The only comprehensive security platform providing maximum protection of applications and data wherever they reside
Starlight works better by first gathering the right data and then sharing that data on one platform with over 20 tightly integrated applications.
- See the whole picture through sensors, agents, threat intelligence and log forwarders
- Sensors and agents transform raw data into Interflow™ records and send it to a centralized data processor and data lake that deduplicates, enriches, correlates and stores the data that it receives
- Complex analytics are run on the dataset to identify high-fidelity breach events
- Built-in analytics leverage machine learning to eliminate alert noise and improve the accuracy of detecting critical security events
Starlight's GUI is aligned with the kill chain:
Supercharge analyst productivity
- Starlight eliminates blind spots through its unique set of data collectors that include agent sensors, network sensors, security sensors and deception sensors.
- These sensors can be deployed as software, hardware appliances or virtual appliances and can be collected from any environment.
- The sensors collect packets, files & logs and transforms the data collected into a proprietary Interflow data set that is reduced and fused data.
- Once data has been collected, reduced and given context, Starlight runs advanced machine learning algorithms on the new and improved data set in order to detect higher fidelity security events.
- With this methodology of getting the data set right before applying detection techniques, Starlight solves the age-old problem of garbage in, garbage out.
- Security Analysts benefit with this approach by chasing down less false alarms.
- Starlight’s Interflow data is the foundation for security investigation and threat hunting.
- Because Interflow fuses contextual data into packet and log records, security analysts have a single record that can be looked at when trying to prove that a detection is accurate and actionable.
- When looking for evidence for security detections, analysts no longer have to mentally try and stitch together data from packets and logs make sense of things.
- Starlight delivers a variety of response actions once security events have been detected.
- The system can generate email or slack alerts, send PDF reports, submit data to SOAR tools such as Demisto and Phantom Cyber and even manually or automatically instructing firewalls to take appropriate response actions
- Actions include blocking an IP address or redirecting a user to a captive portal for further authentication.