Digging into the components of EDR
EDR has two primary components, detection and response. The purpose of the detection function of EDR is to provide something like a black box flight recorder for your endpoints, a system that is constantly recording telemetry to allow the investigation of suspicious activity in your environment. The purpose of the response function is to allow you to respond to confirmed malicious activity in meaningful ways. These tools are intended to shorten the time it takes to triage and respond to security events within your estate, and to reduce the potential impact as much as possible.
Cold snack
What’s important to note is that MDE is not dependent on your ability to build detections and add intelligence. Out of the box, the system has an incredible amount of threat intelligence built in and uses a deterministic model that leverages sophisticated scoring to determine whether to raise the alarm. This typically produces well-qualified and actionable...