1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Review: SentinelOne blocks and dissects threats

Discussion in 'Network World' started by RSS, Aug 31, 2016.

  1. RSS

    RSS New Member Member

    SentinelOne Endpoint Protection Platform (EPP) is an antimalware solution that protects against targeted attacks, malware, and zero-day threats through behavioral analysis and process whitelisting and blacklisting. The client agent, which analyzes the behavior of processes on Windows, OS X, Linux, and Android endpoints, can replace or run alongside other signature-based antimalware solutions. SentinelOne EPP stands out not only for its protection capabilities but also for its excellent forensics and threat analysis.

    SentinelOne evaluates process behavior based on "dynamic execution patterns." The agent scans endpoints, indexes application files and processes, and sends information about them to the cloud where they are assigned reputation scores. When scores surpass policy thresholds, processes can be killed, files quarantined, and endpoints rolled back to the last known-good state. Metadata about processes and files are pooled among SentinelOne's customers, building an anonymous threat intelligence network that benefits everyone.

    To read this article in full or to leave a comment, please click here

    (Insider Story)

    Continue reading...

Share This Page