build 7bbbddf7 | content blog-content@c8490fa · 338 posts | profiles 20 · corpus 267 | 0 skipped | | format
apiVersion: soultec.ch/v1kind: Solutionmetadata: name: endpoint-security locale: en labels: capability/endpoint-security: 3.54 capability/security: 2.16 vendor/vmware: 0.88 vendor/microsoft: 2.53 annotations: source: src/content/solutions/en/endpoint-security.md route: /en/solutions/endpoint-security/ schema: /nerd/schema/solutions.json markdown: /en/solutions/endpoint-security.mdspec: title: Endpoint Security tags: [endpoint-security, security] vendors: [vmware, microsoft] summary: >- Devices left the company network faster than they were secured. Two products cover this, and choosing between them is rarely the hard part. photoNeed: A security console on screen with real alerts in it, being triaged stub: false draft: false kind: vendor addon: false status: current sections: - heading:

Why this is its own category

body: | Devices left the company network, and not everywhere was securing them thought through first. Most attacks now use techniques like lateral movement and island hopping: they do damage through tools that are already permitted on the machine. A scanner comparing files against a list sees none of it. - heading:

What these products do differently

body: | VMware Carbon Black and Microsoft Defender read system events to learn what normal activity looks like in an estate. What stands out is then not the file but the sequence: why is this Office document starting PowerShell. Much of the value is in the recording. After an incident you can reconstruct what happened, and that is the difference between "we had something" and "we know what we had". - heading:

The question that actually matters

body: | Which of the two fits is usually settled by existing licensing rather than by detection rates. The harder question comes after: who is looking. EDR with nobody assigned to it is a data store.status: corpus: 267 services: - {ref: services/modern-workplace, score: 0.81} - {ref: services/security, score: 0.76} - {ref: services/network, score: 0.49} - {ref: services/cloud, score: 0.41} posts: - {ref: posts/vmware-security-advisory, score: 0.57} - {ref: posts/vmware-security-advisory-vmsa-2024-0012, score: 0.57} - {ref: posts/vmware-security-advisory-vmsa-2022-0030, score: 0.57} - {ref: posts/vmware-security-advisory-2022-021, score: 0.57} - {ref: posts/how-to-renew-the-sts-signing-root-certificate-in-vcenter, score: 0.51} - {ref: posts/how-to-broadcom-download-token, score: 0.51} experts: - {ref: experts/matthias-frech, score: 0.38} neighbours: - {ref: solutions/endpoint-security/vmware-carbon-black, score: 1.00} - {ref: solutions/endpoint-security/microsoft-defender-atp, score: 1.00} - {ref: solutions/vmware/vmware-cloud-foundation/addon/advanced-cyber-compliance, score: 0.51}
{ "apiVersion": "soultec.ch/v1", "kind": "Solution", "metadata": { "name": "endpoint-security", "locale": "en", "labels": { "capability/endpoint-security": "3.54", "capability/security": "2.16", "vendor/vmware": "0.88", "vendor/microsoft": "2.53" }, "annotations": { "source": "src/content/solutions/en/endpoint-security.md", "route": "/en/solutions/endpoint-security/", "schema": "/nerd/schema/solutions.json", "markdown": "/en/solutions/endpoint-security.md" } }, "spec": { "title": "Endpoint Security", "tags": [ "endpoint-security", "security" ], "vendors": [ "vmware", "microsoft" ], "summary": "Devices left the company network faster than they were secured. Two products cover this, and choosing between them is rarely the hard part.", "photoNeed": "A security console on screen with real alerts in it, being triaged", "stub": false, "draft": false, "kind": "vendor", "addon": false, "status": "current" }, "sections": [ { "heading": "

Why this is its own category

",
"body": "Devices left the company network, and not everywhere was securing them thought through\nfirst. Most attacks now use techniques like lateral movement and island hopping: they do\ndamage through tools that are already permitted on the machine. A scanner comparing files\nagainst a list sees none of it." }, { "heading": "

What these products do differently

",
"body": "VMware Carbon Black and Microsoft Defender read system events to learn what normal activity\nlooks like in an estate. What stands out is then not the file but the sequence: why is this\nOffice document starting PowerShell.\n\nMuch of the value is in the recording. After an incident you can reconstruct what happened,\nand that is the difference between \"we had something\" and \"we know what we had\"." }, { "heading": "

