Overview
NPAV EDR enhances endpoint visibility by integrating antivirus detection events with comprehensive endpoint telemetry. Every malware detection, prevention, or remediation event is automatically correlated with endpoint activities, enabling security teams to gain complete context around potential threats from a single management console.
This unified approach allows analysts to quickly investigate incidents, understand attack timelines, and respond effectively without switching between multiple security tools.
Enriched Endpoint Telemetry
Whenever the NPAV antivirus engine detects or blocks a threat, the event is enriched with detailed endpoint telemetry, including:
- Endpoint and user information
- Malware name and threat classification
- Detection timestamp
- File name and file path
- Process and parent process details
- Process execution history
- Command-line arguments
- File hash and reputation information
- Quarantine or remediation status
- Security policy applied
- Network connection details (where applicable)
This contextual information helps security analysts understand how a threat entered the endpoint, what actions it performed, and whether additional investigation is required.
Centralized Visibility
All antivirus detections and endpoint telemetry are available through the NPAV EDR Management Console, providing a single pane of glass for security monitoring and incident investigation.
Administrators and analysts can:
- View real-time antivirus detection events.
- Search detection records using multiple criteria.
- Filter events by endpoint, user, malware type, severity, or time range.
- Review associated endpoint activities and security events.
- Correlate antivirus detections with behavioral alerts and endpoint telemetry.
- Investigate incidents from a centralized dashboard.
Advanced Search and Investigation
The NPAV EDR console provides powerful search capabilities that enable security teams to quickly locate and analyze security events.
Analysts can search using:
- Endpoint name
- Username
- Malware family
- Threat severity
- File name or file hash
- Process name
- Detection status
- Date and time
- Event type
These search capabilities significantly reduce investigation time and improve incident response efficiency.

Benefits
- Unified visibility across antivirus and EDR events.
- Complete threat context for faster investigations.
- Centralized search and event correlation.
- Improved threat hunting and forensic analysis.
- Faster detection, investigation, and response.
- Enhanced operational efficiency through a single management console.
By enriching antivirus detections with endpoint telemetry, NPAV EDR provides security teams with comprehensive visibility into endpoint activities, enabling faster, more accurate threat detection and effective incident response from a unified platform.