What is our primary use case?
The main use case for me is to get network detection and response as we are migrating many network devices, so we get a very broad idea about all the information that we may miss normally from this product and get all the security alerts and incidents recorded and investigated through that and have a very clear picture of any issues that bother us during the migration.
In this project, while we connect the devices from the old system to the new system, it gives us a great view to understand the threats or risks that might be on the old devices and helps us to mitigate those alerts and to respond to those security threats and to improve on them. Plus, it gives us a clear picture of what work we will need to do during and after the migration.
It also helps us to control the lateral movements of the devices by securing them, and we also get the asset discovery and network visibility through that. Last but not least, it helps us to do threat hunting as well.
What is most valuable?
In my experience, the features that are available with
ExtraHop Reveal(x) 360, one of the best features I have seen is their dashboard in the NDR, the way it shows you and how you can deeply dive into protocol level settings. Plus, it helps to do asset discovery and profiling. It also has good behavioral AI and ML related pattern recognition, and I have also seen it does a very good job in terms of advanced decryption, plus lateral movement detections and packet forensics. One other thing I have noticed it does is threat hunting and MITRE ATT&CK mapping.
In terms of the dashboard, the key features focused on the network security team are basically security overview, posture, the active detections, its risk levels, and severities it's showing, so during the migration, we can see the overall security posture of the devices and network and also understand the detection dashboard from the high critical or critical detections and suspicious behavior of the devices, any sort of credential attacks I have seen, or policy and security violations. Also, we can see the top communicating devices in it as well.
I think what we can add more is the application network performance area in that as well, so in terms of any issues with applications I have seen, we can mitigate that and we have seen we can pinpoint what can be the root cause during that application flow, specifically looking at the application response time, the network latency, errors, throughputs, and application dependencies in that.
In terms of workload and pinpointing issues, ExtraHop Reveal(x) 360 has helped us a lot and made our life as network Level 3 support easier. As most of the application-related issues were really hard to troubleshoot, we have now real-time visibility. We can do deep level, protocol level analysis from Layer 2 to Layer 7, and we can have automatic threat detection and we have investigation workflows. We can do integration from the new environments easily, and we can integrate it with our SIEM which is Splunk easily, plus we have operational collaboration. So it has made our life very easy.
What needs improvement?
In terms of improvement, I have found sometimes ExtraHop Reveal(x) 360 duplicates data a bit because it basically spans the data information from the sources within the network, so sometimes it's very hard to correlate data because it sometimes gets multiple feeds. I would to say that it needs to have some sort of internal check to validate data rather than duplicating from multiple sources so that we don't have to manually correct the source of truth.
Plus, I think I would like to see continued improvements in AI-assisted threat hunting and natural language queries so the analysts can move from high-level detection to the relevant user, device, application, and network evidence with fewer manual pivots. Making advanced features easier for less experienced analysts to use would help organizations to get more value from the platforms.
I would like to add one more thing: if we could have more customization of dashboards and role-based views, stronger out-of-the-box correlations with SIEM, EDR, and identity platforms, and maybe further automation of investigation response workflows, that will be great.
For how long have I used the solution?
I have been using ExtraHop Reveal(x) 360 for around three years now, and I have worked on it in my previous company with Cleanaway Private Limited as well as I'm working on it now, and we are working on the NDR module to get network detection and response from it.
What do I think about the stability of the solution?
I have seen only once or twice that ExtraHop Reveal(x) 360 has gone offline. Other than that, it's pretty much stable as per my understanding.
What do I think about the scalability of the solution?
In terms of scalability, I have seen that ExtraHop Reveal(x) 360 can be easily scaled up as it has a lot of potential.
How are customer service and support?
Customer support for ExtraHop Reveal(x) 360 was fantastic. I have worked with multiple account managers as well, and they have all been great and no problems with them.
Which solution did I use previously and why did I switch?
I did not use any solution previously. Before ExtraHop Reveal(x) 360, to be honest, I did not have a lot of options as not a lot of solutions were there in the market. I think only one of the solutions we were getting around was Cisco's
ThousandEyes. But the main reason for preferring ExtraHop was it was more suitable for our needs as we were mostly buying smaller companies, and we needed to get a lot of quick analysis done all the time through their quick network connectivity. The
ThousandEyes solution was not easy to implement all the time on a quick basis, and plus, its features were mostly restricted to the application-based issues and application latencies, but whereas in ExtraHop Reveal(x) 360, we had a lot more analysis and understanding of more issues. That's why we opted for ExtraHop.
How was the initial setup?
In terms of our environment, we deployed ExtraHop Reveal(x) 360 as on-premise completely, as we were trying to basically merge and join multiple networks into our network in the data center. We deployed two big boxes of their devices to span all the data onto it to get all the feeds and data analyzed on that, so this was done on-premises.
What other advice do I have?
My advice to other users who want to use ExtraHop Reveal(x) 360 is to go and procure it with confidence if you know what purpose you are trying to achieve from it. It's definitely a product to go through, and you won't be disappointed.
Regarding governance and security, I would say that though I'm not using the AI part a lot, it does help in the context of the AI. It has two useful angles: AI security and AI governance, which I have seen. It shows that it has controls in AI governance, such as approved AI tools, models, data classification, and access control. So if employees are using an external Gen AI service, we will need to get control over them, but with ExtraHop Reveal(x) 360, it comes with the AI security and AI governance as per my understanding.
In terms of the accuracy and reliability of the AI's capabilities, I would distinguish between generative and AI threat detection and such assistants. In terms of the behavioral machine language, it's very strong for identifying deviations from established network behavior and detecting anomalous activities. If you talk about threat detection, it combines the machine language and behavioral detections with signature detection, giving it coverage for both known and behavioral threats. In terms of accuracy, I would not claim that ExtraHop Reveal(x) 360's AI is 100% accurate or quote a generic accuracy percentage; cybersecurity AI's quality depends heavily on network visibility. ExtraHop itself uses a review process for detection types, evaluating them for efficiency and accuracy before progressively making them available. Where I think AI is particularly strong is in network behavioral analysis.
I would rate this review a 9 out of 10.