{"id":1094,"date":"2023-02-03T21:28:16","date_gmt":"2023-02-03T13:28:16","guid":{"rendered":"https:\/\/www.aqwu.net\/wp\/?p=1094"},"modified":"2023-02-03T21:29:04","modified_gmt":"2023-02-03T13:29:04","slug":"cortex-xdr-vs-crowdstrike","status":"publish","type":"post","link":"https:\/\/www.aqwu.net\/wp\/?p=1094","title":{"rendered":"Cortex XDR vs CrowdStrike"},"content":{"rendered":"\n<p>\u7aef\u70b9\u4fdd\u62a4\u4e3a\u6709\u6548\u7684\u5b89\u5168\u7b56\u7565\u5960\u5b9a\u4e86\u57fa\u7840\uff0cCortex XDR \u7684\u7aef\u70b9\u4fdd\u62a4\u5728\u72ec\u7acb\u7684\u7b2c\u4e09\u65b9\u8bc4\u4f30\u4e2d\u59cb\u7ec8\u4f18\u4e8e CrowdStrike EDR\u3002\u5728MITRE ATT&amp;CK\u00ae \u7b2c3\u8f6e\u8bc4\u4f30\u4e2d\uff0cCortex XDR\u963b\u6b62\u4e86100%\u7684\u653b\u51fb\uff0c\u800cCrowdStrike\u5219\u4e3a70%\u3002\u800c\u5728<a href=\"https:\/\/www.paloaltonetworks.com\/cortex\/cortex-xdr\/mitre\">MITRE ATT&amp;CK\u7b2c4\u8f6e\u8bc4\u4f30<\/a>\uff0cCortex XDR \u4ee5 98% \u7684\u6280\u672f\u7ea7\u68c0\u6d4b\u7387\u9886\u5148\u4e8e CrowdStrike \u7684 71%\uff0c\u7ee7\u7eed\u5728\u7aef\u70b9\u4fdd\u62a4\u548c\u68c0\u6d4b\u65b9\u9762\u8868\u73b0\u51fa\u9886\u5148\u5730\u4f4d\u3002<\/p>\n\n\n\n<p>\u539f\u6587\u94fe\u63a5\uff1ahttps:\/\/www.paloaltonetworks.com\/cortex\/xdrvscrowdstrike<\/p>\n\n\n\n<p>\u90a3\u4e48\uff0c\u5f53\u8fd9\u4e9b\u4ee5\u7aef\u70b9\u4e3a\u4e2d\u5fc3\u7684\u7ed3\u679c\u660e\u786e\u65f6\uff0c\u4e3a\u4ec0\u4e48\u8981\u76f8\u4fe1CrowdStrike\u5462\uff1f\u90a3\u4e48\uff0c\u8de8\u7aef\u70b9\u3001\u7f51\u7edc\u3001\u4e91\u7b49\u7684\u771f\u6b63 XDR \u7684\u66f4\u5168\u9762\u8303\u56f4\u53c8\u5982\u4f55\u5462\uff1fCortex XDR \u662f\u7b2c\u4e00\u6b3e\u62e5\u6709\u6210\u529f\u8bb0\u5f55\u7684 XDR\u00ae\uff0c\u53d7\u5230 3\uff0c000 \u591a\u5bb6\u5ba2\u6237\u7684\u4fe1\u8d56\u3002\u5728\u4e0b\u9762\u4e86\u89e3\u6709\u5173Cortex XDR\u5982\u4f55\u8d85\u8d8aCrowdStrike\u7684\u8be6\u7ec6\u4fe1\u606f\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u6700\u597d\u7684\u4fdd\u62a4<\/h2>\n\n\n\n<p>\u9884\u9632\u4f18\u5148\u7684\u65b9\u6cd5\u5e94\u8be5\u662f\u7ec4\u7ec7\u7ec8\u7ed3\u70b9\u5b89\u5168\u7b56\u7565\u7684\u57fa\u7840\u3002\u5f53\u6d89\u53ca\u5230\u672a\u77e5\u6076\u610f\u8f6f\u4ef6\u65f6\uff0cCortex XDR\u7684\u884c\u4e3a\u5a01\u80c1\u9632\u62a4\u548cAI\u9a71\u52a8\u7684\u5206\u6790\u5728\u73b0\u5b9e\u4e16\u754c\u4e2d\u90fd\u4f18\u4e8eCrowdStrike\u3002<a href=\"https:\/\/www.paloaltonetworks.com\/blog\/2022\/03\/mitre-engenuity-evaluations-round-4-results\/\">\u7c73\u7279\u96f7\u00b7\u963f\u7279\u514b<\/a>\u8bc4\u4f30\u548c<a