Cato Endpoint Protection (EPP)

Cato Endpoint Protection (EPP) is the industry’s first SASE-managed EPP solution protecting endpoints against advanced malware, evasive attacks and zero-day threats. Cato EPP adds endpoint protection and detection to Cato’s multi-layer SASE architecture while reducing management overhead, increasing security teams efficiency, and improving the enterprise security posture.

Endpoint Protection Configuration Endpoint Protection Client Protected Endpoints View Cato Client Rollout Management Cato Datalake Events

Cato EPP Capabilities

Stop Malware Before File Execution and in Runtime

Cato EPP scans over 300 file types for threats, including archives and packed files. It uses advanced rule-based analysis and machine learning algorithms, to identify known, polymorphic, and zero-day malware based on file characteristics analysis. Cato EPP uses heuristics and process behavioral analysis to detect suspicious and malicious activity in real-time. This capability enables the detection and prevention of fileless malware operating directly in the system memory, evasive exploits and zero-day attacks, and ”living-off-the-land” attacks that leverage legitimate tools for malicious purposes. To further minimize attack surface, Cato can block the use of USB drives with device control.

Endpoint Protection Configuration

Flexible Containment Options for Compromised Endpoints

Responding to threats in real time is critical to minimizing the potential damage of a malware outbreak. However, delicate balance is often needed between automated response and user productivity. Cato provides administrators with the flexibility to adjust the containment policies to meet their organization security requirements including threat blocking, file quarantine, or process termination.

Endpoint Protection Client

Endpoint Protection Convergence into SASE Streamlines Security Management

Cato EPP is fully managed through the Cato Management Application (CMA), seamlessly integrated with all other Cato SASE Cloud Platform capabilities. Administrators gain the advantage of overseeing the protected endpoints from a unified console, where user data, network information, and security policies are consolidated. Cato EPP saves administrators the need to integrate, maintain, and manage a standalone endpoint protection solution. Manual SIEM integration is also eliminated as all EPP events and alerts are now a native part of the Cato SASE Cloud platform.

Protected Endpoints View

Instant Protection with Rapid Deployment and No User Impact

Cato EPP is provisioned via the Cato Management Application (CMA) or through the Customer’s selected Mobile Device Management tool (MDM). Administrators can onboard and start protecting thousands of endpoints in a matter of minutes. Once installed, the Cato EPP agent runs in the background and is completely transparent to the end-user. No login is required, and users get instantly protected and alerted when a security event occurs on the endpoint. Ad-hoc malware scanning activities can be initiated by the user or by the administrator directly from the Cato Management Application.

Cato Client Rollout Management

One Data Lake for Network and Endpoint Makes Detection and Response Faster, XDR-ready

Cato EPP events are stored in the same data lake with all other events generated by the various Cato SASE Cloud Platform engines. Cato XDR leverages high-quality endpoint data, alongside network-based sensors, for optimal AI/ML threat detection and investigation. Administrators can easily filter events by user or device seeing a unified list of all endpoint and network security events in one screen, enabling efficient incident investigation and response.

Cato Datalake Events

Endpoint Protection Platform Video Demo

Cato Endpoint Protection (EPP) is a SASE-managed EPP solution, that protects endpoints against advanced malware, evasive attacks and zero-day threats. It is seamlessly integrated and fully managed through the Cato Management Application (CMA).

진정한 SASE 플랫폼의 전략적 이점

처음부터 끝까지 진정한 클라우드 네이티브 SASE 플랫폼으로 설계된 Cato의 모든 보안 기능은 현재 Cato 플랫폼의 글로벌 배포, 대규모 확장성, 높은 복원력, 자율적 수명주기 관리, 일관된 관리 모델을 활용하고 있으며 미래에도 그러할 것입니다.

 

일관된 적챙 적용

Cato는 모든 보안 기능을 전 세계적으로 확장하여 대규모 데이터 센터에서 단일 사용자 장치에 이르기까지 모든 곳에서 모든 사람에게 일관된 정책을 시행합니다.

 

확장 가능하고 복원력이 뛰어난 보안

Cato는 전체 TLS 복호화 및 모든 보안 기능을 통해 다중 기가 트래픽 스트림을 검사하도록 확장하고 서비스 구성 요소 오류를 자동으로 복구하여 지속적인 보안을 보장합니다.

 

자율적 수명주기 관리

Cato는 SASE 클라우드 플랫폼이 고객의 개입 없이 모든 사용자와 위치에 대해 최적의 보안 상태, 99.999% 서비스 가용성, 보안 처리 시 짧은 대기 시간을 유지하도록 보장합니다.

 

단일 창

Cato는 구성, 분석, 문제 해결, 사고 감지 및 대응을 비롯한 모든 보안 및 네트워크 기능을 일관적으로 관리할 수 있는 단일 창을 제공합니다. 이 통합 관리 모델을 통해 IT와 비지니스는 새로운 기능을 쉽게 채택할 수 있습니다.

 

“Cato에서 침해 및 공격 시뮬레이터를 실행한 결과 감염률과 내부망 이동은 감소했지만 감지율은 급증했습니다. 이것이 Cato 보안을 신뢰할 수 있는 가장 큰 이유입니다.”

Cato 체험하기

IT 팀이 바라던 솔루션입니다.

기대해주세요!