Endace and the EndaceProbe Analytics Platform

Additional Info

CompanyEndace
Websitehttp://www.endace.com
Company size (employees)50 to 99
Headquarters RegionNorth America
Type of solutionHardware

Overview

Packets provide crucial, tamper-resistant evidence of network activity. But always-on packet capture with deep history has traditionally been out of reach for many enterprises, due to cost of storage, rack space and the resources required to sift through and analyze petabytes of recorded packets of interest.

The EndaceProbe Analytics Platform addresses these barriers to adopting continuous packet capture. EndaceProbe is the industry’s only open packet capture platform — being able to host, and integrate with, leading third-party solutions — which enables SecOps and NetOps teams to quickly deploy analytics tools to where the data resides, making it easy to adapt their infrastructure as new threats emerge.

In September 2022, Endace announced a next-generation series of EndaceProbes, specifically built for high-speed packet capture at network edge and branch locations. The 2100 Series EndaceProbes provide sustained recording at up to 40 Gbps, with up to 120 TB of effective packet storage in a compact, 1RU form factor. They are purpose-built for network edge locations, such as remote offices and branch offices. The new models dramatically increase packet capture performance and storage depth, quadrupling the hosting capacity of previous models. And in March 2022, Endace announced a software upgrade, extending support for threat hunting and security incident response with easier file reconstruction, log generation, and multi-tenancy support.

By combining EndaceProbes with the tools and applications they use every day, customers can leverage network recording to significantly improve the security of their critical network infrastructure. EndaceProbes dramatically increase a team’s ability to defend the entire network, from core to edge, and quickly remediate even the most serious threats. Customers gain a better, faster, more efficient and affordable process for recording, accessing and sharing recorded packet data. SecOps and NetOps teams gain access to the definitive evidence needed to accelerate threat investigation and response.

How we are different

• The new 2100 Series EndaceProbes provide sustained recording at up to 40 Gbps, with up to 120 TB of effective packet storage in a compact, 1RU form factor. They are purpose-built for network edge locations, such as remote offices and branch offices. The new models dramatically increase packet capture performance and storage depth. They also quadruple the hosting capacity of previous models, enabling customers to deploy third-party network security and performance monitoring solutions.


• The Endace OSm 7.1 software update: empowers security analysts, regardless of packet forensics experience, to easily reconstruct and extract files from recorded packet data to rapidly understand the nature and extent of threats or breaches, allows analysts to generate detailed logs from recorded packet data, and enables MSSPs or organizations with multiple tenants to securely share packet recording infrastructure.


• EndaceProbe’s ability to host third-party security and performance monitoring tools ensures all tools have access to a common, accurate source of network data for analysis and enables hardware consolidation and rapid tool deployment. The ability to integrate a common packet capture technology across tools from multiple vendors, as well as with custom or open-source solutions, lets customers choose best-in-breed security tools without being locked-in to a single-stack vendor solution. This enables flexibility, freedom of choice and the ability to quickly change or upgrade tools in the future without having to rip-and-replace existing hardware.