Gigamon ThreatINSIGHT 365-Day Data Retention Levels the Playing Field Against Adversaries’ Dwell Time Advantage

The first NDR solution to grant SOC teams the time, historical data, and insights into adversary behavior required to effectively identify security incidents, truncate dwell time and mitigate business risk

Santa Clara, CA — February 9, 2022 – Gigamon, the leader in cloud visibility and analytics, today announced the latest release of Gigamon ThreatINSIGHT Guided-SaaS NDR. As the first NDR (network detection and response) solution on the market to provide 365-day rich network metadata retention, ThreatINSIGHT provides SOC (security operation center) teams with visibility into historical network data and the tools to use that data to identify adversary activity across the MITRE ATT&CK framework.

Average adversary dwell times are over 285 days, giving adversaries the opportunity to find and breach an organization’s most sensitive data and intellectual property, aiming to hold it for ransom. NDR solutions typically provide 30-day data retention, missing these “low and slow” threats. Today, Gigamon ThreatINSIGHT becomes the only NDR to address lengthy dwell times with 365-day retention of rich network metadata. Extended data retention enables more proactive threat hunting, lessening the pressure of ransomware, advanced persistent threats, and cybercrime that results in 70 percent of SOC teams reporting burnout.

“Adversaries continue to capitalize on lengthy dwell times, and security teams need a solution that gives them an advantage,” said Chris Kissel, IDC Research Director, Security and Trust. “With the ability to analyze 365 days of network metadata and out-of-the-box tools that facilitate collaboration and coordinate investigative and threat hunting efforts, Gigamon helps organizations speed up and improve their forensics and incident response capabilities.”

"With the advancements in this release, Gigamon continues to stay out ahead of the pack in NDR solutions," said Bob Reilly, vice president of sales for Access IT Group, an industry leading cybersecurity solution provider and Gigamon Platinum partner. “Offering 365 days of visibility into suspicious network activity and an experienced team of threat analysts as part of the standard package makes ThreatINSIGHT very competitive in the NDR marketplace."

“Timing, teamwork and access to historical data are mission critical to thwarting potentially crippling cyberattack attempts by threat actors that are already inside your network,” said Clinton Mills, CEO of Spartan Cyber Services. “The ability to launch real-time investigations with proven, guided playbooks based on the work of the world renown Gigamon ATR enables us to quickly navigate the modern threat environment and help protect our customers.”

In today’s threat landscape, it is critical that organizations arm their security teams with a solution that matches - and beats - adversaries’ sophisticated techniques. ThreatINSIGHT equips organizations with the resources to not only detect a potential threat, but also to respond to that threat in real-time. More data with deep insights levels the playing field for SOC teams.

Gigamon ThreatINSIGHT Guided-SaaS NDR equips security teams with:

  • Up to 365-day retention -- With more than 10x longer data retention than other NDR offerings, ThreatINSIGHT enables better threat hunting including XDR (extended detection and response) programs. SOC analysts can also respond with immediate validation on whether newly reported vulnerabilities have been exploited in the past.
  • Guided Playbooks -- 52 percent of SOC analysts report the need to access more out-of-the-box content. ThreatINSIGHT’s guided playbooks empower investigators to identify attackers based on real-world behaviors – all within a few mouse clicks, guided by the battle-tested playbooks perfected by Gigamon ATR (Applied Threat Research).
  • Parallel Hunting -- SOC teams can coordinate faster with more effective threat hunting efforts across the globe via parallel queries and investigations. When combined with guided playbooks, SOC teams can rapidly leverage their institutional knowledge to stay ahead of attackers.
  • Extended Reporting (90-day at-a-glance dashboards) -- With the increase of global privacy regulations, organizations must comply with reporting mandates following data breaches. A lack of historic network visibility can impede compliance, digital forensics, and audit efforts across the organization. ThreatINSIGHT provides a 90-day dashboard to support compliance needs by offering organizations unparalleled visibility into their networks.

“Every new data breach, insider threat, and ransomware attack underscores the need for high-fidelity detections that are as effective as adversaries are persistent,” said Michael Dickman, chief product officer at Gigamon. “We’re extremely proud of this new release of Gigamon ThreatINSIGHT Guided-SaaS NDR, giving incident responders a full year of metadata, prescriptive playbooks to automate the basics, and the ability for teams to work on the same case in parallel.”

To learn more, check out the most recent blog here, visit the Gigamon ThreatINSIGHT Guided-SaaS NDR page and then request a demo today.

About Gigamon

Gigamon helps the world’s leading organizations run fast, stay secure and innovate. We provide the industry’s first Guided-SaaS NDR (network detection and response) solution which closes the Security Operations Center (SOC) visibility gap, removes unnecessary distractions and provides expert advisory guidance when it matters most. With visibility into network traffic across their entire hybrid cloud infrastructure, organizations eliminate security blind spots while benefiting from Gigamon security expert guidance, helping improve SOC effectiveness and reducing burnout of their security teams.

Gigamon has been awarded over 125 technology patents and enjoys world-class customer satisfaction with more than 4,000 organizations, including over 80 percent of the Fortune 100 and hundreds of government and educational organizations worldwide. Headquartered in Silicon Valley, Gigamon operates globally. For the full story on how Gigamon can help you to run fast, stay secure and innovate, please visit and follow us on Twitter and LinkedIn.