Vectra vs. Darktrace, ExtraHop, Cisco Stealthwatch and Coreligh

The right data source is critical to expose attacks fast

Network metadata
Network metadata contains vital descriptors of the data itself to create a searchable index in real time and at a fraction of the size of full packet captures. Metadata as a source is the right data type, but used alone it lacks indicators of compromise that show analysts where to hunt.

Security-enriched network metadata
Enrichment techniques, used to identify data such as host ID and beaconing, are employed to augment network metadata. This data cocktail is essential to quickly  identify threat activity in security event messages and conduct more conclusive incident investigations.

NetFlow
NetFlow is network performance monitoring data remarketed for security. It shows connections that were made but does not show what these connections were used for. Network detection requires details, such as whether an SMB connection was used to authenticate a user, mount a share or execute code. NetFlow does not provide these details, rendering it blind to network visibility and incapable of detecting threats.

Full packet captures
Network packets provide deep network visibility but are difficult and expensive to scale. The sheer amount of packets causes slow search performance that makes incident investigations frustratingly painful.

graph showing SIEM, Netflow, IDS, PCAP and security-enriched metadata on a scale of relevance and visibility. Security-enriched metadata is the highest for both.

Vectra vs. Darktrace, ExtraHop, Cisco and Corelight 2019-10-10 08-47-50

Leave a comment