In today's fast-paced digital landscape, staying one step ahead of potential security threats is paramount. Real-time security notifications serve as the frontlines of defense, enabling swift actions that can prevent potential breaches and minimize damage.
The integration with popular collaboration platforms like Microsoft Teams and Slack marks a pivotal advancement in security workflows.
We are introducing new capability to post events from Flowmon ADS into Teams channel or Slack to instantly notify security teams. Integrations scripts are based on simple webhooks and available out of the box on our support portal both for Teams and Slack.
Notification via Teams
Let’s look at posting events into Teams. Whenever there is a high severity event detected it get instantly posted into specific channel. The result in Teams may look like this. (Picture 1: Event posted in Teams channel)
Most important information is highlighted. There is an active link from event ID which leads to event details in Flowmon ADS. This event represents a situation when a new, previously unknown device, is connected to the network.
Security team can now communicate about the event via Teams as they are used to. When there is a need for drill down to more details in Flowmon ADS it is one click away. (Picture 2: Event details in Flowmon ADS. Drill down from event summary in Teams.
How to set it up?
Configuration is easy. First you need to configure an Incoming webhook in Teams and get unique URL. Next you need Flowmon hostname or its IP address. It is required parameter to be able to construct URL pointing back to event details. Install the Teams integration custom script obtained from our support portal and create a custom action using the script.
Summary
In conclusion, the fusion of Flowmon ADS with Microsoft Teams and Slack heralds a new era of efficient and effective security management. The seamless transition from high-level notifications to detailed event insights within Flowmon ADS ensures that no crucial information is overlooked.
Pavel Minarik
With over 20 years of experience in enterprise IT and security, Pavel’s career at Progress started in 2021 after the acquisition of Kemp Technologies and Flowmon Networks. As Acting CISO at Progress, Pavel is responsible for overseeing enterprise-wide information security strategy, risk management and regulatory compliance. His role is focused on aligning security initiatives with business objectives, strengthening security posture, building resilient security programs and leading cross-functional teams in complex, fast-paced environments.
As Vice President of Product Security at Progress, he is responsible for the secure software development life cycle across all Progress products, defining and implementing product security standards and ensuring that security is inherent to the product development practice. During M&A initiatives, Pavel leads product security reviews and assessments as part of technical due diligence.
In his previous role as Vice President of Technology, he was responsible for the overarching technology strategy of Progress’ Flowmon, Loadmaster and WhatsUp Gold Infrastructure Management products—as well as experimental development in this area. With his experience as the former CTO of Flowmon Networks, Pavel led product management for Progress’ flagship Flowmon NPMD & NDR solution.
As a former senior researcher at the Institute of Computer Science of Masaryk University, Pavel has participated in several R&D projects across network traffic monitoring, analysis and cybersecurity domains. He is also the author of more than ten publications on behavior analysis and algorithms for traffic processing and anomaly detection, summarized in his Ph.D. thesis, “Building a System for Network Security Monitoring.”
Areas of Expertise:
- Cybersecurity
- Network Detection & Response
- Network Performance Monitoring & Diagnostics
- Software Development
Credentials & Publications
- 10+ years membership in AFCEA Czech Chapter
- MINAŘÍK, Pavel. Building a System for Network Security Monitoring. Ph.D. thesis. Brno, 2012.
- VYKOPAL, Jan; Tomáš PLESNÍK and Pavel MINAŘÍK. Network-based Dictionary Attack Detection. In Proceedings of International Conference on Future Networks (ICFN 2009). Los Alamitos, CA, USA: IEEE Computer Society, 2009, pp. 23-27. ISBN 978-0-7695-3567-8.
- MINAŘÍK, Pavel; Vojtěch KRMÍČEK and Jan VYKOPAL. Improving Host Profiling With Bidirectional Flows. In 2009 International Conference on Computational Science and Engineering. Vancouver, Canada: IEEE Computer Society, 2009, p. 231-237. ISBN 978-0-7695-3823-5.
- DYMÁČEK, Tomáš and Pavel MINAŘÍK. NetFlow Data Visualization Based on Graphs. In Visualization for Computer Security, 5th International Workshop, VizSEC 2008 Proceedings. Berlin, Heidelberg, Germany: Springer-Verlag, 2008, pp. 144-151. ISBN 978-3-540-85931-4.