Skip to main content

Endpoint Detection and Response

The Endpoint Detection and Response (EDR) feature is an event correlation component, capable of identifying advanced threats or in-progress attacks. As part of our comprehensive and integrated Endpoint Protection Platform, EDR brings together device intelligence across your enterprise network. This solution comes in aid of your incident response teams' effort to investigate and respond to advanced threats.

Endpoint Detection and Response (EDR) is a lightweight solution that enables you to:

  • Detect activity that evades classic endpoint prevention mechanisms.

  • Take actions to eliminate vulnerabilities and eliminate the risk of recurrent attacks.Remediation

Start the trial

To start the trial, follow the steps below:

  1. Log in to GravityZone Control Center with a partner account.

  2. Go to the Companies page from the left side menu.

  3. Click on the name of the company you want to enroll in the trial.

    msp_trial_companies_select_485859_en.png

    Tip

    Only eligible companies can be enrolled in a product trial. Check the MSP Trial Status column to see the companies that are eligible for a trial.

    msp_trial_companies_filters_485859_en.psd

    The Edit company window is displayed.

  4. Go to the Product Trials Hub tab.

    msp_trial_companies_select_2_485859_en.png
  5. Select Learn more under the Endpoint Detection and Response section.

    msp_trial_companies_select_2_1_485859_en.png

    The individual product trial page is displayed.

  6. Select Start free trial.

    A confirmation window is displayed.

    msp_trial_companies_select_3_485859_en.png
  7. Confirm your company's location and industry and select Start trial to confirm the enrollment.

The trial has started. The Product Trial Hub tab is displayed, containing updated trial information and buttons.

msp_trial_companies_select_4_485859_en.png

A Reconfigure Agent task is created for every eligible endpoint on the target company, which will deploy the EDR Sensor module.

The company's trial status is updated:

msp_trial_companies_trial_status_485859_en.png

The features included in the trial are enabled in the company's Licensing page:

msp_trial_companies_licensing_status_485859_en.png

Configure and install the feature

If your endpoints already have the BEST agent deployed, a Reconfigure Agent task is created automatically when the trial starts to add the EDR Sensor module to all eligible endpoints on the target company.

Tip

If the reconfigure client task fails, you can go back to the Product Trial Hub page for EDR and click the Add new module button:

msp_trial_companies_add_module_button_485859_en.png

If the task fails to add the module to your endpoints, check the task status and try manually creating another one. If the problem persists, contact support.

If no agent is installed, you will need to use an installation package to deploy BEST on your endpoints along with all required modules.

To start using this feature, follow the steps below:

View EDR activity

Manually stop the trial

  1. Log in to GravityZone Control Center with a partner account.

  2. Go to the Companies page from the left side menu.

  3. Click on the name of the company you want to remove from the trial.

    msp_trial_companies_select_485859_en.png

    Tip

    You can use the the Product Trial status column to see the companies that are have an ongoing trial.

    msp_trial_companies_filters_2_485859_en.png

    The Edit company window is displayed.

  4. Go to the Product Trials Hub tab.

    msp_trial_companies_select_2_485859_en.png
  5. Select Learn more under the Endpoint Detection and Response section.

    The Endpoint Detection and Response trial page is displayed.

  6. Select Stop trial.

    A confirmation window is displayed.

    msp_trial_companies_stop_485859_en.png
  7. Select the Remove module from endpoints checkbox to automatically create a Reconfigure agent task and remove the EDR Sensor module from all eligible endpoints on the target company.

    If requested, a Reconfigure Agent task is created for every eligible endpoint on the target company, which will remove the EDR Sensor module.

    Tip

    If the task fails to remove the module from your endpoints, check the task status and try manually creating another one. If the problem persists, contact support.

    If you do not remove the modules, they will remain on the company's endpoints, but the feature will no longer be licensed.

  8. Click End trial to confirm the request.

The trial has ended.

msp_trial_companies_end_485859_en.png