Definition and core concepts of EDR
EDR tools are a security system for endpoints that smoothly combines ongoing real-time monitoring and the gathering of data from endpoints, enhanced by automated analysis and response functions powered by rule-based algorithms. EDR tools are strategically placed on specific workstations or servers (endpoints) with the primary objective of collecting security-related environmental data, often referred to as telemetry. It’s essential to be familiar with the definitions of some specific terms to enhance your comprehension of this book.
Endpoints
These are individual devices such as computers, servers, and mobile devices. We can define them as any device that connects and consumes data from your network.
Endpoint visibility (monitoring)
This means a holistic view of activities occurring on endpoints, empowering security teams to conduct meticulous incident investigations. EDR actively records and captures real-time endpoint data, streamlining...