Investigating endpoint security solutions alerts
Endpoint security solutions are security solutions that are implemented on an organization’s hosts to protect them against cyber threats such as malware infections, credential theft, and suspicious behavior. There are several types of endpoint security solutions; the most common and widely used types are AV and EDR solutions. In this section, we will learn how to investigate samples of the alerts received from both AVs and EDRs.
Investigating AV alerts
The AntiVirus (AV) is an endpoint security solution that is designed to detect and prevent different malware types such as Trojans, worms, and ransomware, based on a signature, which could be a file hash or malware code characters.
The alerts received from the AV solutions contain at least the following details:
- An infected machine name
- An infected filename
- An infected file path
- An infected file hash
- A malware name
- A malware category
While...