
Sophos - Sophos acquires Braintrace
Sophos
Further enhancing Sophos's adaptive cybersecurity ecosystem with Network Detection and Response (NDR) technology.
Sophos has announced the acquisition of Braintrace, an innovative provider of Network Detection and Response (NDR) technology. Braintrace's NDR provides deep insights into network traffic patterns, including encrypted traffic, without the need for man-in-the-middle (MitM) decryption.
Braintrace's NDR technology will enhance and extend Sophos's Managed Threat Response (MTR), Rapid Response and Extended Detection and Response (XDR) solutions by integrating with the Adaptive Cybersecurity Ecosystem that underpins all Sophos products and services. With the integration of Braintrace, defenders benefit from an "air traffic control system" that sees all network activity, uncovers unknown and unprotected assets, and exposes evasive malware more reliably than intrusion protection systems (IPS).
Braintrace has developed this technology specifically to provide better security outcomes for its Managed Detection and Response (MDR) customers. It's hard to beat the effectiveness of solutions developed by teams of experienced practitioners and developers to solve real-world cybersecurity problems.
Braintrace technology will also serve as a launching point for the collection and routing of third-party event data from firewalls, proxies, virtual private networks (VPNs) and other sources. These additional layers of visibility and event capture will greatly enhance threat detection, threat hunting and response to suspicious activity.
Sophos will deploy Braintrace's NDR technology as a virtual machine fed by traditional observation points such as a switched port analyzer (SPAN) port or a network test access point (TAP) to examine both north-south traffic at borders and east-west traffic within networks. These deployments help detect threats within any type of network, including those that remain encrypted, and serve as a complement to the decryption capabilities of the Sophos Firewall. As a virtual machine, Braintrace's NDR technology can run both on-premise and in the cloud to protect your network.
The technology's packet and flow engine feeds a variety of machine learning models trained to detect suspicious or malicious network patterns, such as connections to command-and-control (C2) servers, lateral movement and communications with suspicious domains. Because Braintrace developed its NDR technology specifically for predictive, passive monitoring, the engine also delivers intelligent network packets that can be used by IT security administrators and threat hunters as supporting evidence in investigations. The novel NDR analysis and prediction technology is patent pending.
"We developed Braintrace's NDR technology from the ground up for detection, and now it is being integrated with Sophos into a complete system to enable cross-product detection and response in a multi-vendor ecosystem."
Bret Laughlin, CEO and Co-Founder, Braintrace
Sophos plans to launch Braintrace's NDR technology for MTR and XDR in the first half of 2022.
If you are interested in a Sophos security solution, or a solution from another company, we are happy to offer you a free initial consultation. Simply contact us via phone, email or our contact form.