href=\"https:\/\/www.paloaltonetworks.com\/blog\/2022\/01\/active-prevention-in-av-comparative-epr\/\">\u5f71\u97f3\u6bd4\u8f83<\/a>\u6d4b\u8bd5\u3002<br><br>\u884c\u4e3a\u5a01\u80c1\u9632\u62a4\u5f88\u91cd\u8981\u3002\u901a\u8fc7\u8ddf\u8e2a\u6d3b\u52a8\u94fe\u7684\u987a\u5e8f\u5e76\u5728\u8fd9\u4e9b\u64cd\u4f5c\u53d1\u751f\u65f6\u5e94\u7528\u4e0a\u4e0b\u6587\uff0c\u884c\u4e3a\u5a01\u80c1\u9632\u62a4\u80fd\u591f\u81ea\u52a8\u51c6\u786e\u5730\u8bc6\u522b\u548c\u9632\u6b62\u9ad8\u5ea6\u89c4\u907f\u7684\u590d\u6742\u653b\u51fb\u3002\u7ed3\u5408\u57fa\u4e8e\u6280\u672f\u7684\u6f0f\u6d1e\u5229\u7528\u9632\u5fa1\u3001\u5168\u7403\u5a01\u80c1\u60c5\u62a5\u548c\u4e91\u8f85\u52a9\u5206\u6790\uff0c<a rel=\"noreferrer noopener\" href=\"https:\/\/www.paloaltonetworks.com\/content\/dam\/pan\/en_US\/assets\/pdf\/guides\/cortex-xdr-endpoint-protection-solution-guide.pdf\" target=\"_blank\">\u76ae\u8d28\u900f\u4f53\u900f\u4f53 XDR \u4ee3\u7406<\/a>\u63d0\u4f9b\u66f4\u597d\u3001\u66f4\u5f3a\u5927\u7684\u4fdd\u62a4\u3002<br><br>CrowdStrike\u5bf9\u57fa\u4e8e\u54c8\u5e0c\u7684\u4fdd\u62a4\u548cIoC\u7684\u4f9d\u8d56\u53ea\u5173\u6ce8\u5df2\u77e5\u7684\u653b\u51fb\u548c\u4e8b\u540e\u68c0\u6d4b\uff0c\u56e0\u6b64\u4fdd\u62a4\u4f1a\u53d7\u5230\u5f71\u54cd\uff0c\u6b63\u5982\u4ed6\u4eec\u7684\u8bc1\u660e\u3002<a href=\"https:\/\/attackevals.mitre-engenuity.org\/enterprise\/participants\/crowdstrike\/results?adversary=carbanak_fin7&amp;scenario=protections\">\u65e0\u6cd5\u963b\u6b62 30% \u7684\u653b\u51fb<\/a>\u5728 MITRE \u7b2c 3 \u8f6e\u4e2d\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"822\" height=\"460\" src=\"https:\/\/www.aqwu.net\/wp\/wp-content\/uploads\/2023\/02\/\u56fe\u7247.png\" alt=\"\" class=\"wp-image-1095\" srcset=\"https:\/\/www.aqwu.net\/wp\/wp-content\/uploads\/2023\/02\/\u56fe\u7247.png 822w, https:\/\/www.aqwu.net\/wp\/wp-content\/uploads\/2023\/02\/\u56fe\u7247-300x168.png 300w, https:\/\/www.aqwu.net\/wp\/wp-content\/uploads\/2023\/02\/\u56fe\u7247-768x430.png 768w\" sizes=\"auto, (max-width: 822px) 100vw, 822px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">\u660e\u663e\u5353\u8d8a\u7684\u68c0\u6d4b\u6027\u80fd<\/h2>\n\n\n\n<p>\u4fdd\u62a4\u4ece\u6765\u90fd\u4e0d\u662f\u5b8c\u7f8e\u7684\u3002\u5728\u68c0\u6d4b\u548c\u53ef\u89c1\u6027\u65b9\u9762\uff0cCortex XDR \u518d\u6b21\u51fa\u73b0<a href=\"https:\/\/www.paloaltonetworks.com\/cortex\/cortex-xdr\/mitre\">\u660e\u663e\u4f18\u8d8a<\/a>\u5230\u4eba\u7fa4\u7f62\u5de5\u3002Cortex \u4e30\u5bcc\u7684\u9065\u6d4b\u96c6\u5408\u548c\u5e7f\u6cdb\u7684\u57fa\u4e8e\u4e91\u7684\u5206\u6790\u68c0\u6d4b\u6a21\u5757\u53ef\u8bc6\u522b\u6574\u4e2a\u653b\u51fb\u751f\u547d\u5468\u671f\u4e2d\u7684\u6076\u610f\u6d3b\u52a8\uff0c\u5e76\u4e3a\u5206\u6790\u5e08\u63d0\u4f9b\u89e3\u51b3\u95ee\u9898\u6240\u9700\u7684\u6570\u636e\u3002<br><br>\u8fd9\u4e9b\u5353\u8d8a\u7684\u68c0\u6d4b\u529f\u80fd\u6709\u52a9\u4e8e\u89e3\u91ca\u4e3a\u4ec0\u4e48Cortex XDR\u5728MITRE ATT&amp;CK\u8bc4\u4f30\u4e2d\u59cb\u7ec8\u4f18\u4e8eCrowdStrike\u3002<a href=\"https:\/\/attackevals.mitre-engenuity.org\/enterprise\/participants\/crowdstrike\/?adversary=wizard-spider-sandworm\">\u5728 MITRE \u7b2c 4 \u8f6e<\/a>\uff0cCrowdStrike\u572894\u4e2a\u5206\u6790\u68c0\u6d4b\u4e2d\u53ea\u53d1\u73b0\u4e86109\u4e2a\uff0c\u5176\u4e2d11\u4e2a\u5ef6\u8fdf\u68c0\u6d4b\u3002\u5ef6\u8bef\u53ef\u80fd\u4f1a\u4ea7\u751f\u4e25\u91cd\u540e\u679c\u3002\u5b9e\u65f6\u68c0\u6d4b\u610f\u5473\u7740\u66f4\u5feb\u7684\u54cd\u5e94\u65f6\u95f4\u548c\u5bf9\u7ec4\u7ec7\u7684\u5f71\u54cd\u66f4\u5c0f\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"822\" height=\"460\" src=\"https:\/\/www.aqwu.net\/wp\/wp-content\/uploads\/2023\/02\/\u56fe\u7247-1.png\" alt=\"\" class=\"wp-image-1096\" srcset=\"https:\/\/www.aqwu.net\/wp\/wp-content\/uploads\/2023\/02\/\u56fe\u7247-1.png 822w, https:\/\/www.aqwu.net\/wp\/wp-content\/uploads\/2023\/02\/\u56fe\u7247-1-300x168.png 300w, https:\/\/www.aqwu.net\/wp\/wp-content\/uploads\/2023\/02\/\u56fe\u7247-1-768x430.png 768w\" sizes=\"auto, (max-width: 822px) 100vw, 822px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">\u66f4\u5feb\u3001\u66f4\u5b8c\u6574\u7684\u8c03\u67e5\u548c\u54cd\u5e94<\/h2>\n\n\n\n<p>Cortex XDR \u81ea\u52a8\u5c06\u8b66\u62a5\u5206\u7ec4\u5230\u4e8b\u4ef6\u4e2d\uff0c\u63d0\u4f9b\u5a01\u80c1\u5efa\u6a21\uff0c\u6536\u96c6\u5b8c\u6574\u7684\u4e0a\u4e0b\u6587\u5e76\u6784\u5efa\u65f6\u95f4\u7ebf\u548c\u653b\u51fb\u5e8f\u5217\uff0c\u4ee5\u4e86\u89e3\u653b\u51fb\u7684\u6839\u672c\u539f\u56e0\u548c\u5f71\u54cd\u3002\u5ba2\u6237\u7814\u7a76\u8868\u660e\uff0cCortex XDR \u53ef\u4ee5\u5c06\u5b89\u5168\u8b66\u62a5\u51cf\u5c11 98%* \u4ee5\u4e0a\uff0c\u5e76\u5c06\u8c03\u67e5\u65f6\u95f4\u7f29\u77ed 88%\u3002 \u6b64\u5916\uff0c\u4e00\u952e\u5f0f\u4fee\u590d\u53ef\u52a0\u5feb\u6240\u6709\u53d7\u5f71\u54cd\u7aef\u70b9\u7684\u653b\u51fb\u6062\u590d\u901f\u5ea6\u3002<br><br>CrowdStrike\u66f4\u4f9d\u8d56\u4e8e\u5206\u6790\u5e08\u6765\u8c03\u67e5\u5e76\u4ece\u653b\u51fb\u4e2d\u6062\u590d\u3002\u4e8b\u4ef6\u5355\u72ec\u663e\u793a\uff0c\u54cd\u5e94\u5355\u72ec\u5b8c\u6210\uff0c\u4fee\u6b63\u624b\u52a8\u5b8c\u6210\uff0c\u81ea\u52a8\u5316\u7a0b\u5ea6\u6709\u9650\u3002\u6700\u7ec8\u7ed3\u679c\u53ef\u80fd\u662f\u98ce\u9669\u66f4\u5927\u3001\u6548\u7387\u66f4\u4f4e\u548c\u6062\u590d\u5ef6\u8fdf\u3002<small><em>*\u57fa\u4e8e