CyberArk has integrated its Privileged Threat Analytics with McAfee Enterprise Security Manager (ESM). The integrated solution allows customers to pinpoint and immediately act against privileged-based threats in their security information and event management (SIEM) data.
CyberArk Privileged Threat Analytics 2.0 collects and analyses privileged account activity data to provide organisations with visibility into potentially malicious behaviour. McAfee Enterprise Security Manager collects, correlates, and analyses intelligence and event data in real time and orchestrates adaptive protection to disrupt the attack chain and prevent data loss.
[caption id=“attachment_76923” align=“alignleft” width=“380”]
 Image: Thinkstock[/caption]
CyberArk Privileged Threat Analytics reports on malicious privileged behaviour in real time over the McAfee DXL messaging bus, making it available to all McAfee products. McAfee Enterprise Security Manager reads the CyberArk Privileged Threat Analytics event data, and issues alerts, response and remediation activity in real time to threat response teams, and enables watch lists that can monitor and mine event data to detect related future and historical events.
By becoming ‘DXL-ready’, CyberArk Privileged Threat Analytics will also be able to selectively publish its data to and subscribe to updates from other products from McAfee and Security Innovation Alliance partners, without the cost and overhead of direct integrations.
“Leveraging the McAfee data exchange layer (DXL), CyberArk’s full integration with McAfee Enterprise Security Manager will provide customers with more context to the information CyberArk Privileged Threat Analytics collects, while increasing the real-time visibility and the precision of actions that can be driven by the McAfee SIEM,” according to the company.
“The integration of CyberArk Privileged Threat Analytics with McAfee Enterprise Security Manager will help incident responders cut through the clutter of big data security analytics to pinpoint and enable action on previously undetected malicious privileged behaviour and disrupt in-progress attacks,” Roy Adar, vice president, product management, CyberArk stated.


)
)
)
)
)
)
)
)
)
