A modern company may possess hundreds, or even thousands, of security data sources.
Examples include:
Infrastructure
- Windows servers
- Linux servers
- Active Directory
- domain controllers
- DNS
- DHCP
- file servers
- databases
- hypervisors
- virtualization solutions.
Network
- firewalls
- routers
- switches
- VPN
- proxy
- Wi-Fi
- IDS
- IPS
- SD-WAN equipment.
Endpoints
- antivirus
- EDR
- XDR
- Windows machines
- Linux machines
- macOS
- servers.
Identify
- Active Directory
- Entra ID
- identity providers
- MFA
- SSO
- IAM/PAM solutions.
Cloud
- Microsoft Azure
- AWS
- Google Cloud
- Kubernetes
- containers
- SaaS.
Applications
- ERP
- CRM
- financial applications
- HR applications
- web applications
- API
- e-commerce platforms.
Messaging and collaboration
- Microsoft 365
- Exchange
- Teams
- SharePoint
- Google Workspace
- third-party messaging solutions.
Security
- EDR
- antivirus
- WAF
- IDS/IPS
- DLP
- CASB
- vulnerability solutions
- scanners
- attack protection systems.
The problem is therefore generally not the lack of information.
The problem is their fragmentation.