Cortex XDR \u5ba2\u6237\u73af\u5883\u7684\u5206\u6790\u3002<\/em><\/small><br><small><em>** Palo Alto Networks SOC \u5206\u6790\u663e\u793a\u8c03\u67e5\u65f6\u95f4\u4ece 40 \u5206\u949f\u7f29\u77ed\u5230 5 \u5206\u949f\u3002<\/em><\/small><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"822\" height=\"460\" src=\"https:\/\/www.aqwu.net\/wp\/wp-content\/uploads\/2023\/02\/\u56fe\u7247-2.png\" alt=\"\" class=\"wp-image-1097\" srcset=\"https:\/\/www.aqwu.net\/wp\/wp-content\/uploads\/2023\/02\/\u56fe\u7247-2.png 822w, https:\/\/www.aqwu.net\/wp\/wp-content\/uploads\/2023\/02\/\u56fe\u7247-2-300x168.png 300w, https:\/\/www.aqwu.net\/wp\/wp-content\/uploads\/2023\/02\/\u56fe\u7247-2-768x430.png 768w\" sizes=\"auto, (max-width: 822px) 100vw, 822px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td><\/td><td>Cortex XDR<\/td><td>CrowdStrike<\/td><\/tr><tr><td><strong>\u6700\u597d\u7684\u4fdd\u62a4<\/strong><\/td><td><strong>100% \u5a01\u80c1\u9632\u5fa1 \u2013 \u9886\u5148<\/strong><br><strong><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-ast-global-color-0-color\">\u221a<\/mark><\/strong> \u5728 MITRE ATT&amp;CK \u8bc4\u4f30\u4e2d\u8fde\u7eed 100 \u5e74\u5b9e\u73b0 3% \u5a01\u80c1\u9884\u9632\uff0c\u5728 AV-\u6bd4\u8f83 EPR \u4e2d\u5b9e\u73b0 100% \u6574\u4f53\u4e3b\u52a8\u9884\u9632\u3002<br><strong><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-ast-global-color-0-color\">\u221a<\/mark><\/strong> \u5355\u4e2a\u4ee3\u7406\u5305\u62ec\u4e13\u95e8\u6784\u5efa\u7684\u52d2\u7d22\u8f6f\u4ef6\u5f15\u64ce\u3001\u57fa\u4e8e AI \u7684\u672c\u5730\u5206\u6790\u548c\u884c\u4e3a\u5a01\u80c1\u9632\u62a4\uff0c\u4ee5\u963b\u6b62\u590d\u6742\u548c\u89c4\u907f\u653b\u51fb\u3002<br><strong><strong><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-ast-global-color-0-color\">\u221a<\/mark><\/strong> <\/strong>\u5185\u7f6e\u7aef\u70b9\u9632\u706b\u5899\u3001\u8bbe\u5907\u63a7\u5236\u548c WildFire\u00ae \u6c99\u76d2\u52a0\u5206\u6790\u529f\u80fd\u53ef\u8bc6\u522b\u65b0\u5a01\u80c1\u5e76\u81ea\u52a8\u5206\u53d1\u66f4\u65b0\u3002<\/td><td><strong>70%\u7684\u4fdd\u62a4\u662f\u5426\u8db3\u591f\u597d\uff1f<\/strong><br><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-ast-global-color-0-color\">\u00d7<\/mark> \u672a\u80fd\u963b\u6b62 MITRE \u7b2c 30 \u8f6e\u548c\u7b2c 3 \u8f6e\u4e2d 