Lumu
![]()
IU13 Statewide Software Sales partners with Connection to offer Lumu to schools across the state of Pennsylvania.
![]()
Lumu’s portfolio is centered on Continuous Compromise Assessment (CCA), which helps organizations identify confirmed compromises in real time by analyzing network, endpoint, cloud, and identity telemetry. Unlike traditional security vendors, Lumu focuses on continuous visibility into active compromise rather than prevention alone.
Lumu Defender
Flagship Network Detection & Response (NDR) platform
Lumu Defender continuously analyzes telemetry across networks, endpoints, cloud environments, and identities to identify malicious communications with known attacker infrastructure. It provides real-time detection, incident context, and automated response capabilities.
Key capabilities:
- Network Detection & Response (NDR)
- Endpoint visibility
- Cloud attack visibility
- Identity-based threat visibility
- Automated remediation and response
- Integrations with firewalls, EDR, SIEM, VPN, and ZTNA platforms
Lumu Insights: Compromise visibility and investigation platform
Lumu Insights provides detailed incident information, asset-level visibility, compromise analysis, and historical context. Security teams can determine:
- Which assets were affected
- When the compromise occurred
- Which indicators of compromise (IOCs) were involved
- Attack timelines and severity levels
Best suited for organizations seeking compromise detection and investigation without automated response workflows.
Continuous Compromise Assessment® (CCA): Lumu’s foundational security model
CCA continuously measures whether an organization is communicating with adversarial infrastructure by analyzing network metadata and validating it against threat intelligence. Lumu’s philosophy is:
“Assume you’re compromised and prove otherwise.”
Features include:
- Continuous monitoring
- Real-time compromise detection
- Threat intelligence correlation
- Incident prioritization
- Automated alerting and reporting
Data Collection Products: Lumu Agent
Endpoint-based collector for:
- Windows
- macOS
- Linux
- ChromeOS
The agent provides visibility into remote and roaming devices, even when they are outside the corporate network.
Lumu Virtual Appliance (VA)
A virtual appliance that collects network metadata from:
- DNS
- Firewalls
- Proxies
- NetFlow
- Network infrastructure
The appliance forwards telemetry to the Lumu cloud for analysis.
Gateways
Used to identify and monitor an organization’s public IPs and internet-facing traffic.
Log Forwarders
Collect and send security telemetry from security tools and infrastructure into the Lumu platform.
API Collectors
Integrate cloud and security services directly through APIs for telemetry collection and analysis.
Automated Response Integrations
Lumu integrates with numerous security tools to automate containment and remediation actions, including:
- Fortinet
- Sophos
- WatchGuard
- SonicWall
- Jamf
- Kaspersky
- ESET
- OPNsense
These integrations can automatically block malicious IPs, isolate devices, or update firewall policies when compromises are detected.
Learn more: https://lumu.io/
For more information contact IU13 Software Sales at softwaresales@iu13.org or call 717-606-1810.
Source: https://lumu.io/