DoD-Cyber-Security-Blogs NDR

AWS now offers SophosNDR.

All NDR and XDR/MDR customers can now use the Sophos RDR integration pack, which requires a log collector, in AWS AMI.

For threat detection and response, Sophos NDR in AWS offers a number of benefits:

what you receive

Monitoring of cloud-native security:

  • In AWS environments, native NDR sensors can now effectively provide visibility into network traffic and security events. For tracking and safeguarding cloud-based workloads, this is essential.
  • The network traffic must be routed to the external NDR sensor at a significant data transfer cost if it is outside the AWS environment.

Scalability:

  • You can increase your security monitoring capabilities based on the expansion of your AWS infrastructure by using an NDR sensor as an AMI. To cover larger environments or heavier workloads, you can quickly launch multiple instances of the sensor.
  • Through a span/rspan configuration, each deployed sensor can handle 1GBS network traffic.

Threat detection and response in real-time:

  • In real time, Sophos NDR keeps track of both encrypted and unencrypted network traffic, spotting and alerting users to potential security breaches.
  • Real-time Active Threat Response is made possible by combining Sophos NDR, XDR/MDR with AWS’s Firewall to stop active foes in their tracks.

the process

A pre-configured virtual machine image called Amazon Machine Image ( AMI ) is used in the Amazon Web Services ( AWS ) environment to create Amazon Elastic Compute Cloud (EC2 ) instances. The operating system, application server, and any additional software needed to run your application are all included in an AMI, which also contains the information required to launch an instance. Additionally, the AWS AMI supports NDR and log collectors for third-party integrations.

beginning to

For instructions on how to get started right away, see the video, documentation, and AWS links on the Sophos NDR community.

Skip to content