The question that actually matters

",
"body": "Which of the two fits is usually settled by existing licensing rather than by detection\nrates. The harder question comes after: who is looking. EDR with nobody assigned to it is a\ndata store." } ], "status": { "corpus": 267, "services": [ { "ref": "services/modern-workplace", "score": "0.81" }, { "ref": "services/security", "score": "0.76" }, { "ref": "services/network", "score": "0.49" }, { "ref": "services/cloud", "score": "0.41" } ], "posts": [ { "ref": "posts/vmware-security-advisory", "score": "0.57" }, { "ref": "posts/vmware-security-advisory-vmsa-2024-0012", "score": "0.57" }, { "ref": "posts/vmware-security-advisory-vmsa-2022-0030", "score": "0.57" }, { "ref": "posts/vmware-security-advisory-2022-021", "score": "0.57" }, { "ref": "posts/how-to-renew-the-sts-signing-root-certificate-in-vcenter", "score": "0.51" }, { "ref": "posts/how-to-broadcom-download-token", "score": "0.51" } ], "experts": [ { "ref": "experts/matthias-frech", "score": "0.38" } ], "neighbours": [ { "ref": "solutions/endpoint-security/vmware-carbon-black", "score": "1.00" }, { "ref": "solutions/endpoint-security/microsoft-defender-atp", "score": "1.00" }, { "ref": "solutions/vmware/vmware-cloud-foundation/addon/advanced-cyber-compliance", "score": "0.51" } ] }}
apiVersion = "soultec.ch/v1"kind = "Solution"[metadata]name = "endpoint-security"locale = "en"[metadata.labels]"capability/endpoint-security" = "3.54""capability/security" = "2.16""vendor/vmware" = "0.88""vendor/microsoft" = "2.53"[metadata.annotations]source = "src/content/solutions/en/endpoint-security.md"route = "/en/solutions/endpoint-security/"schema = "/nerd/schema/solutions.json"markdown = "/en/solutions/endpoint-security.md"[spec]title = "Endpoint Security"tags = ["endpoint-security", "security"]vendors = ["vmware", "microsoft"]summary = "Devices left the company network faster than they were secured. Two products cover this, and choosing between them is rarely the hard part."photoNeed = "A security console on screen with real alerts in it, being triaged"stub = falsedraft = falsekind = "vendor"addon = falsestatus = "current"[[sections]]heading = "

Why this is its own category

"
body = '''Devices left the company network, and not everywhere was securing them thought throughfirst. Most attacks now use techniques like lateral movement and island hopping: they dodamage through tools that are already permitted on the machine. A scanner comparing filesagainst a list sees none of it.'''[[sections]]heading = "

What these products do differently

"
body = '''VMware Carbon Black and Microsoft Defender read system events to learn what normal activitylooks like in an estate. What stands out is then not the file but the sequence: why is thisOffice document starting PowerShell.Much of the value is in the recording. After an incident you can reconstruct what happened,and that is the difference between "we had something" and "we know what we had".'''[[sections]]heading = "

The question that actually matters

"
body = '''Which of the two fits is usually settled by existing licensing rather than by detectionrates. The harder question comes after: who is looking. EDR with nobody assigned to it is adata store.'''[status]corpus = 267[[status.services]]ref = "services/modern-workplace"score = "0.81"[[status.services]]ref = "services/security"score = "0.76"[[status.services]]ref = "services/network"score = "0.49"[[status.services]]ref = "services/cloud"score = "0.41"[[status.posts]]ref = "posts/vmware-security-advisory"score = "0.57"[[status.posts]]ref = "posts/vmware-security-advisory-vmsa-2024-0012"score = "0.57"[[status.posts]]ref = "posts/vmware-security-advisory-vmsa-2022-0030"score = "0.57"[[status.posts]]ref = "posts/vmware-security-advisory-2022-021"score = "0.57"[[status.posts]]ref = "posts/how-to-renew-the-sts-signing-root-certificate-in-vcenter"score = "0.51"[[status.posts]]ref = "posts/how-to-broadcom-download-token"score = "0.51"[[status.experts]]ref = "experts/matthias-frech"score = "0.38"[[status.neighbours]]ref = "solutions/endpoint-security/vmware-carbon-black"score = "1.00"[[status.neighbours]]ref = "solutions/endpoint-security/microsoft-defender-atp"score = "1.00"[[status.neighbours]]ref = "solutions/vmware/vmware-cloud-foundation/addon/advanced-cyber-compliance"score = "0.51"
<?xml version="1.0" encoding="UTF-8"?><manifest kind="Solution"> <apiVersion>soultec.ch/v1</apiVersion> <metadata> <name>endpoint-security</name> <locale>en</locale> <labels> <entry key="capability/endpoint-security">3.54</entry> <entry key="capability/security">2.16</entry> <entry key="vendor/vmware">0.88</entry> <entry key="vendor/microsoft">2.53</entry> </labels> <annotations> <source>src/content/solutions/en/endpoint-security.md</source> <route>/en/solutions/endpoint-security/</route> <schema>/nerd/schema/solutions.json</schema> <markdown>/en/solutions/endpoint-security.md</markdown> </annotations> </metadata> <spec> <title>Endpoint Security</title> <tags> <item>endpoint-security</item> <item>security</item> </tags> <vendors> <item>vmware</item> <item>microsoft</item> </vendors> <summary>Devices left the company network faster than they were secured. Two products cover this, and choosing between them is rarely the hard part.</summary> <photoNeed>A security console on screen with real alerts in it, being triaged</photoNeed> <stub>false</stub> <draft>false</draft> <kind>vendor</kind> <addon>false</addon> <status>current</status> </spec> <sections> <section> <heading>

