EDRF allows you to query endpoint and enterprise data to investigate threats, validate security posture, and support forensic analysis. Depending on the type of search, you can retrieve data in real time, review historical records, or search across the enterprise for specific artifacts.
The search options include:
Real-time Search — Collects live data from endpoints. Use this when you need current information, such as active processes, registry values, or network connections.
Historical Search — Queries data that has already been collected and stored in the EDRF repository. This search is useful for analyzing past activity and correlating events over time.
Device Search — Searches for a specific endpoint by attributes such as hostname, IP address, or user. Use this option to quickly isolate or investigate a single endpoint.
Enterprise Search — Runs searches across the entire enterprise to identify the presence of files, processes, or indicators of compromise (IOCs) on multiple endpoints.