Document toolboxDocument toolbox

Endpoint Detection and Response

This group includes tags that start with the level edr. These tags identify data generated by Endpoint Detection and Response (EDR) systems.

Company

Product/Service

Data tables

Company

Product/Service

Data tables

Carbon Black Endpoint Detection and Response

  • edr.carbonblack.alert

  • edr.carbonblack.binary

  • edr.carbonblack.feed

  • edr.carbonblack.ingress

  • edr.carbonblack.watchlist

    More information


Crowdstrike Endpoint Detection & Response

  • edr.crowdstrike.cannon

  • edr.crowdstrike.cannon.associateindicator

  • edr.crowdstrike.cannon.associatetreeidwithroot

  • edr.crowdstrike.cannon.asepvalueupdate

  • edr.crowdstrike.cannon.channelversionrequired

  • edr.crowdstrike.cannon.dnsrequest

  • edr.crowdstrike.cannon.endofprocess

  • edr.crowdstrike.cannon.neighborlistip4

  • edr.crowdstrike.cannon.networkconnectip4

  • edr.crowdstrike.cannon.other

  • edr.crowdstrike.cannon.processrollup2

  • edr.crowdstrike.cannon.processrollup2stats

  • edr.crowdstrike.cannon.sensorheartbeat

  • edr.crowdstrike.cannon.syntheticprocessrollup2

  • edr.crowdstrike.falcon

  • edr.crowdstrike.falconstreaming.agents

  • edr.crowdstrike.falconstreaming.auth_activity

  • edr.crowdstrike.falconstreaming.behaviors

  • edr.crowdstrike.falconstreaming.customer_ioc

  • edr.crowdstrike.falconstreaming.detection_summary

  • edr.crowdstrike.falconstreaming.external_api

  • edr.crowdstrike.falconstreaming.firewall_match

  • edr.crowdstrike.falconstreaming.identity_protection

  • edr.crowdstrike.falconstreaming.idp_detection_summary

  • edr.crowdstrike.falconstreaming.incidents

  • edr.crowdstrike.falconstreaming.incident_summary

  • edr.crowdstrike.falconstreaming.mobile_detection_summary

  • edr.crowdstrike.falconstreaming.other

  • edr.crowdstrike.falconstreaming.recon_notification_summary

  • edr.crowdstrike.falconstreaming.remote_response_session

  • edr.crowdstrike.falconstreaming.scheduled_report_notification

  • edr.crowdstrike.falconstreaming.user_activity_groups

  • edr.crowdstrike.falconstreaming.user_activity_quarantined_files

  • edr.crowdstrike.falconstreaming.user_activity_sensor_update_policy

  • edr.crowdstrike.falconstreaming.user_activity_other

  • edr.crowdstrike.falconstreaming.recon_notification_summary

  • edr.crowdstrike.falconstreaming.user_activity_devices

  • edr.crowdstrike.falconstreaming.user_activity_detections

  • edr.crowdstrike.falconstreaming.user_activity_prevention_policy

  • edr.crowdstrike.falconstreaming.user_activity_ip_whitelist

  • edr.crowdstrike.falconstreaming.vulnerabilities

  • edr.crowdstrike.falcon

  • edr.crowdstrike.cannon

  • edr.crowdstrike.cannon.associateindicator

  • edr.crowdstrike.cannon.associatetreeidwithroot

  • edr.crowdstrike.cannon.asepvalueupdate

  • edr.crowdstrike.cannon.channelversionrequired

  • edr.crowdstrike.cannon.detectionexcluded

  • edr.crowdstrike.cannon.dnsrequest

  • edr.crowdstrike.cannon.endofprocess

  • edr.crowdstrike.cannon.neighborlistip4

  • edr.crowdstrike.cannon.networkconnectip4

  • edr.crowdstrike.cannon.other

  • edr.crowdstrike.cannon.processrollup2

  • edr.crowdstrike.cannon.processrollup2stats

  • edr.crowdstrike.cannon.sensorheartbeat

  • edr.crowdstrike.cannon.syntheticprocessrollup2

    More information


Cylance PROTECT 

  • edr.cylance.app

  • edr.cylance.audit

  • edr.cylance.device

  • edr.cylance.memory

  • edr.cylance.script

  • edr.cylance.threats

    More information


Fireeye Endpoint Detection & Response


 

Microsoft Defender Endpoint

  • edr.microsoft_defender.endpoint.software

  • edr.microsoft_defender.endpoint.vulnerabilities

  • edr.microsoft_defender.endpoint.alerts

  • edr.microsoft_defender.endpoint.assessment_software_vulnerabilities

  • edr.microsoft_defender.endpoint.assessment_software_inventory

  • edr.microsoft_defender.endpoint.investigations

  • edr.microsoft_defender.endpoint.assessment_secure_configuration

  • edr.microsoft_defender.endpoint.machines

  • edr.microsoft_defender.endpoint.recommendations

More information


Minerva Labs anti-evasion platform


ObserveIT Insider Threat Detection

  • edr.observeit.events


Palo Alto Cortex XDR


Symantec Endpoint Detection & Response

  • edr.symantec.events


Cylance Blackberry

  • edr.blackberry.cylance.users

  • edr.blackberry.cylance.policies

  • edr.blackberry.cylance.threats

  • edr.blackberry.cylance.optics_detections

  • edr.blackberry.cylance.optics_detections_rules

  • edr.blackberry.cylance.optics_detections_exceptions

  • edr.blackberry.cylance.devices

More information