Transcript
powered by SentinelOne Vigilance. Enable Managed EDR provides managed security services designed for MSPs that have standardized on Enable EDR. For this offering, we've enlisted SentinelOne's Security Operations Center and Vigilant cybersecurity experts who can monitor your endpoints 24-7, review, analyze, and act upon any Enable EDR-identified threat, hunt for unknown threats, and proactively notify you of malicious or suspicious activities. Now, let's put on the MSP technician hat and walk you through a threat event scenario and the steps taken to resolve it. For the purposes of this demo, we'll be looking at an account with one device set up for testing. We're in the SentinelOne console now. Everything looks good. Clean dashboard, no issues on this device at all. No incidents or threats identified by the SentinelOne EDR agent yet. So what we're going to do now is perform an action that will cause a detection by the default policy settings of the EDR agent. For this example, we'll use a free tool that an end user might download onto a managed endpoint, which can actually be used to look at browser passwords on Firefox, Chrome, or Edge. It looks pretty secure, so they go ahead and download it. What could go wrong? In order to open the zip file and run it, you need to grab the password provided. Zip files and other archive-formatted files are a popular attack vector for some of today's active threat groups. Once you do that and you open the file, the EDR agent almost immediately detects it as suspicious activity. The notification that is presented to the end user is in the OS-provided notification format and can be switched on and off in the console as needed by the MSP. If we go back to the SentinelOne console, we will now see the web browser pass view file marked as a malicious threat. The incident status is currently set as unresolved, given the fact that the response process has just begun. Also, the analyst verdict field is in an undefined state, as that will be decided by the vigilance team shortly. When we click on the threat, we are taken to the incident details page, where information about the incident status, threat file details, and endpoint is available. This dynamic page will provide up-to-date status information as the vigilance team conducts their investigation and response activities. There are no notes added yet. A malicious file notification is triggered to indicate that the AI detection engine has determined that this RISCware is a malicious file and has been added in the console as blacklist hash. And this is what the device user can see on their desktop notifications as well as in the agent UI. Customizable configuration, contact information, as well as the actual threat history. Now, if we go back to the SentinelOne console and into the activity tab, we can see an activity log of all the actions taken by the EDR agent. This helps facilitate and accelerate threat investigation. And with all this information, the vigilance analyst can annotate their assessment in the threat section. Now, going back to the threat in the incidents tab, we can see the vigilance annotation, as well as the updates to the verdict and incident status based on the vigilance team's investigation. And you can see the notification that comes up. This is the agent letting you know that the security incident has been resolved. In the upper right corner, you can see when the threat was identified at 1.07. It was also reported to the console up to the cloud at the same time, which means it took 10 minutes for the vigilance team to identify it and categorize it at 1.17. And that's when the incident was closed. The end user didn't have to do anything, and the MSP didn't get woken up in the middle of the night because of an infected device. There you have it. This is just a simple scenario showing how vigilance can take threat incident response off your shoulders rapidly and efficiently, so you and your team can focus on strategic initiatives and sleep soundly. Learn more about Enable Managed EDR powered by SentinelOne at enable.com.