Make security simple with Secure Cloud
Recently active
OpenText EDR & MDR Integrations: API-First Power with Flexible Log IngestionOpenText EDR and MDR are designed to adapt to your needs. We are committed to developing and supporting integrations with the data sources and tools used by your business and your customers.Integrations fall into two categories:Advanced API-first product integrations Syslog-based log ingestionAPI-First IntegrationsAPI integrations provide rich functionality and tightly aligned use cases.Provide rich functionality aligned to real-world security workflows. Support bidirectional workflows and data synchronization where supported. Enable deeper automation and response actions. Included at no additional cost.Application SecuritySaltminerAuthentication LogsOkta Workforce IdentityAutomation AuditingAutomation AnywhereCloud SecurityAmazon EventBridge AWS CloudTrail Microsoft (Defender, Intune, Identity Management, Microsoft 365)DNS and URL MonitoringCisco UmbrellaEndpoint SecurityCisco Secure Endpoint (AMP) CrowdSt
Captains Log: Sending Email Threat alerts to EDR via SyslogA Practical Guide for MSP Partners Email remains one of the most important telemetry sources in the modern MSP security stack. OpenText Core Email Threat Protection can identify spam, phishing, malware, quarantine events, and link-based activity long before a compromise reaches the endpoint.However, getting those alerts into OpenText Core EDR in a reliable and operationally safe way is not always straightforward.Unlike platforms that offer a native event streaming integration, OpenText Core Email Threat Protection exposes SIEM data through an API. That means MSP engineers must account for:poll timing and overlap API response handling duplicate suppression event normalisation Syslog / CEF forwarding In this guide, we’ll walk through how to deploy a lightweight Linux collector that polls the Email Threat Protection SIEM API, captures all relevant alerts, normalises them, and forwards them to OpenText Core EDR via Syslog.The confi
Captains Log: Sending Proxmox Logs to EDR via SyslogA Practical Guide for MSP Partners Modern MSP environments rely heavily on virtualisation platforms. While VMware and Hyper-V have traditionally dominated this space, Proxmox VE has rapidly gained popularity thanks to its flexibility, open architecture, and strong community support.However, one area that’s often overlooked is security monitoring of the hypervisor itself.If you're running OpenText Core EDR, integrating your Proxmox hosts into your logging pipeline can provide valuable visibility into the infrastructure layer. This allows your SOC to detect suspicious activity, operational failures, and potential attacks much earlier in the incident lifecycle.In this guide, we’ll walk through how to configure Proxmox to forward meaningful security events to OpenText Core EDR using Syslog, while keeping noise low and signal high.The configuration described here is designed to be:SOC-friendly Easy to deploy across multiple hosts Low-noise
It’s an exciting time to be a managed service provider (MSP). More than ever, small and medium businesses (SMBs) are looking to MSPs as trusted advisors to help safeguard them from today’s growing cyber threats. One of the services in high demand right now? Managed detection and response (MDR). When asked about their biggest growth drivers, MSPs cite addressing clients’ cybersecurity concerns and awareness as the top new-business drivers (54%).1For MSPs, adding MDR to your lineup can create new revenue streams while enhancing the value you bring to your clients. By offering OpenText MDR to your MSP clients, you gain access to skilled security experts and advanced technology infrastructure—without the complexity and cost of building it all in-house.Here’s why more MSPs are partnering with OpenText to power their MDR security services: 1. Seamless integration with your existing toolsOne of the greatest advantages of choosing OpenText MDR is its compatibility with your existing tools. Ope
Watch step-by-step videos covering Endpoint Protection, DNS Protection, Security Awareness Training, and Detection and Response features. Learn how to start a trial in the Management console and install the Detection and Response agent on Mac. These quick how-to guides make setup and training easier for everyone.Click HERE for the Video Library
One of our core commitments when we began developing Webroot® Security Awareness Training was to remain relevant. We pledged to continuously develop content that reflected the latest threats faced by businesses and users as they arose. One of the most significant challenges we’ve seen since the launch of our user training tool has been the shift to remote workforces forced by the novel coronavirus outbreak. It’s dealt a serious blow to the cyber resilience of many organizations and is something, we felt, needed to be addressed. We’re happy to announce that a course designed to do just that is now available. It’s a guide for organizations and their users to maintain their cyber resilience with dispersed workforces, and we hope you’ll enroll. Why bother developing a Cyber Resilience while Working from Home Course? Cybercriminals know many remote workforces are no longer always under the watchful eyes of IT teams. They know some are even working from their own devices, often outsid
We're looking for a few volunteers to chat about EDR & MDR, and how correlating signals and using automation could help reduce the cognitive load.Either reply to this thread or drop me a DM and I’ll arrange for us to jump on a call.
