Now on Demand Ransomware Resilience & Recovery Summit - All Sessions Available
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybersecurity Funding

Cybereason Partners With Google Chronicle on XDR Product

Extended Detection and Response (XDR) is touted as the security solution for the increasingly complex modern IT ecosphere. The principle is to extend EDR threat hunting beyond the endpoint and across the entire infrastructure. Cybereason has announced a partnership with Google Chronicle – the latter to provide ecosphere data, and the former to provide the threat hunting capability.

Extended Detection and Response (XDR) is touted as the security solution for the increasingly complex modern IT ecosphere. The principle is to extend EDR threat hunting beyond the endpoint and across the entire infrastructure. Cybereason has announced a partnership with Google Chronicle – the latter to provide ecosphere data, and the former to provide the threat hunting capability.

Yonatan Striem-Amit, CTO and co-founder at Cybereason, explains the concept: “Over the last 18 months the old paradigm for what a network looks like has completely changed. Now IT professionals need to secure an insanely complex and heterogeneous environment,” he told SecurityWeek.

“To be effective today, an analyst needs to understand endpoint threats, and network threats, and IoT threats,and e-mail, and SaaS and cloud and its services and infrastructure. Securing all of those with disparate tools becomes an incredibly complex problem.”

For an EDR solution to become an XDR solution, it requires a combination of first accumulating data from the existing IT security stack, and then extending the EDR data analytics to also analyze the accumulated data. 

Cybereason has partnered with Google Chronicle to provide the data accumulation. And it has extended its MalOps analytics engine to examine the wider set of elements, such as email, SaaS solutions, and cloud. Cybereason XDR is no longer the first source of the data. Best of breed solutions can onboard their data into the new system and the customer gets the best solution from Google, SIEMs, and other tools combined with Cybereason’s hunting engine.

“We expanded the engine,” says Cybereason, “but the core fundamentals remain the same. The same MalOps engine, the same ability to hunt across the stack, the same ability to find complex stories and complex attack story lines no matter where they started or how complex or expanded they are – we can capture it all and respond to them in one click.”

“By combining forces with Google Chronicle, we take Google’s 20+ years of understanding how to index and extract value from data and map the world,” continued Striem-Amit. “We’re bringing Cybereason’s analytics engine – our ability to bring the operational centric approach – to find and recover threats and provide the complete end to end story. The combination of our XDR engine and Google Chronicle allows us to prevent, automate, detect, and respond to threats across the entire IT landscape within one system. It means that hackers can no longer hide between the seams.”

According to XDR proponents, the need is real and pressing. Over the last year there have been dozens of major attacks, from SolarWinds to the attacks against Microsoft Exchange Servers, and crippling ransomware threats from DarkSide, REvil and others.

Advertisement. Scroll to continue reading.

“These are not just an asset-based attack,” Striem-Amit said. “The attackers are no longer playing within the same old assets they and defenders used to play in. It’s no longer an endpoint problem separate from a network problem separate from a security policies problem. But by using Google’s ability to bring data from all these sources and make them accessible and normalized at the scale that only Google can deliver, and then combining that with Cybereason’s XDR hunting engine, we can deliver our operational centric approach, with our MalOps engine, throughout the stack.”

The Cybereason/Google partnership was announced at Google Cloud Next ’21.

“Google Cloud is dedicated to delivering the industry’s most trusted cloud to accelerate customers’ digital transformation efforts with security products that meet them wherever they are. Cybereason continues to disrupt the market and deliver on their vision for a future-ready extended detection and response defense platform,” said Thomas Kurian, CEO, Google Cloud.

If you believe in Cybereason’s EDR, then Cybereason’s XDR, partnered with Google Chronicle, delivers the same capabilities across the entire IT stack.

Related: XDR is a Destination, Not a Solution

Related: How Integration is Evolving: The X Factor in XDR

Related: XDR Platform Provider SentinelOne Files for IPO

Related: XDR Firm Cynet Raises $40 Million Series C Funding

Written By

Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Bill Dunnion has joined telecommunications giant Mitel as Chief Information Security Officer.

MSSP Dataprise has appointed Nima Khamooshi as Vice President of Cybersecurity.

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

More People On The Move

Expert Insights

Related Content

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.

Cybersecurity Funding

SecurityWeek investigates how political/economic conditions will affect venture capital funding for cybersecurity firms during 2023.

Cyber Insurance

Cyberinsurance and protection firm Boxx Insurance raises $14.4 million in a Series B funding round led by Zurich Insurance.

Cybersecurity Funding

2022 Cybersecurity Year in Review: Top news headlines and trends that impacted the security ecosystem

Endpoint Security

Today, on January 10, 2023, Windows 7 Extended Security Updates (ESU) and Windows 8.1 have reached their end of support dates.

Cybersecurity Funding

Network security provider Corsa Security last week announced that it has raised $10 million from Roadmap Capital. To date, the company has raised $50...

Funding/M&A

Thirty-five cybersecurity-related M&A deals were announced in February 2023

Funding/M&A

Forty-one cybersecurity-related M&A deals were announced in March 2023.