SCUGBE_Lowlands_Unite_2017_1E tachyon

15
® October 2017 Navin Bagga Solutions Engineer, 1E Email: [email protected]

Transcript of SCUGBE_Lowlands_Unite_2017_1E tachyon

®

October 2017

Navin BaggaSolutions Engineer, 1E

Email: [email protected]

1E: 20 years of systems management experience

Technology Awards

Licenses

Customers>100,000

users

Patented Innovations

Employee owned

Years of systems

management

Organizations

Estimated yearly savings for the

US Dept. of Veterans Affairs

31 31m

76

40+

100%

20

1700

$25m

Employees300+

Weeks Days Hours Minutes

Increasing demand for operations agility

Security monitoring

Operational issues

Digital disruption

Security remediation

SAM audits

M&A planning

Business Priorities

Accelerate Digital

Business

Faster Incident

Response

Automate Compliance

Digital demands greater speed and automation

Front end User Many Intermediary

processes

Many Intermediary

processes LargeDatabases

End Point

Great for:• Policy based management and complex

repetitive tasks: application management and OS migration

• Any task where an immediate response is not required

Are not agile:• Can’t respond to new requests, threats

and opportunities• Require highly sophisticated operators• Take a long time to configure, action,

validate and report

IT operations tools today

Ask questions,

Get immediate answers

Establish patterns through forensics

Have instructions carried out instantly

“Videoconferencing rather than letter writing”

So they can

A new capability is neededThe capability for the operator to have a conversation with all endpoints in real time

Introducing TachyonReal-time conversation with all endpoints

Direct connection from the operator to the endpoint No staging points, no batch processesClients can be outside the LAN in coffee shops, airports, anywhere

Scales to the whole organization for completeness and correlation1m+ endpoint supportAlmost zero impact on network, clients and IT operationsCorrelate: software, processes, network, users, configuration and history

Product PacksExpert learning shared across the organization

Tachyon provides a direct connection to the endpointTachyon provides a direct connection to the endpointTachyon provides a direct connection to the endpoint

Tachyon provides a direct connection to the endpointTachyon: Instructions

Instructions

Questions Actions

Tachyon Example – Simple question across all endpoints

Some use cases…

Software and/or Hardware inventory

• Of data not available by default in SCCM – in real time

• Troubleshoot by identifying changes over past X days… correlate with app/device crash data…

Operational issue that requires an update to a file or registry key

• No need to create a script for SCCM, deploy same, etc. takes days… capability is already in Tachyon, takes seconds –can be tested and rolled out in stages, in minutes.

Monitor which users are accessing which domains/websites

• Track usage of Cloud based applications

• Identify who is logging into/administering AWS and Azure workloads

Windows 10 readiness assessment

• Hardware compatibility, BIOS/UEFI, TPM versions, etc. Real time/instant.

And much, much more!

E.g. Use Case: Ransomware – detection and response

• Investigate and understand exposure in seconds– Including on machines NOT on VPN/WAN… any internet connection is ok

• Remediate as soon as kill-switch or patch is available

• Leverage “Tachyon Exchange” to download 1E or community driven IOC searches and remediation's

• Emergency changes were leveraged for Petya– Can take 48 hours to remove Local Administrative Rights

– Tachyon can identify machines with identical passwords and enable LAR administration in minutes rather than hours.

• With Tachyon, as soon as the change is approved it can be actioned and confirmed

Link in emailinfects devices

Devices

Email linkexploits Java

Java downloadsmalware

Threatactors

Watch the demo here:https://vimeo.com/200328814/9d0403b206

Fastest EDR solution - enables a conversation with endpoints everywhere

Almost zero impact on network, clients and IT operations

While standalone, makes SCCM even more effective

Real answers from all endpoints – no caching

Product Pack - Expert learning shared across the organization

Correlation of all IT data for rapid analysis and remediation

Why Tachyon instead of alternatives?

Thank you

Navin BaggaSolutions Engineer, 1E

Email: [email protected]