EDR
Endpoint Detection and Response
EDR tools monitor endpoint devices for malicious activity and provide visibility into processes, file changes, and network connections. They record telemetry that analysts use to investigate and contain threats on workstations and servers.
Cómo se usa en ciberseguridad
SOC analysts review EDR alerts to determine if a process execution is malicious or benign. Incident responders use EDR to isolate infected endpoints and collect forensic artifacts. Threat hunters query EDR telemetry to search for indicators of compromise across the fleet.
Término relacionado en el glosario: edr
Las definiciones son explicaciones originales escritas con fines de desarrollo profesional. Para definiciones técnicas autorizadas, consulta NIST, ISO o el organismo de normalización correspondiente.