Symantec Corporation, founded in 1982 and headquartered in Mountain View, California, evolved from a broad technology vendor into a security-focused company after entering the antivirus market in the early 1990s. In 2015, it split into two entities, with Veritas taking information management solutions and Symantec concentrating solely on cybersecurity. The company operates at global scale, with more than 12,000 employees across 35+ countries, a long-standing presence in consumer and enterprise protection under the Norton brand, and a threat intelligence network covering over 175 million protected endpoints. Its security portfolio spans endpoint protection, malware defense, data loss prevention, encryption, and strong authentication, and was strengthened further by acquiring Blue Coat Systems in August 2016 to expand web and cloud security capabilities.
Against a backdrop of increasingly sophisticated, multi-vector attacks that can remain undetected for months, the text positions next-generation security analytics—built on large-scale data collection, correlation, and machine learning—as the industry response for reducing detection times to hours or minutes. Symantec Advanced Threat Protection (ATP) is presented as an integrated platform that combines traditional detection methods with newer analytics and threat intelligence across three primary vectors: endpoints, networks, and email. The product is delivered as a virtual or hardware appliance, can be deployed module-by-module, and provides a single console for unified visibility, investigation, and remediation.
Endpoint ATP integrates with Symantec Endpoint Protection for EDR without additional agents and uses Symantec Cynic cloud sandboxing, including physical-hardware execution to expose VM-aware malware. Network ATP can run standalone and enriches detections using DeepSight threat intelligence and Insight reputation data, while Email ATP requires Symantec Email Security.cloud and does not support alternative email services. Symantec Synapse correlation reduces noise, ranks incidents by criticality, stores artifacts for forensics, and integrates with SIEM, ServiceNow, and APIs. The solution is recommended as a turn-key, highly integrated option—especially for existing Symantec customers and smaller organizations—while noting limits in extensibility, orchestration, and built-in reporting compared to dedicated security analytics platforms.
See All Locations
See All Locations