Unified asset visibility has improved investigations and now simplifies tracking security assets
What is our primary use case?
Our main use case for JupiterOne is as an asset catalog tool where we document all our assets that are integrated from different platforms such as Device42, Qualys, Microsoft M365, and Defender. We are aggregating all our assets from different tools into JupiterOne.
A specific example of how we use JupiterOne day-to-day is being able to draw a network flow of how network traffic travels through the network, starting from the edge devices to the internal devices. We are also using JupiterOne to track assets that are being brought in and assets that are leaving the environment. Additionally, we are using JupiterOne as the source of truth for many other things that we are doing. Some of my other teammates in areas such as data are tapping into it for asset categorization.
How has it helped my organization?
JupiterOne has had a significant impact on our organization. Previously, when looking at security alerts, we would need to examine different tools separately. Now, we often take the IP address or the FQDN and input it into JupiterOne, which usually tells us what that asset is. We are ingesting data from places such as AWS, Azure, Device42, Qualys, Defender, and Trend Micro. These are different tools that, on a good day without JupiterOne, we would have to look at separately to determine where a particular asset is. JupiterOne helps us aggregate all those things on one single platform, allowing us to quickly identify what environment that asset lives in and what type of asset it is.
One feature we also value is the ability to enter custom tags so we can create asset types or asset locations and detail who owns the asset. These features have positively impacted us at Landmark Information Group.
What is most valuable?
I think one of the best features JupiterOne offers is blast radius, being able to see assets that could be directly or indirectly affected by any cyber incident or to see how some assets communicate with other assets and some do not communicate with other assets. I also think it is easy to query assets and find assets using queries and build out graphs that often make it easy for us to drill down on certain types of assets or categories of assets.
The blast radius feature has helped our team because, in security operations, one of the first places we look when investigating an alert is JupiterOne. We might enter the IP address or the FQDN of the server to find out where it is, who owns it, and what it does. At that point in time, we identify other assets that might be in the same environment or the same place where that asset lives, which helps us when we are doing security operations and investigating alerts.
What needs improvement?
There are some features that I have shared with our customer service manager. One of them that is relevant to us at this time is the need for better determination of unified devices. Currently, JupiterOne uses hostname weights, MAC addresses, or IP addresses to tie devices together, but we have actually requested a way for us to make those determinations ourselves. For example, when externally scanning a device using Qualys, internally it gives an IP address or FQDN, while externally it might be different. We want to be able to decide ourselves that these two devices are the same device even when they have different names and IP addresses for external and internal use. The unified devices feature is valuable and did not used to exist, and it has been fantastic. However, I believe more can be done regarding unified devices, and giving users the privilege to tie them together would be a good addition to the platform.
One of the other things that interest us in JupiterOne and why we really wanted to use the tool is the compliance feature. We wanted to use it to track our compliance since we are ISO 27001 certified. However, the compliance module has not worked well, and we have had to continue tracking our compliance manually with the tools we use. Although there are some works in progress to improve the compliance part of the tool, I think if they can get it up to speed, that would be a really good improvement.
For how long have I used the solution?
I have been using JupiterOne for three years. I was initially recruited with Landmark Group to be a subject matter expert for JupiterOne.
What other advice do I have?
JupiterOne has many features. Although none comes to mind almost immediately, I know it often depends on how we are able to write or craft the queries. JupiterOne has been very instrumental to me in my work. Being the subject matter expert for JupiterOne at Landmark, I think it has been very beneficial for me.
JupiterOne has been quite helpful to us, especially in information security. One of the things it helps us with is housekeeping, allowing us to see where there are duplicates and address those.
I would rate JupiterOne an eight. JupiterOne is a strong tool, and there are some issues that need to be addressed, but overall, I think it is a good tool. The reason I am giving it an eight is that there are features that are not its strengths, which is understandable, but it performs very well in the aggregation of assets from different platforms.
I would definitely recommend JupiterOne because some of the features I have mentioned here are part of what makes it strong. The aggregation of tools from different platforms into one single repository allows you to easily query assets by typing their IP address, hostname, or FQDN. I believe that is JupiterOne's greatest strength. Additionally, you can create dashboards or widgets for a high-level overview, and JupiterOne can track trends over time, telling you if something is increasing, decreasing, or remaining stable. Those are part of the great features that JupiterOne has, and I would recommend it to anyone needing a single cyber asset tool.
Good application
What do you like best about the product?
Cloud native cyber asset, security configuration
What do you dislike about the product?
Nothing to dis like about this. Good application
What problems is the product solving and how is that benefiting you?
problems related to cybersecurity asset visibility and management, providing a platform to aggregate and analyze data from various sources to gain a comprehensive view of an organization's digital assets and attack surface
An user friendly solution for writing queries with intuitive flow
What is our primary use case?
