EDR
Also known as: Endpoint Detection and Response
Following adds this technology to your private workspace so related learning is easier to organise and revisit.
What is EDR?
Endpoint detection and response combines endpoint telemetry, behavioural detection, investigation and containment capabilities. This profile connects the concept to KBY's practical engineering guidance.
EDR agents record process, file, identity and network activity so suspicious behaviour can be correlated beyond traditional malware signatures. Operational value depends on coverage, tuned detections, retention and a rehearsed response path for isolating or remediating devices.
Detect, investigate and contain malicious activity on endpoint devices.
- Detecting malware and ransomware
- Investigating security incidents
- Isolating compromised endpoints
1 resource for EDR
Browse by purpose, from definitions and learning through operations, diagnostics and controlled recovery.
Learn and operate with EDR
Ordered as a reader progression -- from core definitions through to operational reference -- using only the content already connected in the technology registry.
Lexicon Definitions(1)
Start here: understand the core vocabulary.