Zscaler MDR’s detection is designed to find every possible type of threat that an adversary can deploy against your organization. This broad approach generates a large number of false positives for the Zscaler MDR team to investigate, but it delivers the best results.
If Zscaler MDR discovers threat intelligence or analytics that correspond to your endpoint data or security products, we generate a potentially threatening “event” that is reported to our Cyber Security Incident Response Team (CIRT) for investigation.
Learn more about potentially threatening events and how to list, filter, and review specific events.
What analytics do you use to detect threats?
Zscaler MDR’s detection process uses two primary classes of analytics:
Every piece of telemetry is tested to determine if it matches a compromise indicator that we’ve seen or heard adversaries use. These are brittle and often short-lived analytics, but if an adversary is foolish enough to reuse infrastructure or tools, they are easy to catch.
Behavioral detectors identify sequences of system activity that match techniques used by adversaries. These could be as simple as running PowerShell with an encoded command line, or a highly complex chain of behavior over a long period of time. We map every detector to MITRE ATT&CK® techniques so you can quantify your detection coverage.
How long does it take to onboard and tune threats?
Zscaler MDR, unlike other security products, does not require you to define your own detection rules and indicators of compromise in order to achieve extremely effective results. From day one, you get the benefits of years of Zscaler MDR detection engineering.
How can I review and understand your threat coverage?
Understanding how Zscaler MDR fits into your security stack requires transparency. You need to know where we provide coverage and where we do not, and we strive to make that information easily accessible.
Zscaler MDR’s threat coverage is most easily viewed in a MITRE ATT&CK heatmap. From there, you can drill into a specific technique and learn whether Zscaler MDR has coverage for it.
What standards or frameworks do you map to?
The MITRE ATT&CK taxonomy of behavioral techniques best fits Zscaler MDR’s internal classification, so we've switched to using MITRE ATT&CK exclusively (supplemented by our own techniques when appropriate, which we contribute back to MITRE ATT&CK).
Every Zscaler MDR analytic is mapped to one or more MITRE ATT&CK techniques making it easy to understand what Zscaler MDR can and cannot detect.
What sources are used for data enrichment?
Zscaler MDR’s primary enrichment source for contextual IP address information is IPQualityScore (IPQS). This source provides geolocation, internet service provider (ISP) details, virtual private network (VPN) status, Tor usage, and fraud score data. This enrichment directly informs our disposition and publication of identity based threats.
We poll this enrichment at the time we process the data into an event. As a result, contextual details such as geolocation, VPN status, or Fraud Score may change over time. Additionally, other enrichment sources may provide conflicting information due to differences in data freshness or fraud scoring methods.
Can I suggest or create a new analytic/threat?
Absolutely! Please submit a support case and let us know what behavior you’re looking to detect or share threat intelligence you think we should use.
If you believe Zscaler MDR failed to detect adversary behavior, please let us know about these false negatives.