Back to main siteBack Contact us
Managed Detection and Response

eSentire

Managed Detection and Response

Signals from five places, one verdict

The Atlas XDR platform ingests network, endpoint, log, cloud and identity telemetry, correlates it into a single picture, and hands that picture to a staffed security operations centre that is authorized to act on it.

NETWORK ENDPOINT LOG CLOUD IDENTITY CORRELATE normalize + score SOC + TRU human decision ISOLATE SUSPEND PURGE
The pipeline

How a signal becomes a contained host

Each stage exists because the previous one produces something unusable on its own. Raw telemetry is not evidence, and evidence is not a decision.

01

Ingest from every layer, not just the endpoint

Agents and collectors gather network traffic, endpoint process activity, system logs, cloud service events and identity provider records. Coverage across layers matters because most intrusions are only anomalous when two layers are compared: an ordinary login and an ordinary file copy become a problem when they happen together at an unusual hour from an unfamiliar network.

A single-layer product will see one of those two events and score it as routine, which is how quiet intrusions survive their first week.

02

Normalize and correlate into one timeline

Signals arrive in different formats with different clocks and different names for the same machine. The platform normalizes them, resolves the identities involved, and assembles a single ordered account of what happened, which is the artefact an analyst can actually reason about.

eSentire reports that this layer automatically disrupts more than two thousand five hundred network events per customer per day before a human sees them, which is the volume that would otherwise fill the queue.

03

Investigate with a research team attached

The Threat Response Unit is eSentire's in-house research function. It publishes original research, runs proactive hunts and indicator sweeps across customer estates, and feeds updated detection logic back into the platform from real investigations rather than from a vendor feed.

The Threat Center view exposes that work to the customer directly, with MITRE ATT&CK mapping on the hunts being run, so the service is inspectable rather than opaque.

04

Respond inside the estate, not by email

Response actions include isolating a host, blocking a file hash, suspending a compromised account, purging a malicious message retroactively from mailboxes, and restarting affected systems. These are performed by the operations centre as part of handling the incident.

eSentire publishes a mean time to contain of under fifteen minutes, and states that 99.3 percent of incidents are contained at the first host, meaning the intrusion does not reach a second machine.

Specification

What the service includes at each layer

The table below is the practical scope, stated plainly, so it can be compared against what you run today.

LayerCollectedResponse available
networkTraffic patterns and disruptionsBlock and disrupt
endpointProcess and behavioural telemetryHost isolation
identityAuthentication and directory eventsAccount suspension
cloudService and configuration eventsSession revocation
emailDelivered message recordsRetroactive purge
logSystem and application logsCorrelation evidence
What changes

Where it sits in your stack

The service is not a replacement for every control you own. It is the layer that watches the controls and decides when something has gone wrong.

FIREWALL ENDPOINT AV IDENTITY DETECTION, DECISION AND RESPONSE
Honest qualification

What this suits, and what it asks of you

A strong fit

Estates with several security products that nobody correlates: an endpoint tool, a firewall, a cloud platform and an identity provider, each with its own console and its own alerts. The value delivered is the correlation and the decision, which is precisely the work a small team cannot staff.

What it requires

Telemetry has to be available for the service to reason about. Systems that cannot be instrumented, or cloud services with logging disabled to save cost, stay invisible regardless of how good the analysis is. Scoping that coverage honestly is part of the deployment rather than an afterthought.

In short

Start with what is currently correlated

The useful first exercise is a look at which telemetry sources exist today, which of them anyone reads, and what would happen if two of them disagreed at midnight.

Book the architecture review

Get in touch with Your Company

Questions about this solution? Reach us directly.