Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 12 Next »

This group includes tags that start with the level edr. These tags identify data generated by Endpoint Detection and Response (EDR) systems.

Company Product / service Valid tags

Carbon Black Endpoint Detection and Response

  • edr.carbonblack.alert
  • edr.carbonblack.binary
  • edr.carbonblack.feed
  • edr.carbonblack.ingress
  • edr.carbonblack.watchlist

Crowdstrike Endpoint Detection & Response

  • edr.crowdstrike.cannon

  • edr.crowdstrike.cannon.asepvalueupdate

  • edr.crowdstrike.cannon.channelversionrequired

  • edr.crowdstrike.cannon.dnsrequest

  • edr.crowdstrike.cannon.endofprocess

  • edr.crowdstrike.cannon.neighborlistip4

  • edr.crowdstrike.cannon.networkconnectip4

  • edr.crowdstrike.cannon.other

  • edr.crowdstrike.cannon.processrollup2

  • edr.crowdstrike.cannon.processrollup2stats

  • edr.crowdstrike.cannon.sensorheartbeat

  • edr.crowdstrike.cannon.syntheticprocessrollup2

Cylance PROTECT 

  • edr.cylance.app
  • edr.cylance.audit
  • edr.cylance.device
  • edr.cylance.memory
  • edr.cylance.script
  • edr.cylance.threats

Fireeye Endpoint Detection & Response

  • edr.fireeye.alerts

Minerva Labs

Minerva Labs anti-evasion platform

  • edr.minervalabs

ObserveIT Insider Threat Detection

  • edr.observeit.events

Palo Alto Cortex XDR

  • edr.paloalto.cortex_xdr
  • edr.paloalto.cortex_xdr_agent

image2021-6-15_11-33-45.png

Symantec Endpoint Detection & Response

  • edr.symantec.events
  • No labels