Data Security for Dell
Introduction
Superna Data Security Edition is an active defense solution for Dell PowerScale and Dell ECS environments. It assumes that perimeter defenses — endpoint antivirus, email gateways, network IDS/IPS — can be, and eventually will be, bypassed, and it builds a second line of defense directly at the storage layer, where the data actually lives.
This documentation provides guidance for deploying, configuring, and operating the Data Security features of Cyberstorage for Dell. It is intended for technical professionals responsible for managing storage infrastructure, ensuring data integrity, and responding effectively to cybersecurity incidents.
Data Security presents this defense as a single, unified experience built around five areas of the interface:
- Threat Detections — the primary workspace where both behavioral ransomware detections and policy-based Active Auditor detections appear together as a single event stream, with a shared triage and response workflow.
- Detection Controls — where you configure detection behavior: thresholds and severities, response and lockout settings, snapshot protection, Active Auditor triggers, false-positive management (Learned Thresholds, Ignored List, Monitor Only), and Application Fingerprinting.
- Threat Hunting — ML-based anomaly detection that looks for reconnaissance and insider-threat behavior patterns that precede or accompany a ransomware event, with its own interface for reviewing and investigating anomaly events.
- Data Auditing — querying, reporting, and real-time activity monitoring (WireTap) across file system events, used both to support security investigations and for general data governance and compliance reporting.
- Health Check — operational validation of the detection and audit pipeline itself, through Security Guard, Robo Audit, and Manage Services (confirming your ECA nodes are connected and actively processing events).
Ransomware Defender and Active Auditor are not separate product areas — they are the two detection sources that feed the Threat Detections event list, and both are configured through Detection Controls. When you need to investigate a specific event and recover affected data, you do so through Investigate & Recover, reached directly from an event on the Threat Detections page.
The Problem Data Security Solves
Traditional security defenses are built around keeping malicious code out of the network entirely: endpoint antivirus, email/web gateways, and perimeter IDS/IPS. When one of these layers is bypassed — a phishing email is opened, a workstation is compromised — nothing at the storage layer itself is watching for the behavior a ransomware attack produces once it starts encrypting, renaming, or deleting files on a mounted SMB share or an object bucket.
Data Security is designed to be that missing layer. It assumes malware has already circumvented other defenses and focuses on detecting the behavior of an active attack against NAS or object data, then automatically containing it before it spreads further.
Data Security is not a replacement for endpoint antivirus, email/web security, or offline/immutable backups. It is intended to complement these existing layers, not substitute for them. See Disclaimers for more on this shared operational responsibility.
Core Solution Capabilities
- Unified threat detection — behavioral (Ransomware Defender) and policy-based (Active Auditor) detections both surface as events on the same Threat Detections page, sharing one triage and response workflow regardless of which detector raised them. See Threat Detections.
- Tiered, automated response — detections are classified into Warning, Major, and Critical severities, with automated responses that escalate accordingly: alerting only, a timed lockout that can be canceled before it takes effect, or an immediate lockout for the most severe events. Response behavior, thresholds, and severities are configured through Detection Controls.
- Investigate & Recover — administrators review affected items, assets, and activity for an event, and recover affected data, from the Investigate & Recover page reached directly from the event. See Recovery.
- Snapshot protection — SnapshotIQ-based snapshots can be triggered automatically on affected share paths so that recovery is possible without relying solely on lockout, and are configured alongside other detection behavior in Detection Controls. See Snapshot Settings.
- Detection controls and false-positive management — Active Auditor triggers (Mass Delete, DLP, Custom Triggers), Learned Thresholds, the Ignored List, Monitor Only, and Application Fingerprinting are all configured in one place. See Detection Controls.
- Data auditing — searchable audit reports, built-in and custom queries, and real-time activity streaming (WireTap) across file system events, supporting both security investigations and broader data governance needs. See Data Auditing.
- AI-driven threat hunting — Threat Hunting applies anomaly detection models to the same audit event stream to surface reconnaissance and insider-threat patterns for analyst review, in its own dedicated interface. See Threat Hunting.
