Combine cutting-edge XDR technology, multi-signal threat intelligence and 24/7 Elite Threat Hunters to help you build a world-class security operation.
Our team delivers the fastest response time in the industry. Threat suppression within just 4 hours of being engaged.
Cyber risk and advisory programs that identify security gaps and build security strategies to address them.
24/7 SOC-as-a-Service with unlimited threat hunting and incident handling.
XDR with machine learning that eliminates noise, enables real-time detection and response, and automatically blocks threats.
Seamless integration and threat investigation across your existing tech stack.
Proactive threat intelligence, original threat research and a world-class team of seasoned industry veterans.
Extend your team capabilities and prevent business disruption with expertise from eSentire.
We balance automated blocks with rapid human-led investigations to manage threats.
Guard endpoints by isolating and remediating threats to prevent lateral spread.
Defend brute force attacks, active intrusions and unauthorized scans.
Investigation and threat detection across multi-cloud or hybrid environments.
Remediate misconfigurations, vulnerabilities and policy violations.
Investigate and respond to compromised identities and insider threats.
Stop ransomware before it spreads.
Meet regulatory compliance mandates.
Detect and respond to zero-day exploits.
End misconfigurations and policy violations.
Defend third-party and supply chain risk.
Prevent disruption by outsourcing MDR.
Adopt a risk-based security approach.
Meet insurability requirements with MDR.
Protect your most sensitive data.
Build a proven security program.
Operationalize timely, accurate, and actionable cyber threat intelligence.
THE THREAT On November 18th, 2024, Palo Alto disclosed a critical actively exploited authentication bypass zero-day vulnerability impacting Palo Alto Networks PAN-OS. The…
Nov 13, 2024THE THREAT Update: eSentire has observed multiple exploitation attempts targeting CVE-2024-8069. In real-world attacks, threat actors successfully achieved RCE and attempted to…
eSentire is The Authority in Managed Detection and Response Services, protecting the critical data and applications of 2000+ organizations in 80+ countries from known and unknown cyber threats. Founded in 2001, the company’s mission is to hunt, investigate and stop cyber threats before they become business disrupting events.
We provide sophisticated cybersecurity solutions for Managed Security Service Providers (MSSPs), Managed Service Providers (MSPs), and Value-Added Resellers (VARs). Find out why you should partner with eSentire, the Authority in Managed Detection and Response, today.
Multi-Signal MDR with 300+ technology integrations to support your existing investments.
24/7 SOC-as-a-Service with unlimited threat hunting and incident handling.
Three MDR package tiers are available based on per-user pricing and level of risk tolerance.
The latest security advisories, blogs, reports, industry publications and webinars published by TRU.
Compare eSentire to other Managed Detection and Response vendors to see how we stack up against the competition.
See why 2000+ organizations globally have chosen eSentire for their MDR Solution.
The Advanced Threat Analytics (ATA) team operates as eSentire’s advanced threat research and development branch. They concentrate on ways to solve the challenges posed by disparate data sets and expanding attack surfaces. Leveraging data science and machine learning expertise, the ATA team has created several proprietary and proven applications designed to identify threat actor tactics, techniques, and procedures that legacy security tools miss.
As part of our commitment to providing market-leading Managed Detection and Response (MDR) services, eSentire chose to partner with the Cyber Science Lab[1] at the University of Guelph and Mitacs[2] for two research projects. The collaboration between academia and industry aims to bring the best of both worlds to cyber security and eSentire customers.
Two promising University of Guelph students, Alex Chen and Samira Eisaloo Gharghasheh, enrolled in the Master of Cyber Security and Threat Intelligence program, were chosen to work closely with eSentire’s ATA team in an effort to research machine learning solutions to the problems that have been difficult to solve using legacy approaches.
Under the supervision of Ali Dehghantanha, director of the Cyber Science Lab and a professor at the University of Guelph, and myself, manager of the Advanced Threat Analytics team, both students spent four months analyzing large amounts of data and developing machine learning approaches to discovering adversaries and anomalous data points.
In the first project, titled “Detection of Enumeration Attacks in Cloud Environments Using Infrastructure Log Data,” Samira focused on data found in eSentire’s esLOG service.
With the complexities present in modern cloud environments, it can be a daunting task to keep track of permissions and policies. Users and service accounts often have more access than is strictly necessary, opening the doors for adversaries. Enumeration attacks are a common way for adversaries to expand their reach within a victim’s cloud environment. Once a set of credentials has been compromised or authentication tokens intercepted, the attacker will aim to discover resources they have gained access to. In order to achieve this, cloud services and accounts will be enumerated. Successful access will be further explored until a vulnerable system is found or data can be extracted.
In this project, Samira worked off AWS IAM logs that can be found and analyzed in esLOG. Through the use of Open Source red team tooling and real-world data, a wide variety of data points made up the training and validation data sets. Samira created long-short term memory (LSTM) and convolutional neural network (CNN) models to compare their performance and found that over 99% detection accuracy can be achieved.
“Classification and Anomaly Detection of Network Traffic at the Edge Using Transfer Learning” is a project Alex focused on, evaluating the benefits of transfer learning to introduce machine learning models that can accurately identify malicious network traffic in disparate customer environments.
Network traffic analysis traditionally employs large rule sets that identify well-known malicious behavior in the data stream. A subset of rules is usually specific to a customer’s environment and requires careful adjustment and monitoring when first deployed. Using machine learning, Alex attempted to reduce the need for manual intervention.
Having started out with a dataset provided by the Canadian Institute for Cybersecurity (CIC), a variety of different approaches were required to arrive at a solid model that would identify malicious actors based on network traffic. Using transfer learning techniques, a model was then trained to classify traffic captured as part of eSentire’s services. The new model used multiple fully-connected layers on top of the original one, leading to correct identification of malicious activity in over 94% of the cases.
Going forward, the Advanced Threat Analytics team, along with the eSentire organization, will continue to improve upon the above projects and integrate the detections into our portfolio. We hope to continue our partnerships and collaboration efforts in the future, and look forward to congratulating Samira and Alex on their Master’s degrees at the end of the semester.
Throughout this collaboration, the different perspectives and expertise from Samira, Alex, Ali and The University of Guelph and Mitacs have allowed all of us to grow and produce fantastic results and will be used to better serve eSentire customers around the world.
Tim leads eSentire's Advanced Threat Analytics team, working at the forefront of Machine Learning in the MDR space. He and his team deliver solutions to the most difficult to detect adversarial tactics.