Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
How to Protect NetApp/ONTAP using Endpoint Detect and Respond Solutions (RE: Crowdstrike Falcon)
2024-04-02
05:37 AM
4,572 Views
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
My Security & Risk Oversight Director is asking how we can "install" Crowdstrike on NetApp - knowing that is not realistically possible. But the true ask here is, how do we protect the NetApp OS (ONTAP/Free BSD) using established Endpoint Detect & Response (EDR) or Managed Detect & Response (MDR) solutions?
Our organization uses CrowdStrike Falcon. So I'm being asked to check with NetApp and other relevant vendors if they allow for the installation of EDR tools like CrowdStrike Falcon or are there established solutions to meet this need?
Thank you in advance!
Solved! See The Solution
1 ACCEPTED SOLUTION
nicholsongc has accepted the solution
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ONTAP is an Appliance Model - NetApp supports the entire environment - you should not modify or attempt to modify any portions of the ONTAP distribution, including underlaying OS components, including installing third party software on it. ONTAP does an integrity check at boot and will not boot if modified.
You could also ask CrowdStrike if they support running their software on ONTAP controllers (the answer will be no).
6 REPLIES 6
nicholsongc has accepted the solution
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ONTAP is an Appliance Model - NetApp supports the entire environment - you should not modify or attempt to modify any portions of the ONTAP distribution, including underlaying OS components, including installing third party software on it. ONTAP does an integrity check at boot and will not boot if modified.
You could also ask CrowdStrike if they support running their software on ONTAP controllers (the answer will be no).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
Alex is right ... Ontap cannot support EDR on there OS, but you have many solution to "sucure" the system :
- ARP : Autonomous Ransomware Proection
- MAV: Muti Admin validation, Ask two persons to do an action, like a volume delete for exemple
- Anitvirus, an external engine, can be connected to Ontap to analyse in live the write on filesyste, like Trend, kaspersky, symantec ...
With all this points you can demonstrate the good level of security of your Ontap environnement
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you @cedric_renauld and @AlexDawson for the quick and informative responses!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@AlexDawson , is there a white paper or tech sheet/article that would address my question with your response. My management would like to be able to present an "official NetApp document" as well as the responses from this group. Thank you again for your contribution!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi there, you'd probably be best opening a ticket with Crowdstrike asking them about it - their negative would probably placate your management more than ours 🙂
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