7% \u7684\u653b\u51fb\uff0c\u9519\u8fc7\u4e86\uff08\u5b50\u6b65\u9aa4\uff09\u4fdd\u62a4<br><mark><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-ast-global-color-0-color\">\u00d7<\/mark><\/mark> <a href=\"https:\/\/www.paloaltonetworks.com\/blog\/security-operations\/exploring-protection-tests-in-mitre-round-4-not-all-prevention-is-created-equal\/\">\u7c73\u7279\u96f7\u7b2c\u56db\u8f6e<\/a>\u8bc4\u4f30\u3002CrowdStrike\u7ee7\u7eed\u4e0e\u672a\u547d\u4e2d\u548c\u5ef6\u8fdf\u6d4b\u8bd5\u7684\u5a01\u80c1\u4f5c\u6597\u4e89\u3002<br><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-ast-global-color-0-color\">\u00d7<\/mark> \u4fdd\u62a4\u7f3a\u4e4f\u884c\u4e3a\u5a01\u80c1\u9632\u62a4\u548c\u5bf9\u9759\u6001\u54c8\u5e0c\u5206\u6790\u7684\u4f9d\u8d56\u3002<br><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-ast-global-color-0-color\">\u00d7<\/mark> \u6709\u9650\u7684\u9884\u9632\u6a21\u5f0f\uff0c\u7aef\u70b9\u9632\u706b\u5899\u548c\u8bbe\u5907\u63a7\u5236\u4ec5\u4f5c\u4e3a\u6602\u8d35\u7684\u9644\u52a0\u9009\u9879\u63d0\u4f9b<\/td><\/tr><tr><td><strong>\u660e\u663e\u5353\u8d8a\u7684\u68c0\u6d4b\u6027\u80fd<\/strong><\/td><td><strong>\u57fa\u4e8e\u5206\u6790\u7684\u68c0\u6d4b\u63a8\u52a8\u7ed3\u679c<\/strong><br><strong><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-ast-global-color-0-color\">\u221a<\/mark><\/strong> MITRE \u7b2c 98 \u8f6e\u8bc4\u4f30\u4e2d\u7684\u5206\u6790\u8986\u76d6\u7387\u548c\u6280\u672f\u7ea7\u68c0\u6d4b\u7387\u4e3a 2.4%\u3002<br><strong><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-ast-global-color-0-color\">\u221a<\/mark><\/strong> \u5e7f\u6cdb\u7684\u6570\u636e\u6536\u96c6\u548c AI \u9a71\u52a8\u7684\u6570\u636e\u5206\u6790\u63a8\u52a8\u4e86\u5feb\u901f\u51c6\u786e\u7684\u68c0\u6d4b\u3002<br><strong><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-ast-global-color-0-color\">\u221a<\/mark><\/strong> \u65b0\u7684\u68c0\u6d4b\u89c4\u5219\u5206\u6790\u65b0\u6570\u636e\u548c\u5386\u53f2\u6570\u636e\uff0c\u4ee5\u5b9e\u73b0\u5b8c\u5168\u53ef\u89c1\u6027\u3002<\/td><td><strong>\u53ef\u89c1\u6027\u4e0d\u5b8c\u6574\u548c\u9057\u6f0f\u68c0\u6d4b<\/strong>\u5728 <br><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-ast-global-color-0-color\">\u00d7<\/mark> MITRE \u7b2c 15 \u8f6e\u8bc4\u4f30\u4e2d\u9519\u8fc7\u4e86 4 \u6b21\u6280\u672f\u68c0\u6d4b\uff0c\u5176\u4e2d 11 \u6b21\u5ef6\u8fdf\u68c0\u6d4b\u3002<br><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-ast-global-color-0-color\">\u00d7<\/mark> \u673a\u5668\u5b66\u4e60\u72ed\u9698\u5730\u4e13\u6ce8\u4e8e\u4e0e\u8eab\u4efd\u76f8\u5173\u7684\u4e8b\u4ef6\u548c\u65e5\u5fd7\uff0c\u5e76\u4e14\u53ea\u80fd\u652f\u4ed8\u989d\u5916\u8d39\u7528\u3002<br><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-ast-global-color-0-color\">\u00d7<\/mark> \u5386\u53f2\u6570\u636e\u4ece\u65b0\u7684\u68c0\u6d4b\u89c4\u5219\u8303\u56f4\u4e2d\u6392\u9664\u3002<\/td><\/tr><tr><td><strong>\u66f4\u5feb\u3001\u66f4\u5b8c\u6574\u7684\u8c03\u67e5\u548c\u54cd\u5e94<\/strong><\/td><td><strong>\u81ea\u52a8\u5316\u52a0\u901f\u83b7\u5f97\u7ed3\u679c<\/strong><br><strong><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-ast-global-color-0-color\">\u221a<\/mark><\/strong> \u4e8b\u4ef6\u7684\u81ea\u52a8\u5173\u8054\u4f7f\u5206\u6790\u5e08\u80fd\u591f\u67e5\u770b\u6574\u4e2a\u4e8b\u4ef6\uff0c\u8b66\u62a5\u5206\u7ec4\u548c\u4e8b\u4ef6\u8bc4\u5206\u53ef\u5c06\u8c03\u67e5\u65f6\u95f4\u7f29\u77ed 88%\u3002<br><strong><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-ast-global-color-0-color\">\u221a<\/mark><\/strong> \u673a\u5668\u9694\u79bb\u548c\u6062\u590d\u53ef\u4ee5\u5355\u72ec\u6216\u6279\u91cf\u5b8c\u6210\u3002<br><strong><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-ast-global-color-0-color\">\u221a<\/mark><\/strong> \u4e00\u952e\u5f0f\u4fee\u590d\u4f7f\u54cd\u5e94\u8005\u80fd\u591f\u5feb\u901f\u4ece\u4e8b\u4ef6\u4e2d\u6062\u590d\u3002<\/td><td><strong>\u624b\u52a8\u6d3b\u52a8\u4f1a\u589e\u52a0\u5ef6\u8fdf<\/strong><br><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-ast-global-color-0-color\">\u00d7<\/mark> \u6bcf\u4e2a\u4e8b\u4ef6\u90fd\u5355\u72ec\u5448\u73b0\uff0c\u9700\u8981\u66f4\u591a\u7684\u7cbe\u529b\u548c\u65f6\u95f4\u6765\u5206\u6790\u548c\u786e\u5b9a\u4e8b\u4ef6\u8303\u56f4\u3002<br><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-ast-global-color-0-color\">\u00d7<\/mark> \u7f3a\u4e4f\u81ea\u52a8\u5316\u4efb\u52a1\u610f\u5473\u7740\u5206\u6790\u5e08\u6d6a\u8d39\u4e86\u5b9d\u8d35\u7684\u65f6\u95f4\uff0c\u4ed6\u4eec\u5fc5\u987b\u5355\u72ec\u548c\u624b\u52a8\u54cd\u5e94\uff0c\u800c\u65e0\u9700\u4e00\u952e\u4fee\u590d\u3002<\/td><\/tr><tr><td><strong>\u4f01\u4e1a\u5951\u5408\u5ea6<\/strong><\/td><td><strong>\u4e3a\u60a8\u7684\u7ec4\u7ec7\u91cf\u8eab\u5b9a\u5236<\/strong><br><strong><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-ast-global-color-0-color\">\u221a<\/mark><\/strong> \u51e0\u4e4e\u53ef\u4ee5\u4ece\u4f01\u4e1a\u8303\u56f4\u5185\u7684\u4efb\u4f55\u7cfb\u7edf\u65e5\u5fd7\u3001\u4e8b\u4ef6\u65e5\u5fd7\u3001\u6587\u4ef6<strong><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-ast-global-color-0-color\">\u221a<\/mark><\/strong> \u62cd\u6216\u6e90\u4e2d\u63d0\u53d6\u6570\u636e\u3002<br><strong><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-ast-global-color-0-color\">\u221a<\/mark><\/strong> XDR \u5305\u62ec\u7aef\u70b9\u4fdd\u62a4\uff0c\u5e76\u901a\u8fc7\u5355\u4e2a\u7edf\u4e00\u4ee3\u7406\u5b8c\u5168\u4ea4\u4ed8\u3002<br>\u884c\u4e1a\u9886\u5148\u7684 Linux \u64cd\u4f5c\u7cfb\u7edf\u8986\u76d6\u8303\u56f4\u3002<br><strong><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-ast-global-color-0-color\">\u221a<\/mark><\/strong> \u68c0\u6d4b\u89c4\u5219\u548c\u4eea\u8868\u677f\u53ef\u8f7b\u677e\u81ea\u5b9a\u4e49\uff0c\u4ee5\u652f\u6301\u6bcf\u4e2a\u7ec4\u7ec7\u7684\u72ec\u7279\u9700\u6c42\u3002<br><strong><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-ast-global-color-0-color\">\u221a<\/mark><\/strong> \u7ecf\u8fc7\u9a8c\u8bc1\u7684\u6210\u719f XDR \u4ea7\u54c1\uff0c\u62e5\u6709 5\uff0c000 \u591a\u5bb6\u5ba2\u6237\u3002<\/td><td><strong>\u4e00\u79cd\u5c3a\u5bf8\u5e76\u4e0d\u9002\u5408\u6240\u6709\u4eba<\/strong><br><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-ast-global-color-0-color\">\u00d7<\/mark> \u7aef\u70b9\u4ee5\u5916\u7684\u6570\u636e\u4ec5\u9650\u4e8eCrowdSrike\u8054\u76df\u5408\u4f5c\u4f19\u4f34\u3002<br><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-ast-global-color-0-color\">\u00d7<\/mark> \u7528\u4e8e EDR \u548c\u8eab\u4efd\u5206\u6790\u7684\u5355\u72ec\u4ee3\u7406\u589e\u52a0\u4e86\u590d\u6742\u6027\u548c\u7528\u6237\u4f53\u9a8c\u3002<br><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-ast-global-color-0-color\">\u00d7<\/mark> Linux \u8986\u76d6\u8303\u56f4\u4e0d\u5b8c\u6574\uff0c\u529f\u80fd\u652f\u6301\u6709\u9650\u3002<br><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-ast-global-color-0-color\">\u00d7<\/mark> \u57fa\u672c\u548c\u6700\u5c0f\u7684\u81ea\u5b9a\u4e49\u9009\u9879\u3002<br><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-ast-global-color-0-color\">\u00d7<\/mark> \u672a\u7ecf\u9a8c\u8bc1\u7684\u9996\u6b21\u53d1\u5e03 XDR \u4ea7\u54c1\u3002<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"612\" src=\"https:\/\/www.aqwu.net\/wp\/wp-content\/uploads\/2023\/02\/\u56fe\u7247-3-1024x612.png\" alt=\"\" class=\"wp-image-1098\" srcset=\"https:\/\/www.aqwu.net\/wp\/wp-content\/uploads\/2023\/02\/\u56fe\u7247-3-1024x612.png 1024w, https:\/\/www.aqwu.net\/wp\/wp-content\/uploads\/2023\/02\/\u56fe\u7247-3-300x179.png 300w, https:\/\/www.aqwu.net\/wp\/wp-content\/uploads\/2023\/02\/\u56fe\u7247-3-768x459.png 768w, https:\/\/www.aqwu.net\/wp\/wp-content\/uploads\/2023\/02\/\u56fe\u7247-3.png 1280w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Cortex XDR\u5728MITRE