The middle of a migration runs on claims — parity reached, cutover ready, the old one is gone. Panaptico captures a live baseline of the outgoing system, verifies the dual-run against it field by field, backs cutover readiness with evidence, and gates decommission on verified absence.
Outgoing · baseline
Symantec Endpoint Protection
Incoming · under verification
CrowdStrike Falcon
Dual-run verification
8,940 / 14,112 hosts · 63% coverage
Verified parity
4 caps
Adapted · verified
4 caps
Re-homed
2 caps
Declared exception
1 cap
The gap
01
Half the policies protecting the business were toggled on by someone who left in 2022. Before anyone can verify the new tool matches the old one, someone has to observe what the old one actually does.
02
Two agents, two consoles, two tellings of the same estate. Unless the dual-run is compared against the baseline field by field, parity is whatever the last status meeting decided it was.
03
The new system goes live, the project declares victory, and the old vendor keeps ingesting. Nothing proves that nothing still depends on it — and silence should never become a pass.
Behavioral parity
Every capability the outgoing system performs is verified against the baseline — matched, adapted to a new declared target, re-homed to another system, or declared out of scope. Each row carries its evidence, not a promise.
Real-time malware scanning
SEP AV engine
Falcon prevention
verifiedbehavior matches baseline · detections reconcile
Behavioral detection
SEP Insight / SONAR
Falcon behavioral engine
adaptedtelemetry schema differs · new target declared and verified
Application / device control
SEP ADC policies
Falcon USB / app groups
verified21 of 23 rules at target · 2 off target, before/after on record
Firewall policy
SEP client firewall
Falcon firewall mgmt
adapted47 → 41 rules · every mapping compared field by field
EDR / telemetry
SEP EDR add-on
Falcon Insight
adaptedevents verified landing in the new schema · Splunk route observed live
Tamper protection
SEP tamper
Falcon sensor protection
verifieddefault on · verified across all sensors
Disk encryption bind
SEP + BitLocker hook
Falcon + BitLocker hook
verifiedrecovery keys unchanged · verified held in Intune
Vulnerability scanning
SEP Risk Insight
Falcon Spotlight
adaptedCVSS model differs · new thresholds declared, results verified
DLP (endpoint)
SEP DLP module
— not in Falcon
re-homedre-homed to Netskope · dependents verified re-pointed
Web / URL filtering
SEP web control
— not in Falcon
re-homedre-homed to Zscaler · nothing still routes to SEP
Mobile device protection
SEP Mobile
— out of scope
exceptiondeclared out of scope in the verification contract · Intune MAM keeps mobile
Coexistence
The overlap is the riskiest stretch of any migration. Panaptico observes both systems live and compares them against the baseline — which hosts each agent actually covers, whether detections reconcile, what still depends on the old system — as the overlap collapses day by day.
Overlap window
65 days
Hosts compared live
8,940
Detections reconciled
27.4K / wk
Unknowns surfaced
46 hosts
Cutover readiness
Overall
86%
6 verified checks · the CISO owns the gate
SEP events ↔ Falcon lake
180d of history compared record for record · 30d of live events dual-written and matching
47 → 41 rules
Every mapping compared field by field · 2 off target with before/after values on record
9 SIEM + 3 ticketing
Each declared route observed delivering — Splunk indices, ServiceNow queues, PagerDuty services
18 of 29 consumers
Systems that consumed SEP telemetry, each verified against the new source · 11 still on the old path
117 of 164 closed
Hosts and rules that could not be observed, each driven to a result — silence never becomes a pass
SEP re-enable · intact
The return path stays observed until decommission closes · your IT lead owns the call
Verified absence
Decommission is gated on verified absence. For every asset the outgoing vendor touched, Panaptico verifies the negative — no agent still reporting, nothing still depending on it, no access still open — with evidence behind every closing entry.
7 asset classes · each closed on evidence, not on silence
SEP endpoint agents
14,112 hostsVerified absent, host by host — no agent still reporting
IT Ops
Day 75–90
On-prem SEPM servers
3 VMsPowered down · verified unreachable
Platform
Day 92
Symantec license
1 agreementLapsed at renewal · entitlements verified revoked
Procurement
2026-08-15
SIEM TAs (Splunk)
3 TAsRemoved · verified no SEP events still ingesting
SecOps
Day 78
Historical telemetry
180 daysArchived cold · retained 7y · access verified read-only
Data
Day 80
Firewall ACL carve-outs
23 rulesSEP URLs removed under CHG-7491 · verified no rule references them
Network
Day 88
Endpoint install records
Ansible rolesRepo archived · verified frozen read-only
Platform
Day 95
Panaptico baselines the outgoing system, verifies the dual-run against it, backs the cutover gate your team owns, and proves the old system is actually gone. Nothing rots in the middle.