+
+

Related Products

  • ManageEngine Log360
    190 Ratings
    Visit Website
  • Graylog
    438 Ratings
    Visit Website
  • Daylight
    11 Ratings
    Visit Website
  • ManageEngine EventLog Analyzer
    211 Ratings
    Visit Website
  • Blumira
    150 Ratings
    Visit Website
  • Criminal IP
    457 Ratings
    Visit Website
  • ThreatLocker
    700 Ratings
    Visit Website
  • Omnilert
    26 Ratings
    Visit Website
  • Criminal IP ASM
    21 Ratings
    Visit Website
  • ManageEngine ADAudit Plus
    619 Ratings
    Visit Website

About

Standing watch, by your side. Intelligent security analytics for your entire enterprise. See and stop threats before they cause harm, with SIEM reinvented for a modern world. Microsoft Sentinel is your birds-eye view across the enterprise. Put the cloud and large-scale intelligence from decades of Microsoft security experience to work. Make your threat detection and response smarter and faster with artificial intelligence (AI). Eliminate security infrastructure setup and maintenance, and elastically scale to meet your security needs—while reducing IT costs. Collect data at cloud scale—across all users, devices, applications, and infrastructure, both on-premises and in multiple clouds. Detect previously uncovered threats and minimize false positives using analytics and unparalleled threat intelligence from Microsoft. Investigate threats with AI and hunt suspicious activities at scale, tapping into decades of cybersecurity work at Microsoft.

About

NetWitness Platform brings together evolved SIEM and threat defense solutions that deliver unsurpassed visibility, analytics and automated response capabilities. These combined capabilities help security teams work more efficiently and effectively, up-leveling their threat hunting skills and enabling them to investigate and respond to threats faster, across their organization’s entire infrastructure—whether in the cloud, on premises or virtual. Gives security teams the visibility they need to detect sophisticated threats hiding in today’s complex, hybrid IT infrastructures. Analytics, machine learning, and orchestration and automation capabilities make it easier for analysts to prioritize and investigate threats faster. Detects attacks in a fraction of the time of other platforms and connects incidents to expose the full attack scope. NetWitness Platform accelerates threat detection and response by collecting and analyzing data across more capture points.

Platforms Supported

Windows Not Supported
Mac Not Supported
Linux Not Supported
Cloud Supported
On-Premises Supported
iPhone Not Supported
iPad Not Supported
Android Not Supported
Chromebook Not Supported

Platforms Supported

Windows Not Supported
Mac Not Supported
Linux Not Supported
Cloud Supported
On-Premises Not Supported
iPhone Not Supported
iPad Not Supported
Android Not Supported
Chromebook Not Supported

Audience

IT security teams

Audience

IT security teams looking for an accelerated threat detection and response from endpoint to the cloud to rapidly detect targeted attacks

Support

Phone Support Supported
24/7 Live Support Supported
Online Supported

Support

Phone Support Supported
24/7 Live Support Supported
Online Supported

API

Offers API Supported

API

Offers API Not Supported

Screenshots and Videos

Screenshots and Videos

Pricing

Logs from Microsoft 365 are ingested for free.
Free Version Supported
Free Trial Supported

Pricing

No information available.
Free Version Not Supported
Free Trial Not Supported

Reviews/Ratings

Overall 5.0 / 5
ease 4.5 / 5
features 5.0 / 5
design 4.0 / 5
support 5.0 / 5

Reviews/Ratings

Overall 0.0 / 5
ease 0.0 / 5
features 0.0 / 5
design 0.0 / 5
support 0.0 / 5

This software hasn't been reviewed yet. Be the first to provide a review:

