SentinelOne® Launches Singularity™ RemoteOps Forensics for Incident Response and Evidence Acquisition
- SentinelOne's Singularity RemoteOps Forensics allows security teams to perform efficient and streamlined investigations with unprecedented speed and scale
- The solution optimizes resources and accelerates Mean Time to Resolution
- It automates evidence collection and consolidates it into one data pool for comprehensive analysis
- Integrated with SentinelOne agent, it eliminates the need for multiple tools during investigations
- None.
New solution combines forensics evidence with real-time telemetry to deliver unified insights into security incidents analysts need to perform investigation and response activities with efficiency and speed
“As timelines for reporting and responding to breaches shrink, it is imperative that security teams have advanced forensics capabilities that make investigations faster and more efficient, and with Singularity RemoteOps Forensics, we are delivering them," said Jane Wong, Senior Vice President of Products and Strategy, SentinelOne.
Seamlessly integrated with the SentinelOne Singularity™ Platform and offered as an add-on to Sentinel One’s Endpoint and Cloud Workload Security solutions, RemoteOps Forensics is a fast, efficient, and flexible digital forensics and incident response solution that security teams can use to:
- Optimize resources and accelerate Mean Time to Resolution
- Perform ad-hoc or conditional trigger-based evidence collection, enabling targeted investigations on one or multiple assets including endpoints and server workloads.
- Automate the collection of evidence, such as processes, ports, service listings, MFT, Amcache, JumpLists, and memory dumps, and orchestrate them in less than a minute.
- Consolidate evidence into one data pool through the Singularity Security DataLake, correlating SentinelOne and partner data with forensics data in the same search to create a comprehensive picture of an attack, quickly identify the root cause and take measures to mitigate risk.
- Analyze collected evidence alongside Endpoint Detection and Response (EDR) data in one console to proactively defend against future threats.
- Correlate and analyze integrated data to uncover hidden indicators of compromise, identify advanced attack patterns, and understand the tactics, techniques, and procedures employed by threat actors.
And, fully integrated with the SentinelOne agent, RemoteOps Forensics eliminates the need to deploy and provision multiple tools during investigations, saving organizations both time and resources. The solution also makes investigations more forensically sound, as less changes are made on disk, and SentinelOne employs its anti-tampering capabilities as well as metadata collection capabilities to ensure data integrity is maintained.
“SentinelOne's new forensic capabilities are reinventing incident response by empowering security teams to perform deep investigations in less time without the need for niche expertise or additional tools,” Wong said.
Singularity RemoteOps Forensics is available and in use by customers today. Click here for a free demo to learn more about the solution and the value it can deliver for your organization.
About SentinelOne
SentinelOne is the leader in autonomous cybersecurity. SentinelOne’s Singularity™ Platform detects, prevents, and responds to cyber attacks at machine speed, empowering organizations to secure endpoints, cloud workloads, containers, identities, and mobile and network-connected devices with speed, accuracy and simplicity. Over 11,000 customers, including Fortune 10, Fortune 500, and Global 2000 companies, as well as prominent governments, trust SentinelOne to secure the future today. To learn more, visit www.sentinelone.com
View source version on businesswire.com: https://www.businesswire.com/news/home/20230913365573/en/
Karen Master
SentinelOne
karen.master@sentinelone.com
+1 (440) 862-0676
Source: SentinelOne