Product Overview
Infoblox BloxOne™ Threat Defense protects users, devices, and systems no matter where they are to strengthen and optimize their security postures from the foundation up. BloxOne Threat Defense is cloud-native and protects your brand by securing your existing networks and digital transformation activities, including SD-WAN, IoT, and cloud adoption.
BloxOne Threat Defense also coordinates threat intelligence across the security stack, automates investigation and response activities, and otherwise uplifts the security ecosystem and Security Operations to improve cybersecurity while lowering the total cost of defense.
Specifications
Maximize brand protection
Protect your brand and your organization from escalating cyberthreats that can adversely affect your business. BloxOne Threat Defense uniquely combines advanced analytics based on machine learning, highly accurate and aggregated threat intelligence and automation to detect and prevent a broad range of threats, including DGA families, data exfiltration, look-alike domain use, fast flux and many others.
Detect anywhere, protect everywhere
The unique hybrid security of BloxOne Threat Defense uses the power of the cloud to detect a broad range of threats while tightly integrating with your on-premises ecosystem. It also provides resiliency and redundancy not available in cloud-only solutions. Through a common console, you can centrally and automatically secure IoT and other devices, apps, virtual machines and switch ports wherever they reside.
Boost SecOp efficiency
Our solution reduces incident response time by two-thirds by enabling all the major components of your security stack, including Security, Orchestration, Automation and Response (SOAR) systems, to respond to security events sooner, before they cause harm. It does so through extensive API integrations, valuable network context and data enrichment of the entire security ecosystem.
Reduce the total cost of cybersecurity
Infoblox lowers the total cost of your enterprise threat defense by reducing the burden on stretched perimeter defenses. In addition, our solution enables security teams to get more value out of your third-party security solutions through the real-time, two-way sharing of security event information and through automation that lowers the costs associated with manual effort and human error.
Protect everywhere
Maintain effective visibility and security easily even through workplace (e.g., work from anywhere) and digital transformations (e.g., SD-WAN, IoT and cloud adoption)
Block malware and data exfiltration
Block malicious site access, command-and-control (C&C) communications, DNS-based data theft, and other malicious activity leveraging multi-sourced threat intel and powerful AI/ML
Accelerate threat investigation and response
Automatically correlate event, network and threat intelligence from dozens of sources to speed investigations by as much as two-thirds
Enhance visibility
Get precise visibility with rich context, like IPAM and asset metadata, to improve event correlation and support confident decision making
Automate incident response
Reduce time to remediation by automating coordinated response activities across multiple security ecosystem solutions
Empower SIEM, SOAR and more
Leverage rich event, threat intel, and other data to get more out of your SIEM and SOAR platforms as well as integrations with other security tools
Control misuse
Manage risky user behavior by controlling the use of technologies like DoH (DNS over HTTPS) and preventing inappropriate Internet activity
Improve ROI
Recognize maximum value with minimal effort, quickly, through stronger defenses and greater efficiencies in security operations

