Document toolboxDocument toolbox

Endpoint Detection and Response

This group includes tags that start with the level edr. These tags identify data generated by Endpoint Detection and Response (EDR) systems.

Company

Product/Service

Data tables

Company

Product/Service

Data tables

Carbon Black Endpoint Detection and Response


Crowdstrike Endpoint Detection & Response

  • edr.crowdstrike.cannon

  • edr.crowdstrike.cannon.asepvalueupdate

  • edr.crowdstrike.cannon.channelversionrequired

  • edr.crowdstrike.cannon.dnsrequest

  • edr.crowdstrike.cannon.endofprocess

  • edr.crowdstrike.cannon.neighborlistip4

  • edr.crowdstrike.cannon.networkconnectip4

  • edr.crowdstrike.cannon.other

  • edr.crowdstrike.cannon.processrollup2

  • edr.crowdstrike.cannon.processrollup2stats

  • edr.crowdstrike.cannon.sensorheartbeat

  • edr.crowdstrike.cannon.syntheticprocessrollup2

    More info about these parsers


Cylance PROTECT 


Fireeye Endpoint Detection & Response


Minerva Labs anti-evasion platform


ObserveIT Insider Threat Detection

  • edr.observeit.events


Palo Alto Cortex XDR


Symantec Endpoint Detection & Response

  • edr.symantec.events