259 views
Endpoint Detection & Response (EDR) is a class of solutions for detecting and studying malicious activity on endpoints: network-connected workstations, servers, Internet of Things devices, etc. Unlike antiviruses, whose task is to combat typical and mass threats, EDR solutions are focused on identifying targeted attacks and complex threats. At the same time, EDR solutions cannot completely replace antiviruses (EPP), since these two technologies solve different problems. EDR solution architecture In general, an Endpoint Detection & Response class system consists of agents installed on endpoints and a server part. The agent monitors running processes, user actions, and network communications and transmits information to a local server or to the cloud. The server component analyzes the received data using machine learning technologies, compares it with indicator of compromise (IoC) databases and other available information about complex threats. If the EDR system detects an event with signs of a cyber incident, it notifies security personnel about it. EDR Product Capabilities Most modern EDR solutions can: Collect data from endpoints in real time. Record and store information about user actions, network activity, and running programs for subsequent study and research. Detect and classify suspicious activity, and notify security services about it. Take steps to block the attack - isolate suspicious files, stop malicious processes, break network connections. Integrate with endpoint security solutions, SIEM systems, and other security tools. _________________________________________________________________ You can support me not only with a kind word: 1. http://www.donationalerts.ru/r/seminiva 2. Via Yandex money 410014791010027 https://money.yandex.ru/to/4100147910... 3. Bitcoin wallet 1KwWYbgzbHeSK4HC9jLW9EFecntvyQSvM6 4. advcash - [email protected] 5. Ethereum - 0xf45329aee04a895dc624e88ff15e817ceecc9e09 6. Ripple - rPmmFytjV6H7X2655BDdLBLivJkAFkQiXU 7. Bitcoin Cash - 1EqqXNt5irfRqwKp7q9SuZ8Xac5bfXczh6 Social groups: _________________________________________________________________ My Vkontakte group https://vk.com/zapiskiinzhinerz My Facebook group / budni.inzhenera My Twitter / cinquefoil2014 My telegram https://t.me/pyatilistnikorg ________________________________________________________________