Endace Integrates with Microsoft Sentinel for Deep Network Visibility
AUCKLAND, New Zealand and AUSTIN, Texas – April 21, 2025 – Packet capture authority Endace today announced an integration between EndaceProbe and Microsoft Sentinel, a next-generation cloud security, information, and event management (SIEM) solution. The integration provides NetOps and SecOps teams with one-click access to definitive, full packet evidence from within Microsoft Sentinel to streamline investigations. Access to Endace’s Always-On packet capture enables accurate event reconstruction and helps security teams to investigate and respond to threats more quickly, with absolute confidence.
Benefits of the integration include:
- Streamlined investigation workflows, alerts, and playbooks from Microsoft Sentinel, with one-click, drill-down access to definitive, full packet evidence captured by EndaceProbe.
- Continuously capture weeks or months of full packet data, across Hybrid, On-Prem, and Multi-Cloud environments.
- Single central console for searching and analyzing recorded packet data across global scale networks, integrated with Microsoft Sentinel.
- Deep visibility that shows exactly what happened before, during, and after every event.
- Zero-Day Threat (ZDT) risk validation using playback of recorded network traffic
- Combining EndaceProbe’s centralized search with Microsoft Sentinel’s AI-powered SIEM enables faster, more efficient incident investigation and resolution.
- Military-grade Security: EndaceProbe appliances are FIPS 140-3 compliant and are listed on the DoDIIN APL.
Read the solution brief and watch the demo here: https://www.endace.com/microsoft-sentinel
“Deep visibility into network activity is essential when responding to serious cybersecurity events, service outages, or performance issues. One-click access to EndaceProbe’s recorded packet data directly from Microsoft Sentinel shows incident responders exactly what happened before, during, and after any serious event,” said Cary Wright, VP Product at Endace.
“Microsoft Sentinel’s built in machine learning reduces noise and uncovers sophisticated threats while EndaceProbes provide a complete, packet-level record of network history. Integrating these two solutions gives SecOps teams easy access to definitive evidence required to triage the most serious threats on the network.”
Next week, Endace will be demonstrating EndaceProbe and EndaceProbe Cloud at RSAC™ 2025 in booth N-5176, and Endace is securing RSAC™ by equipping and operating the SoC @ RSAC™. For more information about Endace at RSAC™, visit https://www2.endace.com/rsa-2025-resources-lp.
Latest News & Announcements
-
30 September 2025
Endace Sets New Industry Benchmarks for Packet Capture Storage Density, Performance, and Value
EndaceProbe EP-94C8-G5 High Capacity and High Speed models are security-hardened, and offer up to three petabytes of packet storage and up to 100 Gbps recording
-
9 September 2025
EndaceProbes Achieve Common Criteria and NIAP Certification
Endace’s focus on security standards sees EndaceProbes certified for Common Criteria/NIAP NDcPP v2.2e, NIST FIPS 140-3, and listed on DoDIN APL
-
29 July 2025
Immersive and Endace Team Up to Deliver Hands-On, Data-Driven Cyber Training for SOC Teams
Collaboration Brings Together Immersive Cyber Exercises and Real-world Packet Forensics to Upskill SOC Teams and Strengthen Cyber Resilience
-
28 May 2025
Endace Secures FIPS 140-3 Validation for EndaceProbes
NIST validation ensures highest cryptographic security standards, enhances data protection, streamlines customer procurement and deployment
-
26 May 2025
Endace Wins At Computing Magazine's Security Excellence Awards 2025
EndaceProbe Cloud announced as winner of the Cloud Security award