Sangfor Simplified Security Operations Solution

The Simplified Security Operations solution equips organizations with a systematic and future-proof security fabric by integrating Sangfor and third-party security products and services. It enhances the effectiveness and efficiency of daily security operations, including risk and asset management, threat and incident detection, and response. The solution empowers security teams to tackle various challenges, from managing massive alert volumes to handling complex investigations.

Sangfor Simplified Security Operations Solution

Solution Components

icon plus flip icon cross flip
Athena XDR

Athena XDR

Athena XDR

Provides advanced threat detection through cross-layered correlation analysis and automated response. Serves as the unified SecOps platform covering essential SecOps workflows.

icon plus flip icon cross flip
Athena EPP

Athena EPP

Athena EPP

Provides endpoint protection and management, feeds endpoint telemetry and alerts to the SecOps platform (XDR/MDR), and executes automated response actions.

icon plus flip icon cross flip
Athena STA

Athena STA

Athena STA

Network sensor that performs network traffic analysis on traffic mirrored from the core switch and feeds results to the SecOps platform (XDR/MDR) for another layer of analysis.

icon plus flip icon cross flip
Athena NGFW

Athena NGFW

Athena NGFW

Provides perimeter protection, feeds network telemetry and alerts to the SecOps platform (XDR/MDR), and executes automated response actions.

icon plus flip icon cross flip
Athena MDR

Athena MDR

Athena MDR

Integrates with the customer’s security tools, both Sangfor and third-party, to provide expert-led, 24/7 monitoring, threat detection and response services.

icon plus flip icon cross flip
Athena NDR

Athena NDR

Athena NDR

Customers who have purchased Athena NDR with Athena STA can also integrate it with Athena XDR to forward alerts for unified analysis and management.

Solution Advantages

Integration with Native and Third-party Products

The solution integrates various Sangfor security components and a wide range of third-party products through APIs. This integration results in higher cyberattack detection accuracy and faster response times.

Integration with In-house and Third-party Products

GenAI SecOps Assistant

Sangfor Security GPT is a generative AI SecOps assistant built using Sangfor’s proprietary large language model (LLM). It generates security posture summaries and reports, reconstructs attack processes, and explains analysis results. Security GPT improves the detection of threats such as phishing, web attacks, and C2, with an average false positive rate of less than 3%.

GenAI SecOps Assistant

Intelligent Investigation

The solution provides complete visibility into each security incident by correlating alerts and logs from various security components. This level of visibility allows security teams to easily determine the root cause and the details of any compromise.

Intelligent Investigation

Automatic Response

Built-in predefined and customizable response policies enable automatic response to most security incidents. For incidents not covered by response policies, security teams only need to handle them once manually and create an automatic response policy for future cases.

Automatic Response

Worry-Free Services

The solution is available with Sangfor Athena Managed Detection and Response (MDR) and Managed Threat Response (MTR) services that cover security incident investigation, threat identification and analysis, and remediation to recover business operations.

Worry-Free Services

Flexible Delivery Models

Choose from Self-Managed, Fully-Managed, or Co-Managed operations to best fit your business requirements.

  • Self-operated SecOps: Provides complete control and flexibility, ideal for organizations with the resources and expertise to manage their own security operations.
  • Co-managed SecOps: Combines Sangfor’s protection of critical assets with the customer's management of other aspects of security. Ideal for organizations that want to maintain some control while benefiting from expert oversight for key areas.
  • Fully-managed SecOps: Delivers comprehensive, expert-managed security operations, ideal for SMEs without the internal resources or expertise to handle security on their own.
Flexible Delivery Models