Talk to Your Tenant: Querying Netskope with Claude
Education, Training, Certification, and Thought Leadership
Recently active
Deploying Enterprise Browser to your Mac DevicesIntroductionEnterprise Browser allows organizations to provide secure access to sensitive applications & content for unmanaged devices or devices not running the Netskope client. Here at Netskope the Global Information Security and Information Technology teams partnered closely to successfully launch this technology internally. Below you will find instructions on how the IT team deployed this solution to our fleet of Mac devices.Netskope Enterprise Browser application is deployed through Iru/Kandji MDM using a DMG containing a .app file. The deployment process was automated with a pre-install script to audit the app’s presence, download it if needed, and ensure proper installation. Additionally, a bash script handled profile enrollment, enabling a completely zero-touch activation process. This approach significantly streamlined deployment, ensuring minimal user intervention and high success rates. Iru/KandjiIru/Kandji is a purpose-bui
Deploying Netskope Enterprise Browser to your Windows FleetIntroductionEnterprise Browser allows organizations to provide secure access to sensitive applications & content for unmanaged devices or devices not running the Netskope client. Here at Netskope the Global Information Security and Information Technology teams partnered closely to successfully launch this technology internally. Below you will find instructions on how the IT team deployed this solution to our fleet of Windows machines. This method is for deploying with Microsoft Intune. This guide details how to deploy the Netskope Enterprise Browser with auto profile enrollment. Netskope Enterprise Browser profiles are leveraging users' corporate email address and for Entra Joined Windows machines, this allows admins to leverage the UPN to have the browser auto enroll upon deployment. The method described in this guide consists of 2 steps, deploying the installer and config file to the local machine via Win32 Deployment,
In case you missed the latest webinar in our Inside Netskope series—where Netskope experts show you how we protect our users, applications, and data using our own cloud-based architecture—a recording and recap of our recent session on Operationalizing UEBA UCI Alerts can be found below. Feel free to comment and continue the discussion! 📽 Watch on-demand 🍿 Q: How can UEBA be used to detect when someone may be looking to leave the company. Can they automatically be added to a “watch list"?A: This is one of those cool ones. I've always thought UEBA has the potential to predict when someone's leaving the company before they've fully made up their mind.The two custom alerts that Uday talked about are some of the key features. For example, if those types of things start happening where a user is uploading to personal spaces instead of going to the corporate environment, which is not normal for them, this would definitely be a trigger. The automations that Uday talked about when the UCI sco
Hear from our Product Management and Product Adoption leads as they cover the latest platform updates from Release 121, 122, and 123. Key product updates: Automated root cause analysis for DEM User Experience Score Direct Internet Access Application Performance Monitoring via Enterprise Station Support remote access over RDP and SSH without using Netskope client One time password-based disable option for Netskope Client SWG services Integration of Netskope Private Access Client and Publisher with NewEdge Traffic Management API to learn and connect to the closest (by RTT) PoP GA of CloudTAP, capture traffic between a managed endpoint with Netskope Client or branch offices using IPsec or GRE tunnels and the Netskope platform Explore past webinars in this series!
User and Entity Behavior Analytics, UEBA, is a platform used to spot anomalous actions through users behavior. This platform leverages algorithms and machine learning to continuously learn and evolve based on each behavior Our analytics program includes a wide variety of detections to help provide our analysts with the best visibility. Allowing our analyst to get more insight rather than focusing on alerts made in Security Information and Event Management (SIEMs) or Endpoint Detection and Response (EDRs), having the use of UEBA can fill in the void where visibility is lacking. As the security team continues to integrate UEBA within the SOC, it's crucial to understand its functionality and how it operates. All of the information can be reached through Netskope’s user-interface (UI), but for more in-depth information you can check out the online reference information for it here. The benefits of Netskope using UEBA include detecting anomalous insider behavior, identifying unknown data m
This short demo will walk you through how to configure the ChatGPT Enterprise Compliance API within Netskope. Netskope's integration with OpenAI’s ChatGPT Enterprise Compliance API enables organizations to adhere to compliance standards, receive advanced detection and safeguarding of sensitive data, and protect against threats. Learn more about how Netskope integrates with ChatGPT Enterprise and other generative AI platforms at https://www.netskope.com/solutions/netskope-for-chatgpt-and-generative-ai.
