Combine cutting-edge XDR technology, multi-signal threat intelligence and 24/7 Elite Threat Hunters to help you build a world-class security operation.
Our team delivers the fastest response time in the industry. Threat suppression within just 4 hours of being engaged.
Cyber risk and advisory programs that identify security gaps and build security strategies to address them.
XDR with machine learning that eliminates noise, enables real-time detection and response, and automatically blocks threats.
24/7 SOC-as-a-Service with unlimited threat hunting and incident handling.
Proactive threat intelligence, original threat research and a world-class team of seasoned industry veterans.
Extend your team capabilities and prevent business disruption with expertise from eSentire.
Stop ransomware before it spreads.
Meet regulatory compliance mandates.
Detect and respond to zero-day exploits.
End misconfigurations and policy violations.
Defend third-party and supply chain risk.
Prevent disruption by outsourcing MDR.
Adopt a risk-based security approach.
Meet insurability requirements with MDR.
Protect your most sensitive data.
Defend brute force attacks, active intrusions and unauthorized scans.
Guard endpoints by isolating and remediating threats to prevent lateral spread.
Investigation and threat detection across multi-cloud or hybrid environments.
Remediate misconfigurations, vulnerabilities and policy violations.
Defend brute force attacks, active intrusions and unauthorized scans.
THE THREAT On February 20th, ConnectWise confirmed that two recently disclosed ScreenConnect vulnerabilities are now under active exploitation. The vulnerabilities are currently tracked as…Feb 09, 2024
THE THREAT On February 7th, CISA, NSA, FBI, along with Five Eyes intelligence partners, published a joint advisory related to state-sponsored threat actors from the People’s Republic of…
eSentire is The Authority in Managed Detection and Response Services, protecting the critical data and applications of 2000+ organizations in 80+ countries from known and unknown cyber threats. Founded in 2001, the company’s mission is to hunt, investigate and stop cyber threats before they become business disrupting events.
Waterloo, ON–February 7, 2024 – eSentire, Inc., the Authority in Managed Detection and Response (MDR), today announced that three of Australia’s top Value-Added Resellers (VARs): Advance Vision Technology, Exigo Tech, and Rubicon 8 have joined eSentire’s CRN 5-Star e3 partner…
We provide sophisticated cybersecurity solutions for Managed Security Service Providers (MSSPs), Managed Service Providers (MSPs), and Value-Added Resellers (VARs). Find out why you should partner with eSentire, the Authority in Managed Detection and Response, today.
We believe a multi-signal approach is paramount to protecting your complete attack surface. See why eSentire MDR means multi-signal telemetry and complete response.
See how our 24/7 SOC Cyber Analysts and Elite Threat Hunters stop even the most advanced cyberattacks before they disrupt your business.
Choose the right mix of Managed Detection and Response, Exposure Management, and Incident Response services to strengthen your cyber resilience.
Try our interactive tools including the MITRE ATT&CK Tool, the SOC Pricing Calculator, the Cybersecurity Maturity Assessment, and our MDR ROI Calculator.
Read the latest security advisories, blogs, reports, industry publications and webinars published by eSentire's Threat Response Unit (TRU).
See why 2000+ organizations count on eSentire to build resilience and prevent business disruption.
The Advanced Threat Analytics (ATA) team operates as eSentire’s advanced threat research and development branch. They concentrate on ways to solve the challenges posed by disparate data sets and expanding attack surfaces. Leveraging data science and machine learning expertise, the ATA team has created several proprietary and proven applications designed to identify threat actor tactics, techniques, and procedures that legacy security tools miss.
As part of our commitment to providing market-leading Managed Detection and Response (MDR) services, eSentire chose to partner with the Cyber Science Lab at the University of Guelph and Mitacs for two research projects. The collaboration between academia and industry aims to bring the best of both worlds to cyber security and eSentire customers.
Two promising University of Guelph students, Alex Chen and Samira Eisaloo Gharghasheh, enrolled in the Master of Cyber Security and Threat Intelligence program, were chosen to work closely with eSentire’s ATA team in an effort to research machine learning solutions to the problems that have been difficult to solve using legacy approaches.
Under the supervision of Ali Dehghantanha, director of the Cyber Science Lab and a professor at the University of Guelph, and myself, manager of the Advanced Threat Analytics team, both students spent four months analyzing large amounts of data and developing machine learning approaches to discovering adversaries and anomalous data points.
In the first project, titled “Detection of Enumeration Attacks in Cloud Environments Using Infrastructure Log Data,” Samira focused on data found in eSentire’s esLOG service.
With the complexities present in modern cloud environments, it can be a daunting task to keep track of permissions and policies. Users and service accounts often have more access than is strictly necessary, opening the doors for adversaries. Enumeration attacks are a common way for adversaries to expand their reach within a victim’s cloud environment. Once a set of credentials has been compromised or authentication tokens intercepted, the attacker will aim to discover resources they have gained access to. In order to achieve this, cloud services and accounts will be enumerated. Successful access will be further explored until a vulnerable system is found or data can be extracted.
In this project, Samira worked off AWS IAM logs that can be found and analyzed in esLOG. Through the use of Open Source red team tooling and real-world data, a wide variety of data points made up the training and validation data sets. Samira created long-short term memory (LSTM) and convolutional neural network (CNN) models to compare their performance and found that over 99% detection accuracy can be achieved.
“Classification and Anomaly Detection of Network Traffic at the Edge Using Transfer Learning” is a project Alex focused on, evaluating the benefits of transfer learning to introduce machine learning models that can accurately identify malicious network traffic in disparate customer environments.
Network traffic analysis traditionally employs large rule sets that identify well-known malicious behavior in the data stream. A subset of rules is usually specific to a customer’s environment and requires careful adjustment and monitoring when first deployed. Using machine learning, Alex attempted to reduce the need for manual intervention.
Having started out with a dataset provided by the Canadian Institute for Cybersecurity (CIC), a variety of different approaches were required to arrive at a solid model that would identify malicious actors based on network traffic. Using transfer learning techniques, a model was then trained to classify traffic captured as part of eSentire’s services. The new model used multiple fully-connected layers on top of the original one, leading to correct identification of malicious activity in over 94% of the cases.
Going forward, the Advanced Threat Analytics team, along with the eSentire organization, will continue to improve upon the above projects and integrate the detections into our portfolio. We hope to continue our partnerships and collaboration efforts in the future, and look forward to congratulating Samira and Alex on their Master’s degrees at the end of the semester.
Throughout this collaboration, the different perspectives and expertise from Samira, Alex, Ali and The University of Guelph and Mitacs have allowed all of us to grow and produce fantastic results and will be used to better serve eSentire customers around the world.
Tim leads eSentire's Advanced Threat Analytics team, working at the forefront of Machine Learning in the MDR space. He and his team deliver solutions to the most difficult to detect adversarial tactics.