P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Security and edge

Endpoint protection (EDR): what it is and how it is attacked

Software on each computer watching for hostile behaviour.

Also known as

  • EDR
  • antivirus
  • AV
  • XDR

Typing any of them into the editor finds this object.

Why it matters on a security diagram

It is often the only witness to what happened on a machine, which makes it both a defence and evidence.

How it gets attacked, and what reduces it

How it gets attacked

  • Being switched off or excluded before anything else happens
  • Machines that were never enrolled at all

What reduces it

  • Alert on the agent being switched off or excluded, since that is usually the first step
  • Reconcile enrolled machines against the asset register, because the gap is where the incident happens

Where it sits

Group
Security and edge · The things that sit in front of something else and check what is trying to reach it.
Whose side, by default
Ours · Belongs to the organisation the diagram is about.
Catalogue identifier
endpoint-agent

Reviewed . CC BY 4.0.

Others in security and edge

The security and edge group lists all 11 of them side by side.

Endpoint protection on your own diagram

Open the editor, press N, and type EDR. The object is placed and connected to whatever was selected, and Tab adds the next one already joined to it. Nothing is uploaded: the page is served with a Content Security Policy that forbids the browser from making any outbound request at all.

Open the diagram maker