Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Use of Hexadite to Accelerate Incident Resolution and Improve Security Operations
Articles

Use of Hexadite to Accelerate Incident Resolution and Improve Security Operations

ISBuzz TeamBy ISBuzz TeamApril 17, 2015Updated:April 17, 20158 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
IDT Corporation Uses Hexadite
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

When it comes to incident response (IR), enterprises end up wasting 80 percent of their resources because it takes much longer than it should to address attackers in their networks. This is because they’ve been trying to utilize people in ways that systems can automate instead of having them focus on the tasks that truly require human intelligence and interaction.

IDT Corporation’s IT environment is somewhat unique in that it’s at the nexus of three very highly targeted industries – telecom, energy and oil, and banking and finance. The responsibility always lands squarely on the security team to keep the organization up and running and the critical resources in our varied cloud and data center environments protected. The environment is made up of best-in-breed network, endpoint, systems, storage and database solutions. The problem was none of the systems worked together, so we had a fragmented view of what was going on. We had to use people in between all these systems.

When we would get an alert from any of our systems generating indicators of compromise (IOCs), it went to our live event stream and was loaded into our SIEM. Best case scenario, it would take 15 minutes for the SIEM to correlate everything it needed to generate an alert for the SOC. Then someone in the SOC had to see it and decide to act, which meant they had to pick up the phone and start calling the user or the network manager to get them to manually shut off the laptop or deal with the switch. If it all worked well, we could contain the infection in 30 minutes. The problem is attackers can get in and exfiltrate data in mere minutes.

Service level response times from leading managed security service providers (MSSPs) are two hours for a high-level threat targeting vulnerable assets; it only gets worse for other attacks, and the reality is most organizations don’t even see the problem until it gets out of hand.

Once an attack is contained, there is a list of steps needed to remediate it; it could be a couple days before a user might get their system back. We needed a faster way to figure it out and then do automatic remediation—a real-time system that could provide us access to real-time alerts.

Duo Security RSAC 2015 – Register to win a free Quadcopter

There are several solutions we evaluated that automated portions of the incident response process. We had even built some of our own scripts and capabilities to get better visibility and response times, but we kept looking for something that could really help us address our issues. When I met with Hexadite, I didn’t have to explain our pain points; they just got it. Hexadite was able to go in right away, give us results and help solve our problems.

Hexadite AIRS can automatically investigate and contain attacks in seconds. It’s designed to handle multiple investigations and remediate large scale events impacting multiple systems in parallel. It provides out-of-the box incident response logic that implements industry best practices to ensure an organization can efficiently and effectively respond to an attack from day one. The solution is able to proactively collect and analyze data from the IT security infrastructure, endpoints, threat feeds, log repositories and more to provide the intelligence and response capabilities organizations need to confidently address the threats they are facing.

My team at IDT liked that the solution supported multiple platforms and was extremely lightweight, agile and simple to use. Unlike other solutions that need a client to be installed and managed on every endpoint, Hexadite doesn’t require the organization to download any agents.

Rolling out Hexadite is simple. For the implementation, all we had to do was create inclusion lists, grant access to our identity and access systems and tell Hexadite AIRS to do automatic investigations. Hexadite simply logs into a system when there is a problem, deposits itself to do its analysis and then deletes itself and goes away. We were able to go from 1000 systems to 3000 systems protected by Hexadite in one day.

We started doing automated investigations on alerts for the areas we were most concerned with, such as the workstation environment in our corporate offices in New Jersey. We quickly rolled it out across the U.S., then to Europe, the Middle East and Africa, and Central and South America.

We take the IOCs from a variety of sources and feed them into Hexadite, which is integrated with many systems throughout the network to improve overall analysis and efficiencies. When we know something bad has happened but are not sure what it is or have an incomplete alert, Hexadite will immediately launch an investigation and fill in the blanks of what just happened.

The solution is able to discover the critical information that is missing from most alerts, which we used to get manually. Because Hexadite automatically goes out and looks at every threat, we immediately know what the threat level really is. We may start at 15 percent confidence, but after Hexadite looks and comes back to us, we know it is really much higher. Hexadite enables us to save our people from having to do that.

Hexadite is also able to address those widespread, spray attacks that try to get a whole bunch of people. There is just no way for an individual to investigate and quickly contain hundreds or thousands of systems. Hexadite’s automation enables us to scale.

By immediately pulling in data directly from Splunk and all these components in seconds, Hexadite already eliminates the 15 minutes we used to have to wait for the SIEM to correlate alerts. Plus, by automating, we gain the 15-30 minutes that it takes someone to contain an infection.

The fact is, it takes people time to figure out what’s going on and make any necessary changes to try to contain an infection; it could be 4-5 hours that are saved through automation. That’s assuming that someone is there when an alert lands in the SOC. Humans are inconsistent in their knowledge, skills and time; they may or may not know where to look or what to do for a particular alert, which means there is a lot of room for error.

Hexadite saves us a lot of time with the ability to log in milliseconds after the alert to look for impropriety. Hexadite can automatically look for new files, search Windows event logs and make comparisons to other systems, threat feeds, etc. during the course of their investigation, which manually could run you eight hours.

Hexadite helps us get consistent coverage, which is absolutely essential and enables us to deliver across the entire organization, rather than just the parts that are most critical.

The threat landscape is evolving, and Hexadite is able to adapt and translate requirements into iterative enhancements. The combination of people and technology at Hexadite is really something special. The automation they enable frees up resources, so that our people can work on the kinds of problems that really need people.

By Golan Ben-Oni, CSO and SVP of network architecture, IDT Corporation

Golan Ben-OniBIO : Golan Ben-Oni is Chief Security Officer (CSO) and SVP of Architecture for IDT Corporation. Golan oversees IDT’s Security and Architecture Program in its three vertical markets, Telecom, Finance and Energy where he is responsible for Security (Law Enforcement and Investigations, Security Operations, Legal and Compliance), Architecture and Networking (Hybrid Cloud and Software Defined Data Center, Big Data and Analytics), Research and Development (Software Defined Security and SDN), and Provides Executive Leadership for Startup Security Vendors. Golan also heads IDT’s Computer Security and Networking College in Newark, NJ in order to create the next generation of Security engineers to meet the need of our current and future security challenges.

About IDT Corporation

IDT Corporation (IDT) is a multinational holding company with operations primarily in the telecommunications and payments industries. The Company has three reportable business segments, such as Telecom Platform Services, Consumer Phone Services, and Zedge Holdings, Inc. (Zedge). Telecom Platform Services provides retail telecommunications and payment offerings as well as wholesale international long distance traffic termination. Consumer Phone Services provides consumer local and long distance services in certain United States. Telecom Platform Services and Consumer Phone Services comprise the Company’s IDT Telecom division. Zedge owns and operates an online platform for mobile phone consumers interested in obtaining free games, apps and mobile phone customization including ringtones, wallpapers and notification sounds. All other businesses of the Company include real estate holdings and other, smaller businesses.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}