Review: Promisec goes the extra step to secure PCs
Summary
Even as we struggle to put security controls in place for prevention, we know that many of these endpoints are already compromised by active threats that need to be detected, assessed, quarantined, and remediated. Like other EDR products, PEM can scan endpoints on a schedule to detect anomalies or abnormalities and verify that security controls -- such as required applications, patches, settings, and so on -- are in place. My focus in this review was on finding abnormalities on endpoints indicative of malware, in which case PEM can push the suspect binaries to sandboxes (Blue Coat, Palo Alto Networks, FireEye) for analysis, correlate with SEIM tools for reporting, issue alerts, and orchestrate remediation. PEM is also useful for incident response, where it can help you build a complete understanding of the full scope of the infection and revert endpoints back to their original uninfected state. The Sentry interrogates endpoint operating systems (supporting Windows, MacOS, and Linux) using presupplied credentials, formats and encrypts the information it discovers, and forwards it to PEM Analyzer to be compared against policy and placed in the database.