We are looking into some sort of on-prem endpoint security solution and are wondering what the general thoughts are on ESET. Do you have a recommendation for an on-prem that you like/are familiar with?

1 Spice up

Are you talking about ESET?

Yes I was, sorry about the Typo.

No worries, I just got confused for a sec :sweat_smile:. We use ESET on-prem in our environment. Eset is ok, their pricing is great and I think we have the base ESET protect package and its pretty feature rich as is. Some of the things I noticed was that their agents due tend to be resource intensive. Their on-prem webui was pretty impressive with the amount of analytics and information you could pull.

The biggest thing to note is configuration and maintenance. If you want to take advantage of all the features, I highly recommend taking the time to understand the system and come up with a game plan for implementation and maintenance. There is a lot to configure with ESET and failure to maintain it will prevent your environment from leveraging some of it’s best perks.

As for detection, I think most solutions are great at finding well known threats, but having said that, I have also used Crowdstrike before and the heuristics and pattern detection does not really compare to most modern cloud mdr solutions. The caveat would be that you would not get as many false flag detections that I have gotten with Crowdstrike.

Overall ESET is great but you have to have someone stay on top of it in order to make it effective, if not, then it becomes a check in the box for whatever security requirements you have and not really worth trusting in actively finding hard to detect threats.

Hey OP! As other folks chime in with their experience, I think it depends on a couple of different factors… Do you have any other specs you’re working with? Number of endpoints, budget, etc.?

I think that applies to just about anything to be honest. I have always found their admin interface to be a bit odd but that’s probably because I only ever touch it for upgrades for a third party org.

The stay on top of it comment applies to just about any AV. You want to keep an eye on it regardless of the vendor.

Products like Crowdstrike and SentinelONE I feel are on another level above that ESET offers in terms of EDR/XDR.

1 Spice up

We are looking at around 50-55 endpoints, and do not want to do anything in the cloud. As far as budget was concerned we were looking at $3000 or less a year.

I appreciate the response. We have a good group staying on top of things here, so that shouldn’t be a problem.

Can’t help you on this one as I don’t know what those tier solutions are priced at but thank you for providing the scope, it will make it much easier for someone else in a similar range to give feedback.

What AV or security solutions are you currently using ?

We are currently using Kaspersky

What are your pain points ?

What are the features you looking for ?

• Device control (like USB thumb drives, cameras, phones, etc…)
• Application Control (can we block certain apps from running on workstations, e.g., powershell)
• Content Control
• Application Management (Patch and vulnerability scanning and pushing)
• Drive encryption
• Email Protection
• Firewall
• Network Threat protection
• Bad USB protection (emulates a keyboard to insert data)
• Web Control

Sophos with Sophos central

Well, it sounds like your budget is “new hardware friendly”. If that’s the case, then end points with security enhancements might be something to look at seriously. Hopefully I don’t sound spammy on this one.

Intel vPro has remote management and security built into the hardware. Intel vPro uses Threat Detection Technology to identify and mitigate threats before they have time to happen. We’ve partnered with both ESET and CrowdStrike on a few security collaborations and seen the benefits of pairing both the software and hardware for security.

Remote management is accessed through a server that you set up either on prem or on the cloud. I know you said you’re not doing anything in the cloud, hopefully this option wouldn’t be a game changer.

Hopefully you’re still reading. Here’s a link with more resources and info.
Intel vPro® Platform

#IAmIntel

1 Spice up