ATT&amp;CK\u00ae\u8bc4\u4f30\u4e2d\u7684\u8868\u73b0\u59cb\u7ec8\u4f18\u4e8eCrowdStrike\u3002<\/h2>\n\n\n\n<p>\u5728<a href=\"https:\/\/www.paloaltonetworks.com\/cortex\/cortex-xdr\/mitre\">MITRE ATT&amp;CK\u7b2c4\u8f6e\u8bc4\u4f30<\/a>\uff0cCortex XDR\u901a\u8fc7\u201c\u6280\u672f\u7ea7\u5206\u6790\u68c0\u6d4b\u201d\u8bc6\u522b\u4e86\u8d85\u8fc797%\u7684\u653b\u51fb\u5b50\u6b65\u9aa4\uff0c\u800cCrowdStrike\u7684\u8fd9\u4e00\u6bd4\u4f8b\u4e3a71%\u3002\u6280\u672f\u68c0\u6d4b\u662f\u9ec4\u91d1\u6807\u51c6\uff0c\u63d0\u4f9b\u4e86\u89e3\u6240\u6267\u884c\u64cd\u4f5c\u3001\u539f\u56e0\u548c\u65b9\u5f0f\u6240\u9700\u7684\u6240\u6709\u8be6\u7ec6\u4fe1\u606f\u548c\u4e0a\u4e0b\u6587\uff0c\u4f7f\u5b89\u5168\u5206\u6790\u5e08\u80fd\u591f\u91c7\u53d6\u63aa\u65bd\u5e76\u4fee\u6b63\u5a01\u80c1\u3002Cortex XDR \u4e3a\u60a8\u7684\u5206\u6790\u5e08\u63d0\u4f9b\u5353\u8d8a\u7684\u60c5\u62a5\uff0c\u4ee5\u4fbf\u5728\u65e9\u671f\u9636\u6bb5\u963b\u6b62\u653b\u51fb\u8005\u3002<\/p>\n\n\n\n<p>\u60a8\u5e94\u8be5\u8981\u6c42\u7aef\u70b9\u5b89\u5168\u63d0\u4f9b\u5546\u80fd\u591f\u9632\u5fa1\u6240\u6709\u5bf9\u624b\u7684\u7b56\u7565\u548c\u6280\u672f\uff0c\u4ee5\u907f\u514d\u60a8\u7684 SOC \u56e2\u961f\u56e0\u8b66\u62a5\u3001\u4e8b\u4ef6\u548c\u53ef\u80fd\u7684\u8fdd\u89c4\u884c\u4e3a\u800c\u8fc7\u8f7d &#8211; \u6240\u6709\u8fd9\u4e9b\u90fd\u662f\u53ef\u4ee5\u9884\u9632\u7684\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u7aef\u70b9\u4fdd\u62a4\u4e3a\u6709\u6548\u7684\u5b89\u5168\u7b56\u7565\u5960\u5b9a\u4e86\u57fa\u7840\uff0cCortex XDR \u7684\u7aef\u70b9\u4fdd\u62a4\u5728\u72ec\u7acb\u7684\u7b2c\u4e09\u65b9\u8bc4\u4f30\u4e2d\u59cb\u7ec8\u4f18\u4e8e CrowdS [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[11,8,5],"tags":[265,112],"class_list":["post-1094","post","type-post","status-publish","format-standard","hentry","category-crowdstrike","category-paloalto","category-infosec","tag-cortex-xdr","tag-crowdstrike"],"views":2088,"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=\/wp\/v2\/posts\/1094","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1094"}],"version-history":[{"count":1,"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=\/wp\/v2\/posts\/1094\/revisions"}],"predecessor-version":[{"id":1099,"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=\/wp\/v2\/posts\/1094\/revisions\/1099"}],"wp:attachment":[{"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1094"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1094"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1094"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}