| | SLO | ENG | Cookies and privacy

Bigger font | Smaller font

Show document Help

Title:Orodja za odkrivanje in odzivanje na kibernetske grožnje : primerjalna analiza Cortex XDR in Microsoft Defender
Authors:ID Veršnik, Tim (Author)
ID Vrhovec, Simon (Mentor) More about this mentor... New window
Files:.pdf MAG_Versnik_Tim_2025.pdf (2,57 MB)
MD5: 70FB60B103A0E498DC68A0F86586B475
 
Language:Slovenian
Work type:Master's thesis/paper
Typology:2.09 - Master's Thesis
Organization:FVV - Faculty of Criminal Justice and Security
Abstract:Magistrska naloga se ukvarja z raziskovanjem orodij za odkrivanje in odzivanje na kibernetske grožnje. V sklopu raziskave smo izvedli primerjalno analizo med dvema vodilnima produktoma, Cortex XDR podjetja Palo Alto Networks in Microsoft Defender for Endpoint (MDE). S hitrim razvojem digitalizacije, pojavom interneta stvari (IoT), uporabo pristopa BYOD in vse bolj sofisticiranimi napadi postaja jasno, da tradicionalni varnostni mehanizmi, kot so protivirusne rešitve, ne zadoščajo več za učinkovito zaščito informacijskih sistemov. Prav zaradi teh razlogov se organizacije vse pogosteje poslužujejo naprednih varnostnih rešitev, kot sta EDR in XDR. Te rešitve omogočajo zaznavanje, analizo ter odzivanje na incidente v realnem času. Teoretični del naše naloge obravnava temelje penetracijskega testiranja, koncepte rdečih in modrih ekip, uporabo okvirja matrike Mitre ter orodja Caldera, ki omogoča emulacijo kibernetskih napadov. Ti koncepti služijo kot osnova za razumevanje metodologije praktičnega dela, v katerem je bilo v okolju VMware Aria vzpostavljeno testno okolje z osmimi virtualnimi napravami. Tri naprave so bile zaščitene z rešitvijo MDE, tri z rešitvijo Cortex XDR, dve pa sta bili uporabljeni kot napadalno orodje in podporni strežnik za aplikacijo Caldera. V praktičnem delu je bilo izvedenih pet različnih napadov, zasnovanih na matriki Mitre. Pri vsakem napadu so bili merjeni ključni kazalniki, kot sta čas zaznave in odzivnost sistema. Napadi so bili izvedeni tako na več napravah hkratno kot tudi na posameznih napravah ločeno, da se pridobi širši spekter rezultatov. Analiza rezultatov je pokazala, da obe orodji ponujata dobro raven zaščite, vendar z določenimi razlikami. Rešitev MDE se je izkazala kot hitrejša, medtem ko je rešitev Cortex XDR nudila boljše odzivanje. Na podlagi končnega rezultata smo ugotovili, da je poleg varnostnega orodja bistvenega pomena prav usposobljen kader, varnostna politika ter zavedanje zaposlenih o grožnjah. Slednji skupaj z varnostnim orodjem tvorijo celovit in učinkovit pristop k varnostni drži organizacije.
Keywords:kibernetski napad, zaznavanje kibernetskih groženj, magistrska dela
Publication status:Published
Publication version:Version of Record
Place of publishing:Ljubljana
Place of performance:Ljubljana
Publisher:T. Veršnik
Year of publishing:2025
Year of performance:2025
Number of pages:X f., 57 str.
PID:20.500.12556/DKUM-95305 New window
UDC:004.056(043.2)
COBISS.SI-ID:261995011 New window
Publication date in DKUM:18.12.2025
Views:121
Downloads:39
Metadata:XML DC-XML DC-RDF
Categories:FVV
:
Copy citation
  
Average score:(0 votes)
Your score:Voting is allowed only for logged in users.
Share:Bookmark and Share



Hover the mouse pointer over a document title to show the abstract or click on the title to get all document metadata.

Licences

License:CC BY-NC-ND 4.0, Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International
Link:http://creativecommons.org/licenses/by-nc-nd/4.0/
Description:The most restrictive Creative Commons license. This only allows people to download and share the work for no commercial gain and for no other purposes.
Licensing start date:11.09.2025

Secondary language

Language:English
Title:Tools for detecting and responding to cyber threats: a comparative analysis of cortex xdr and microsoft defender : magistrsko delo
Abstract:This master's thesis deals with researching tools for detecting and responding to cyber threats. As part of the research, we conducted a comparative analysis between two leading products, Cortex XDR by Palo Alto Networks and Microsoft Defender for Endpoint (MDE). With the rapid development of digitalization, the emergence of the Internet of Things (IoT), the use of BYOD, and increasingly sophisticated attacks, it is becoming clear that traditional security mechanisms, such as antivirus solutions, are no longer sufficient to effectively protect information systems. For these reasons, organizations are increasingly turning to advanced security solutions such as EDR and XDR. These solutions enable real-time detection, analysis, and response to incidents. The theoretical part of our thesis covers the basics of penetration testing, the concepts of red and blue teams, the use of the Mitre matrix framework, and the Caldera tool, which enables the emulation of cyber attacks. These concepts serve as a basis for understanding the methodology of the practical work, in which a test environment with eight virtual machines was set up in the VMware Aria environment. Three devices were protected with the MDE solution, three with the Cortex XDR solution, and two were used as an attack tool and support server for the Caldera application. In the practical work, five different attacks based on the Mitre matrix were carried out. Key indicators such as detection time and system responsiveness were measured for each attack. The attacks were carried out on multiple devices simultaneously as well as on individual devices separately to obtain a broader range of results. Analysis of the results showed that both tools offer a good level of protection, but with certain differences. The MDE solution proved to be faster, while the Cortex XDR solution offered better responsiveness. Based on the final result, we concluded that, in addition to security tools, trained staff, security policies, and employee awareness of threats are essential. Together with security tools, these form a comprehensive and effective approach to an organization's security posture.
Keywords:cyber security, cyber threat detection, cyber attack, MDR, EDR, Cortex XDR, Microsoft MDE, Caldera


Comments

Leave comment

You must log in to leave a comment.

Comments (0)
0 - 0 / 0
 
There are no comments!

Back
Logos of partners University of Maribor University of Ljubljana University of Primorska University of Nova Gorica