Connect with us

Top Stories

Rapid7 Attacker Behaviour AnalyticsBrings Together Machine Learning and Human Security Expertise

Rapid7 Attacker Behaviour AnalyticsBrings Together Machine Learning and Human Security Expertise

InsightIDR is now the only SIEM providing User Behaviour Analytics, Endpoint Detection and Response, and Attacker Behaviour Analytics 

Rapid7, Inc. (NASDAQ: RPD), powering SecOps through its visibility, analytics and automation cloud, today announced a new capability, Attacker Behaviour Analytics (ABA), in its InsightIDR solution. Attacker Behaviour Analytics are detections that reveal unknown variants of successful attacker techniques, and are continually crafted by Rapid7’s global security analysts and threat intelligence teams. With ABA, InsightIDR customers directly benefit from this stream of intelligence from Rapid7 SOCs, resulting in earlier attack chain detection and faster possible response to evolving attacks.

“In order for a modern SIEM to be trusted as the heart of an incident detection program, it needs to collect and centralize the right data, apply the right analytics, and explain why the output is meaningful,” says Rebekah Brown, Threat Intelligence Leader at Rapid7.  “Technology is a great start, but security still requires a persistent focus on human adversaries. Attacker Behaviour Analytics allows our security analysts and threat intel teams to share what we are seeing on the frontlines automatically with all of our InsightIDR customers. Organisational blue teams don’t just want defence-in-depth, but expect agile detection engineering and guidance around adversary intent, capability, and opportunity. Now that our SOCs can directly contribute to InsightIDR, if we identify a novel attacker technique, we can push out a new detection to be automatically matched against customer data in hours.”

With the addition of ABA, all InsightIDR customers will automatically receive high-fidelity alerts on evolving attacker behaviours built from thousands of incident investigations, including the use of fileless malware, cryptojacking, and spear phishing. When these malicious techniques are identified, alerts highlight notable behaviour from the affected user and asset, making it significantly easier for security teams to respond quickly and with confidence.

Rapid7’s SIEM, InsightIDR, recognizsd as a Visionary in Gartner’s 2017 Magic Quadrant for Security Information and Event Management, is one of the company’s analytic and automation cloud solutions used by teams around the world to power the internal practice of SecOps. InsightIDR provides centralised log management, threat detection rules and correlations, user behavior analytics, machine learning, compliance dashboards, and integrates easily into existing workflows. With the addition of Attacker Behaviour Analytics, InsightIDR is the only SIEM solution that combines machine learning and ongoing human input to surface attacks as early as possible, and provide critical context about both the user and adversary in order to accelerate incident response.

Sign up for a free trial of InsightIDR:

Editorial & Advertiser disclosure
Our website provides you with information, news, press releases, Opinion and advertorials on various financial products and services. This is not to be considered as financial advice and should be considered only for information purposes. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third party websites, affiliate sales networks, and may link to our advertising partners websites. Though we are tied up with various advertising and affiliate networks, this does not affect our analysis or opinion. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you, or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish sponsored articles or links, you may consider all articles or links hosted on our site as a partner endorsed link.
Global Banking and Finance Review Awards Nominations 2021
2021 Awards now open. Click Here to Nominate


Newsletters with Secrets & Analysis. Subscribe Now