Overview

EDR

Endpoint detection and response
solutions monitor all endpoint activity, look for anomalies that indicate threats, and address them in a timely fashion. Our EDR product allows for early stage detection and provides the tools for active manual and automatic response

85%

threats affect endpoint devices

6 in 10

tools most commonly used for attacks in 2023 are legitimate

25 days

the average time that attackers dwelled in a compromised infrastructure prior to detection
Advanced early stage detection
A variety of detection technologies and a large library of automatic detection rules allow for an early identification of complex attacks that bypass standard preventive security solutions
Greater endpoint transparency
Our solution captures all endpoint activity in real time, which enables a more precise response and accurate tracing of the attack in its entirety
Higher effectiveness of response
A multitude of built-in tools enables cybersecurity specialists to respond to incidents both manually and automatically. This saves time and money, and helps to quickly stop adversaries
Proactive threat hunting
The search interface in the single telemetry database provides ample opportunity for retrospective event analysis and threat hunting. This allows for the detection of unknown threats invisible to automatic detection rules
Detection of misconfigurations
Continuous detection of endpoint software with vulnerabilities or configuration issues that could be abused by threat actors

Capabilities

Infrastructure monitoring
  • 200+ monitoring and inventory events
  • Flexible enrichment of telemetry with context (e.g., information about containers) for balanced decision-making
  • Fine configuration of telemetry collection profiles for all infrastructure types, including high‑load systems
  • Event enrichment with Threat Intelligence data
All collected data is used for threat hunting
Threat detection
  • Automated detection based on IoC
    Indicators of compromise
    , behavioral IoA
    Indicators of attacks
    , and YARA rules
  • Threats categorized in accordance with the MITRE ATT&CK matrix
  • Continuous detection even when the server is offline
  • Creation of custom detection rules
  • Deception module for more efficient detection
  • Identification of critical system misconfigurations
Incident response
  • Live response through an interactive command line interface with the defined host
  • Automatic (online and offline) and automated response
  • Library of ready-made popular response tasks
  • Active incident containment: termination of suspicious processes, host isolation
  • Incident remediation: deletion of files, autorun entries, and other traces of malicious activity
  • Collection of forensics data for investigation
  • Program and script execution for response purposes
  • Retrospective telemetry analysis
  • Development of automatic threat blocking rules and multistep response tasks (playbooks)

How it works

WAF_Desktop_EN
Agent
  • Continuous endpoint monitoring
  • On-demand or scheduled endpoint inventory
  • Detection of threats and configuration shortcomings
  • Automatic response
  • Regular server polling for response tasks
  • Response task execution and transfer of results to the server
  • Offline operation without communicating to the server
  • Event collection with own telemetry generation tools
  • Agent self-protection
  • Functionality extension modules
The EDR agent works on Windows, Linux, and macOS
Server
  • Management of agents and their groups
  • Management of response tasks
  • Storage of task results
  • Management of monitoring policies and detection rules (IoC, IoA, YARA)
  • Processing of detection alerts
  • Storage of telemetry searchable via a web interface

Advantages

Proprietary agent for all OS, allowing telemetry generation without third-party solutions
Ready-to-use telemetry collection profiles for quick start-up
Ability to tailor telemetry collection profiles for all infrastructure types, including high-load systems
Interactive terminal with a specified host for live response
Detection of both attacks and system misconfigurations that could lead to them
Expertise of DTM threat detection teams consolidated into a single product

You might also need