Badges

70 Points
6 Years

User Activity

About 2 years ago
Netanya Good question. I hope to give you a very simplistic answer.A DoS attack would be generated by a single IP or machine vs the Distributed DoS which is a multitude of hosts attacking a target from multiple IP's/ machines.In other words, a 1 to 1 attack vs a many to 1…
Over 2 years ago
Paul While I've not used Carbon I have used Cylance and Optics for years before moving away from them in favor of a more robust and easy to manage solution. Cylance, IF properly configured can stop the majority of attacks out there and incorporates machine learning. I would…
Over 2 years ago
@Satish Singh Thank you for your question it's one that requires deeper thought and understanding of the impacted environment. Several things you can do is to have an up-to-date IRP (Incident Response Plan) - This plan includes all layers of your organization from top to…
Over 2 years ago
Ariel Thank you for your question hope you are finding many answers to assist you here. My own opinion on this will probably be in line with multiple others here. Several questions I like to ask during this process are as follows: -Will this be hosted on cloud or on-prem?…
Over 2 years ago
Satish Thank you for your well-thought-out and detailed question on this topic. Many will have many opinions on this so prepare to get a little overwhelmed. Is this protection for your 10k+ staff or you're looking to resell this as a service? Sophos EDR is a possible…
Over 2 years ago
I haven't used Cortex. My worry with it and every other solution is how well does it perform when disconnected from the cloud/ the internet S1 - I have been using it for a couple of years now without an issue. I had been using Cylance prior. I've been very happy with the S1…
Over 2 years ago
@Samy Adel Thank you for the question. I hope you discover the answers here. First off does this company want to manage the EDR solution on-prem, or would they prefer a hosted solution? Windows-based shop or are the end points Mac, and Linux as well? EDR's I do prefer…
Over 2 years ago
Having used both I'd go with something other than either of these two solutions.  Both deep dive onto your local computers making them impossible to remove, Should the need arise you'll end up having to reimage equipment to fully remove the products. Bloated and they dig…
Over 2 years ago
S1 for sure.  Disconnect Falcon from the internet and it looses its ability to do anything. Falcon is still a fine product, for EDR I'd go S1.
Over 5 years ago
Consult with several VARs with any product being looked at. If possible work directly with the vendor of the product to avoid the VAR pressing you in any one direction. The product vendor can then point you to the proper/ best fit VAR offering the best price for the product…
About 6 years ago

About me

For the past 20+ yrs I’ve been in the information technology field. I earned an AAS degree in Network Administration. At my previous positions I’ve been responsible for the following:
Network Administartion
System Administration
Implementing and supporting new and existing IT Infrastructure and deployment of such equipment nationwide
Project management for those tasks and reporting back to VP and CIO of information technology
Mentoring and working with new helpdesk staff and new users
Infrastructure backup and establishment of DR locations
Administration of Active Directory, Group Policy
Implementation of CMMC standards
Wireless and SDWAN setups
Setup of new or relocation of warehouse location and researching new technology to assist in meeting business needs.