-

ExtraHop Accelerates Security Operations with High Fidelity Network Intelligence Through New Integration with Splunk SOAR

Security teams can now seamlessly increase the speed of investigations with more reliable threat intelligence

SEATTLE--(BUSINESS WIRE)--ExtraHop, the leader in cloud-native network intelligence, today announced a new integration between Reveal(x), its network detection and response (NDR) platform, and Splunk SOAR. Using the Reveal(x) integration, Splunk SOAR users now have expanded visibility with packet-level insights from IoT to the cloud including unmanaged devices, legacy systems, and all network assets. Users can correlate logs with network intelligence to gain a greater understanding of threats and more confidence in automation of tier 1 and tier 2 incident response.

Register Now: Extract Value From Your SOAR Faster with NDR

Analysts and IT security managers receive thousands of alerts every day, many of which are ignored due to bandwidth. In fact, according to a research study by ESG, 27% of cybersecurity teams surveyed said they spend most of their time addressing cybersecurity emergencies, not top tier priorities, leaving them little time to work on strategy or process improvement. Even more alarming, 23% said not being able to keep up with the workload contributed to security events in the past two years. Most security teams simply don’t have enough people staffed to stay on top of their workload and be effective.

SOAR platforms excel at streamlining data-gathering from multiple security tools into a single interface, but logs alone are not always reliable and can be inaccurate, disabled, or destroyed by adversaries. ExtraHop for Splunk SOAR enables security teams to enrich any SOAR playbook with high-fidelity data about detections, devices, network artifacts, or even full packet capture. In addition, Reveal(x) covers more network-detectable MITRE ATT&CK techniques than any other NDR product, covering nearly 90% —including privilege escalation, lateral movement, exfiltration, and command & control.

“The network is a source of ground truth, difficult for an attacker to evade, and nearly impossible to turn off. As such, network traffic analysis offers an effective means to detect suspicious behaviors and potential threats with high signal and low noise,” said Jesse Rothstein, co-founder and CTO, ExtraHop. “Our new integration with Splunk SOAR combines our rich, contextualized data with an advanced platform to enable defenders to prioritize alerts, accelerate investigation, and run trusted playbooks to ultimately stop threats faster.”

With strong expertise in attack detection, unusual behavior, and risk analysis, ExtraHop provides reliable insights and full context analytics, powered by its cloud-based machine learning. Security analysts can respond to alerts that matter, and have everything they need to know about an incident automatically gathered before they start investigating.

“This integration between Splunk and ExtraHop helps overburdened SOC analysts streamline their workflow so they can leverage out-of-the-box playbooks to handle low level alerts and focus on orchestrating the response and forensics needed for the alerts that matter,” said Chris Kissel, research vice president, security and trust, IDC. “A key benefit of integrating with ExtraHop is visibility into encrypted traffic. Encryption is vital for security and privacy, but it can be a double-edged sword when attackers use it to hide their actions. ExtraHop decrypts traffic and provides near real-time insights that are vital for SOC analysts to make faster decisions.”

“Together, ExtraHop and Splunk significantly increase the visibility we have into our environment, and the integration between products reduces the amount of time it takes our analysts to address security threats," said Dan White, network engineering manager, Ketchikan Public Utilities.

To learn more about how to detect unknown threats and accelerate response times with integrated Reveal(x) and Splunk, visit extrahop.com/splunk. The on-prem and cloud versions of Splunk SOAR will be available soon on Splunkbase.

About ExtraHop

Cyberattackers have the advantage. ExtraHop is on a mission to help you take it back with security that can’t be undermined, outsmarted, or compromised. Our dynamic cyber defense platform, Reveal(x) 360, helps organizations detect and respond to advanced threats—before they compromise your business. We apply cloud-scale AI to petabytes of traffic per day, performing line-rate decryption and behavioral analysis across all infrastructure, workloads, and data-in-flight. With complete visibility from ExtraHop, enterprises can detect malicious behavior, hunt advanced threats, and forensically investigate any incident with confidence. ExtraHop has been recognized as a market leader in network detection and response by Gartner, Forbes, SC Media, and numerous others. Learn more at www.extrahop.com.

© 2022 ExtraHop Networks, Inc., Reveal(x), Reveal(x) 360, Reveal(x) Enterprise, and ExtraHop are registered trademarks or marks of ExtraHop Networks, Inc.

Contacts

Catherine Segar
ExtraHop
pr@extrahop.com

ExtraHop Networks, Inc.

Details
Headquarters: Seattle, Washington
CEO: Greg Clark
Employees: 700
Organization: PRI

Release Versions

Contacts

Catherine Segar
ExtraHop
pr@extrahop.com

Social Media Profiles
More News From ExtraHop Networks, Inc.

ExtraHop® Unveils Advanced Network Detection Capabilities to Stop Malicious PowerShell Attacks

SEATTLE--(BUSINESS WIRE)--ExtraHop®, a leader in modern network detection and response (NDR), today announced powerful new capabilities to detect the malicious use of PowerShell. These enhancements deliver the critical visibility needed to dismantle the attack kill chain, providing essential insight to stop lateral movement in its tracks. Remote management tools like PowerShell have become a notable weapon for attackers, like the Qilin Ransomware-as-a-Service (RaaS) operation, which has hit man...

ExtraHop® Expands Presence in EMEA to Meet Enterprise Demand for NDR

SEATTLE & LONDON--(BUSINESS WIRE)--ExtraHop®, a leader in modern network detection and response (NDR), today announced its expansion into the Nordics and Benelux markets. This strategic move strengthens the company's European footprint on the heels of a period of significant enterprise growth. Following a strong 2024, in which ExtraHop more than doubled its sales to Global 2000 customers in EMEA, the company is bringing its proven momentum to two of the continent's most dynamic markets housing...

ExtraHop® Report Finds Ransomware Payouts Hit Record Highs as Attackers Adapt

SEATTLE--(BUSINESS WIRE)--ExtraHop®, a leader in modern network detection and response (NDR), today released the 2025 ExtraHop Global Threat Landscape Report, which offers a comprehensive analysis of the ever-shifting cybersecurity landscape. The report examines the ever-expanding attack surface, detailing the evolving tactics threat actors are leveraging to exploit organizations and carry out lucrative attacks. According to the findings, threat actors are shifting away from broad, indiscrimina...
Back to Newsroom