The EDR agent is the core of the Security Suite. It runs on your laptops, desktops, and servers, watches behavior rather than just signatures, and can respond to a threat on its own or on an analyst's command.
What the agent does
- Behavioral detection — flags malicious behavior (credential theft, ransomware encryption patterns, living-off-the-land abuse) even when the file is unknown.
- Next-gen antivirus — blocks known malware pre-execution.
- Continuous recording — keeps a timeline of process, file, network, and registry activity for investigation.
- Device control — policy over USB and removable media.
Telemetry flows to the Managed SOC automatically — no separate connector — so detections become analyst-triaged cases.
Response actions
When something malicious is confirmed, the agent (or an analyst) can:
| Action | Effect |
|---|---|
| Isolate host | Cut the device off the network except the management channel. |
| Kill / quarantine | Stop a process and quarantine the file. |
| Rollback | Revert changes from a ransomware or malware event where supported. |
| Collect | Pull an evidence package for investigation. |
Where other vendors' agents are still in the estate, the same actions are available across them from the Suite's unified endpoint inventory and response actions — isolate, scan, quarantine, or trigger a vendor action from one view.
Isolate a compromised device
Open the device
In the Network Portal, find the endpoint under Security Suite → Devices (or open it from the linked SOC case).
Isolate
Choose Isolate. The device is cut off from the network in seconds while staying reachable for investigation and remediation.
Investigate & remediate
Use the activity timeline to find root cause, remove the threat, then Release the device once it's clean.
Isolation is immediate
Isolating a host drops its network sessions right away — the user will lose live connections. It's the right call for a confirmed compromise; for suspected-only cases, investigate first or use a narrower containment action.
Supported platforms
Windows, macOS, and mainstream Linux server distributions. See Deployment for how to roll the agent out, and Device policies for hardening settings.
