Skip to content

Sekoia Defend

Licensing and ecosystem

Sekoia Defend is the core detection and response module of the Sekoia SOC platform. It can operate as a standalone product and expand with Sekoia Intelligence, Reveal for Asset Intelligence, and Sekoia Elevate for AI-assisted SOC workflows.

Defend collects and analyzes security events from applications, endpoints, cloud services, and SaaS environments. It gives security teams the tools to detect suspicious activity, investigate incidents, automate response actions, and report on their security operations.

Product features

Collect security data

Sekoia Defend supports multiple ingestion methods for bringing security data into the platform. Teams can connect applications, endpoints, cloud services, and SaaS environments, then organize and enrich the events they collect.

The collection workflow includes:

  1. Choose an ingestion method: Select the method that fits the data source and deployment model. See the supported ingestion methods.
  2. Connect an integration: Use the supported Integrations catalog to collect data from security and business applications.
  3. Configure Intakes: Set up the Intakes that receive and process incoming logs.
  4. Organize Intakes into Entities: Structure data sources around the systems, environments, or business units they represent with Entities.
  5. Enrich events with Assets: Add asset context to help analysts understand which systems and resources are involved.

Detect threats

Sekoia Defend combines Cyber Threat Intelligence (CTI), anomaly detection, and detection scenarios to identify suspicious activity, intrusions, and compromises.

Security teams can:

Investigate alerts and incidents

Analysts can investigate activity directly from a security alert or through the event history. Case management helps teams connect related alerts, document findings, and collaborate throughout an investigation.

Defend supports:

  • Security alert investigation: Review alerts and examine the activity behind them.
  • Event history and threat hunting: Search historical events and drill down into relevant activity.
  • Case management: Centralize observations, evidence, and investigation results around an incident with Case Management.

Automate response

Sekoia Defend includes Security Orchestration, Automation and Response (SOAR) capabilities for repeatable response actions. Teams can use Playbooks to automate parts of their SOC workflows, coordinate actions across security tools, and maintain an auditable record of what happened.

Report on security operations

Use dedicated Dashboards or create custom views to monitor security activity and operational metrics. Teams can build dashboards around the measures that matter to their SOC, including alert activity, investigation status, and response performance.