
Good use of network data to provide info on a given IP. Is it a AD server or endpoint, what protocols is it using.
A strong set of "out of the box" Security alerts with little to no configuration. Machine learning or deviation from normal alerts + threat specific alerts like "cobalt-strike"
Realtime analysis of network data such as DNS requests without storing all the DNS data Review collected by and hosted on G2.com.
RevealX security detections are usually correct but still point to some legitimate network traffic. There high threat detections like "DNS C2 channel" are effective but there is still work to be done. Especially at the lower end of there threat score modeling.
These low threat alerts are more like "notable behavior" and they provide great info when investigating an end point but there not worth the analyst time to investigate each one individually. I would like to see more intelligence in there detection algorithms, whereby and endpoint with 4 or 5 suspicious behaviors would score higher then an endpoint with 2. Extrahop needs to work on presenting there alert data in a more meaningful way and reduce the signal to noise ratio. Review collected by and hosted on G2.com.