Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Threat Intelligence

12/1/2020
01:00 PM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Secureworks to Deliver New Threat Detection and Response Security Analytics Features

ATLANTA, Dec. 01, 2020 (GLOBE NEWSWIRE) -- Secureworks®, a leader in software-driven security solutions, is delivering on its commitment to protect customers with flexible log collection and retention; a new search query language and flexible reporting; and custom use case support and alert customization capabilities on its cloud-native security analytics application, Threat Detection and Response (TDR).

The announced improvements to Secureworks’ TDR directly address customers’ needs for a compelling SIEM alternative. Now, security operations teams can detect, investigate and respond to security incidents with greater detection visibility. They can also proactively hunt for, and gain actionable insights on, both known and unknown threats.

Secureworks’ TDR takes a holistic approach to security with superior detection and remediation capabilities informed and enriched by threat intelligence, machine learning, and integrations with a variety of 3rd-party point products.

"Updates to the Secureworks’ TDR application are in line with the market’s need for improved detection of advanced threats and the sentiment that SIEM is stronger on known threats than unknown threats," said Jon Oltsik, Senior Principal Analyst & ESG Fellow, ESG.

New Log Collection, Health and Retention

Security operations teams require data collection and retention flexibility to make informed decisions and power better business outcomes. In response to this need, Secureworks’ TDR supports the ingest and normalization of a growing list of supported data sources, including Endpoint, Network, Cloud and Business Systems, and is expanding capabilities to support additional data sources when investigating incidents. TDR will now support the collection and storage of raw data from any syslog-based log source in investigations, reporting and enrichment activities. This support, coupled with expanded retention options, allows TDR buyers the data retention flexibility they need to power business outcomes in addition to TDR’s existing security investigation capabilities. These latest improvements also help practitioners and IT professionals understand the health of their data sources in TDR, which further establishes TDR as a trusted analytics solution.

New Search and Reporting

Secureworks is enhancing TDR’s flexible search and reporting capabilities to help security operations leaders and administrators quickly find the data they need, and more easily share insights across the organization to improve communication and decision making in an increasingly complex threat environment. Building on application capabilities, such as storage of normalized data which have been embedded in the application since its launch in 2019, these latest enhancements deliver an improved intuitive data query experience, allowing users to search across all raw data up to three years, including custom log sources, and use search results for on demand, export or scheduled reports.

New Custom Use Case Support and Alert Customization

Secureworks’ TDR will have new and improved alert customization and suppression capabilities, with custom detection rules for Secureworks supported data sources. This extension enables security operations teams to customize the software application to better fit their varying security use cases.

“Our cloud-native security applications are designed to grow and transform with security operations to outpace a continually evolving threat landscape. These updates to TDR reflect that growth,” said Steve Fulton, Secureworks’ Chief Product Officer. “To be truly effective in the fight against the adversary, we must strengthen and enable the security community at large, and that begins by sharing and innovating our software.”

About Secureworks

Secureworks® (NASDAQ: SCWX) a global cybersecurity leader, protects customer progress with the cloud-native security analytics software of choice. Informed by 20+ years of threat intelligence and research, no other security platform provides this much real-world experience.

 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
News
Former CISA Director Chris Krebs Discusses Risk Management & Threat Intel
Kelly Sheridan, Staff Editor, Dark Reading,  2/23/2021
Edge-DRsplash-10-edge-articles
Security + Fraud Protection: Your One-Two Punch Against Cyberattacks
Joshua Goldfarb, Director of Product Management at F5,  2/23/2021
News
Cybercrime Groups More Prolific, Focus on Healthcare in 2020
Robert Lemos, Contributing Writer,  2/22/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Building the SOC of the Future
Building the SOC of the Future
Digital transformation, cloud-focused attacks, and a worldwide pandemic. The past year has changed the way business works and the way security teams operate. There is no going back.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-26854
PUBLISHED: 2021-03-03
Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26412, CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065, CVE-2021-27078.
CVE-2021-26855
PUBLISHED: 2021-03-03
Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26412, CVE-2021-26854, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065, CVE-2021-27078.
CVE-2021-26857
PUBLISHED: 2021-03-03
Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26412, CVE-2021-26854, CVE-2021-26855, CVE-2021-26858, CVE-2021-27065, CVE-2021-27078.
CVE-2021-26858
PUBLISHED: 2021-03-03
Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26412, CVE-2021-26854, CVE-2021-26855, CVE-2021-26857, CVE-2021-27065, CVE-2021-27078.
CVE-2021-27065
PUBLISHED: 2021-03-03
Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26412, CVE-2021-26854, CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27078.