-

Endace Integrates with Microsoft Sentinel for Deep Network Visibility

EndaceProbe and Microsoft Sentinel combine AI-powered intelligent SIEM with always-on packet capture, and deep network visibility for accelerated incident response in hybrid cloud environments

AUCKLAND, New Zealand & AUSTIN, Texas--(BUSINESS WIRE)--Packet capture authority Endace today announced an integration between EndaceProbe and Microsoft Sentinel, a next-generation cloud security, information, and event management (SIEM) solution. The integration provides NetOps and SecOps teams with one-click access to definitive, full packet evidence from within Microsoft Sentinel to streamline investigations. Access to Endace’s Always-On packet capture enables accurate event reconstruction and helps security teams to investigate and respond to threats more quickly, with absolute confidence.

Benefits of the integration include:

  • Streamlined investigation workflows, alerts, and playbooks from Microsoft Sentinel, with one-click, drill-down access to definitive, full packet evidence captured by EndaceProbe.
  • Continuously capture weeks or months of full packet data, across Hybrid, On-Prem, and Multi-Cloud environments.
  • Single central console for searching and analyzing recorded packet data across global scale networks, integrated with Microsoft Sentinel.
  • Deep visibility that shows exactly what happened before, during, and after every event.
  • Zero-Day Threat (ZDT) risk validation using playback of recorded network traffic
  • Combining EndaceProbe’s centralized search with Microsoft Sentinel’s AI-powered SIEM enables faster, more efficient incident investigation and resolution.
  • Military-grade Security: EndaceProbe appliances are FIPS 140-3 compliant and are listed on the DoDIIN APL.

Read the solution brief and watch the demo here: https://www.endace.com/microsoft-sentinel

“Deep visibility into network activity is essential when responding to serious cybersecurity events, service outages, or performance issues. One-click access to EndaceProbe’s recorded packet data directly from Microsoft Sentinel shows incident responders exactly what happened before, during, and after any serious event,” said Cary Wright, VP Product at Endace.

“Microsoft Sentinel’s built in machine learning reduces noise and uncovers sophisticated threats while EndaceProbes provide a complete, packet-level record of network history. Integrating these two solutions gives SecOps teams easy access to definitive evidence required to triage the most serious threats on the network.”

Next week, Endace will be demonstrating EndaceProbe and EndaceProbe Cloud at RSAC™ 2025 in booth N-5176, and Endace is securing RSAC™ by equipping and operating the SoC @ RSAC™. For more information about Endace at RSAC™, visit https://www2.endace.com/rsa-2025-resources-lp.

About Endace:

Endace’s scalable, always-on packet capture gives Network Operations and Security teams the deep visibility they need for fast, accurate incident investigation with rich forensic evidence at their fingertips from all their tools. EndaceProbes provide enterprise-class packet sniffing in on-prem, public and private cloud environments, with rapid, centralized search and one-click access to full pcap data from leading security and performance solutions (including Microsoft, Palo Alto Networks, Fortinet, Cisco, Splunk, Elastic, and many others). Analyze network traffic using a single, unified console across all on-prem, private, or public cloud infrastructure for total hybrid cloud visibility. Capture every packet. See every threat. www.endace.com

All trademarks mentioned herein belong to their respective owners.

Contacts

Email: pr@endace.com

Phone:
Mark Evans, mobile +64-21-494 850 – New Zealand / APAC
Kimber Smith-Fidler, mobile +1 775 298 5260 – USA / North America
Leah Jones (The CommsCo) +44 203 697 6680 – UK / EMEA

Endace


Release Summary
EndaceProbe and Microsoft Sentinel combine AI-powered intelligent SIEM with always-on packet capture for accelerated incident response
Release Versions

Contacts

Email: pr@endace.com

Phone:
Mark Evans, mobile +64-21-494 850 – New Zealand / APAC
Kimber Smith-Fidler, mobile +1 775 298 5260 – USA / North America
Leah Jones (The CommsCo) +44 203 697 6680 – UK / EMEA

Social Media Profiles
More News From Endace

Endace Announces New Integration with CrowdStrike Falcon Next-Gen SIEM

AUCKLAND, New Zealand & AUSTIN, Texas--(BUSINESS WIRE)--Endace today announced a new integration with CrowdStrike Falcon® Next-Gen SIEM that brings EndaceProbe™ always-on packet capture directly into the CrowdStrike Falcon® platform. The integration enables security teams to access definitive packet-level evidence within Falcon Next-Gen SIEM, accelerating investigations, improving threat hunting, and providing greater visibility across complex hybrid and multi-cloud environments. By combining E...

Endace and Aviz Networks Partner to Combine Intelligent Network Traffic Optimization with Always-on Packet Capture

AUCKLAND, New Zealand & SAN JOSE, Calif.--(BUSINESS WIRE)--Endace, the premier packet capture authority, and Aviz Networks, a pioneer in multi-vendor AI networking observability, today announced a technical partnership that combines EndaceProbe's always-on packet capture and visibility with the intelligent traffic optimization of Aviz Networks’ Deep Network Observability (DNO). As AI workloads become mainstream, network monitoring must rapidly evolve to ensure organizations meet customer securi...

Endace Expands Alliance with Vectra AI

AUCKLAND, New Zealand & AUSTIN, Texas--(BUSINESS WIRE)--Vectra AI, the leader in AI-native security and observability, and packet capture authority, Endace, today announced an agreement that will enable Vectra AI to sell Endace products.“Vectra AI has been an important partner in our Fusion program for many years. We’re excited to enable Vectra AI to sell EndaceProbes to its customers,” said Stuart Wilson, CEO Endace. “Endace’s always-on packet capture is a perfect complement to Vectra AI’s powe...
Back to Newsroom