Combine cutting-edge XDR technology, multi-signal threat intelligence and 24/7 Elite Threat Hunters to help you build a world-class security operation.
Our team delivers the fastest response time in the industry. Threat suppression within just 4 hours of being engaged.
Cyber risk and advisory programs that identify security gaps and build security strategies to address them.
24/7 SOC-as-a-Service with unlimited threat hunting and incident handling.
XDR with machine learning that eliminates noise, enables real-time detection and response, and automatically blocks threats.
Seamless integration and threat investigation across your existing tech stack.
Proactive threat intelligence, original threat research and a world-class team of seasoned industry veterans.
Extend your team capabilities and prevent business disruption with expertise from eSentire.
We balance automated blocks with rapid human-led investigations to manage threats.
Guard endpoints by isolating and remediating threats to prevent lateral spread.
Defend brute force attacks, active intrusions and unauthorized scans.
Investigation and threat detection across multi-cloud or hybrid environments.
Remediate misconfigurations, vulnerabilities and policy violations.
Investigate and respond to compromised identities and insider threats.
Stop ransomware before it spreads.
Meet regulatory compliance mandates.
Detect and respond to zero-day exploits.
End misconfigurations and policy violations.
Defend third-party and supply chain risk.
Prevent disruption by outsourcing MDR.
Adopt a risk-based security approach.
Meet insurability requirements with MDR.
Protect your most sensitive data.
Build a proven security program.
Operationalize timely, accurate, and actionable cyber threat intelligence.
THE THREAT In recent weeks, eSentire’s Threat Response Unit (TRU) has traced numerous email account compromise cases to infrastructure hosted on several related hosting…
Dec 10, 2024THE THREATUpdate: Security patches to address this vulnerability were released by Cleo on December 12th. Organizations need to update to Cleo Harmony, VLTrader, and LexiCom versions…
eSentire is The Authority in Managed Detection and Response Services, protecting the critical data and applications of 2000+ organizations in 80+ countries from known and unknown cyber threats. Founded in 2001, the company’s mission is to hunt, investigate and stop cyber threats before they become business disrupting events.
We provide sophisticated cybersecurity solutions for Managed Security Service Providers (MSSPs), Managed Service Providers (MSPs), and Value-Added Resellers (VARs). Find out why you should partner with eSentire, the Authority in Managed Detection and Response, today.
Multi-Signal MDR with 300+ technology integrations to support your existing investments.
24/7 SOC-as-a-Service with unlimited threat hunting and incident handling.
Three MDR package tiers are available based on per-user pricing and level of risk tolerance.
The latest security advisories, blogs, reports, industry publications and webinars published by TRU.
Compare eSentire to other Managed Detection and Response vendors to see how we stack up against the competition.
See why 2000+ organizations globally have chosen eSentire for their MDR Solution.
In our recent post about the SolarWinds “Sunburst” supply chain compromise, we examined the importance of operationalizing threat intelligence, explained our response, shared our early observations and highlighted the potential of a broader cyberthreat that goes beyond the headlines.
In this post, we’ll address the three main questions our customers have asked us, each of which corresponds to a particular scenario in which you might find yourself.
But first—and very quickly—we want to reiterate that while this cyberattack is notable for many reasons, it would be a mistake to forget about the other, more common cyberthreats, which are always lurking about. For example, just a few days ago the eSentire MDR endpoint service, esENDPOINT, detected an unknown Drive-by Compromise that threatened a customer in the Venture Capital & Private Equity industry. Our investigation suggests that a user visited a website which, after a series of automated redirects, ultimately led to a site that exploited CVE-2019-0752.
Exploitation led to execution of a malicious VBA file, which in turn initiated a PowerShell command that executed a cmd.exe process that wrote a file to disk. That file was then used as part of a WScript command that downloaded a binary from the internet, the attempted execution of which was detected by esENDPOINT—leading to isolation, alerting and escalation.
So, while Sunburst warrants attention, make sure not to forget about other high-priority threats that are always active!
Many customers of ours, who are not SolarWinds Orion customers, have reached out with questions about whether or not this cyberthreat affects them and what, if any, action is needed on their part.
For organizations in this situation, here are the three most important things to do:
And in general, keep in mind that the security community is still learning more about this cyberattack every day and will introduce new capabilities as warranted—ensure your AV signatures are up-to date, as hashes will keep being added as they are discovered.
Some of our customers have stated they are users of SolarWinds Orion software and that they are behind in patching. They are looking for advice on next steps, asking questions including:
For organizations in this position, we recommend migrating to the latest platform version 2019.4 HF 6 or 2020.2.1 HF 2 as soon as possible.
Note that SolarWinds does not recommend rebuilding if you did not run an affected version of Orion.
eSentire has performed indicator of compromise (IoC) sweeps and Managed Vulnerability Service (MVS) scans across our customer base to look for evidence of post-compromise activity—and these actions continue with new IoCs as they emerge from our ongoing research.
So far (across hundreds of customers):
However, these sweeps and scans will only examine assets visible to eSentire, so we recommend that you perform post-compromise IoC checks across any/all additional assets.
Additionally:
Also, note that there are reports of threat actors exploiting a separate, previously unknown authentication bypass vulnerability which is also present in Sunburst-vulnerable versions of SolarWinds Orion. This cyberthreat, “Supernova,” is tracked as CVE-2020-10148. SolarWinds recommends:
SolarWinds has developed a program to provide professional consulting resources, at no charge, to customers with active maintenance plans.
It’s important to avoid overfocusing on Sunburst at the expense of your vigilance against other cyber threats. You might recall that this incident originally made headlines when FireEye announced that their Red Team tools were stolen—even though those tools exploit known vulnerabilities (some of which are several years old). Data, from our Managed Vulnerability Service, suggests that many organizations have not yet installed the requisite patches.
So please, don’t forget about good cybersecurity hygiene: apply patches, keep your security solutions up to date, employ a multi-layer security strategy, make sure employees are aware of the most common cyber risks, and so on.
And of course, if you have any questions, please don’t hesitate to contact us.
The eSentire Threat Response Unit (TRU) is an industry-leading threat research team committed to helping your organization become more resilient. TRU is an elite team of threat hunters and researchers that supports our 24/7 Security Operations Centers (SOCs), builds threat detection models across the eSentire XDR Cloud Platform, and works as an extension of your security team to continuously improve our Managed Detection and Response service. By providing complete visibility across your attack surface and performing global threat sweeps and proactive hypothesis-driven threat hunts augmented by original threat research, we are laser-focused on defending your organization against known and unknown threats.