Tuesday, October 12, 2021

EDR vs Sysmon+ELK for midsize company

Hi!

I just want to have some additional visibility for a company with about 400 seats.

Option 1: EDR like Sentinelone Complete

Option 2: Sysmon with ELK + EPP (Sentinelone Core/Control)

What do you think? Do you use full blown EDR for networks of that size?

Does Sysmon provide a visibility that is comparable to an EDR?

Thank you for your thoughts

ITStril



No comments:

Post a Comment