Netskope integrates with ChatGPT Enterprise to deliver API-enabled controls that bolster security and compliance for organizations. With our integration, organizations gain enhanced features including application visibility, robust policy enforcement, advanced data security, and comprehensive security posture management—all achieved by directly connecting to ChatGPT Enterprise.Key outcomes of our integration include:Adherence to compliance standards: From healthcare to retail, many industries require certain compliance regulations to be followed. These regulations can dictate how you handle personally identifiable information (PII), protected health information (PHI), payment card information and other regulated data. With over 50 compliance templates and 3,000+ data identifiers, help enforce data loss prevention (DLP) and compliance policies around sensitive data to support meeting compliance regulations like GDPR, HIPAA, GLBA, etc. Advanced detection and safeguarding of sensitive dat
In case you missed the latest webinar in our Inside Netskope series—where Netskope experts show you how we protect our users, applications, and data using our own cloud-based architecture—a recording and recap of our recent session on off-boarding user monitoring protections in practice can be found below. Feel free to comment and continue the discussion! 📽 Watch on-demand 🍿 Q: Can you go back to before the user was identified as off-boarding?A: Depending on how long you have data retention set up for your tenant, this would determine how long you can look back for some of the user's activities. When you do the look backs, the dashboards we put together will pull all that data within Netskope and give you a view of what was actually happening. Q: Off-boarding users can be sneaky, especially those coming from a technical background. Can you suggest how Netskope can detect data exfil using common protocols, such as DNS or encrypted communication channels?A: Yes, there's definitely way
Get a glimpse into some of the off-boarding protections that our internal security team has developed to aid them in monitoring users who transition from Netskope. In the webinar we’ll touch on: Who gets monitored and why How we use policies to collect data and maintain security posture How we use automation to start collecting data almost instantly View past events in this series!
Netskope products serve the purpose of security AND as tools to troubleshoot with. Tools that are often overlooked by everyone, including us!In this article, we are going to cover one of our newest products acquired through the purchase and partnership of Infiot’s Borderless WAN (BWAN). BWAN is the technology commonly known as Software Defined Wide Area Networking (SD-WAN). We will answer the questions of:How does the Netskope Endpoint SD-WAN Client become a tool to be used? How am I able to use the Netskope Endpoint SD-WAN Client for displaying bypasses in the Netskope Endpoint SD-WAN console?As a little background information, “Netskope BWAN extends the concept of network segmentation beyond traditional network perimeters, catering to the needs of a modern workforce that operates from varying locations and uses a multitude of devices. Netskope BWAN ensures network segmentation for any device by encapsulating each session in a secure and encrypted tunnel. This segmentation extends
Stating the Obvious: The Rise of QR Code-Based AttacksQR code-based attacks are on the rise, and it's no surprise why. Almost everyone carries a smartphone, making QR codes effortless to scan. QR codes are everywhere—on restaurant menus, event tickets, and even advertisements—creating a massive attack surface for bad actors to exploit.You may have come across the term “Quishing”—a blend of QR code and phishing. Essentially, it’s phishing using a QR code to lure victims. However, this is just the tip of the iceberg. Threat actors can use QR codes to deliver malicious payloads, exploit browser vulnerabilities, or carry out other harmful activities.What’s the Right Security Approach?For QR-based phishing, the guidance might seem straightforward: treat it like any other phishing attempt. Don’t enter sensitive information unless you’re confident in the source, and stay vigilant for suspicious signs. However, the sheer size of the attack surface and users’ reduced caution—especially when out
Stating the Obvious: The Rise of QR Code-Based Attacks QR code-based attacks are on the rise, and it's no surprise why. Almost everyone carries a smartphone, making QR codes effortless to scan. QR codes are everywhere—on restaurant menus, event tickets, and even advertisements—creating a massive attack surface for bad actors to exploit.You may have come across the term “Quishing”—a blend of QR code and phishing. Essentially, it’s phishing using a QR code to lure victims. However, this is just the tip of the iceberg. Threat actors can use QR codes to deliver malicious payloads, exploit browser vulnerabilities, or carry out other harmful activities. What’s the Right Security Approach? For QR-based phishing, the guidance might seem straightforward: treat it like any other phishing attempt. Don’t enter sensitive information unless you’re confident in the source, and stay vigilant for suspicious signs. However, the sheer size of the attack surface and users’ reduced caution—especially when
If DLP is not utilized in the right manner, the Admin is in for a nightmare with the number of alerts they would receive every single day. Netskope’s DLP has an extensive suite of offerings, with respect to detection of content and object types, to help eliminate this risk. Hear from our security team as they discuss how to use Netskope DLP to effectively allowlist and minimize false positives. Learn how to: Create effective DLP policies per your organization's situation Build processes to identify DLP exceptions within your organization Utilize different techniques to Allowlist the DLP exceptions Use Netskope’s Cloud Exchange for Allowlisting Check out our blog for more information!
