https://store-images.s-microsoft.com/image/apps.8596.3867f274-016c-4a46-aed6-8b69254837bc.2aa63117-373c-4a74-b9e0-aa79d8f31182.983f1401-0d1c-429e-a585-20f70d681c4d

EtherSensor

Microolap Technologies

EtherSensor

Microolap Technologies

Application level network traffic analyzer for detecting internal security policies violations

EtherSensor Insider Threat Visibility (ITV) edition for Azure - a cloud-based application level network traffic analyzer for detecting internal security policies violators in organization.
As a result of traffic processing, EtherSensor ITV creates information security events that are transmitted to consumer systems.

The use of the following consumer systems is recommended:

  • Splunk UBA
  • IBM QRadar UBA
  • ArcSight UBA
  • InfoWatch Traffic Monitor
  • McAfee Total Protection for DLP
  • Symantec DLP

Security events content and metadata help consumer systems to discover:

  • atypical (abnormal) user behavior
  • illegal access to internal information resources
  • unintentional or malicious leaks of confidential data

Additionally obtained security events at the investigation stage allow to answer the following questions:

  • who and when got access to particular internal information resource
  • how certain confidential data was actually distributed within the company
  • with whom the user was communicating inside and outside the company, which files were transferred
  • what external services were used

EtherSensor ITV features:

  • works with a copy of network traffic from various data sources (SSL Visibility, Web Proxy, Network Appliance)
  • as a result, normalized information security events are transmitted to consumer systems (SIEM, DLP, IAM)
  • analyzes high-speed network flows, which allows you to process all network traffic (and not just traffic from the perimeter of the network)

Supported data sources:

  • network devices which support port mirroring
  • NGFW with SSL decryption features
  • SSL Visibility Appliance
  • Web Proxy with ICAP functions
  • Lotus Notes Transaction Log
  • PCAP files
https://store-images.s-microsoft.com/image/apps.28349.3867f274-016c-4a46-aed6-8b69254837bc.2aa63117-373c-4a74-b9e0-aa79d8f31182.c0f09b8f-e52f-45cf-9961-b9c7adb1aba3
https://store-images.s-microsoft.com/image/apps.28349.3867f274-016c-4a46-aed6-8b69254837bc.2aa63117-373c-4a74-b9e0-aa79d8f31182.c0f09b8f-e52f-45cf-9961-b9c7adb1aba3
https://store-images.s-microsoft.com/image/apps.63250.3867f274-016c-4a46-aed6-8b69254837bc.a95fb789-3b40-435d-addf-263e146ac5a6.a4b7703a-131c-4b72-ac21-848ff5bf0faa