- Health and operational validation — Security Guard and Robo Audit continuously validate that the detection and audit pipelines are functioning end to end, and Manage Services confirms your ECA nodes and Eyeglass itself are connected and actively processing events. See Health Check.
- Zero Trust API integration — an external API exposes active threat state so that other systems (for example, Superna Data Orchestration/Golden Copy backup jobs) can automatically pause or gate their own actions while a threat is active. See API Guide.
High-Level Architecture
Data Security is deployed as an Eyeglass Clustered Agent (ECA) cluster — a set of VMs, separate from the Eyeglass appliance itself, dedicated to processing PowerScale and ECS audit data in real time.
- PowerScale / ECS generate audit events (file/object access, modification, deletion) as users and applications interact with data.
- The ECA cluster ingests and processes these audit events using an active-active architecture across its member nodes, so that the loss of a single node does not stop event processing. The ECA cluster performs the behavioral and policy-based analysis behind both Ransomware Defender and Active Auditor detections, and (when Threat Hunting is installed) hosts the Threat Hunting machine learning components.
- Eyeglass is the management and control plane, presented through the areas described above: it licenses and registers each ECA, receives detected threats and heartbeats from it, and executes the configured response (lockout, snapshot, notification) against the affected PowerScale or ECS cluster. Administrators review and triage events through Threat Detections, investigate and recover affected data through Investigate & Recover, configure detection behavior through Detection Controls, review file system activity through Data Auditing, review anomaly findings through the Threat Hunting interface, and confirm pipeline health through the applicable Health Check pages.
For guidance on how to size and place the ECA cluster relative to your PowerScale/ECS clusters, see the Design Guide (reached through Prerequisites → Deployments).
Data Security Documentation
This documentation helps you get Superna Data Security Edition up and running in your Dell environment (e.g., Dell PowerScale or ECS). It’s organized to support you through installation, configuration, and the day-to-day use of the system’s threat detection and response features.
How-To Guides
Have a quick "how do I..." question — configuring a trigger, closing an event, running a report, setting up a webhook? Start here. How-To Guides answers common questions in a short FAQ format, organized by area, with a link to the full guide for each one.
Prerequisites
This section introduces key tasks for preparing a Data Security deployment: platform compatibility and system requirements, storage platform agent configuration, and deployment topology and sizing for Eyeglass, ECAs, Mini-ECAs, and the Threat Hunting ML VM. The Installation Guide then helps administrators like you to:
- Deploy the Eyeglass Clustered Agent (ECA) cluster
- Upload your Data Security license(s)
- Prepare your Dell environment
- Complete an initial configuration
- Enable Data Auditing features
Configuration and Features
Configure and operate the Data Security Solution:
- The Configuration section provides steps for setting up threat detection and prevention features, configuring lockout mechanisms, and defining security policies to protect your data.
- The Features section covers Threat Detections, Data Auditing, Threat Hunting, and Health Check — the day-to-day interfaces built on top of that configuration.
- The Use Cases section includes the day-to-day operations which follow a successful configuration. These tasks focus on readiness, response, and recovery.
Use Cases
Integrations & API
This section covers the Zero Trust API and third-party SIEM/SOAR webhook integrations that let external systems consume Data Security threat events and, where licensed, trigger response actions.
Reference
This section provides supporting information that complements the core guides. It includes CLI commands, compliance/hardening guidance, detection type definitions, and disclaimers — content that isn't part of the main setup or operational procedures.
Use this section to find relevant information as needed.
User Help
See Also
Data Security focuses on active protection and threat detection at the storage level. For a fully protected environment, pair it with recovery/failover and an isolated last-resort backup copy.
Disaster Recovery
Build a robust recovery plan for your enterprise data. Learn how to configure Disaster Recovery for Dell environments.
AirGap
Isolate critical backup copies, enforce immutability, and help prevent encryption or deletion of your last-resort data copy.
Data Orchestration (Golden Copy) provides Zero Trust API integration with Data Security for pausing backup/archive jobs during an active threat. See Smart AirGap / Ransomware Defender Integration in the Data Orchestration documentation for the Golden Copy side of this configuration.