ON PREMISES SOLUTIONS

Configuration

For EDR to correlate endpoint events and generate incidents you need to turn on the Incidents Sensor.

Note

For EDR to work properly, in advance, you must configure the Incidents Server role from GravityZone Virtual Appliance, and deploy the BEST agent with EDR module on your endpoints.

The Incidents Sensor continuously monitors endpoint activity such as running processes, network connections, registry changes, and user behavior. This metadata is being collected, reported and processed by machine learning algorithms and prevention technologies that detect suspicious activity on the system, and generate Incidents.

Go to Policies > Add > Incidents sensor and select the check box to activate the Incidents sensor.

IncidentsActivateSensor.png

Suggest a new sensor

You can request a new sensor type in GravityZone Control Center by accessing Configuration > Sensors Management > Add new > Need a different sensor?

suggest-sensor.png