What is our primary use case?
Securonix UEBA is used for lateral movement detection, ransomware detection, multiple malware detections, user activity monitoring, and behavior analysis.
We have completed a large number of additional use cases based on specific effects and commitment.
What is most valuable?
Their user and entity behavior analysis algorithms are the most valuable features. I believe, the cyber analytics algorithm is the unique differentiator.
The built-in algorithms for detecting anomalies and threats.
What needs improvement?
When compared to others, if you look at the integration aspect, I believe that some aspects of integration can be enhanced. There are numerous other integrations with various packages that are possible.
For how long have I used the solution?
I have been working with Securonix UEBA for almost seven years.
What do I think about the stability of the solution?
The stability of Securonix UEBA is good. We have not had any problems.
What do I think about the scalability of the solution?
In terms of scalability, we tested 180,000 events per second with no problems.
It is not calculated based on the number of users. In terms of scalability, we calculate security platforms based on events per second. It can be one of the factors, but it is not the determining factor for scalability. Scalability is determined by the number of events that can be processed per second.
When looking at enterprise users who are connected to the SOC. An organization can have 100,000 employees, contractors, or staff, but that is not how the same solutions are allocated.
In that organization, based on assets, end users, endpoint network devices, and so on and so forth, the result will be events per second. In terms of the same tool usage, the same tool or Securonix tool will be used only by the number of SOC analysts who are monitoring the entire environment. Nobody else uses it.
The data for all employees and staff in that organization is consolidated. That is one way of looking at it, and it is not proportional. The number of employees and security events per second is not a direct correlation factor.
We are an MSSP. We use it based on the needs of our customers. We are not using it for our own internal purposes.
Based on our customer's requirements we deploy it.
How are customer service and support?
As platinum partners, we have excellent technical support. We have had no issues.
Which solution did I use previously and why did I switch?
We are using other log management tools such as RSI, IBM, Splunk, and ArcSight but not LogRhythm, or ELK.
We haven't used the NTA solution in a lot of places because it comes with Corelight. We've used it a few times, but that is not the quote. For the NTA, we use different packages.
We haven't used the SOR solution yet. We're looking into it right now and will make a decision later.
How was the initial setup?
The initial setup is not simple, but it is also not complicated; it is medium.
It will be determined by size. Securonix will be used by 30, or 40 analysts who monitor and manage the cyber environment.
There will not be thousands of people logging into Securonix because no one logs into Securonix UEBA. Only the SOC analyst will have access to Securonix.
What about the implementation team?
We are global system integrators for all these products.
What was our ROI?
ROI is evident. The ROI is there from cost optimization and everything else. However, it is dependent on how you deploy it, engineer it, and provide the necessary automation.
I would rate it a three out of five.
What's my experience with pricing, setup cost, and licensing?
When compared to other solutions, it is less expensive.
What other advice do I have?
It is a good tool. They can evaluate based on their business use case and requirements, and it will work.
I will rate them based on their scalability, flexibility, and adoption, as well as their specific analysis of threat detection via behavioral models. And, of course, there's the price. It is less expensive than the others. also deployment simplicity, it's simple to set up. It's not difficult.
We are partners as well as resellers.
I would rate Securonix UEBA an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
*Disclosure: My company has a business relationship with this vendor other than being a customer: Partner