TMCnet News

Guidance Software Speeds and Synthesizes Incident Response
[November 04, 2015]

Guidance Software Speeds and Synthesizes Incident Response


Guidance Software, makers of EnCase®, the gold standard for digital investigations and endpoint data security, today announced EnCase® Endpoint Security version 5.10. Named the market leader in endpoint detection and response by industry analysts, the company has focused this release on reducing the time required by security teams to triage and validate alerts from a rapidly growing number of internal security tools and external threat-intelligence sources.

"Incident response teams need open standards and integrations like these in order to bring the most power to bear in their daily work," said Doug Cahill, senior analyst covering cybersecurity at ESG. "Enabling Indicators of Compromise (IOCs) in a standardized and thus actionable format is a big step in the right direction and will help not only promote endpoint detection and response functionality, but the company's commitment to open standards."

In Version 5.10, EnCase Endpoint Security focuses on synthesizing workflow for security teams with:

  • Support for the Indicator of Compromise searching of YARA rules, allowing teams to search for known IOCs and identify threats validated by internal or external industry sources
  • Integration with Splunk (News - Alert) Enterprise to collect and present trusted endpoint telemetry automatically when a security alert is generated, ensuring faster decisions and a dramatic reduction in false positives for security teams
  • File reputation checking from Lastline, allowing security analysts to validate threat artifacts of suspect files directly within EnCase, accelerating the decision process
  • The EnCase Integrated Threat Toolkit (EITT), which adds reach to 15 critical open-source tools and integrates additional functionality for incident responders
  • Remediation of the complete threat, including malicious files, derivatives, and persistence mechanisms, preventing re-exposure to the same malware

"Security teams cannot tolerate inefficiency in their daily activities. We've worked to solve this by increasing interoperability etween the tools they use most often and by delivering fast access to trusted endpoint data," said Roger Angarita, director of product management at Guidance Software. "Our customers demand continuous innovation that meets them right where they live and work."



EnCase Endpoint Security version 5.10 will be available through Guidance Software authorized resellers in late November. For more information on pricing, packaging and upgrades, please contact [email protected].

About EnCase Endpoint Security


EnCase® Endpoint Security provides proactive threat detection and incident response capabilities to the growing number of organizations who require endpoint visibility to detect, validate and prioritize unknown threats, assess the scope and impact of a compromise, and return devices to a trusted state.

Leveraging the lightweight EnCase agent that enables the industry's deepest endpoint visibility, EnCase Endpoint Security exposes threats not recognized by signature-based products. It does this by baselining normal endpoint activity, and then spotting anomalies occurring where sensitive data resides. Once a potential threat has been identified, automated processes can be launched to take critical first steps for triage, threat validation and incident response. Finally, EnCase Endpoint Security surgically remediates all instances of the validated threat, eliminating the need to wipe and reimage systems.

About Guidance Software

Guidance (NASDAQ: GUID) exists to turn chaos and the unknown into order and the known-so that companies and their customers can go about their daily lives as usual without worry or disruption, knowing their most valuable information is safe and secure. Makers of EnCase®, the gold standard in digital investigations and endpoint data security, Guidance provides a mission-critical foundation of applications that have been deployed on an estimated 25 million endpoints and work in concert with other leading enterprise technologies from companies such as Cisco (News - Alert), Intel, Box, Dropbox, Blue Coat Systems, and LogRhythm. Our field-tested and court-proven solutions are used with confidence by more than 70 of the Fortune 100 and hundreds of agencies worldwide.

Guidance Software®, EnCase®, EnScript®, EnCE™, EnCEP™, Linked Review™, EnPoint™ and Tableau™ are trademarks owned by Guidance Software and may not be used without prior written permission. All other trademarks and copyrights are the property of their respective owners.

GUID-F


[ Back To TMCnet.com's Homepage ]