Response & Remediation Capabilities

The EDR solution provides comprehensive Response & Remediation Capabilities that enable security analysts to investigate threats, perform real-time response actions, contain affected endpoints, and remediate security incidents from the centralized management console.

The solution combines live endpoint assessment, IOC-based response, risk-based actions, automated remediation, file recovery, endpoint isolation, and centralized incident management to support rapid containment and recovery from security threats.

1. Endpoint Sweep and Assessment

The EDR solution provides the capability to perform security sweeps across multiple endpoints using rich and flexible search criteria.

Analysts can define search conditions based on different endpoint attributes and indicators to identify suspicious or malicious activities across the environment.

The sweep capability helps security teams proactively investigate endpoints for known indicators, suspicious behaviour, and potential compromise.

2. Live Point-in-Time Endpoint Assessment

The solution provides an option to perform a live assessment of the current state of an endpoint.

Analysts can perform targeted searches and scans without waiting for a scheduled scan or predefined assessment cycle.

The live assessment supports:

Disk File Scanning

Analysts can scan files stored on the endpoint to identify malicious, suspicious, or potentially unwanted files.

Memory Process Scanning

The solution can inspect running processes and their memory state to identify suspicious or malicious activity, including threats that may not have a traditional malicious file on disk.

Registry Search

Analysts can search the Windows Registry for suspicious keys, values, configurations, or persistence mechanisms associated with potential threats.

3. Real-Time MITRE ATT&CK-Based Response

The EDR solution provides real-time response capabilities for detected MITRE ATT&CK techniques.

When suspicious activity associated with a specific attack technique is detected, the solution provides relevant detection and response capabilities to enable analysts to investigate and contain the threat quickly.

This allows security teams to move from detection to response without requiring a separate manual workflow.

4. Advanced Endpoint Response Actions

The solution provides advanced response actions that can be executed directly on affected endpoints.

Supported actions include:

  • Kill Process
  • Isolate Device
  • Block Process
  • Quarantine malicious files
  • Delete malicious files
  • Other supported remediation actions

The available response actions are applied according to the nature and severity of the detected threat.

5. IOC Ingestion and Blocking

The EDR solution supports the ingestion of Indicators of Compromise (IOCs) for proactive detection and response.

Supported IOC types include:

  • URLs
  • File Hashes
  • Other supported threat indicators

Once an IOC is identified as malicious, the solution can apply appropriate blocking controls, including blocking malicious files or file hashes across protected endpoints.

This enables security teams to rapidly distribute newly identified indicators throughout the endpoint environment.

6. Risk-Based Endpoint Response

The EDR solution supports risk-based response actions based on endpoint characteristics and observed behaviour.

The endpoint reputation is determined using behavioural information collected over time, including unusual, suspicious, or malicious activities observed on the endpoint.

Based on the calculated risk or reputation, the solution can apply appropriate security responses, helping organizations prioritize high-risk endpoints and respond proportionately to detected threats.

7. Live Query Monitoring and Command Detection

The solution provides a Live Query capability for performing real-time investigation of endpoint information.

Commands executed during a live query session are detected and logged, providing visibility into the investigative activities performed against endpoints.

This provides analysts with an auditable record of live investigation activities.

8. Suspicious and Malicious Behaviour Alerts

The EDR solution generates alerts for both suspicious and confirmed malicious behaviour.

This enables security teams to investigate potential threats at an early stage rather than waiting until activity is conclusively classified as malware.

Alerts can provide relevant contextual information to help analysts determine the severity and appropriate response.

9. Process Termination and Quarantine

The solution provides the ability to terminate offending processes and quarantine associated malicious files.

When a process is identified as malicious or posing a significant security risk, an analyst can take immediate action to:

  1. Terminate the offending process.
  2. Quarantine the associated file where applicable.
  3. Prevent further execution.
  4. Continue investigation and remediation.

This helps minimize the impact of active threats on the endpoint.

10. File Backup and Restoration

The EDR solution provides file backup and restoration capabilities to help recover from destructive security incidents.

This capability is particularly useful during ransomware attacks where malicious processes may encrypt, modify, or otherwise damage important files.

Where supported, protected files can be restored to an earlier safe state, helping organizations reverse destructive data changes and recover affected information.

11. Network Quarantine

The solution provides the ability to network-quarantine an affected endpoint to contain an active threat.

When an endpoint is isolated, its network communication can be restricted according to the configured quarantine policy while maintaining the required management or remediation communication.

Administrators can configure the network quarantine behaviour according to organizational security requirements.

This helps prevent compromised endpoints from:

  • Communicating with command-and-control infrastructure
  • Spreading malware
  • Performing lateral movement
  • Accessing other systems
  • Exfiltrating sensitive information

12. Automated Threat Response

The EDR solution provides automated threat response capabilities that allow predefined response actions to be triggered based on detected threats, events, or risk conditions.

Security teams can automate repetitive response operations and reduce the time between detection and containment.

A typical automated workflow can include:

Threat Detection → Risk Assessment → Process Termination → File Quarantine → Network Isolation → Investigation

13. Response Across Multiple Endpoints

The solution provides the capability to execute remediation actions across multiple systems simultaneously.

Analysts and administrators can select multiple affected endpoints and apply supported response actions from the centralized management console.

This is particularly useful during widespread malware outbreaks, ransomware incidents, or IOC-based investigations where the same remediation action is required across multiple endpoints.

14. Incident Notes and Status Management

The EDR solution provides options for analysts to add notes and comments to security issues, alerts, and events.

Analysts can also track the current status of an issue using statuses such as:

  • In Progress
  • Resolved
  • Unresolved

This enables security teams to maintain investigation context and track the progress of remediation activities.

15. Centralized Response and Remediation

The EDR solution provides a centralized workflow for:

Sweep → Detect → Investigate → Assess Risk → Respond → Contain → Remediate → Recover → Track

By combining live endpoint assessment, IOC ingestion, risk-based response, process control, network quarantine, automated remediation, multi-endpoint actions, and incident tracking, the solution enables security teams to respond rapidly to both individual endpoint incidents and large-scale security events.