This section provides a complete workflow for configuring your environment to detect threats, monitoring for alerts, and using advanced modules to hunt for suspicious activity.
The EDRF platform collects endpoint telemetry, such as process executions, network connections, and user authentications. HX modules analyze this data to identify suspicious activity that may not match known IOCs. The modules can analyze event chains to uncover stealthy attacker techniques, like lateral movement or the malicious use of legitimate system tools.
This allows you to:
Hunt for anomalous behaviors and tactics, not just known malicious files or IP addresses.
Focus on critical activities with high-potential, contextual alerts that reduce noise in the EDRF platform.
Identify sophisticated threats early by hunting for attacker tactics, techniques, and procedures (TTPs), even without known malware signatures.