Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 4 Next »

This group includes tags that start with the level edr. These tags identify data generated by Endpoint Detection and Response (EDR) systems.

Company

Product/Service

Data tables

Carbon Black Endpoint Detection and Response


Crowdstrike Endpoint Detection & Response

  • edr.crowdstrike.cannon

  • edr.crowdstrike.cannon.associateindicator

  • edr.crowdstrike.cannon.associatetreeidwithroot

  • edr.crowdstrike.cannon.asepvalueupdate

  • edr.crowdstrike.cannon.channelversionrequired

  • edr.crowdstrike.cannon.dnsrequest

  • edr.crowdstrike.cannon.endofprocess

  • edr.crowdstrike.cannon.neighborlistip4

  • edr.crowdstrike.cannon.networkconnectip4

  • edr.crowdstrike.cannon.other

  • edr.crowdstrike.cannon.processrollup2

  • edr.crowdstrike.cannon.processrollup2stats

  • edr.crowdstrike.cannon.sensorheartbeat

  • edr.crowdstrike.cannon.syntheticprocessrollup2

  • edr.crowdstrike.falcon

  • edr.crowdstrike.falconstreaming.agents

  • edr.crowdstrike.falconstreaming.auth_activity

  • edr.crowdstrike.falconstreaming.behaviors

  • edr.crowdstrike.falconstreaming.customer_ioc

  • edr.crowdstrike.falconstreaming.detection_summary

  • edr.crowdstrike.falconstreaming.external_api

  • edr.crowdstrike.falconstreaming.firewall_match

  • edr.crowdstrike.falconstreaming.identity_protection

  • edr.crowdstrike.falconstreaming.idp_detection_summary

  • edr.crowdstrike.falconstreaming.incidents

  • edr.crowdstrike.falconstreaming.incident_summary

  • edr.crowdstrike.falconstreaming.mobile_detection_summary

  • edr.crowdstrike.falconstreaming.other

  • edr.crowdstrike.falconstreaming.recon_notification_summary

  • edr.crowdstrike.falconstreaming.remote_response_session

  • edr.crowdstrike.falconstreaming.scheduled_report_notification

  • edr.crowdstrike.falconstreaming.user_activity_groups

  • edr.crowdstrike.falconstreaming.user_activity_quarantined_files

  • edr.crowdstrike.falconstreaming.user_activity_sensor_update_policy

  • edr.crowdstrike.falconstreaming.user_activity_other

  • edr.crowdstrike.falconstreaming.recon_notification_summary

  • edr.crowdstrike.falconstreaming.user_activity_devices

  • edr.crowdstrike.falconstreaming.user_activity_detections

  • edr.crowdstrike.falconstreaming.user_activity_prevention_policy

  • edr.crowdstrike.falconstreaming.user_activity_ip_whitelist

  • edr.crowdstrike.falconstreaming.vulnerabilities

  • edr.crowdstrike.falcon

  • edr.crowdstrike.cannon

  • edr.crowdstrike.cannon.associateindicator

  • edr.crowdstrike.cannon.associatetreeidwithroot

  • edr.crowdstrike.cannon.asepvalueupdate

  • edr.crowdstrike.cannon.channelversionrequired

  • edr.crowdstrike.cannon.detectionexcluded

  • edr.crowdstrike.cannon.dnsrequest

  • edr.crowdstrike.cannon.endofprocess

  • edr.crowdstrike.cannon.neighborlistip4

  • edr.crowdstrike.cannon.networkconnectip4

  • edr.crowdstrike.cannon.other

  • edr.crowdstrike.cannon.processrollup2

  • edr.crowdstrike.cannon.processrollup2stats

  • edr.crowdstrike.cannon.sensorheartbeat

  • edr.crowdstrike.cannon.syntheticprocessrollup2

    More info about these parsers


Cylance PROTECT 


Fireeye Endpoint Detection & Response


Microsoft Defender Endpoint

  • edr.microsoft_defender.endpoint.software

  • edr.microsoft_defender.endpoint.vulnerabilities

  • edr.microsoft_defender.endpoint.alerts

  • edr.microsoft_defender.endpoint.assessment_software_vulnerabilities

  • edr.microsoft_defender.endpoint.assessment_software_inventory

  • edr.microsoft_defender.endpoint.investigations

  • edr.microsoft_defender.endpoint.assessment_secure_configuration

  • edr.microsoft_defender.endpoint.machines

  • edr.microsoft_defender.endpoint.recommendations

More info about these parsers


Minerva Labs

Minerva Labs anti-evasion platform


ObserveIT Insider Threat Detection

  • edr.observeit.events


Palo Alto Cortex XDR


image2021-6-15_11-33-45.png

Symantec Endpoint Detection & Response

  • edr.symantec.events


Cylance Blackberry

  • edr.blackberry.cylance.users

  • edr.blackberry.cylance.policies

  • edr.blackberry.cylance.threats

  • edr.blackberry.cylance.optics_detections

  • edr.blackberry.cylance.optics_detections_rules

  • edr.blackberry.cylance.optics_detections_exceptions

More info about these parsers

  • No labels