This case study is password protected
Enter the password to view.
XDR — Network
Extending Endpoint Telemetry with Network Analysis Workflows
Problem Statement
Carbon Black Cloud was a traditional EDR, with detection and response limited to telemetry collected from the endpoint itself. The product had a huge blindspot when it came to network telemetry — Application Layer information, the ability to detect network intrusions and anomalies in network traffic, and the ability to block traffic to and from malicious IPs, ports, and domains.
The Goal
My design aimed to incorporate network data into the existing product, placing it alongside device data, and weaving it into the already familiar workflows for analysts, threat hunters, and incident responders so they could get the data where they need it without changing the way they mitigate cyber attacks.
The Process
Requirements Gathering, Planning, and Prioritization
With 18 engineering teams, and me leading a team of 5 UX designers, researchers, and content writers, it was imperative to keep the teams organized and prioritizing the right work.
- Created planning aids like Gantt charts and a Kanban board, ran discovery workshops, wrote user stories
- Established new practices for user acceptance testing, deprecating old portions of the product, and onboarding strategies future projects could use
Gantt-Style Project Tracking
During our scaled-agile quarterly planning exercises, I found it helpful to track the rolling release cycle in a Gantt chart to visualize when we needed to complete UX tasks in advance of a release — also helping engineers know exactly which code-freeze they needed to aim for.
Kanban-Style Task Tracking
As the lead of 10 other UX practitioners over the course of the project, we all needed visibility into the status of all the moving parts. We worked in Miro during quarterly planning, and I brought the user stories over to Jira to track alongside engineering work during our sprint cycles.
Defining the Underlying Data Model
The first phase involved working closely with product managers and solution architects to analyze the network data. Since the primary interface centers around search, it was critical to design the data itself so it was clear and matched our users' mental models.
- Designed schemas for TLS, HTTP, DNS network connections and new detection types for network traffic anomalies and intrusions
- Determined what details to display in which contexts
- Decided what to call each field in the backend and in the UI, how to order and group them
- Helped plan and run user research sessions to validate our concept for clarity
- Research identified issues with our local/remote terminology of the sensor and how that conflicted with the source or destination of the netconn
- Iterated to address our users' concerns
Data Schema Design
The magic sauce of the Carbon Black Cloud EDR product has always been the depth and richness of data, and some of the biggest pain points have stemmed from poor or inconsistent labeling and organization. Before wireframing, I needed to understand the core of our solution, what was possible to show, and what that meant to users. I presented the data in a stripped-back list to users early on to understand what was important to them, what was confusing, and how to organize it in a clear and skimmable manner.
Mapping User Journeys for Impacted Personas
Before jumping into design, I studied the existing user personas and spoke with a former cyber analyst to understand which personas would need the data, and how they might use it in their existing, daily workflows.
- Identified four personas with workflows that would be impacted: analysts reviewing and triaging alerts, incident responders mitigating perceived threats, threat hunters seeking unidentified threats, and developers creating and maintaining integrations
- Used information architecture and workflow diagrams to identify where and how to insert the new data without disrupting the existing structure
- Used the output to draft initial concepts, put them in front of users for feedback, and break the project into logical parts so multiple designers could own their own slice
Leading UX & Tech Discussions
For a project with over 100 individual contributors across 18 teams, we sometimes found an abundance of cooks in the kitchen. I took charge of discovery and strategy discussions, prioritizing points and keeping us on topic — my teammates came to love our weekly UX and Tech discussions because we tackled complicated problems and moved the project forward together.
Wireframing, Prototyping, and User Testing
Through multiple rounds of iteration and testing, we released a product in less than a year. We tested with users every step of the way, which helped prioritize the most beneficial functionality and release subsequent features over a rolling cadence.
- Analyst workflow concept research with wireframes
- Threat hunter workflow test with clickable prototype
- Usability testing with an early-access working product
- Incorporating feedback from an in-product survey
- Further usability testing with a second set of features
Service Design Mapping
I used service design techniques to organize and categorize workflows by persona to understand how certain pages would be used by multiple personas simultaneously, and identified areas of the product being worked on by other designers and initiatives so we could stay aligned.
Organizing Figma Files
I came up with a system of organizing Figma file pages by user workflow, keeping the latest designs always at the top of the file while maintaining older versions below for reference — useful when we needed to jog our memory on decisions made months prior, and helped maintain a consistent link for engineers locating designs.
Enhancing Readability and Comprehension
One design problem for XDR was taking dense, complicated network telemetry and delivering it in a format that provided maximum clarity. Since cybersecurity is an industry with many junior security analysts performing critical work, it was critical to help analysts learn by giving them the right information at the right time and place.
