What is our primary use case?
We have configured multiple scenario-based alerts for Cybereason Managed Detection & Response, such as known malware, potential unwanted programs, and PowerShell execution. We monitor suspicious activities and take action based on the priority of these alerts. We work with Cybereason to implement new features and ensure protection and exploit prevention.
What is most valuable?
The most valuable features of Cybereason Managed Detection & Response are its ability to categorize low-priority alerts as PUP alerts and its capability to trigger alerts for PowerShell execution and ransomware. It provides alerts for canary files and shadow volume activities, enabling us to validate whether they are performed by the admin team or are suspicious. The anti-ransomware and exploit prevention features are highly beneficial.
What needs improvement?
Initially, we observed multiple false positive alerts with Cybereason Managed Detection & Response. We've worked with Cybereason to whitelist and fine-tune alerts, particularly those related to ESLR detection, which created more noise in our environment. Identifying the purpose of each feature and its necessity for detection needs improvement.
For how long have I used the solution?
I have nearly four years of experience with Cybereason Managed Detection & Response. However, as of last September, we migrated to CrowdStrike EDR.
What was my experience with deployment of the solution?
The initial setup was easy. I would rate it as nine out of ten due to minor errors based on operating systems. The initial deployment was managed by previous teams, so I did not handle it personally.
What do I think about the stability of the solution?
Cybereason Managed Detection & Response is highly stable. It's a crucial tool for organizational security, allowing us to identify high-level attacks and ransomware effectively.
What do I think about the scalability of the solution?
I would rate the scalability of Cybereason Managed Detection & Response as nine out of ten. It is a great tool for detection and response, with prompt vendor support.
How are customer service and support?
I would rate the technical support as nine out of ten. Sometimes, follow-ups are required to get a response from Cybereason, but we've not experienced severe issues.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
Before Cybereason, I worked with Cisco AMP but faced issues with configuration and policy creation, leading to more noise from alerts. Cybereason was a better alternative.
How was the initial setup?
The initial setup was smooth and easy. Based on minor errors related to operating systems, I would rate the setup as nine out of ten.
What about the implementation team?
The initial implementation of Cybereason Managed Detection & Response was done by previous teams, so I am not fully aware of the process details.
What was our ROI?
After installing Cybereason Managed Detection & Response, we reduced the number of people needed for monitoring, effectively decreasing costs. Previously, 20 to 30 members were needed; now, it's managed by only five to ten members.
Which other solutions did I evaluate?
In evaluating other options, both Cybereason and CrowdStrike are equal in effectiveness. The choice depends on client requirements and cost considerations.
What other advice do I have?
I rate Cybereason Managed Detection & Response nine out of ten overall. It is a scalable and stable solution, offering good features for organizational security.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
*Disclosure: I am a real user, and this review is based on my own experience and opinions.