Review this Software

Pros & Cons from Real Users

Pros

  • Seamlessly integrates with other Microsoft services such as Azure and Office 365, leveraging existing infrastructure and familiarity. Utilizes AI and machine learning to detect and respond to advanced threats quickly. Scales effectively to meet the needs of both small businesses and large enterprises, handling vast amounts of data efficiently. Provides automation capabilities for incident response and remediation, improving efficiency and reducing manual effort. Helps organizations meet compliance requirements with built-in tools and capabilities.
  • Built on Azure, Microsoft Sentinel scales effortlessly to handle increasing log volumes without requiring on-premises infrastructure upgrades Deep integration with M365, Azure Active Directory, Defender for Endpoint, and mdCloud enhances security monitoring across endpoints, identities, and workloads Sentinel collects and correlates data from a wide range of sources, including third-party solutions, using connectors. Integration with threat intelligence feeds enhances its detection capabilities Supports KQL (Kusto Query Language) for custom query creation, giving analysts flexibility in analyzing and visualizing log data Sentinel leverages built-in AI and ML to identify anomalies, detect threats, and reduce false positives. Customizable analytics rules allow security teams to focus on relevant alerts

Cons

  • Users may face a learning curve, especially if they are not familiar with Azure or Microsoft's ecosystem, impacting initial setup and configuration. Depending on usage and scale, costs associated with Azure Sentinel can be significant, especially for smaller organizations or those with limited budgets.
  • While Sentinel follows a pay-as-you-go model, costs for data ingestion can escalate quickly, especially for large-scale organizations generating high volumes of logs. Retention beyond 90 days incurs additional expenses, making cost management a challenge Sentinel works best within the Microsoft ecosystem. Organizations with diverse tech stacks or heavy reliance on non-Microsoft services may find its integrations with third-party tools less seamless or feature-rich compared to vendor-agnostic SIEM solutions

Training

Documentation Supported
Webinars Supported
Live Online Supported
In Person Supported

Training

Documentation Supported
Webinars Supported
Live Online Supported
In Person Not Supported

Company Information

Microsoft
Founded: 1975
United States
azure.microsoft.com/en-us/products/microsoft-sentinel/

Company Information

NetWitness
Founded: 1997
United States
www.netwitness.com

Alternatives

Alternatives

Fidelis Elevate

Fidelis Elevate

Fidelis Security
NetworkMiner

NetworkMiner

Netresec

Categories

Categories

SIEM Features

Application Security Supported
Behavioral Analytics Supported
Compliance Reporting Supported
Endpoint Management Supported
File Integrity Monitoring Supported
Forensic Analysis Supported
Log Management Supported
Network Monitoring Supported
Real Time Monitoring Supported
Threat Intelligence Supported
User Activity Monitoring Supported

Endpoint Detection and Response (EDR) Features

Behavioral Analytics Supported
Blacklisting/Whitelisting Not Supported
Continuous Monitoring Supported
Malware/Anomaly Detection Supported
Prioritization Supported
Remediation Management Supported
Root Cause Analysis Supported

Integrations

Google Digital Risk Protection Supported
Microsoft Defender for IoT Supported
SOC Prime Platform Supported
AWS AppFabric Not Supported
Admin By Request Endpoint Privilege Management Supported
Amazon Simple Queue Service (SQS) Supported
Baits Supported
D3 Smart SOAR Not Supported
Delinea Cloud Access Controller Supported
Docusign Supported
Intezer AI SOC Supported
Liminal Supported
Microsoft Security Copilot Supported
NXLog Supported
Prancer Supported
Recorded Future Not Supported
SIGNL4 Supported
TYCHON Supported
Vimeo Supported
Workday HCM Supported

Integrations

Google Digital Risk Protection Supported
Microsoft Defender for IoT Supported
SOC Prime Platform Supported
AWS AppFabric Supported
Admin By Request Endpoint Privilege Management Not Supported
Amazon Simple Queue Service (SQS) Not Supported
Baits Not Supported
D3 Smart SOAR Supported
Delinea Cloud Access Controller Not Supported
Docusign Not Supported
Intezer AI SOC Not Supported
Liminal Not Supported
Microsoft Security Copilot Not Supported
NXLog Not Supported
Prancer Not Supported
Recorded Future Supported
SIGNL4 Not Supported
TYCHON Not Supported
Vimeo Not Supported
Workday HCM Not Supported
Claim Microsoft Sentinel and update features and information
Claim Microsoft Sentinel and update features and information
Claim NetWitness and update features and information
Claim NetWitness and update features and information