OpenDNS is now part of Cisco Learn More

Umbrella Platform

Cloud-Delivered Network Security and Threat Intelligence that Protects Any Device, Anywhere

Umbrella adds a new predictive network security layer for DNS and IP activity providing breach protection and Internet-wide visibility. The cloud-delivered service protects any device, both on and off the corporate network. Umbrella prevents command & control callbacks, malware, and phishing from compromising systems or exfiltrating data over any port or protocol. In real-time, all Internet activity is logged and categorized by type of security threat, Web content, or cloud service. Retain this visibility for as long as required.

Is it right for me?

Umbrella Platform is for security practitioners and established incident response teams who need to provide security against, and reduce dwell time of, Internet threats, advanced attacks and security breaches.


    • Worldwide coverage in minutes

      OpenDNS protects devices anywhere and stays up-to-date without admin intervention because there is no hardware to install or software to maintain.

    • Comprehensive protection

      Our global network infrastructure handles over 80 billion Internet requests a day, which our Security Graph engine analyzes to learn where attacks are being staged even before the first victim is hit—automatically blocking known or emergent threats.

    • Superior performance

      With OpenDNS there is no added latency, as there is no need to reroute every connection through proxy or VPN gateways to secure mobile users or remote offices. OpenDNS Global Network has proven reliability, handling more than two percent of the world’s Internet requests daily with 100 percent uptime.

    • Enforcement for both our intelligence and yours

      FireEye, Cisco, Check Point, ThreatConnect, and other existing systems continuously discover new malicious domains, but hours or days go by before action is taken. By leveraging OpenDNS APIs, you can programmatically add or remove these domains with Umbrella Platform. Internet activity destined to these domains are blocked at the DNS layer—reducing the time between detection and prevention to seconds. OpenDNS’s predictive intelligence is enforced at both the DNS and IP layers, including URL-level inspection without performance sacrifices using our Intelligent Proxy.

    • Actionable plus extended visibility

      In real-time, all Internet activity is logged and categorized by type of security threat, Web content, or cloud service (including IoT). View globally aggregated reports in your dashboard, and identify targeted attacks by comparing your DNS requests to the world’s. Or schedule and send these reports to your inbox. And retaining this total visibility forever could not be simpler using our integration with Amazon S3. Umbrella Platform includes the Investigate Console to enrich your local intelligence with our global context. Observe related attacks using a live graph of all Internet activity.

    • Integrated management workflow

      Umbrella Platform includes our Virtual Appliance and Connector components to enable you to identify internal networks or Active Directory users infected or targeted by attacks, without touching devices or re-authenticating users. It enables consistent policy management by AD user or computer group membership. Our Log Management feature enables a simple cloud-to-cloud log storage solution with Amazon S3 that retains all DNS logs for as long as required. Start a free trial to experience all the enterprise-grade features and how easy our Web UI is to use.