2020-05-18T12:28:00Z

Which ransomware is the biggest threat in 2020?

99

Which EPP provider does the best job at ransomware protection? Which provider is best at proactively defending against unknown threats?

ITCS user
Guest
66 Answers

author avatar
Top 5LeaderboardReal User

SentinelOne is my recommended solution.


The SentinelOne Endpoint Protection Platform (EPP) unifies prevention, detection, and response in a single purpose-built agent, powered by machine learning and automation. It is not reliant on hash signatures or an internet connection. SentinelOne provides prevention and detection of attacks across all major vectors and rapid elimination of threats with a fully automated real-time response without human intervention.


SentinelOne can also detect and protect against zero-day, file less and lateral movement attacks.


SentinelOne has not been breached and offers upto $1,000,000 warranty if it cannot roll back a ransomware attack.


Please contact me at cybersec@global.co.za for more information, a demonstration, or a quote.

2020-08-26T10:53:20Z
author avatar
Top 5LeaderboardReal User

OK a real tricky answer. There are so many out there now and all seem to have one or the other upper hand on the ransomware arena. It all depends on their back end system finally - How they analyse and how fast they analyse (even if in the wild) . And most importantly how fast u can get tech support - Try out Crowdstrike, Checkpoint, Sophos, McAfee, TrendMicro. Remember this - you need to be more specific with your actual physical scenario to get a better answer. This one is very generic in purpose.

2020-05-19T06:30:37Z
author avatar
Real User

Cortex XDR de Palo Alto Networks is the best solution in the market, because it has protection methods multiples, like are Local Machine Learning/IA, Static Analysis, Dynamic Analysis, Network Profiling, Baremetal, Exploits Protection (By technical or method, no by exploit), Kernel Protection, Behavior Anomaly Protection, etc. Best score in the Mitre att&ck Evaluation.

2020-05-18T23:02:28Z
author avatar
User

There are several good ones and it depends on budget, integrations needed, staff levels, etc. Crowdstrike Falcon is great if you can afford it. Price reflects "set it and forget it" type of EPP. No need to hire FTE to manage it and comes with 24x7x365 SOC. If you can manage, SentinelOne offers great detections and incident response capabilities (it is really an EDR). S1 has a ransomware rollback feature in case it gets through initial detections (can restore encrypted files if needed) and provides up to 1 million in ransom costs to back up their confidence. If you are a Checkpoint shop and want to leverage some of their other features (Cloudguard SaaS, Endpoint Encryption, etc.) then their Sandblast agent also offers great detections and a rollback feature of their own. Palo Alto traps is decent if you are a PAN shop but can get heavy on admin overhead. Same with Cisco AMP. We do not sell traditional A/V anymore because of polymorphic threats and zero day. Must have behavioral analytics and anomaly detection capabilities.

2020-05-18T21:50:39Z
Find out what your peers are saying about CrowdStrike, SentinelOne, Cisco and others in Endpoint Protection for Business (EPP). Updated: September 2021.
534,226 professionals have used our research since 2012.