Introduction In my previous post I introduced the Netskope Provider for Terraform and showed you how it can be used to deploy publishers and applications inside of a Netskope tenant. While I think this capability on it's own is extremely exciting, I know we can do better. When looking at creating automation for Netskope, our goal was always to ensure a new publisher including the underlying infrastructure could be managed in the same configuration. In fact this concept is one of the primary reasons that we choose to use Terraform as our initial entry into Infrastructure as Code(IaC). In this post I will expand upon what we introduced previously by walking you through how to use the Terraform Module for automating Netskope Publishers running in Amazon EC2. This should be fun! What is a module? For those that are new to Terraform let me start by explaining what a module is. The definition of a module is something along the lines of 1 or more .tf configuration files i
In case you missed the latest webinar in our Inside Netskope series—where Netskope experts show you how we protect our users, applications, and data using our own cloud-based architecture—a recording and recap of our recent session on protecting lost/stolen managed devices with Netskope Client can be found below. Feel free to comment and continue the discussion! 📽 Watch on-demand 🍿 Q: Can a client be flagged as stolen via API?A: The client cannot be directly flagged as stolen via API, but you can use APIs to move users or devices between groups. This will have to be done within the Groups section and not with the client directly. Q: How to setup monitoring and tracking of stolen devices? Also, can we pinpoint the location of the lost/stolen device?A: If the device comes back online and connects back to the tenant, we can get all of the location data (wifi connected to, geographic location, etc.). Regarding how to setup monitoring and tracking, the presentation covers quite a few use
In this article, we will cover how to silent deploy the Netskope Client on Mac devices using IDP enrollment mode with Jumpcloud MDM. Prerequisite: SAML Forward Proxy integration with Jumpcloud as an IDP must be configured prior to deploying the Netskope Client. Configuration Steps 1 - Install Netskope CertificatesDownload both certificates from the Netskope Tenant on Settings > Manage > Certificates > Signing CA: Jumpcloud allows you to choose only one certificate per policy. Follow the steps off the link Create a Mac or iOS Install Certificate Policy and create two certificate policies on Jumpcloud. One for the Netskope Root Certificate and one for the Netskope Intermediate Certificate: Approve System Extension and Network ExtensionCreate a new Jumpcloud policy following the steps of the link Create Mac System Extension Policy to Approve the System Extension and use the following details on the policy:In the latest SO versions it is necessary to check the System extension
Hear from our Product Management and Product Adoption leads as they cover the latest platform updates from Release 118, 119, and 120. Key product updates:Site, User—App Synthetic Monitoring for Web Apps and Custom Web Applications E2E Encrypted App Inspection and AI generated insights for CCI attributes (CCI copilot) Enhanced risk profiling for 3rd party applications—Workday, Entra ID, and Google Workspace Expanded App Coverage for Box, Slack, ServiceNow, and Cisco Webex on a new NG CASB API platform Comprehensive categorization and classification insights for URLs, domains, and IPs using the URL lookup API for SWG Malware workflow for submitting false positive and allowlisting Reset UEBA UCI score to 1000 for use-cases such as role changes and test users Leverage MIP and Box Labels for DRM Integration for Classification Provide visibility into custom classifier performance, including insights into the training data Endpoint DLP Printer Content Control Support for AIP/MIP Sensitivi
This Azure Bicep template facilitates the automated deployment of Netskope Publisher instances in Azure environments. It's designed to streamline the deployment process for DevOps teams, enabling quick and consistent Publisher setups while following infrastructure-as-code best practices.This can be a key item on how to achieve ZTNA in PaaS environments: You can check out the files here: https://github.com/Mitsj0l/nskpub_azureSupported Functions ✨Azure Integration: Automated deployment of Netskope Publisher Marketplace VMs Integration ready for Azure Pipelines End-to-end deployment in 3-4 minutes Network Management: Support for existing networking components VNet, Subnet, and NSG integration Option to create new or use existing network components Security & Configuration: Secure parameter handling through dedicated parameter files API token and SSH key management Cloud-init based post-deployment setup Automated Publisher registration with Netskope tenant Project Structure
Elevate your network monitoring and user experience with the advanced capabilities of P-DEM Enterprise. Thierry Notermans, Product Management Director for Proactive Digital Experience Management (P-DEM), demonstrates the innovations introduced with P-DEM Enterprise using three key use cases. Learn how to: Monitor onramp, app performance, and user experience from sites connecting to Netskope via SD-WAN, SASE gateways or private connectivity Monitor any application, from over 80K predefined apps or any custom web-based application, including synthetic application monitoring for how apps are performing Streamline operations and deliver a cohesive, transformative monitoring experience with the integration of Real User Monitoring (RUM) and Synthetic Monitoring Get a consistent 360-degree view of digital experiences across the entire path from users to apps
Unveiling Netskope Proactive Digital Experience Management (P-DEM) Enterprise, a groundbreaking solution that delivers unmatched end-to-end insights and user experience monitoring within SASE and SD-WAN environments. Discover how P-DEM Enterprise eliminates blind spots, provides complete transparency across your entire network, and empowers you to optimize performance at every stage. Key Takeaways:Discover groundbreaking innovations like site-specific, user-specific, and app-specific monitoring that deliver a comprehensive 360-degree view of your digital experience. Learn how advanced contextual visibility and AI/ML-driven insights accelerate troubleshooting and reduce operational costs. Explore how this solution enhances workforce productivity, reduces operational friction, and delivers significant cost savings through proactive monitoring and remediation.
