MAVE provides multiple streams of security assistance for our security team. With the many integrations we have in place across our critical systems, we’ve been able to build out alerts for security issues that reach us 4 to 12 hours earlier than our SOC, while maintaining the same accuracy. This earlier visibility enables a quicker response to potential issues.
It has also enhanced our investigations by dramatically shortening the time it takes to get to root cause and identify remediation steps. On top of that, we value the flexibility to create agents that review critical systems daily and surface only the specific information we need to confirm ongoing safety in our environment.
All of this has also helped us save costs month over month compared to previously used systems, which didn’t provide the same depth of analysis or level of assistance for the team. The setup experience was simple. We connected several systems to MAVE and it immediately started reviewing the alerts in Sentinel and Defender. We added our own SOPs to the system. Over the next 3 days those came online and started to provide alerts to the things we were most interested in. Over the next several months we turned on more integrations and more features such as Applying the remediation with a push of a button. There was not much training needed. Support has been great for new integration asks, for going over new features, and reviewing issues which have been few. Review collected by and hosted on G2.com.
As with all AI products, reviewing content is important. Because the triage agent and the other agents are AI based, they do not provide a “same every time result” like a strict, programmed process would. Findings do provide the context that has been requested but the format of those findings will vary from time to time. Review collected by and hosted on G2.com.