Endpoint Detection and Response

Overview

As part of a defense in depth strategy, it should be assumed that an attacker will make their way through the perimeter of network-based defenses and eventually reach an end user’s device (a desktop, laptop, or phone). As a result, the host needs endpoint security to fend off attacks. An endpoint detection and response (EDR) solution primarily does two things:

  • It monitors the host by continually looking for malicious activity.

  • It responds to attacks to protect the host, preserve evidence, and limit further damage to the endpoint and organization.

Capabilities

EDR can provide the following capabilities:

  • Detection: It continuously monitors processes, alerts, and other resources for potentially malicious activity.

  • Integration: It communicates with other tools to provide end-to-end contextual analysis and supports an organization-level response.

  • Remediation: It contains damage by putting the device into network isolation and restoring critical files from the last known good backup.

  • Evidence collection: It obtains a snapshot of memory, preserves logs, and gathers other artifacts that can support an investigation.

An EDR agent is installed as a process that runs under elevated privileges to access the resources required to be effective.

Detection

There are various behaviors and activities the EDR agent is constantly assessing, evaluating, and comparing against known threat signatures. Tuning is needed to reduce the number of false positives by filtering out benign events and adjusting event severity ratings. It’s also possible to set exclusions for which resources are monitored, such as files, folders, and processes. We set these to make detection efforts more focused and less likely to conflict with other software.

Resources that can be monitored

Here are some resources that EDR can monitor:

  • Processes

  • Objects stored in memory

  • File changes

  • Network and DNS activity

  • Account logins

Get hands-on with 1400+ tech skills courses.