Overview Forward Proxy Authentication (FPA) ensures secure access to cloud applications by requiring SAML-based authentication via an intermediary server that allows organizations to enforce granular authentication policies. Netskope’s FPA allows integration of multiple Identity Providers (IdPs) based on criteria like access methods (IPsec, GRE, Cloud Explicit Proxy, NS Client Enrollment) and network location, enabling flexible and secure user authentication management. Organizations can maintain existing SAML setups while utilizing Netskope’s enhanced authentication features, supporting multiple concurrent IdPs to match specific conditions for robust security and control. Configuration in PingOne Login to the PingOne Admin Console. Navigate to Applications > Application Catalog. Search the Application Catalog for Netskope Client Enrollment and click + Add Instance. Enter temporary values into the ACS URL and Entity ID fields, like https://pingone.com and https://pingone.com
This article is going to cover how to leverage PingOne for SCIM Provisioning via PingOne. SCIM Provisioning Netskope supports provisioning of users and user groups authenticated via Ping Identity. The Netskope SCIM app supports the following: Push New Users: New users created through Ping Identity will also be created in NetskopePush Groups: Groups created through Ping Identity will also be created in NetskopePush Profile Updates: Updates made to the users profile through Ping Identity will also be pushed to NetskopePush User Deletion: Deleting a user in Ping Identity will also delete the user in Netskope.By default a user disabled in Ping Identity will be deleted in Netskope. Configuration Steps Configuration in Netskope Login into your Netskope Admin Console. Select Settings in the lower left. Select Tools > REST API v2. Ensure REST API Status is enabledSelect New Token and enter an appropriate name. Select a token expiry duration (To ensure the security and reliability of your
In case you missed the latest webinar in our Inside Netskope series—where Netskope experts show you how we protect our users, applications, and data using our own cloud-based architecture—a recording and recap of our recent session on Automation of IOC Hunting and Continuous Monitoring using Cloud Threat Exchange can be found below. Feel free to comment and continue the discussion! 📽 Watch on-demand 🍿 Q: Are new IOCs hunted against historic data? Or, only on new events after IOC is known?A: Yes, that's the beauty of this workflow is that it's not just updating tools with new IOCs but it's looking to determine whether we've seen that IOC before. Once we know that it is an indicator of compromise, it looks back to see if anything has happened and alerts an analyst immediately as soon as it finds something. Q: Can you integrate Cortex XDR with Netskope? If so, how?A: Yes, via Cloud Exchange. Check out this doc for more information. Q: Do you have SentinelOne Integration?A: Absolutely!
Hear from our security team as they discuss how Cloud Threat Exchange is implemented within Netskope to streamline the automated integration of IOCs with a ticketing system and perform continuous monitoring. Key topics covered:Cloud Threat Exchange Integration with multiple security tools and technologies such as Netskope, SIEM, EDR, etc. Automation of IOC ingestion from ticketing platforms such as Jira into Github repo The plugin to Ingest IOC's from Github to Cloud Exchange And real-time monitoring of these IOCs (continuous monitoring)
Recently I stumbled upon an interesting campaign carried out by a threat actor dubbed Dark Pink and characterized by the exploitation of a legitimate cloud service, GitHub, to host the malicious payload. GitHub is a well-known service, categorized as "Development Tools" and "Technology" within the Next Gen SWG, and for which a dedicated connector allows to enforce granular security policies in terms of adaptive access control, DLP and threat protection. However, it is common for threat actors to abuse even less-known cloud services for malicious purposes such as malware distribution, command and control and data exfiltration, and the above campaign is no exception. As a matter of fact in the above mentioned case, the attackers exploited an additional less-known cloud service, textbin[.]net, to deliver the malicious payload. Netskope customers are protected out-of-the-box from the malicious exploitation of textbin[.]net as this service is already classified as "Secur
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.