/
Endpoint Detection and Response

Endpoint Detection and Response

This group includes tags that start with the level edr. These tags identify data generated by Endpoint Detection and Response (EDR) systems.

Company

Product/Service

Data tables

Company

Product/Service

Data tables


Crowdstrike Endpoint Detection & Response

  • edr.crowdstrike.cannon

  • edr.crowdstrike.cannon.associateindicator

  • edr.crowdstrike.cannon.associatetreeidwithroot

  • edr.crowdstrike.cannon.asepvalueupdate

  • edr.crowdstrike.cannon.channelversionrequired

  • edr.crowdstrike.cannon.dnsrequest

  • edr.crowdstrike.cannon.endofprocess

  • edr.crowdstrike.cannon.neighborlistip4

  • edr.crowdstrike.cannon.networkconnectip4

  • edr.crowdstrike.cannon.other

  • edr.crowdstrike.cannon.processrollup2

  • edr.crowdstrike.cannon.processrollup2stats

  • edr.crowdstrike.cannon.sensorheartbeat

  • edr.crowdstrike.cannon.syntheticprocessrollup2

  • edr.crowdstrike.falcon

  • edr.crowdstrike.falconstreaming.agents

  • edr.crowdstrike.falconstreaming.auth_activity

  • edr.crowdstrike.falconstreaming.behaviors

  • edr.crowdstrike.falconstreaming.customer_ioc

  • edr.crowdstrike.falconstreaming.detection_summary

  • edr.crowdstrike.falconstreaming.external_api

  • edr.crowdstrike.falconstreaming.firewall_match

  • edr.crowdstrike.falconstreaming.identity_protection

  • edr.crowdstrike.falconstreaming.idp_detection_summary

  • edr.crowdstrike.falconstreaming.incidents

  • edr.crowdstrike.falconstreaming.incident_summary

  • edr.crowdstrike.falconstreaming.mobile_detection_summary

  • edr.crowdstrike.falconstreaming.other

  • edr.crowdstrike.falconstreaming.recon_notification_summary

  • edr.crowdstrike.falconstreaming.remote_response_session

  • edr.crowdstrike.falconstreaming.scheduled_report_notification

  • edr.crowdstrike.falconstreaming.user_activity_groups

  • edr.crowdstrike.falconstreaming.user_activity_quarantined_files

  • edr.crowdstrike.falconstreaming.user_activity_sensor_update_policy

  • edr.crowdstrike.falconstreaming.user_activity_other

  • edr.crowdstrike.falconstreaming.recon_notification_summary

  • edr.crowdstrike.falconstreaming.user_activity_devices

  • edr.crowdstrike.falconstreaming.user_activity_detections

  • edr.crowdstrike.falconstreaming.user_activity_prevention_policy

  • edr.crowdstrike.falconstreaming.user_activity_ip_whitelist

  • edr.crowdstrike.falconstreaming.vulnerabilities

  • edr.crowdstrike.falcon

  • edr.crowdstrike.cannon

  • edr.crowdstrike.cannon.associateindicator

  • edr.crowdstrike.cannon.associatetreeidwithroot

  • edr.crowdstrike.cannon.asepvalueupdate

  • edr.crowdstrike.cannon.channelversionrequired

  • edr.crowdstrike.cannon.detectionexcluded

  • edr.crowdstrike.cannon.dnsrequest

  • edr.crowdstrike.cannon.endofprocess

  • edr.crowdstrike.cannon.neighborlistip4

  • edr.crowdstrike.cannon.networkconnectip4

  • edr.crowdstrike.cannon.other

  • edr.crowdstrike.cannon.processrollup2

  • edr.crowdstrike.cannon.processrollup2stats

  • edr.crowdstrike.cannon.sensorheartbeat

  • edr.crowdstrike.cannon.syntheticprocessrollup2

    More information



Fireeye Endpoint Detection & Response


 

Microsoft Defender Endpoint

  • edr.microsoft_defender.endpoint.software

  • edr.microsoft_defender.endpoint.vulnerabilities

  • edr.microsoft_defender.endpoint.alerts

  • edr.microsoft_defender.endpoint.assessment_software_vulnerabilities

  • edr.microsoft_defender.endpoint.assessment_software_inventory

  • edr.microsoft_defender.endpoint.investigations

  • edr.microsoft_defender.endpoint.assessment_secure_configuration

  • edr.microsoft_defender.endpoint.machines

  • edr.microsoft_defender.endpoint.recommendations

More information


Minerva Labs anti-evasion platform



Palo Alto Cortex XDR



Cylance Blackberry

  • edr.blackberry.cylance.users

  • edr.blackberry.cylance.policies

  • edr.blackberry.cylance.threats

  • edr.blackberry.cylance.optics_detections

  • edr.blackberry.cylance.optics_detections_rules

  • edr.blackberry.cylance.optics_detections_exceptions

  • edr.blackberry.cylance.devices

More information