EDRF On-prem overview

Prev Next

EDRF On-prem is an on-premises endpoint security solution that monitors and analyzes endpoint activity within the organization's network. It collects telemetry on processes, file and registry changes, network connections, and user activity. All data remains within the local infrastructure, supporting environments with strict data residency, regulatory, or air-gapped requirements.

EDRF On-prem supports continuous endpoint visibility and post-incident investigation without reliance on cloud services. Security teams use the stored telemetry to detect suspicious behavior, conduct historical analysis, and perform compliance-driven reviews across managed systems.

The Endpoint Security (HX) server serves as the on-premises investigation interface. It connects to the EDR Telemetry Store and enables analysts to search, correlate, and review endpoint activity without direct access to individual endpoints.

The Historical Search module, hosted on the Endpoint Security (HX) server, enables time-based queries across stored telemetry. It supports retrospective investigations, long-term threat analysis, and incident reconstruction using indexed endpoint data.