EDR Threat Prevention

The EDR solution provides context-aware Endpoint Detection and Response (EDR) capabilities for continuous monitoring, detection, prevention, investigation, and response against modern cyber threats. It records detailed system-level activities and provides security intelligence that enables threat analysts to rapidly understand the nature, scope, and progression of an attack.

The solution combines signature-based detection, behavioural analysis, AI/ML capabilities, threat intelligence, custom detection, endpoint controls, and automated risk-based response to provide comprehensive endpoint protection.

1. Context-Aware EDR

The EDR solution continuously monitors system-level activities and establishes context around processes, files, users, network connections, registry operations, and other endpoint events.

This contextual information helps analysts understand:

  • What happened
  • When it happened
  • Which process initiated the activity
  • Which user was involved
  • What files or system resources were affected
  • Which processes were created
  • What network connections were established
  • How the activity is related to other events
  • Whether the activity represents a potential attack

The solution provides detailed recording, investigation, and reporting capabilities to support rapid threat assessment and incident response.

2. Custom Detection, Intelligence and Controls

The EDR solution provides capabilities for custom detection, threat intelligence, and endpoint security controls.

Security teams can use custom detection logic and threat indicators to identify organization-specific threats and suspicious activities. The solution also provides security controls that can be applied to endpoints to prevent or restrict potentially dangerous activities.

This allows organizations to supplement built-in detections with their own security requirements and threat intelligence.

3. Multi-Platform Endpoint Protection

The EDR solution provides prevention and detection capabilities across major operating system platforms, including:

  • Microsoft Windows
  • Linux
  • macOS

The solution supports the applicable versions of these operating systems and provides centralized visibility and management of protected endpoints.

4. Protection Against Known and Unknown Malware

The solution protects endpoints against both known and unknown malware.

Known threats are identified using established threat intelligence, signatures, hashes, and other detection mechanisms, while unknown and emerging threats are identified through behavioural analysis, machine learning, heuristic techniques, and other advanced detection capabilities.

This layered approach helps protect endpoints against continuously evolving malware.

5. File Operation Protection

The EDR solution continuously monitors file operations and applies malware detection and security controls to read, write, and execute operations.

This provides protection at different stages of a file’s lifecycle and helps prevent malicious files from executing or performing harmful activities on the endpoint.

6. Signature and Behaviour-Based Detection

The EDR solution combines signature-based detection with behavioural analysis to identify sophisticated attacks.

Signature-based detection provides efficient identification of known malware, while behavioural analysis evaluates the actions and relationships of processes and activities on the endpoint.

This combination enables the solution to identify suspicious behaviour even when a threat does not match a known malware signature.

7. Autonomous Offline Protection

The EDR Agent provides autonomous endpoint protection even when the system is disconnected from the network.

The endpoint agent performs local detection and response without requiring continuous dependency on the EDR Management Server, Cloud infrastructure, or other external resources.

When operating offline, the agent can independently monitor endpoint activities, detect threats, and apply appropriate risk-based security responses.

This capability helps maintain protection against sophisticated threats such as:

  • Zero-Day threats
  • Fileless attacks
  • Memory/RAM-based threats
  • Exploits
  • Ransomware
  • Cryptocurrency miners
  • Lateral movement
  • Advanced Persistent Threats (APT)
  • Other sophisticated malware

The endpoint therefore continues to enforce security controls even when centralized connectivity is temporarily unavailable.

8. AI/ML-Based Threat Analysis

The solution leverages Artificial Intelligence (AI) and Machine Learning (ML) capabilities as part of its threat detection approach.

AI/ML-based analysis can be used during:

Pre-Execution:
Files and executables are analysed before execution to identify potentially malicious characteristics and risk indicators.

Runtime:
The behaviour of processes and files is monitored while they are executing to identify suspicious or malicious activities.

Combining pre-execution analysis with runtime behavioural monitoring provides multiple layers of protection against evolving threats.

9. Threat Hunting

The EDR solution provides Threat Hunting capabilities that allow analysts to proactively search endpoint telemetry for suspicious or previously undetected activity.

Analysts can investigate indicators such as:

  • Processes
  • Files
  • File hashes
  • IP addresses
  • Domains
  • Registry activities
  • Command lines
  • Network connections
  • User activities
  • Other endpoint events

Threat Hunting helps identify dormant threats, indicators of compromise, and suspicious activities that may not have generated an active security alert.

10. Malicious Document and Script Protection

The solution protects endpoints against malicious documents and scripts.

It monitors potentially dangerous document and script execution and applies detection and prevention mechanisms to identify suspicious behaviour.

Protection extends to attack techniques involving scripts and document-based malware, including potentially malicious execution through commonly abused scripting mechanisms.

11. Lateral Movement and Insider Threat Protection

The EDR solution monitors endpoint activities associated with lateral movement and potential insider threats.

The solution analyses process, user, file, authentication, and network activities to identify suspicious behaviour that may indicate an attempt to move from one endpoint to another or misuse legitimate access.

This provides security teams with visibility into activities that may indicate compromised credentials, unauthorized access, or suspicious internal movement.

12. Exploit and Fileless Attack Protection

The solution monitors and protects endpoints against exploitation techniques and fileless attacks.

Behavioural monitoring helps identify suspicious activities that may occur without traditional malicious files being written to disk, including abnormal memory, process, scripting, and execution behaviour.

This enables the EDR solution to detect threats that may bypass traditional file-based antivirus detection.

13. Potentially Unwanted Program Detection and Blocking

The EDR solution identifies and blocks Potentially Unwanted Programs (PUPs) and other applications that may introduce security, privacy, or performance risks.

Administrators can apply appropriate controls to prevent unwanted applications from executing or being installed on protected endpoints.

14. Controlled Download of Malicious or Convicted Files

The EDR solution provides administrators with the flexibility to safely retrieve and download malicious, suspicious, or convicted files from the Management Console for authorized investigation and analysis.

This capability allows security teams to obtain samples when required for:

  • Malware analysis
  • Incident investigation
  • Threat intelligence
  • Security research
  • False-positive investigation
  • Forensic analysis

Access to such files can be restricted to authorized personnel and controlled according to the organization’s security policies.

15. Comprehensive Protection Approach

The EDR solution combines multiple security capabilities into a unified protection framework:

Signature Detection → AI/ML Analysis → Behaviour Monitoring → Threat Hunting → Threat Intelligence → Custom Detection → Prevention → Automated Response → Investigation → Reporting

This layered approach enables the EDR solution to protect endpoints against both traditional and advanced threats while providing security analysts with the contextual information required to investigate and respond to incidents effectively.