Documentation

Security Suite · Guides

Endpoint protection (EDR)

Behavioral endpoint detection and response for laptops, desktops, and servers — how the agent detects threats, what response actions it takes, and how to isolate a compromised device.

The EDR agent is the core of the Security Suite. It runs on your laptops, desktops, and servers, watches behavior rather than just signatures, and can respond to a threat on its own or on an analyst's command.

What the agent does

  • Behavioral detection — flags malicious behavior (credential theft, ransomware encryption patterns, living-off-the-land abuse) even when the file is unknown.
  • Next-gen antivirus — blocks known malware pre-execution.
  • Continuous recording — keeps a timeline of process, file, network, and registry activity for investigation.
  • Device control — policy over USB and removable media.

Telemetry flows to the Managed SOC automatically — no separate connector — so detections become analyst-triaged cases.

Response actions

When something malicious is confirmed, the agent (or an analyst) can:

ActionEffect
Isolate hostCut the device off the network except the management channel.
Kill / quarantineStop a process and quarantine the file.
RollbackRevert changes from a ransomware or malware event where supported.
CollectPull an evidence package for investigation.

Where other vendors' agents are still in the estate, the same actions are available across them from the Suite's unified endpoint inventory and response actions — isolate, scan, quarantine, or trigger a vendor action from one view.

Isolate a compromised device

Open the device

In the Network Portal, find the endpoint under Security Suite → Devices (or open it from the linked SOC case).

Isolate

Choose Isolate. The device is cut off from the network in seconds while staying reachable for investigation and remediation.

Investigate & remediate

Use the activity timeline to find root cause, remove the threat, then Release the device once it's clean.

Isolation is immediate

Isolating a host drops its network sessions right away — the user will lose live connections. It's the right call for a confirmed compromise; for suspected-only cases, investigate first or use a narrower containment action.

Supported platforms

Windows, macOS, and mainstream Linux server distributions. See Deployment for how to roll the agent out, and Device policies for hardening settings.

Need a hand with Security Suite?Talk to our team →