edr-xdr

Installation
SKILL.md

EDR/XDR

Purpose

Design and manage endpoint detection and response capabilities including EDR/XDR platform selection, detection rule creation, and endpoint investigation workflows.

Framework/Methodology

DETECT-RESPOND Framework

A six-phase methodology for endpoint detection and response:

Phase 1 - Deploy: Install and configure EDR/XDR agents across all endpoints. Ensure coverage across operating systems, server workloads, and cloud instances. Validate telemetry quality and completeness.

Phase 2 - Enrich: Integrate EDR/XDR with threat intelligence feeds, SIEM, and other security tools. Enrich raw telemetry with context: user identity, asset criticality, threat actor TTPs, vulnerability data.

Phase 3 - Triage: Ingest and normalize alerts from all sources. Apply correlation rules, deduplication, and prioritization. Classify alerts by severity and confidence. Route to appropriate response team.

Phase 4 - Examine: Investigate alerts using EDR capabilities: process tree analysis, file reputation, network connections, registry changes, memory analysis. Determine scope and impact. Document findings.

Phase 5 - Contain: Isolate affected endpoints. Block malicious indicators. Kill malicious processes. Remove persistence mechanisms. Apply containment actions proportionate to threat.

Installs
9
GitHub Stars
21
First Seen
May 30, 2026
edr-xdr — j4flmao/agent-skills