Endpoint Detection and Response
This group includes tags that start with the level edr
. These tags identify data generated by Endpoint Detection and Response (EDR) systems.
Company | Product/Service | Data tables |
---|
Carbon Black Endpoint Detection and Response
edr.carbonblack.alert
edr.carbonblack.binary
edr.carbonblack.feed
edr.carbonblack.ingress
edr.carbonblack.watchlist
More information
Crowdstrike Endpoint Detection & Response
edr.crowdstrike.cannon
edr.crowdstrike.cannon.associateindicator
edr.crowdstrike.cannon.associatetreeidwithroot
edr.crowdstrike.cannon.asepvalueupdate
edr.crowdstrike.cannon.channelversionrequired
edr.crowdstrike.cannon.dnsrequest
edr.crowdstrike.cannon.endofprocess
edr.crowdstrike.cannon.neighborlistip4
edr.crowdstrike.cannon.networkconnectip4
edr.crowdstrike.cannon.other
edr.crowdstrike.cannon.processrollup2
edr.crowdstrike.cannon.processrollup2stats
edr.crowdstrike.cannon.sensorheartbeat
edr.crowdstrike.cannon.syntheticprocessrollup2
edr.crowdstrike.falcon
edr.crowdstrike.falconstreaming.agents
edr.crowdstrike.falconstreaming.auth_activity
edr.crowdstrike.falconstreaming.behaviors
edr.crowdstrike.falconstreaming.customer_ioc
edr.crowdstrike.falconstreaming.detection_summary
edr.crowdstrike.falconstreaming.external_api
edr.crowdstrike.falconstreaming.firewall_match
edr.crowdstrike.falconstreaming.identity_protection
edr.crowdstrike.falconstreaming.idp_detection_summary
edr.crowdstrike.falconstreaming.incidents
edr.crowdstrike.falconstreaming.incident_summary
edr.crowdstrike.falconstreaming.mobile_detection_summary
edr.crowdstrike.falconstreaming.other
edr.crowdstrike.falconstreaming.recon_notification_summary
edr.crowdstrike.falconstreaming.remote_response_session
edr.crowdstrike.falconstreaming.scheduled_report_notification
edr.crowdstrike.falconstreaming.user_activity_groups
edr.crowdstrike.falconstreaming.user_activity_quarantined_files
edr.crowdstrike.falconstreaming.user_activity_sensor_update_policy
edr.crowdstrike.falconstreaming.user_activity_other
edr.crowdstrike.falconstreaming.recon_notification_summary
edr.crowdstrike.falconstreaming.user_activity_devices
edr.crowdstrike.falconstreaming.user_activity_detections
edr.crowdstrike.falconstreaming.user_activity_prevention_policy
edr.crowdstrike.falconstreaming.user_activity_ip_whitelist
edr.crowdstrike.falconstreaming.vulnerabilities
edr.crowdstrike.falcon
edr.crowdstrike.cannon
edr.crowdstrike.cannon.associateindicator
edr.crowdstrike.cannon.associatetreeidwithroot
edr.crowdstrike.cannon.asepvalueupdate
edr.crowdstrike.cannon.channelversionrequired
edr.crowdstrike.cannon.detectionexcluded
edr.crowdstrike.cannon.dnsrequest
edr.crowdstrike.cannon.endofprocess
edr.crowdstrike.cannon.neighborlistip4
edr.crowdstrike.cannon.networkconnectip4
edr.crowdstrike.cannon.other
edr.crowdstrike.cannon.processrollup2
edr.crowdstrike.cannon.processrollup2stats
edr.crowdstrike.cannon.sensorheartbeat
edr.crowdstrike.cannon.syntheticprocessrollup2
More information
Cylance PROTECTÂ
edr.cylance.app
edr.cylance.audit
edr.cylance.device
edr.cylance.memory
edr.cylance.script
edr.cylance.threats
More information
Â
Microsoft Defender Endpoint
edr.microsoft_defender.endpoint.software
edr.microsoft_defender.endpoint.vulnerabilities
edr.microsoft_defender.endpoint.alerts
edr.microsoft_defender.endpoint.assessment_software_vulnerabilities
edr.microsoft_defender.endpoint.assessment_software_inventory
edr.microsoft_defender.endpoint.investigations
edr.microsoft_defender.endpoint.assessment_secure_configuration
edr.microsoft_defender.endpoint.machines
edr.microsoft_defender.endpoint.recommendations
ObserveIT Insider Threat Detection
edr.observeit.events
Symantec Endpoint Detection & Response
edr.symantec.events
Cylance Blackberry
edr.blackberry.cylance.users
edr.blackberry.cylance.policies
edr.blackberry.cylance.threats
edr.blackberry.cylance.optics_detections
edr.blackberry.cylance.optics_detections_rules
edr.blackberry.cylance.optics_detections_exceptions
edr.blackberry.cylance.devices