Endpoint Detection and Response
This group includes tags that start with the level edr
. These tags identify data generated by Endpoint Detection and Response (EDR) systems.
Company | Product/Service | Data tables |
---|
Carbon Black Endpoint Detection and Response
edr.carbonblack.alert
edr.carbonblack.binary
edr.carbonblack.feed
edr.carbonblack.ingress
edr.carbonblack.watchlist
More information
Crowdstrike Endpoint Detection & Response
edr.crowdstrike.cannon
edr.crowdstrike.cannon.associateindicator
edr.crowdstrike.cannon.associatetreeidwithroot
edr.crowdstrike.cannon.asepvalueupdate
edr.crowdstrike.cannon.channelversionrequired
edr.crowdstrike.cannon.dnsrequest
edr.crowdstrike.cannon.endofprocess
edr.crowdstrike.cannon.neighborlistip4
edr.crowdstrike.cannon.networkconnectip4
edr.crowdstrike.cannon.other
edr.crowdstrike.cannon.processrollup2
edr.crowdstrike.cannon.processrollup2stats
edr.crowdstrike.cannon.sensorheartbeat
edr.crowdstrike.cannon.syntheticprocessrollup2
edr.crowdstrike.falcon
edr.crowdstrike.falconstreaming.agents
edr.crowdstrike.falconstreaming.auth_activity
edr.crowdstrike.falconstreaming.behaviors
edr.crowdstrike.falconstreaming.customer_ioc
edr.crowdstrike.falconstreaming.detection_summary
edr.crowdstrike.falconstreaming.external_api
edr.crowdstrike.falconstreaming.firewall_match
edr.crowdstrike.falconstreaming.identity_protection
edr.crowdstrike.falconstreaming.idp_detection_summary
edr.crowdstrike.falconstreaming.incidents
edr.crowdstrike.falconstreaming.incident_summary
edr.crowdstrike.falconstreaming.mobile_detection_summary
edr.crowdstrike.falconstreaming.other
edr.crowdstrike.falconstreaming.recon_notification_summary
edr.crowdstrike.falconstreaming.remote_response_session
edr.crowdstrike.falconstreaming.scheduled_report_notification
edr.crowdstrike.falconstreaming.user_activity_groups
edr.crowdstrike.falconstreaming.user_activity_quarantined_files
edr.crowdstrike.falconstreaming.user_activity_sensor_update_policy
edr.crowdstrike.falconstreaming.user_activity_other
edr.crowdstrike.falconstreaming.recon_notification_summary
edr.crowdstrike.falconstreaming.user_activity_devices
edr.crowdstrike.falconstreaming.user_activity_detections
edr.crowdstrike.falconstreaming.user_activity_prevention_policy
edr.crowdstrike.falconstreaming.user_activity_ip_whitelist
edr.crowdstrike.falconstreaming.vulnerabilities
edr.crowdstrike.falcon
edr.crowdstrike.cannon
edr.crowdstrike.cannon.associateindicator
edr.crowdstrike.cannon.associatetreeidwithroot
edr.crowdstrike.cannon.asepvalueupdate
edr.crowdstrike.cannon.channelversionrequired
edr.crowdstrike.cannon.detectionexcluded
edr.crowdstrike.cannon.dnsrequest
edr.crowdstrike.cannon.endofprocess
edr.crowdstrike.cannon.neighborlistip4
edr.crowdstrike.cannon.networkconnectip4
edr.crowdstrike.cannon.other
edr.crowdstrike.cannon.processrollup2
edr.crowdstrike.cannon.processrollup2stats
edr.crowdstrike.cannon.sensorheartbeat
edr.crowdstrike.cannon.syntheticprocessrollup2
More information
Cylance PROTECT
edr.cylance.app
edr.cylance.audit
edr.cylance.device
edr.cylance.memory
edr.cylance.script
edr.cylance.threats
More information
Microsoft Defender Endpoint
edr.microsoft_defender.endpoint.software
edr.microsoft_defender.endpoint.vulnerabilities
edr.microsoft_defender.endpoint.alerts
edr.microsoft_defender.endpoint.assessment_software_vulnerabilities
edr.microsoft_defender.endpoint.assessment_software_inventory
edr.microsoft_defender.endpoint.investigations
edr.microsoft_defender.endpoint.assessment_secure_configuration
edr.microsoft_defender.endpoint.machines
edr.microsoft_defender.endpoint.recommendations
ObserveIT Insider Threat Detection
edr.observeit.events
Symantec Endpoint Detection & Response
edr.symantec.events
Cylance Blackberry
edr.blackberry.cylance.users
edr.blackberry.cylance.policies
edr.blackberry.cylance.threats
edr.blackberry.cylance.optics_detections
edr.blackberry.cylance.optics_detections_rules
edr.blackberry.cylance.optics_detections_exceptions
edr.blackberry.cylance.devices