- Ja3 fingerprints were long, numerous, and hard to parse between different components — I used both color and tone differentiation so even colorblind users could distinguish the breakpoints
- In network connection events, source and destination were confused with whether the device was local or remote — I added visual indicators to highlight directionality
- In network connection details, we were introducing a breadth of new information that changed between different subtypes of events — I organized the data so many portions maintained consistency no matter the subtype, and grouped changing information together for less jostling when comparing events
- MITRE ATT&CK is known to some analysts, but the details of each tactic and technique are often forgotten, so I provided quick-reminder access points and linked out to the full MITRE site
Visual Cues for Clarity
Users rightfully complained it was difficult keeping common network constructs like source and destination straight among the endpoint-focused "local" and "remote" terminology. By adding light diagramming and directionality with boxes and an arrow, users could identify the source of a network connection easily without stopping to think about whether it was remote or not.
Organized and Scannable
By incorporating consistency via design system components, organizing data by type and highest need, and labelling it in the truest and clearest manner, I found it possible to show a wall of text but maintain scannability and clarity. I then updated the non-network events pages and design components so they could be reused elsewhere too.
Detail When Needed
Users didn't always know what new pieces of data meant. They needed a quick way to get more information as they needed it, allowing them to dig further to the full source of information, but tucked away so it was only accessed when actually needed.
Designing with Agility and Pivoting Hard
A critical moment in the project was when I identified a user experience problem where our data was too buried, and I feared users would not be able to find it, let alone benefit from it.
- In taking my advice, the team decided to expand the scope of the project and update a very old portion of the product to accommodate the new features, without disrupting our customers' existing workflows
- We carefully examined what portions we could keep and what we could add to keep it familiar, but also much more powerful and flexible
- We incorporated an in-console visual walkthrough to point out the new features and help customers acclimate to the changes
- We released the product in stages, letting customers opt in at their own pace over a six-month timeframe before removing the old UI
- We achieved 96% adoption before turning off the old version of the page — our target was 75%
Challenges
We started out the project without a product manager, and once we finally hired one, she ended up quitting after a month, so the team leaned on me to set the direction and create a unified vision.
- Managing the needs of many persona- and customer-types, both highly skilled and beginner level, within the same interface
- Deprecating old portions of the product to build something more extensible and durable for this and future efforts
- Coordinating and leading the efforts of 2 other designers, 2 content writers, and 1 researcher
- Leading design workshops, quarterly planning sessions, and routine UX/ENG/PM reviews to define necessary steps and talk through implementation issues and blockers
- Collaborating across 4 continents, 7 widespread time zones, 18 engineering teams, 4 PMs/product areas, keeping everyone informed of a unified design direction
- External factors, such as a corporate acquisition that resulted in 48% of R&D leaving, so I was constantly shuffling staff, onboarding, and at times doing the job of 3 people to make sure we could still deliver in under a year
Awards and Accolades
Elevate Our Best Award — from Brandon Martin, UX Design Manager
"Lisa, You have done an amazing job leading the XDR effort over the past year! Everyone appreciates your collaborative spirit, and the success of XDR to this point could not have been achieved without you as shown by some of the comments below. I want to say thank you for the fantastic job you've been doing!"
Elevate Our Best Award — from Perry Band, UX Research Manager
"Lisa, I wanted to send a huge thank you for your leadership on XDR, and for being such an incredible user research partner. Thank you for helping Nikki and I get ramped up on all things XDR, for taking time to work through the many many many questions around what we're planning to deliver, and pushing back and challenging the team to ensure we're operating with more clarity and confidence. I am so glad you are on this project!"
From the Engineering Program Manager
"Lisa has been a consummate partner during the XDR Phase 1 Implementation. She stepped in when UX leadership had an emergency and had to take time off and made a seamless transition so that the program could proceed at the same pace with no changes. With no question, I would love to work with Lisa on any other program in the SBU." — Keiko
From the Lead Architect
"XDR would not have happened if it was not for Lisa — her hard work and ability to get so many people engaged around UX discussions was the key!" — Davor
From a Designer on the Team I Led
"Good Morning Lisa, was thinking about my project last evening and thought about how you organized your XDR pages and that led me on a train of thought about how you are always so organized and the excellent products you produce. You're rocking XDR, run weekly stand-up, facilitate open space, and if that's not enough you volunteer to do one-offs like the Analyst workflow! You're always prepared, you always give everything deep thought, you're never short-tempered or stressed, and you always give everyone's ideas & opinions space to flourish — in short you are a wonder. So I decided that, this morning I would say so! Have a great day!"
At Our Best Thanks — from researcher on the team I led, Marissa Keech
"This week has been an exercise in cross-facilitation and collaboration among many teams, and I cannot overstate how incredibly proud I am of our UXers. Everyone has consistently brought their best, stayed engaged, and worked together to ensure UX representation and input for all aspects of the XDR initiative. Abby, Ali, Brandon, Lisa, and Melynda — each of you is a model of dedication and sincerity that results in meaningful progress and outcomes. Thank you, team, for being so spectacular. I am so grateful to be a part of our team!"