What We Do
How we do it
Resources
SECURITY ADVISORIES
Sep 14, 2021
Update 2: Microsoft Zero-Day Vulnerability Announced - CVE-2021-40444
THE THREAT UPDATE 2: As of September 14th, Microsoft has released security patches to address CVE-2021-40444 for all impacted versions of Windows. eSentire has tested the update and confirmed its validity against public exploits. Organizations are strongly recommended to apply these security patches as soon as possible, as exploitation in the wild is ongoing. UPDATE: As of September 11th,…
Read More
View all Advisories →
Company
ABOUT eSENTIRE
About Us
eSentire is The Authority in Managed Detection and Response Services, protecting the critical data and applications of 1000+ organizations in 70+ countries from known and unknown cyber threats. Founded in 2001, the company’s mission is to hunt, investigate and stop cyber threats before they become business disrupting events.
Read about how we got here
Leadership Work at eSentire
LATEST PRESS RELEASE
Aug 25, 2021
eSentire named a Leader in IDC MarketScape for U.S. Managed Detection and Response Services
August 26, 2021 – Waterloo, ON -  eSentire, recognized globally as the Authority in Managed Detection and Response (MDR), announced today that it has been named a Leader in the IDC MarketScape: U.S. Managed Detection and Response Services 2021 Vendor Assessment (doc #US48129921, August 2021). IDC defines the core services an MDR must provide as follows: reduced time for onboarding, 24/7…
Read More
Partners
PARTNER PROGRAM
Partners
Our award-winning partner program offers financial rewards, sales and marketing tools and personalized training. Accelerate your business and grow your revenue by offering our world-class Managed Detection and Response (MDR) services.
Learn about our Partner Program
Search
How we do it
ESENTIRE MDR FOR CLOUD

Simplifying Multi-Cloud Security

We protect your cloud with 24/7 Threat Detection, Investigation and Cloud Security Posture Management. Our experts provide seamless monitoring, scanning and control over your multi-cloud environment delivering unmatched visibility, correlation and protection from cloud-specific threats.

Build a Custom Quote

CLOUD SECURITY BY THE NUMBERS

62 %

of organizations have at least 2 clouds1

53 %

of organizations don’t have the cloud visibility they need2

47 %

of organizations lack qualified cloud security staff3

1 Billion

of records we lost due to misconfiguration of cloud environments in 20194

12021 State of the Cloud & State of Multicloud Reports. 2 Cybersecurity Insiders CISO Cloud/SaaS Report, 2020 Cloud Security Report. 3 2020 Cloud Security Report, Cybersecurity Insiders. 4 2020 IBM Cloud Threat Landscape Report.

Protect Your Multi-Cloud Environment With Confidence

24/7 Threat Detection and Investigation

We detect and investigate threats specific to multi-cloud environments leveraging our cloud-native Atlas XDR platform, proprietary MITRE ATT&CK-mapped detectors, and our 24/7 Security Operations Centers (SOCs) staffed with Elite Threat Hunters and experienced Cyber Analysts.

Cloud Security Posture Management

We reduce your risk by improving cloud visibility, tracking assets and monitoring for misconfigurations, policy notifications and security vulnerabilities. Our cloud services optimize your multi-cloud environment and are aligned to industry best practices across AWS, Microsoft and Google Cloud platforms.

How We Help

Cloud environments are incredibly dynamic. Most cloud threats stem from the misconfiguration and unaccounted use of the cloud platform itself. At eSentire, we prioritize the detection of configuration-related threats and suspicious activity on the cloud platforms you’re leveraging, so you can focus on scaling your business operations securely. Our cloud experts have a deep understanding of the refined tactics, techniques and procedures (TTPs) leveraged by attackers in multi-cloud environments. We deliver MDR for Multi-Cloud environments across AWS, Microsoft and Google to protect your business from cloud-based threats including:

Misconfigurations

Policy Violations

Unauthorized Access

Insecure Interfaces

Unusual Admin Activity

Resource Hijacking

Exposed Data

Insecure APIs and Vulnerabilities

We provide:

24/7 Cloud Visibility and Threat Detection

Elite Threat Hunting Expertise

24/7 Cloud Threat Investigation

Threat Response Unit (TRU) Proprietary Detections

24/7 Data Correlation Across Cloud, Endpoint, Network and Log sources

Deep Knowledge of TTPs Specific for Multi-Cloud Environments

24/7 Cloud Security Posture Management

Actionable Insight and Data Correlation From Your Cloud Escalations

Managed Vulnerability Scanning Across Your Multi-Cloud Environment

Scalable, Reliable, Redundant Cloud-Native MDR Support


How We Help

Your Outcomes


THREAT DETECTION AND INVESTIGATION

How We Help

  • 24/7 threat detection mapped to MITRE ATT&CK framework
  • Rapid human-led investigations
  • Purpose-built detections and automated disruptions from cloud-native XDR Platform
  • Threat Response Unit (TRU) creating proprietary detections

Your Outcomes

  • Reduce risk of security incident in your multi-cloud environment
  • Improved cloud visibility and MITRE coverage
  • Reduced threat actor dwell time
  • Alleviate resource constraints
  • Reduce reliance on legacy security tools
  • Improved cyber resiliency

CLOUD SECURITY POSTURE MANAGEMENT

How We Help

  • 24/7 deep visibility and cloud control
  • Security rules and best practices governing and controlling your multi-cloud
  • Detect, investigate and remediate critical misconfigurations, security vulnerabilities, policy violations and Indicators of Compromise

Your Outcomes

  • Maximize ROI on multi-cloud environments
  • Enforcement of critical security rules
  • Cloud security program that scales
  • Reduce cloud knowledge gaps
  • Improved time to value in managing risks at the administration level of your multi-cloud environment

Managed Detection And Response For Your Multi-Cloud Environment

We understand each cloud platform is unique and has different uses in a multi-cloud strategy. We deliver 24/7 Threat Detection & Investigation and Cloud Security Posture Management across AWS, Microsoft and GCP.

