edr-xdr
EDR/XDR
Purpose
Design and manage endpoint detection and response capabilities including EDR/XDR platform selection, detection rule creation, and endpoint investigation workflows.
Framework/Methodology
DETECT-RESPOND Framework
A six-phase methodology for endpoint detection and response:
Phase 1 - Deploy: Install and configure EDR/XDR agents across all endpoints. Ensure coverage across operating systems, server workloads, and cloud instances. Validate telemetry quality and completeness.
Phase 2 - Enrich: Integrate EDR/XDR with threat intelligence feeds, SIEM, and other security tools. Enrich raw telemetry with context: user identity, asset criticality, threat actor TTPs, vulnerability data.
Phase 3 - Triage: Ingest and normalize alerts from all sources. Apply correlation rules, deduplication, and prioritization. Classify alerts by severity and confidence. Route to appropriate response team.
Phase 4 - Examine: Investigate alerts using EDR capabilities: process tree analysis, file reputation, network connections, registry changes, memory analysis. Determine scope and impact. Document findings.
Phase 5 - Contain: Isolate affected endpoints. Block malicious indicators. Kill malicious processes. Remove persistence mechanisms. Apply containment actions proportionate to threat.