Technology Partner
Overview
Cloud complexity and encrypted traffic create critical blind spots, leaving GCP workloads and assets vulnerable to stealthy lateral movement and misconfiguration abuse. ExtraHop RevealX delivers cloud-native NDR, leveraging GCP Packet Mirroring for deep, real-time Layer 7 visibility across compute instances and container workloads. Gain the network truth needed to enforce Zero Trust, accelerate investigations, and unify SecOps/NetOps across your hybrid environment for superior security and massive performance and resiliency gains.
Challenges
Multi-cloud complexity strains security teams, who must contend with rampant alert noise and organizational silos. Critical threats in GCP stem from misconfigurations—like overly permissive IAM or firewall rules—and attackers abusing cloud APIs (e.g., VM snapshot creation) for lateral movement. Logs fail to capture east-west details, while threats like malware and C2 hide in encrypted TLS 1.3 traffic. The lack of deep visibility slows investigation and response.

Brief
The ephemeral nature of containers demands continuous monitoring, AI-powered analysis, and swift threat response. The RevealX platform unifies security across GCP containers and services in a single pane, providing deep defense for Google Kubernetes Engine (GKE) environments. It offers versatility, visibility via continuous auto-discovery, and superior detection and response using cloud-scale ML and continuous PCAP for fast forensic evidence.
NDR Use Case
Benefits
Identify sophisticated cloud-native threats, including ransomware, insider threats, and supply chain attacks that evade logs.
Solution
Analyzes network payloads and behaviors using cloud-scale ML/AI to uncover C2, advanced persistent threats (APT), and malware hiding in traffic.
NDR Use Case
Benefits
Increase analyst efficiency and reduce alert fatigue by providing enriched, high-fidelity detections and automated forensics context.
Solution
RevealX integrates detections into SIEM/SOAR platforms (i.e., Splunk, SentinelOne) and provides instant packet forensics for rapid root cause analysis.
NPM Use Case
Benefits
Detect misconfiguration abuse and identity-based movement 83% faster before attackers access critical data and cloud resources.
Solution
ML-powered peer-group analysis monitors anomalous lateral/east-west activity in GCP traffic, identifying techniques like snapshot creation abuse instantly.
NDR + NPM Use Case
Benefits
Accelerate investigation and response with automated data gathering and comprehensive packet-level forensic evidence retention.
Solution
Use AI-optimized workflows to pivot from detection to full packet forensics in 3 clicks or less, resolving performance or security issues faster and reducing exposure.
NDR + NPM Use Case
Benefits
Establish continuous, real-time trust verification by analyzing all network communications, user identity, and device behavior.
Solution
Provides L7 visibility into authentication protocols, ensuring policy enforcement and detecting compromised or unmanaged assets deep in the VPC.
NDR + NPM Use Case
Benefits
Unify NetOps and SecOps visibility to preempt performance degradation and reduce MTTR for critical application outages.
Solution
Monitors thousands of real-time network metrics and transactions, identifying performance issues linked directly to application traffic flow in GCP VPCs.
Diane Brown
Senior Director of IT Risk Management & CISO, Ulta Beauty
Platform
ExtraHop RevealX delivers cloud-native NDR for GCP, providing deep, real-time Layer 7 visibility. Detect lateral movement, enforce Zero Trust, and enhance cloud security.

Solution
RevealX delivers the critical, real-time network truth for both performance and security. We decode 90+ protocols and perform line-rate decryption of TLS 1.3/PFS, exposing threats and resolving application and general performance issues hidden in encrypted GCP and hybrid traffic without sacrificing speed. Cloud-scale ML uses behavioral analysis to preemptively detect security threats and application issues other tools miss. And AI-optimized workflows optimize NDR, NPM, and forensics, automating investigation and response across all domains.