Endpoint Detection and Response (EDR)
Antivirus blocks the threats it already knows; EDR catches what it doesn't.
Since the dawn of computing, antivirus software has been the cornerstone of IT security. It works by scanning files against a list of known threats and quarantining anything that matches its list.
But today's attackers have learned to leapfrog known malware attacks and are instead using increasingly sophisticated techniques that slip straight past antivirus safeguards without raising a single red flag.
Securing your devices across your business with Endpoint Detection and Response (EDR) is one of the most critical steps you can take today to protect your organisation. Without the right EDR protection, a single infected laptop can unravel your entire business.
What is EDR?
EDR (Endpoint Detection & Response) is a continuous, intelligence-driven security capability that monitors every laptop, desktop, server and mobile device connecting to your business for signs of malicious activity and can act automatically the moment something looks wrong.
While traditional antivirus checks files against known-threat signatures, EDR watches out for unusual behaviours, e.g it looks at what processes are active, what it's trying to access, and determines whether that behaviour deviates from the norm in order to catch attacks that have never been seen before.
Advanced EDR built for the Latest Cyber Attacks
We’re now seeing cyber threats use a range of techniques designed specifically to avoid detection and with the advent of AI-powered hacks, IT Strategic has introduced advanced EDR products to counter these threats.
Our Advanced EDR offers you defence against these common, high-impact attack scenarios:
Ransomware Deployment. Ransomware is malware that locks up your files by scrambling them, then demands payment to unscramble them. EDR watches for the tell-tale signs of a computer suddenly encrypting large numbers of files very quickly, and can shut that process down and cut the affected device off from the network before it spreads to everyone else's files too.
Fileless Malware. Normally, malware is a "file" - something you can find and delete. Fileless malware doesn't work that way, and instead runs entirely in your computer's active memory, or hijacks tools that are already legitimately installed on your machine, making it harder for antivirus to scan and catch. EDR looks out for suspicious behaviour, not suspicious files, so it can catch this kind of attack before it can cause further harm.
Zero-Day Exploits. A "zero-day" exploit is a brand-new attack technique that nobody has seen or documented before. Since EDR is vigilantly watching for unusual behaviour rather than matching against a list of known threats, it can catch these brand-new attacks based on what they're doing, even on day one.
Living-off-the-Land Attacks (LotL): Every computer comes with pre-installed administrative tools to help users manage and troubleshoot systems. Some attackers have learned to hijack these trusted tools to carry out attacks, embedding in common tools such as Powershell, WMI, BITSAdmin and Rundll32 to fly under the radar. EDR is tuned in to notice when these tools and more are being used unusually or suspiciously.
Command & Control Activity: Once malware infects a device, it often needs to "check in" with the attacker to receive further instructions or send back stolen data. EDR looks out for suspicious network activity and outbound communications, which are often the earliest signs a device has been compromised.
Lateral Movement Attempts: Attackers will rarely stop at the first device they break into. Their goal is to infiltrate deeper into a business, hopping from one computer to the next in search of more valuable data or higher-level access. EDR notices when a device starts trying to connect to other machines it wouldn't normally talk to - a telltale sign of a compromised network.
Suspicious Persistence Mechanisms: When attackers get onto a device, they don't want to lose that access if the computer restarts or gets a fresh reinstall and so they plant hidden ways to automatically regain access afterwards - like leaving a spare key under the mat! EDR proactively hunts for these hidden footholds so that they can be permanently uprooted and removed.Why ITDR is Critical for Australian Businesses Today
Key Elements of an effective EDR Solution
A comprehensive EDR deployment should provide continuous visibility across every endpoint/device in your business. Here are some features to look out for when deciding on your EDR solution.
Continuous Behavioural Monitoring: Through machine learning and threat intelligence, a baseline for normal device activity is set and anomalies are then flagged for our SOC (Security Operations Centre) to investigate.
Proactive Endpoint Hardening. Your service should continuously and proactively hunt down, assess and remediate vulnerabilities, outdated software, and insecure configurations across your entire device fleet, autonomously where possible.
Real-Time Threat Detection: There should be continuous monitoring and tracking of process activity, network connections, and file behaviour to detect “Indicators of Compromise” (IoCs) in real time.
Automated Containment & Response: The ability to instantly isolate an infected device from the network, kill malicious processes, or roll back changes upon detection should be a key feature of these solution.The synergy between ITDR, EDR & MDR
How does EDR, ITDR & MDR work together in cyber security?
While EDR and Identity Threat Detection & Response are two sides of the same security coin, multiplying each other's effectiveness, a Managed Detection & Response (MDR) service provides the 24/7 human intervention required to fully and effectively manage responses when technology alone cannot.
An EDR alert on a compromised device provides the context needed for an ITDR system to investigate associated accounts.
An ITDR alert about a suspicious login provides the context for the EDR system to immediately isolate the endpoint being used for that login.
An MDR service acts as the service and human layer to validate, remediate and report on actions taken to resolve incidents and implement the measures to stop them from recurring.
At IT Strategic, we recommend bundling all three along with Cyber Security Awareness Training to effectively update businesses away from siloed security efforts into a unified solution that can reveal and remediate at any point of an attack chain.
By integrating all three, you will have effectively transitioned from siloed security alerts to a unified view that reveals the complete attack chain: from the initial endpoint breach to the compromised identity, final targeting and remediation to lock-out, secure, fix or wind-back compromises and report on incidences.
Are you ready to protect all of your devices from cyberattack?
Talk to an IT Security consultant today to implement an integrated EDR, identity threat detection and MDR solution that's tailored for your business asap