Why this is its own category

</heading>
<body>Devices left the company network, and not everywhere was securing them thought throughfirst. Most attacks now use techniques like lateral movement and island hopping: they dodamage through tools that are already permitted on the machine. A scanner comparing filesagainst a list sees none of it. </body> </section> <section> <heading>

What these products do differently

</heading>
<body>VMware Carbon Black and Microsoft Defender read system events to learn what normal activitylooks like in an estate. What stands out is then not the file but the sequence: why is thisOffice document starting PowerShell.Much of the value is in the recording. After an incident you can reconstruct what happened,and that is the difference between "we had something" and "we know what we had". </body> </section> <section> <heading>

The question that actually matters

</heading>
<body>Which of the two fits is usually settled by existing licensing rather than by detectionrates. The harder question comes after: who is looking. EDR with nobody assigned to it is adata store. </body> </section> </sections> <status> <corpus>267</corpus> <services> <item> <ref>services/modern-workplace</ref> <score>0.81</score> </item> <item> <ref>services/security</ref> <score>0.76</score> </item> <item> <ref>services/network</ref> <score>0.49</score> </item> <item> <ref>services/cloud</ref> <score>0.41</score> </item> </services> <posts> <item> <ref>posts/vmware-security-advisory</ref> <score>0.57</score> </item> <item> <ref>posts/vmware-security-advisory-vmsa-2024-0012</ref> <score>0.57</score> </item> <item> <ref>posts/vmware-security-advisory-vmsa-2022-0030</ref> <score>0.57</score> </item> <item> <ref>posts/vmware-security-advisory-2022-021</ref> <score>0.57</score> </item> <item> <ref>posts/how-to-renew-the-sts-signing-root-certificate-in-vcenter</ref> <score>0.51</score> </item> <item> <ref>posts/how-to-broadcom-download-token</ref> <score>0.51</score> </item> </posts> <experts> <item> <ref>experts/matthias-frech</ref> <score>0.38</score> </item> </experts> <neighbours> <item> <ref>solutions/endpoint-security/vmware-carbon-black</ref> <score>1.00</score> </item> <item> <ref>solutions/endpoint-security/microsoft-defender-atp</ref> <score>1.00</score> </item> <item> <ref>solutions/vmware/vmware-cloud-foundation/addon/advanced-cyber-compliance</ref> <score>0.51</score> </item> </neighbours> </status></manifest>
Solution · VMware

Endpoint Security

Devices left the company network faster than they were secured. Two products cover this, and choosing between them is rarely the hard part.

VMware Pinnacle Partner

Topics Endpoint Security 3.54 Security 2.16
Vendors VMware 0.88 Microsoft 2.53
04Services
06Posts
02Capabilities
267Corpus

Why this is its own category

Devices left the company network, and not everywhere was securing them thought through first. Most attacks now use techniques like lateral movement and island hopping: they do damage through tools that are already permitted on the machine. A scanner comparing files against a list sees none of it.

What these products do differently

VMware Carbon Black and Microsoft Defender read system events to learn what normal activity looks like in an estate. What stands out is then not the file but the sequence: why is this Office document starting PowerShell.

Much of the value is in the recording. After an incident you can reconstruct what happened, and that is the difference between “we had something” and “we know what we had”.

The question that actually matters

Which of the two fits is usually settled by existing licensing rather than by detection rates. The harder question comes after: who is looking. EDR with nobody assigned to it is a data store.

Posts about it

Who works with it

Do you work with this? Take a look at our open roles.