We use the solution for writing all the queries. There is a lot of variation for machine learning projects like data processing, data analysis, and pipeline creation. It has the flexibility to work on different kinds of things like ML projects and clustering algorithms like regression analysis.
What is most valuable?
The product’s UI is pretty decent and fast. You can increase GPUs and other features like importing files and everything, which is tricky in Google Collab but better in Jupiter.
What needs improvement?
There should be more integration or an update to the visualization part of the charts or other graphs we plot. Currently, it integrates from your local directive with your local PC. If it is integrated into other platforms, that would be great. You can only write Python queries in Jupiter, not other languages, like, SQL or PySpark. Databricks is a software that provides writing queries in different languages. Jupiter should allow us to write in different languages.
For how long have I used the solution?
I have been using JupiterOne for more than three years. We are using the latest version of the solution.
What do I think about the stability of the solution?
The product is stable. I rate the solution’s stability an eight out of ten.
What do I think about the scalability of the solution?
We have 50+ users using this solution. I rate the solution’s scalability a seven out of ten.
How are customer service and support?
There is not much support needed for the software.
Which solution did I use previously and why did I switch?
I’ve used PyCharm before, but I switched to Jupiter because of its interface, query writing, and sequence capabilities. I find it better to write short-form notebooks, as these are easier to see and understand. The flow is also more intuitive, and the output certificate is displayed on the same line.
How was the initial setup?
The initial setup is decent and takes a minute to deploy. It would have taken maybe 15 to 30 minutes for the first time, but it’s not a difficult job to do. One person is enough for setup and maintenance. I rate the initial setup an eight, where one is difficult, and ten is easy.
What other advice do I have?
Overall, I rate the solution an eight out of ten.
Fantastic automated solution for compliance, Cyber security posture, and more.
What do you like best about the product?
I love how easy it is to set up integrations across different applications. Every aspect of JupiterOne encourages smooth automation and visual presentation through its insights tab. As an auditor, I highly appreciate JupiterOne's ability to update and reuse evidence automatically across different security frameworks - cutting down the tedious work of evidence submission/review by around 80%.
What do you dislike about the product?
I wished there was more documentation on how to pull more information from the raw data. More short instructional videos on how to use J1QL. The inability to edit controls on the compliance page, and finally, dark mode 😄
What problems is the product solving and how is that benefiting you?
Cutting down costs and time involving compliance and security posture.
J1 makes it ridiculously easy to find assets for complex queries and know how they connect to others
What do you like best about the product?
The query syntax for finding assets matching filters
What do you dislike about the product?
There's a significant barrier to entry in learning all the different features because it's got so much.
What problems is the product solving and how is that benefiting you?
Finding assets in a large production environment and identifying security risks. J1 also makes completing audits a breeze.
The Industry's Best Compliance Product Backed by Best-of-Class Support!
What do you like best about the product?
Every aspect of using JupiterOne and self-serve product onboarding is simple, painless, and intuitive. Compliance is complicated and this is a VERY sophisticated product, but they have removed the headache from the process.
Virtually anyone can integrate their environment within minutes and begin adding evidence to begin assessing SOC, PCI, and HIPAA controls. This can save organizations hundreds of thousands of dollars and months on SOC, ISO, and PCI certifications.
Their sales and support team are very kind, responsive, and helpful, too!
What do you dislike about the product?
I like everything about JupiterOne - no issues!
What problems is the product solving and how is that benefiting you?
We needed to quickly perform a comprehensive risk assessment and create a cost-effective approach to compliance.
Recommendations to others considering the product:
Proceed with confidence.
Perfect for DevOps
What do you like best about the product?
Ability to inventory assets and configurations with GraphQL API.
What do you dislike about the product?
Performance can be improved because of rate limiting.
What problems is the product solving and how is that benefiting you?
Configuration management of all cloud resources to improve correlation.
Recommendations to others considering the product:
Instead of multiple accounts to monitor configurations, you just need one.
One of the best software to manage cloud-based infrastructure.
What do you like best about the product?
The best thing that I like about JupiterOne is it provides continuous instrumentation and monitoring of cloud environments and controls.
It provides automated reporting and evidence collection for compliance.
We can easily visualize relationships in our digital environment to understand what exactly is going on.
We can ask simple questions for which we will receive strong and satisfying answers.
What do you dislike about the product?
As of now I have not came across any issue or drawbacks because of which I'll dislike JupiterOne. I would like to add/edit my review in future if I come across anything that would incline me towards disliking this software.
What problems is the product solving and how is that benefiting you?
One of the best benefit of this software is we can enables our team to continuously protect our customers, and our business with the help of this software. With the help of automation it eliminates countless hours it takes to build out and maintain our digital environment.
Recommendations to others considering the product:
One of the great software. Must try and explore the features provided by it.