Skip to content
Notifications
Clear all

My honest review after 2 years: It works, but support responsiveness tanked

1 Posts
1 Users
0 Reactions
38 Views
(@integration_maven_2)
Estimable Member
Joined: 6 months ago
Posts: 171
Topic starter   [#4872]

After utilizing Cybereason's Endpoint Protection Platform (EPP) and Extended Detection and Response (XDR) capabilities across our organization's estate for a period of 24 months, I feel compelled to provide a detailed operational review. My primary focus will be on the platform's technical integration stability and the critical, yet deteriorating, dimension of technical support—a key component for any security tool embedded within a broader IT and security automation fabric.

From a pure integration and functionality standpoint, the platform has performed reliably. The API layer, which we leverage extensively for automated alert enrichment and ticket creation, is well-documented and consistent. We have successfully built workflows that funnel Cybereason detection events into our central SIEM and ticketing system using their RESTful APIs. A simplified example of the webhook configuration we employ for alert forwarding is below:

```json
{
"webhook_name": "SIEM_Alert_Forwarder",
"url": "https://our-siem.example.com/api/ingest",
"method": "POST",
"headers": {
"Authorization": "Bearer ",
"Content-Type": "application/json"
},
"format": {
"source": "Cybereason",
"timestamp": "{event_timestamp}",
"severity": "{severity_level}",
"detection_name": "{detection_name}",
"endpoint": "{machine_name}"
}
}
```

The platform's strength lies in its:
* **Consistent API performance:** We have observed no significant downtime or breaking changes in the API schema over the review period.
* **Granular alert data:** The JSON payloads from detection events are rich with endpoint context, process tree information, and MITRE ATT&CK mappings, which are invaluable for downstream correlation.
* **Effective core detection:** The MalOp (Malicious Operation) narrative is genuinely useful for triage, reducing mean time to understand (MTTU) for our analysts.

However, the most pronounced negative shift has been in the responsiveness and depth of technical support. This decline directly impacts operational efficiency and risk posture. Two years ago, support queries, particularly concerning API edge cases or complex deployment scenarios, were addressed within a business day with substantive, engineer-level detail. The current experience is markedly different:

* **Escalation delays:** Tickets now frequently linger in Tier 1 for multiple days, receiving only generic troubleshooting steps (e.g., "please restart the sensor") that are inappropriate for architecture-level questions.
* **Deterioration in API-specific support:** Queries regarding rate limiting nuances, webhook delivery guarantees, or schema interpretation now take 3-5 business days for an initial, often incomplete, response.
* **Impact on automation projects:** This lag has directly delayed the completion of automated response playbooks we were building in Workato, as we were blocked for a week awaiting clarification on a required API field's behavior.

This decline transforms Cybereason from a proactive partner in security orchestration to a mere data source. The burden of troubleshooting and integration depth has shifted almost entirely to our internal team. For organizations considering this platform, I would advise factoring in this increased internal support overhead, especially if your use case extends beyond the GUI into automated workflows (Zapier, Workato, custom scripts) or deep integration with other CRMs and operational tools. The product engine remains solid, but the support scaffolding around it has notably weakened.


connected


   
Quote