What We Do
How we do it
Jul 26, 2021
PetitPotam NTLM Relay Attack
THE THREAT PetitPotam is a variant of NTLM Relay attacks discovered by security researcher Gilles Lionel. Proof of Concept code released last week [1] relies on the Encrypting File System Remote (EFSRPC) protocol to provoke a Windows host into performing an NTLM authentication request against an attacker-controlled server, exposing NTLM authentication details or authentication certificates.…
Read More
View all Advisories →
About Us
eSentire is The Authority in Managed Detection and Response Services, protecting the critical data and applications of 1000+ organizations in 70+ countries from known and unknown cyber threats. Founded in 2001, the company’s mission is to hunt, investigate and stop cyber threats before they become business disrupting events.
Read about how we got here
Leadership Work at eSentire
Jul 12, 2021
Tecala and eSentire Partner to Protect Enterprises across APAC from Business-Disrupting Cyber Attacks
Sydney, 12 July, 2021 - Tecala, Australia’s award-winning technology services and IT consulting provider, today announced it has chosen eSentire, the global Authority in Managed Detection and Response (MDR) cybersecurity services, as their exclusive MDR solution provider in Australia and New Zealand. This partnership will enable Tecala to augment its cybersecurity practice and offer enterprises…
Read More
Our award-winning partner program offers financial rewards, sales and marketing tools and personalized training. Accelerate your business and grow your revenue by offering our world-class Managed Detection and Response (MDR) services.
Learn about our Partner Program
Blog — Jun 30, 2021

Better Together: How Combining MDR and IR Create Stronger Cyber Resilience

4 min read

It’s impossible for businesses to participate in today’s interconnected and data-centric economy without becoming exposed to cyber risk. No matter how strong your safeguards are or how robust your processes are, cyber defenses can—and will—fail.

For small and midsized organizations without the resources to build, staff, and maintain an in-house 24/7 Security Operations Center (SOC), relying on a trusted partner to deliver these Managed Detection and Response (MDR) capabilities is essential.

Beyond detection and containment

While MDR gives you access to 24x7 expert SOC support necessary to detect and contain potential breaches, it’s not designed to provide evidence that can hold in a court of law. By nature, MDR is meant to stop threat actors before they can successfully gain access into your networks, not remediate a breach.

If you need to conclusively determine the precise extent of data loss, or if you’re looking to investigate an incident in granular detail—right down to the level of the individual compromised record—you’ll need to tap into a different skillset: Digital Forensics and Incident Response.

Incident Response (IR) is explicitly designed to fulfill the most exacting requirements of cyber insurers, regulators, and prosecutors. These services comprise a distinct discipline that incorporate evidence-handling techniques as well as the mastery of digital forensics tools.

It’s important to note that while organizations can engage an MDR provider or IR services provider, there will always be a distinct advantage to augmenting MDR capabilities with Digital Forensics and IR.

Adopting an “assume breached” mentality and the emerging imperative of due diligence

Today’s Chief Information Security Officers (CISOs) and IT departments are increasingly adopting the “assume breached” mentality. This approach includes creating robust security monitoring capabilities which enable teams to rapidly detect, respond to, and contain any cyber threat with the potential to disrupt the business.

New and evolving threats are increasingly revealing the shortcomings of traditional IR. For businesses that operate by driving billable hours, on-site client meetings, and a reliance on stale technologies, legacy IR providers are far too slow and expensive to provide the timely and effective incident response needed.

In addition, trusting IR to a non-expert isn’t really a viable option as doing so introduces different kinds of risks, which defeats the purpose. For example:

Since all cyber risk cannot be mitigated, CISOs and their teams must exercise due diligence to demonstrate that they did what any reasonable person would do to balance these risks. Insurers, regulators, and courts frequently expect that organizations will have IR capabilities in-house or will maintain these capabilities through an external IR retainer agreement.

Organizations must be able to meet these expectations, especially as cybersecurity insurance policies continue to change in the face of the current devastating global ransomware epidemic.

Modern IR to deal with modern threats

In our recent announcement to extend our core response capabilities deeper into the incident lifecycle, Bryan Sartin, our Chief Services Officer, stated, “When faced with a security incident, how quickly an organization can contain and recover is paramount to limiting business disruption and reputational damage.”

That’s why our Digital Forensics and Incident Response capabilities provide a 4-hour remote threat suppression service level agreement for organizations anywhere in the world. This agreement is only possible because of our innovative engagement model that converges Incident Response, Threat Intelligence and our 24/7 SOC Cyber Analyst expertise with advanced technology to deliver time-to-value in terms of threat suppression and complete incident resolution.

In addition to determining the true extent of a breach, eSentire’s Artemis IR team can provide support in satisfying reporting obligations, transitioning findings to law enforcement, implementing lessons learned, and providing guidance through crisis communications—tasks that are challenging, if not impossible, for most businesses to perform on their own.

As we explain in our new ebook, MDR + IR: A Recipe for Cyber Resilience in a Twenty-First Century Risk Landscape, by converging MDR and IR within a single response provider, we are able to:

Ultimately, we’ve created modern IR to deal with modern threats.

To learn more about the IR needs of today’s businesses, please check out the on-demand webinar, The Next Generation of Cyber Investigation and Response, featuring eSentire thought leaders, Bryan Sartin, Chief Services Officer, and Mark Sangster, VP and Industry Security Strategist.


eSentire is the Authority in Managed Detection and Response, protecting the critical data and applications of 1000+ organizations in 70+ countries from known and unknown cyber threats. Founded in 2001, the company’s mission is to hunt, investigate and stop cyber threats before they become business disrupting events. Combining cutting-edge machine learning XDR technology, 24/7 Threat Hunting, and proven security operations leadership, eSentire mitigates business risk, and enables security at scale. The Team eSentire difference means enterprises are protected by the best in the business with a named Cyber Risk Advisor, 24/7 access to SOC Cyber Analysts & Elite Threat Hunters, and industry-leading threat intelligence research from eSentire’s Threat Response Unit (TRU). eSentire provides Managed Risk, Managed Detection and Response and Incident Response services. For more information, visit www.esentire.com and follow @eSentire.