Arctic Wolf - Another Layer of Protection
Use Cases and Deployment Scope
Agents installed on all end points and servers. Monitoring location, logins and potential malicious file and scripts running. Email alerts sent to specified contacts and phone call if issue severity is high. Location based alerts for 365 accounts will trigger when a user account is accessed outside of whitelisted countries.
Pros
- Monitoring 365 logins
- Monitoring Windows processes
- Active Directory monitoring
Cons
- Some erroneous 365 alerts about failed logins
- Need an easier method to suppress alerts (outside of email)
- Too many places to look for info in console
Return on Investment
- Stopped unauthorized 365 access on user account
- Pointed out malicious file activity on end point
- Alert sent when a domain admin account was enabled
Alternatives Considered
Check Point Harmony Endpoint, Check Point Harmony Email & Office and NinjaOne