Terminology Index

Glossary

1801 terms

Open concept maps

Showing 577-608 of 1801 terms

D
17
E
15

Endpoint Alerts

SOC alerts originating from endpoint security tools like EDR and antivirus, flagging suspicious processes, malware, persistence, or anomalous host behavior. Endpoints are where much attacker activity executes, making these alerts high-value.

Endpoint alerts come from agents watching hosts, EDR and antivirus, and surface things like malicious or unusual processes, suspected malware, persistence attempts, and command-line anomalies. Because endpoints are where code actually runs, these alerts are central to catching intrusions, but triaging them well requires understanding host context, the process tree, and what is normal for that machine, to separate genuine threats from benign activity.

Introduced in: SOC Analyst Fundamentals

Examples

  • An EDR alert on a process spawning an unexpected child like a shell.
  • Malware detected on a host by the endpoint agent.
  • An alert on a suspicious persistence mechanism being created.

No related terms linked yet.