Aws cloud

MDR for AWS

We hunt and investigate threats across AWS services including but not limited to:

  • AWS Simple Storage Service (S3)
  • AWS Elastic Compute Cloud (EC2)
  • AWS Relational Database Service (RDS)
  • AWS Virtual Private Cloud (VPC)
  • AWS WAF
  • AWS Shield Advanced
  • AWS GuardDuty
  • AWS CloudTrail

We’re certified as an AWS L1 MSSP.

Learn More
Microsoft cloud

MDR for Microsoft

We hunt and investigate threats across Microsoft Cloud services including but not limited to:

  • Azure Sentinel
  • Microsoft Defender for Endpoint
  • Microsoft Defender for Office 365
  • Microsoft Cloud App Security (MCAS)
  • Azure Active Directory
  • Azure Defender
  • Azure Security Center
  • Azure Blob Storage

We’re certified as a Microsoft Silver Partner.

Learn More
Gcp cloud

MDR for Google

We hunt and investigate threats across Google Cloud services including but not limited to:

  • GCP Cloud Storage
  • GCP Compute Engine
  • GCP Cloud IAM
  • GCP Cloud SQL
  • GCP Cloud KMS
  • Google Cloud IAM
  • Google Workspace Security Center

Connect with an eSentire Security Specialist.

Get Started

It's time for comprehensive cloud protection that scales.
Ready to get started?

Build A Quote Now

MDR Built To Scale With Your Growing Multi-Cloud Environment

The eSentire Atlas XDR Cloud Platform makes eSentire’s Managed Detection and Response service possible. Patented machine learning eliminates noise, enables real-time detection and response and automatically blocks known and unknown threats. Our distributed, cloud-native platform was built to provide security, reliability, and redundancy at scale and on demand to grow with your business and cloud security needs.

Cloud page diagram
Learn about the industry’s most advanced XDR Platform.

Cloud Content Driven By Industry Experts

eSentire’s Threat Response Unit (TRU) delivers counter-threat research and proprietary content to stay ahead of attackers targeting multi-cloud environments. TRU builds proprietary detectors, and runbooks across AWS, Microsoft and Google environments, all mapped to the MITRE ATT&CK framework. We publish original research and security advisories so you’re up to date on the latest cyber landscape and cloud security risks.

LEARN MORE ABOUT ESENTIRE’S THREAT RESPONSE UNIT →

eSentire In Action


24/7 MDR with Azure Sentinel & Azure Active Directory (AD)


The Challenge:

Threat actors commonly try to remove important security controls like multi-factor authentication (MFA) to gain or maintain access to a user account they have targeted.

Detection:

24/7 SOC Cyber Analysts are alerted via Azure Sentinel whenever MFA requirements are removed and follow a proprietary runbook to streamline the investigation process.

Response:

A sudden change in MFA requirements is very unusual and a potential indicator of compromise. With the right context established and the eSentire Atlas XDR platform’s direct integration with Azure AD, our analyst can suspend the credentials of the user who removed the MFA policy, minimizing the risk of any other important security policies being tampered with.

Threat Detection and Investigations in Google Cloud Platform (GCP)


The Challenge:

Cloud infrastructure providers like GCP provide significant geographic regional control on where their data is stored. Threat actors can use this to their advantage as a means of evading detection, by creating cloud instances in unused geographic service regions.

Detection:

eSentire has a proprietary GCP detector and investigative runbook designed to regularly scan for cloud administrative activity in typically unused GCP regions and our 24/7 SOC Cyber Analysts are alerted if such activity is identified.

Response:

Our analysts alert would alert you and confirm if the activity is expected or not. If not, SOC analysts would recommend the user’s credentials be suspended, perform further investigative work to determine if any other malicious admin activities happened, and find the initial intrusion source.


What our customers are saying

Venerable greyscale logo
Cloud is essential to meet the demands needed to grow our business. We build upon our existing relationship with eSentire and the robust cybersecurity capabilities they provide to continue to mitigate threats across our growing cloud footprint."
Michael Guenzler
Chief Information Security Officer | Venerable
Mcsaatchi greyscale logo
By combining eSentire’s Atlas XDR cloud platform, with 24/7 Threat Hunting and sophisticated security operations leadership, eSentire has helped shape our security defense and helped us improve our cyber resiliency."
Neil Waugh
Chief Information Officer | M&C Saatchi
Hks greyscale logo
Every time we call the eSentire SOC, we get a true security analyst on the first touch to walk us through our incidents clearly and efficiently. No other provider delivers such personalized service and expertise. Leveraging the eSentire Atlas platform, in conjunction with access to their sophisticated threat intelligence team, we have been able to cut our incident time to resolution in half."
Michael Smith
Vice President, Director of Information Technology | HKS

Ready to get started?

We’re here to help! Submit your information and an eSentire representative will be in touch to demonstrate how eSentire Multi-Signal MDR stops threats before they impact your business.