-

Exabeam Launches First-ever Comprehensive Use Case Coverage for Successful Outcome-based Security

Prescriptive end-to-end framework enables organizations to protect against external threats, compromised insiders and malicious insiders

FOSTER CITY, Calif.--(BUSINESS WIRE)--Exabeam, the security analytics and automation company, today announced a set of new functionalities aligned across Exabeam’s products to solve specific security challenges. The new Threat Detection, Investigation & Response (TDIR) use case packages provide a powerful, prescriptive solution to help security operations centers (SOCs) improve workflows from collection to detection, investigation and response using an outcome-based approach. Generally available in Q2 2021, the TDIR packages address the complete lifecycle of security operations (SecOps) workflows with end-to-end content that includes prescribed data sources, detection models, watchlists, investigation checklists and response playbooks to assist analysts with repeatedly delivering successful outcomes.

“Organizations struggle with failed security implementations because they lack the specialized expertise, detection logic and clearly mapped investigation and response workflows for common threats,” said Adam Geller, chief product officer at Exabeam. “Consequently, organizations waste time and resources customizing products with minimal improvement to their security coverage. With our framework for use cases, security analysts benefit from comprehensive out-of-the-box content so they can be confident in their ability to deliver repeatable, successful outcomes that will improve their security and translate into significant amounts of saved time and resources.”

Customers Validate Approach

“We were able to quickly turn on the 'out of the box' use cases and integrate with our systems and processes, improving our detect and response capabilities,” said Jennifer Shields, vice president of information technology, Procter & Gamble.

“Directly mapping common security use cases to response workflows is critical for SecOps success,” said Marc Crudgington, CISO, SVP information security, Woodforest National Bank. “We look forward to working with Exabeam as its new TDIR framework helps our industry become far more use case-driven.”

“Automated TDIR workflows that are outcome-driven, prescriptive and analytics-powered are required to mature and fortify a healthcare SOC today,” said Joe Horvath, manager, information security, Kelsey-Seybold Clinic. “Exabeam’s TDIR use case packages provide the prescribed content needed to get us there.”

Coverage for common threats

Most security products were designed to provide functionality, not results. The new TDIR use case packages simplify analyst workflows by providing prescriptive content for Exabeam’s analytics and automation engines in order to protect against the top three categories of common threats:

  • External threat use cases that include phishing, malware, ransomware, cryptomining and brute force attacks.
  • Compromised insider use cases that include privileged activity, account manipulation, privilege escalation, evasion, compromised credentials, lateral movement and data exfiltration.
  • Malicious insider use cases that include privileged access abuse, account manipulation, audit tampering, physical access, data access abuse, data leak and destruction of data.

Prescriptive content at each stage of the workflow

Unlike competing solutions, where coverage for common threats is limited to detection logic, Exabeam’s framework includes content for all phases of threat detection, investigation and response. This includes comprehensive onboarding guidance for which specific data sources and context are required to achieve the most successful outcomes. The TDIR framework also includes:

  • Out-of-the-box detection models that incorporate coverage for specific adversary tactics and techniques. These are mapped to the MITRE ATT&CK framework to give security teams a common framework for detection.
  • Tailored watchlists that can be set up to allow analysts to monitor high-risk users and devices.
  • Investigation checklists that include a curated list of investigation, containment and remediation steps. This allows analysts to follow a consistent and repeatable investigation and response workflow.
  • Turnkey Playbooks that contain automatable response actions for addressing common security scenarios without requiring customers to license or configure additional third-party software. These ensure analysts are able to respond in a timely and consistent manner.

“Outcome-based security with prescriptive approaches are strategic to the industry, and this represents a great win for Exabeam customers. These approaches are fundamental to the success of SecOps initiatives,” said Gorka Sadowski, chief strategy officer at Exabeam. “As an example, organizations looking to deploy or improve their insider threat program will be able to quickly gain visibility and response capabilities into malicious behavior and compromised accounts.”

For more information, please visit https://www.exabeam.com/solutions/.

About Exabeam

Exabeam helps security teams outsmart the odds by adding intelligence to their existing security tools – including SIEMs, XDRs, cloud data lakes, and hundreds of other business and security products. Out-of-the-box use case coverage repeatedly delivers successful outcomes. Behavioral analytics allows security teams to detect compromised and malicious users that were previously difficult, or impossible, to find. Automation helps overcome staff shortages by minimizing false positives and dramatically reducing the time it takes to detect, triage, investigate and respond. For more information, visit https://www.exabeam.com.

Exabeam, the Exabeam logo, Threat Hunter, Smart Timelines and Security Management Platform are service marks, trademarks or registered marks of Exabeam, Inc. in the United States and other countries. All other brand names, product names, or trademarks belong to their respective owners. © 2021 Exabeam, Inc. All rights reserved.

Contacts

Media Contact Information:
Allyson Stinchfield
Exabeam, Inc.
415.515.9186
ally@exabeam.com

Alyssa Pallotti
Touchdown PR for Exabeam
860.878.2518
exabeam@touchdownpr.com

Exabeam


Release Summary
Exabeam today announced a set of new functionalities aligned across Exabeam’s products to solve specific security challenges.
Release Versions

Contacts

Media Contact Information:
Allyson Stinchfield
Exabeam, Inc.
415.515.9186
ally@exabeam.com

Alyssa Pallotti
Touchdown PR for Exabeam
860.878.2518
exabeam@touchdownpr.com

More News From Exabeam

Exabeam® Named To Newsweek’s 2024 List of Top 100 Most Loved Workplaces®

FOSTER CITY, Calif.--(BUSINESS WIRE)--Exabeam, a global cybersecurity leader that delivers AI-driven security operations, today announced its inclusion as #68 in the second annual Top 100 Global Most Loved Workplaces® list, published by Newsweek. The Top 100 Global Most Loved Workplaces® list resulted from collaboration with Best Practice Institute (BPI), a leadership development and benchmark research company. The results were determined after surveying more than 2 million employees from busin...

Exabeam Named a Leader in the 2024 Gartner® Magic Quadrant™ for SIEM, Recognized for the Fifth Time

FOSTER CITY, Calif.--(BUSINESS WIRE)--Exabeam, a global cybersecurity leader delivering AI-driven security operations, today announced it has been named a Leader in the 2024 Gartner® Magic Quadrant™ for Security Information and Event Management (SIEM). This marks the fifth time that Exabeam has been recognized by Gartner (2018, 2020, 2021, 2022, 2024). To download a complimentary copy of the full 2024 Gartner Magic Quadrant for SIEM report, click here. “Being recognized in the Gartner Magic Qua...

Exabeam Introduces Transformative Unified Workbench for Security Analysts with Generative AI Assistance

FOSTER CITY, Calif.--(BUSINESS WIRE)--Exabeam, a global cybersecurity leader that delivers AI-driven security operations, today announced two pioneering cybersecurity features, Threat Center and Exabeam Copilot, to its market leading AI-driven Exabeam Security Operations Platform. A first-to-market combination, Threat Center is a unified workbench for threat detection, investigation, and response (TDIR) that simplifies and centralizes security analyst workflows, while Exabeam Copilot uses gener...
Back to Newsroom