A New Era for Advanced Threat Detection and Response

Announcement of the upcoming market release of OpenText™ Core Threat Detection and Response

27 Feb 2025 SintelSedat Akfidan 4 min read
A New Era for Advanced Threat Detection and Response

Why Security Needs to Be Smarter

I have an issue with rules. They're not good enough on their own. Imagine you're a security guard in an office building. You create a rule to keep out unwelcome visitors: everyone without a badge is stopped at the door. It seems effective — until someone realizes they can copy a badge or sneak behind an employee.

So, you add another rule: employees must swipe their badge every time. But what if a hacker steals someone's identity? Or an employee becomes a thief and raids equipment at night? Should another rule be added to block any scans after 5 PM? You'll need a special case and then a way to evaluate that special case. Later, the VPs and higher-ups request a permanent exception for themselves, so another rule is added. Then HR provides the names of people they suspect are not trustworthy. So, you write a rule to alert them when those people enter or leave, but after a while, they start ignoring the alerts because they keep pinging them repeatedly.

Don't worry, I'm also getting a bit tired of the metaphor. The point is that no matter how complex and carefully updated the rules are, they can't protect an organization from insider threats. What the office really needs is a guard who personally knows every individual in the building. A bodyguard who can recognize when someone behaves oddly, even if they act normally. A sentinel who can catch a series of small things and connect them to reveal a big red flag. That single "smoking gun" that supports the feeling we all sometimes have of "something's wrong."

This is where OpenTextTM Core Threat Detection and Response comes in. It's not just about following rules, but also understanding behaviors.

OpenText Core Threat Detection and Response Announcement

Scheduled for release in May 2025, OpenText Core Threat Detection and Response is designed to do what legacy security tools couldn't — it learns not just from rules, but also from behaviors. By using AI-focused behavioral analytics, it detects insider threats, credential misuse, and anomalies in real time, making security smarter, more efficient, and more effective.

Unlike standalone products that force teams to rip out their current tools, OpenText Core Threat Detection and Response is built as an Open XDR solution, strengthening your security infrastructure instead of competing with it. It seamlessly integrates with your environment alongside Microsoft Defender, Entra ID, and other security investments to provide deeper insights without adding complexity. Initially, we focused on Microsoft's ecosystem for seamless integration, but future versions will expand to support additional security platforms.

Why Traditional Security Falls Short

Most security solutions work like an overly eager alarm system triggered by every minor deviation from the rules. This can overwhelm security teams with false positives (a metaphor that speaks to my aging perspective about how city dwellers ignore car alarms). On the other hand, OpenText Core Threat Detection and Response behaves like an experienced investigator, linking multiple behaviors while filtering out noise to identify real threats. This is a boon for overburdened SOC teams and CISOs dealing with skill shortages.

Changing the Game:

  • Adaptive Threat Detection: Instead of static rules, our AI continuously learns from your environment. It detects anomalies in real time — like an employee accessing sensitive files at unusual hours. It doesn't just flag an odd login; it sees the whole picture — who logged in, where, what they accessed, and whether that aligns with their past behavior.
  • Fewer, Smarter Alerts: Rather than drowning SOC teams in false alarms, we provide precise, context-rich alerts that highlight real risks and help teams focus on what matters most. And by context-rich, we mean the AI clearly explains why it's raising an alarm. SOC teams gain the ability to prioritize and determine the best course of action, even when automation isn't yet available.
  • Seamless Integration: Our roadmap for deep integration with Microsoft Defender and Entra ID will expand to include more security ecosystems. This means more organizations can benefit from Core Threat Detection and Response without disrupting their existing investments.

Stronger Security, Smarter Investments

We know security budgets aren't limitless. That's why OpenText Core Threat Detection and Response isn't designed to replace your existing security stack — it's built to enhance it. Think of it as moving from a dashboard full of warning lights to an advanced driver assistance system that predicts and prevents accidents before they happen.

Organizations can gain more value from the tools they already use by adding behavioral analysis and anomaly detection on top of their existing security investments — without the complexity of managing another silo solution (no more spinning plates!) Yes, costs will go up a bit, but the return on investment is exponential.

What's Next?

Early adopters are already testing OpenText Core Threat Detection and Response to help refine and optimize its capabilities before launch. These organizations are shaping the future of insider threat defense by partnering with OpenText — and you can too. If you're ready to adopt a smarter approach to security, we'd like to hear from you.

Source: A New Era of Advanced Threat Detection and Response Has Arrived - OpenText Blogs