Terminology Index
Glossary
1801 terms
Showing 577-608 of 1801 terms
Endpoint Alerts
SOC alerts originating from endpoint security tools like EDR and antivirus, flagging suspicious processes, malware, persistence, or anomalous host behavior. Endpoints are where much attacker activity executes, making these alerts high-value.
Endpoint alerts come from agents watching hosts, EDR and antivirus, and surface things like malicious or unusual processes, suspected malware, persistence attempts, and command-line anomalies. Because endpoints are where code actually runs, these alerts are central to catching intrusions, but triaging them well requires understanding host context, the process tree, and what is normal for that machine, to separate genuine threats from benign activity.
Introduced in: SOC Analyst Fundamentals
Examples
- An EDR alert on a process spawning an unexpected child like a shell.
- Malware detected on a host by the endpoint agent.
- An alert on a suspicious persistence mechanism being created.
No related terms linked yet.
