with - the reporting, easy interface, and robust analytics are all top-notch. They are constantly adding new functionality, integrations, and features to make it more awesome. The bi-weekly support calls for onboarding and health checks are stellar and really help fully utilize the product, not just buy it and forget about it. It's really one of the best products we've adopted, and I can't see us being without it!
Pros
- Analyzing Traffic
- Detecting Device Types
- Finding vulnerabilities by pure magic!
- Searching through all the data - intuitive and no programming required!
- Alerts and policies for anything you can imagine
- Reports and dashboards customizable to any extent you can imagine
- Integrates with so many systems and ties all your data together in one screen
- Create automated processes to handle events automatically by event/data/device etc.
Cons
- I've requested integration with Mosyle Manager for our Apple MDM products - it is on the radar but slow going - Mosyle has an API and a free 30-day trial, so implementation shouldn't be difficult - but honestly, other than that - Armis support has been astonishing, and there are so many integrations already - it's small potatoes.
- Considering Armis has all the data collected and parsed - it would be nice to see a back-end system for those of us who are true nerds and want to really dig into the Syslog data and analyze packets directly - however, building some quick queries is probably easier if you know what you are looking for anyway - which is probably why this is a backward way of my own thinking and no fault of Armis at all. They make the interface so easy to use it's not necessary, but it hurts my inner geek.
Most Important Features
- Vulnerability scanning
- Traffic Analysis
- Integrations to tie device/user information together
- Policies and alerts for specific behavior and traffic
- Network scanning and device identification
- Dashboard management for seeing everything you could possibly want to know about your network at a simple glance - it's really awesome
- Easy searching and drilling down to find exactly what you need - even without a programming degree and SQL query knowledge
Return on Investment
- Armis helped with multiple projects saving incalculable time since we've gotten it
- Network analysis is a breeze
- Device traffic reports and alerts is one click easy peasy
- Blocking devices or specific traffic is super easy and helpful - if you have the right integrations for those options
Alternatives Considered
PRTG Network Monitor, Auvik, LogicMonitor, Lansweeper, Microsoft Endpoint Manager (Microsoft Intune + SCCM), Cisco Meraki MX, Darktrace, Varonis Data Security Platform and Netwrix Auditor
Other Software Used
Darktrace, Varonis Data Security Platform, ManagedMethods, PRTG Network Monitor
