The Vectra AI platform equips security operations centers (SOCs) with integrated signaling to ensure rapid and scalable extended detection and response (XDR) for hybrid attacks
Milan – 5 September 2023 — Vectra AI, a leader in AI-driven cyber threat detection and remediation for hybrid and multicloud enterprises, announced the Vectra AI Platform with Attack Signal Intelligence™ patented to provide the integrated signal businesses need to make extended detection and response (XDR) a reality. With Vectra AI Platform, enterprises can integrate Vectra AI signal for public cloud, identity, SaaS and network with existing signal for endpoint detection and response (EDR), to empower SOC teams to keep pace with the growing sophistication, speed and scale of hybrid attacks.
As companies have begun moving more applications, workloads and data into hybrid and multi-cloud environments, threat detection and response have become increasingly siled and complex. Without an effective solution against advanced hybrid attackers, security teams find themselves faced with a vicious cycle of larger attack surfaces, more evasive attack methods, more alerts and, consequently, more workload and burnout for SOC analysts.
According to one recent research, 63% of SOC analysts say the size of the attack surface has increased over the last three years and 67% cannot handle the number of alerts they receive daily. The Vectra AI Platform enables security teams to move at the speed of modern hybrid attackers to identify behavior that other tools cannot. By harnessing the power of Artificial Intelligence to analyze attacker behavior and automatically classify, correlate and prioritize security incidents, the Vectra AI Platform provides the integrated signal that powers XDR.
"For us, it's always about results, not acronyms. What matters is the end goal, not some predefined definition of how to get there," said Jay DePaul, Chief Cybersecurity & Technology Risk Officer at Dun & Bradstreet. “Vectra AI is helping us achieve our ultimate goals, stop advanced attacks, modernize our security operations, and ultimately improve our cyber resilience.”
According to Jon Oltsik, analyst and member of Enterprise Strategy Group (ESG), "Regardless of the definition of XDR, security professionals are interested in using it to address various threat detection and response challenges. Additionally, they want XDR to streamline security operations and enhance staff productivity.”
Get an integrated signal across all hybrid attack surfaces
The Vectra AI Platform integrates native and third-party attack signals across hybrid cloud domains, including AWS, Microsoft Azure, Google Cloud Platform, Microsoft 365, Microsoft Azure AD, networks of all types, and endpoints, leveraging the customer's chosen Endpoint Detection and Response (EDR) tool. Vectra AI Platform's built-in signaling enables security teams to:
- cover over 90% of MITER ATT&CK techniques with the patented and proven MITER D3FEND countermeasures;
- combine AI-driven detection based on behavior, signatures and threat intelligence to obtain the most accurate representation of active attacks in progress;
- map the progression and lateral movement of attackers from data center to cloud, from cloud to data center, and from cloud to cloud;
- create and grow threat hunting programs and conduct in-depth forensic investigations.
Automate hybrid attack detection with real-time Attack Signal Intelligence
Vectra AI Attack Signal Intelligence leverages patented Artificial Intelligence to automate threat detection, triage and prioritization across hybrid cloud domains:
- identifying attacker behavior, analyzing it across many dimensions to distinguish real attacks from a multitude of different attacks, while the patented Privileged Access Analytics (PAA) focuses on the accounts most useful to attackers;
- learning about customers' unique environments to distinguish between malicious and benign events and eliminate 80% of background noise from alerts;
- privileging entities (hosts and accounts) in the various domains based on urgency and importance, saving individual SOC analysts over three hours a day of triaging alerts.
Accelerate hybrid attack investigations with the response expertise of an analyst
With Vectra AI, security teams accelerate investigation and response workflows with integrated investigations that are sophisticated enough for experienced analysts and simple enough for junior analysts. New features include:
- Instant Investigations, which offer analysts of all skill levels quick guides to investigate priority entities under attack;
- advanced investigations, which allow forensic analysis of Azure AD, Microsoft 365 or AWS Control Plane logs directly in the user interface (UI) of the platform;
- AI-assisted investigations, which leverage large language models (LLM) to provide analysts with an easy way to gain 360-degree contextual information on entities under attack.
Perform targeted response actions natively or via ecosystem integrations and APIs
The Vectra AI Platform puts humans in control of the response, offering flexible response actions, both native and orchestrated, leveraging over 40 ecosystem integrations to:
- manually or automatically block an account or isolate an endpoint;
- enable security orchestration and automation (SOAR) playbooks and workloads;
- streamline ticketing, communication and escalation for incident response processes.
Embracing a Hybrid SOC Model with Vectra Managed Detection and Response (MDR)
SOC teams are increasingly under pressure due to the increasing volume and variety of high-velocity hybrid and multi-cloud attacks. With the Vectra AI Platform, companies can strengthen the work of their analysts with MDR services, which include:
- shared roles and responsibilities for monitoring, detection, investigation, hunting and response;
- shared analyzes on attackers' behavior and emerging techniques, tactics and procedures;
- shared transparency on SLA, metrics and reporting.
“The current approach to threat detection and response is fundamentally inadequate as more organizations move to hybrid environments and security teams continue to face growing cloud complexity, ongoing alert fatigue and analyst burnout,” he said Hitesh Sheth, President and CEO of Vectra AI. “As pioneers in AI-driven cyber threat detection and response, our best-in-class platform provides the most accurate integrated signal across the entire hybrid enterprise landscape today, to make XDR a rapid, scalable reality.”