Running and growing an MSP means solving challenges that go well beyond cybersecurity technology. Marketing, lead generation, compliance, Microsoft 365, business development, and operational growth all play a role.That's where the Accelerate Advantage Network comes in.The Advantage Network connects OpenText Cybersecurity partners with a curated group of organizations offering specialized services, resources, and exclusive benefits designed to help MSPs build, market, and scale their businesses. More than technologyThe Advantage Network is organized around three areas:Strategic Technology PartnersExtend your capabilities with complementary technology and services, including compliance, Microsoft 365 security, and AI solutions.Marketing Growth PartnersTap into specialized MSP marketing resources covering strategy, content, lead generation, campaigns, websites, SEO, and more.Business Acceleration PartnersFind resources focused on sales, customer acquisition, business development, operatio
I have a Mac in a remote office. It’s an old Mac, with macOS 10.15.6, so the agent version is 9.5.0.159I tried to send an uninstall command. The command log shows status delivered at 10:56. However, the agent is still not uninstalled. At 17:20, I still received a warning about this mac. You can see from the attached images. I cut some information which contains the names, but yes, it’s the only mac we have in that location.How to remove remotely the agent from that mac, please? The mac owner is novice, cannot ask him to manually delete this and that on his mac.Thank you
Growing an MSP requires more than adding another product to the portfolio. Partners need the knowledge to position solutions effectively, resources to create demand, support for customer deployments, and a program that provides greater opportunities as their businesses grow.The OpenText Cybersecurity Accelerate Partner Program brings these elements together. Through the Accelerate Partner Portal, participating partners can access sales and marketing resources, training, Secure Cloud guidance, Microsoft expertise, technical support, program benefits, and business-development opportunities.Whether you are new to the program or already an established OpenText Cybersecurity partner, here is what Accelerate can help your organization accomplish. The Accelerate Partner Portal connects participating partners with sales, marketing, training, technical, and business-growth resources. A partner program built around growthAccelerate is designed around three connected goals:Empower partners with k
With the Microsoft release of (KB5095093) Point-In-Time Restore has become available for General use.I was wondering has anyone tried a Point-In-Time Restore with Webroot Secure Anywhere running and if so did the Restore work?In the past I have had to disable Webroot Secure Anywhere when using Windows System Restore.
I am running Windows 11 Pro 25H2 Build 26200.8655 and have seen several times in Windows Security under Device Security the message is “Your device does not meet the requirements for enhanced hardware security”.I checked all the Bios Settings and confirmed everything was set up correctly, Secure Boot, TPM etc.I also reset the Windows Security App including used PowerShell as an Administrator to refresh Windows Security App.I have uninstalled WSA and have been using / monitoring the system for several hours and Windows Security reports everything is fine. I was wondering if anyone else has noticed similar behaviour with Webroot and Windows 11 please?
There is a lot of focus in cybersecurity on XDR, identity, AI and threat hunting.And fair enough. Those capabilities matter...But in many mid-market conversations, I still see email security as one of the most practical areas to invest in.Not because it is new or exciting.But because email is still where a lot of risk starts.Phishing, credential theft, business email compromise, malicious attachments, and impersonation attempts are not rare events. Most organizations still deal with them regularly.That is also why the value of email security is easy to explain.Fewer bad emails reaching users. Fewer risky clicks. Less time spent investigating suspicious messages. Less disruption to normal business.For mid-market organizations, that matters a lot.Most teams are already busy. They do not always have the people, time, or budget to manage every security layer in a complex way. So the best investments are often the ones that reduce real risk without adding too much operational burden.That is
Endpoint Detection and Response (EDR) is often positioned as a critical cybersecurity capability, and technically that is true. It provides the visibility, detection logic, and response options that are essential in a modern threat landscape.Yet in many organizations, the value EDR is expected to deliver, often falls short.The reason is usually not the technology itself. The issue is that EDR is too often treated as a product decision, while in reality it is also an operating model decision.EDR only creates value when detections are consistently monitored, assessed, investigated, and acted upon. That requires time, analytical capacity, and operational continuity. For many organizations, those conditions are limited. Security is often carried by lean IT teams already balancing infrastructure, end-user support, projects, compliance, and business continuity. In that context, continuous follow-up is rarely guaranteed.That is where the gap between capability and outcome begins to show.An al
For many years, DNS was mainly seen as a basic networking service: a way to translate domain names into IP addresses. But the latest NIST SP 800-81r3 Secure DNS Deployment Guide makes it clear that DNS should now be treated as a critical part of the security architecture.Why? Because almost every internet connection starts with DNS.Before a user visits a website, before an application connects to a cloud service, and before malware reaches out to command-and-control infrastructure, a DNS request usually happens first. That makes DNS one of the earliest and most effective places to detect, block, and investigate suspicious activity.Protective DNS as a Security ControlNIST highlights the importance of Protective DNS as part of a modern defence-in-depth and zero trust strategy. Protective DNS can help reduce exposure to phishing, malware, ransomware, and command-and-control traffic by applying security policy at the point of domain resolution.In simple terms, if a user or device tries to
Hello, I took over SAT at my company from another tech who no longer works for us. He had campaigns set up so that when you add a new user to a site, it would automatically send them the campaign. He also had campaigns set to “indefinite” duration and never got around to ending any of them. This seemed fine until recently when I added a user to a site and it triggered the automatic sending of not just the most recent campaign, but also the past ones. Going forward I will change the settings so this doesn’t happen again. However, I was wondering if there was a way to end multiple campaigns at once or do I have to go through them all one-by-one? Any help would be appreciated.Thank you
I downloaded Webroot Anti-Virus Secure Anywhere for another year, making it 10+ years now and all of sudden my password protection was turned on and filled in so know I can’t change any settings for an example… “Advanced Settings or “My Account” ...etc. How can I change the password in the “Advanced setting?” Does anyone have any ideas? I’d be greatly in your debt.
