Endpoint Alerts
SOC alerts originating from endpoint security tools like EDR and antivirus, flagging suspicious processes, malware, persistence, or anomalous host behavior. Endpoints are where much attacker activity executes, making these alerts high-value.
Concept Neighborhood
Start here
Context Gathering
The foundation Endpoint Alerts builds on, worth understanding first.
Context GatheringStart here
Collecting the surrounding information an analyst needs to make sense of an alert, the user, host, asset criticality, recent activity, and related events, so triage decisions rest on a full picture rather than the alert alone.
7
lessons
EDR
Endpoint Detection and Response: software on endpoints that continuously records activity, detects malicious behavior, and lets responders investigate and act, such as isolating a host, giving deep visibility and control over what happens on each device.
1
lesson
Related Lessons
1 lesson covers this conceptSign in to open lesson content directly.
