CrowdStrike
EDREndpoint detection and response through its Falcon platform.
Who uses it?
SOC analysts, incident responders and threat hunters.
Best for
Endpoint detection, containment and threat hunting
Similar tools
Microsoft Sentinel, Splunk
What is it?
CrowdStrike's Falcon platform provides endpoint detection and response using a lightweight agent on devices.
What problem does it solve?
Traditional antivirus misses many attacks. EDR records endpoint activity so suspicious behaviour can be detected and investigated.
How does it work?
An agent on each endpoint records process and network activity. Detections flag suspicious behaviour. Analysts can investigate and isolate a host from the console.
Simple example
A detection shows an office application launching a command shell. The analyst reviews the process tree and isolates the machine.
When would a SOC analyst use it?
When a suspicious detection needs quick containment of a single endpoint while investigation continues.
How does it work?
- 1An agent on each endpoint records process and network activity.
- 2Detections flag suspicious behaviour.
- 3Analysts can investigate and isolate a host from the console.
Simple example
A detection shows an office application launching a command shell. The analyst reviews the process tree and isolates the machine.
When would a SOC analyst use it?
When a suspicious detection needs quick containment of a single endpoint while investigation continues.
Who uses it?
SOC analysts, incident responders and threat hunters.
Pros
- Fast containment from the console
- Cloud-managed, no on-site servers
- Broad endpoint coverage
Cons
- Subscription cost
- Needs skilled analysts to use fully
- Agent must be deployed everywhere