We're looking to [optimize our existing/implement new] OpenText Cybersecurity setup and need expert guidance on security best practices. Seeking a consultant with 1-2 weeks availability to help us:Develop comprehensive threat detection and incident response strategies Set up advanced endpoint protection, email security, and backup management frameworks Integrate OpenText solutions with existing security tools and MSP platforms Optimize security operations, threat intelligence, and compliance management Train our teams on platform best practices and ongoing security optimizationExperience with similar OpenText Cybersecurity implementations and proven security expertise preferred.
When I boot my computer in the morning I get all kinds of virus warnings, note my McAfee has expired (I never had it) and click here to subscribe and clean my computer. I run Webroot and it doesn’t find a thing. Do I just ignore the McAfee warnings? Is it just trying to scare me? (it has) I thought I was protected. Do I ignore it or subscribe. Isn’t that what Webroot is supposed to protect me against. Thanks Darryl
To continue strengthening the security of our communications and align with current industry standards, Webroot will remove support for TLS 1.0 and TLS 1.1 in a future platform update.This announcement is being shared well in advance to give customers several months to review their environments and ensure TLS 1.2 or higher is enabled. Additional details and timing for this change will be communicated in a future update.Once this change is implemented, only TLS 1.2 or higher will be accepted for Webroot product communications including the Console, endpoints, and backend services.This update ensures encrypted communication between Webroot components remains secure, compliant, and compatible with modern operating systems and platforms. Why This Change Is ImportantTransport Layer Security (TLS) is the protocol that secures the exchange of data between your systems and Webroot services.TLS 1.0 and 1.1 are now deprecated and no longer considered secure by major technology vendors and compl
We have begun rolling out Real-Time Agent Communication (RTAC) - Agent Commands for Webroot Business Agents. This enhancement replaces the existing 15-minute polling mechanism with a persistent real-time communication model, significantly improving command delivery speed and responsiveness. What Is ChangingToday, Agent Commands are delivered using a polling mechanism that checks in every 15 minutes.With Real-Time Agent Communication enabled:Agent Commands are delivered almost instantly Command execution latency is significantly reduced No workflow changes are required in the Console No configuration changes are required from MSPs or administratorsThe feature will be automatically enabled as agents upgrade. Agent Rollout PlanThe rollout will occur in phased waves to ensure platform stability and performance validation.Windows agents have already begun deploying and will continue rolling out in phases macOS agents will follow in the coming weeksAs endpoints upgrade to the latest supporte
Hello, I am trying to add images to phishing campaigns for SAT. I want to do this so I can relate the material either to the client itself or to current security events. I have tried using the editor in both the Site List and the Management Console. I have browsed through the posts on here and have read the OpenText Admin Guide. I have tried hosting the image on imgur and Google Drive, as well as a simple Ctrl+C, Ctrl+V combo. Nothing has worked. Using the image addition window (see below) doesn’t work: If I insert a URL in the Image Info tab and press “OK,” the window closes and nothing happens (no image inserted). I I use the link tab, insert a URL and press “OK,” I get the following error: The only thing that DOES work is copying one of your images already available in your pre-built options and pasting it into a new campaign. This however limits me to only images currently available in pre-built OpenText campaigns, which in my opinion are fairly limited and doesn’t allow me to
Hi everyone 👋I’m Chris Saunders, Lead Product Manager at OpenText, where I’m responsible for the strategic development of our Cybersecurity Management Console supporting Endpoint Security, Endpoint Detection & Response, DNS Security and Security Awareness Training.I’ve spent over 20 years in cybersecurity, starting in engineering and enterprise support before moving into product. It means I’m passionate about building solutions that genuinely work in real-world environments and deliver an excellent customer experience.My role involves working closely with MSPs, partners, sales and engineering to translate real operational challenges into practical product improvements, using data and customer insight to prioritise what matters most.Outside of work, I’m a big fan of running and football (and by football I mean the proper kind, not American rugby 😄⚽️).I’m looking forward to connecting with more MSPs here, sharing what we’re building, and inviting you to help shape the roadmap throu
I’d love to get some input from MSPs on where you’d like to see the dashboard and reporting experience evolve in the console.We’re spending more time thinking about how dashboards should surface the right information at the right time, and how reporting can move beyond static exports into something genuinely useful for operations, customers and decision making.A few prompts to get the discussion going: What dashboard tiles do you rely on most today and why? What’s missing or painful in current reporting? What would make dashboards genuinely more actionable for you? How do you use reports with customers versus internally? If you’re happy to share thoughts in the comments or via DM, I’d really appreciate the input. This will directly influence where we invest next.
The computer and laptop keyboards are hanging, and the device needs to be restarted to log in. If we uninstall webroot, it works fine. Please advise how to solve this issue, just renew webroot for another 1 year.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.