
Cybersecurity uses a whole range of tools to deal with the diversity of sources, vectors, and types of cyberattacks. Like the layers of an onion, organizations stack different specialized tools to provide the broadest possible functional coverage for their cyber defense strategy.
What began with antivirus software and firewalls in the 1980s has diversified into dozens or even hundreds of types of tools and acronyms that are constantly evolving in line with technical and marketing innovations, resulting in a landscape that is not always easy to navigate.
The purpose of this series of articles is to shed light on recent cybersecurity acronyms, combining feedback from the field and input from industry experts to provide a clear, concrete, and "no-bullsh.t" overview.
In this first issue, we explore EDRs, or Endpoint Detection and Response, the latest solution for protecting workstations and servers.
This article also serves as a summary of our podcast with HarfangLab, one of France's leading EDR solutions, available here.
Definition of EDRs
Endpoint Detection & Response solutions specialize, as the name suggests, in detecting and mitigating threats that may occur on endpoints (computers, servers, and in some cases, mobile devices).
Theorized in 2015 by Gartner, EDRs are an evolution, if not a revolution, in antivirus software and contribute to the protection of workstations (as well as servers).
Antivirus software, which relies primarily on file signature analysis, was quickly overtaken by malware that modifies its source code on the fly (polymorphism). Similarly, the emergence of "fileless" malware, which writes directly to the computer's memory without creating a file, has rendered antivirus software completely useless.
EDRs are the answer for detecting next-generation malware
Unlike antivirus software, which mainly looks at file signatures, EDRstake a much broader and more systemic approach. Nowadays, EDR is an agent that runs on different machines (PCs, servers, etc.) and focuses on three elements:
– User or system behavior: a process that launches or writes to locations where it is not supposed to write. A user who makes dozens of login attempts at unusual times. In short, any suspicious behavior originating from the computer should generate alerts for the administrator.
– Indicators of compromise: these are IP addresses, domains identified as malicious, sources of suspicious traffic, unusual protocols, etc. EDR uses databases of known threats or sources of threats (YARA databases, IP/URLs known to be malicious, etc.) to raise flags when it finds occurrences.
– Signatures: Much like antivirus software, EDR is on the lookout for unsigned software binaries or files with signatures known to be dangerous,to alert administrators.
An architecture that requires SOC teams or MSSPs
By definition, EDR analyzes large volumes of data to identify unusual or suspicious signals, particularly log files. The agent subscribes to various sources of information on endpoints, such as audit logs, security logs, application logs, and OS system activity logs (Windows, Mac, Linux), to search for suspicious behavior patterns.
Multiply that by the number of machines to be analyzed, and you get a huge volume of data that the user cannot interpret.
An EDR therefore needs a dashboard or administrator console that will bring together all the telemetry and alerts reported by the various agents running on the machines and enable a human operator to investigate the alerts, classify them (false positive or real danger) and take the appropriate action. The dashboard will run on an independent server, either in the customer's IT infrastructure or in a cloud, and will be operated by an MSSP if the customer does not have the necessary expertise in-house. Unlike antivirus or EPP solutions, EDRs are therefore a managed solution.
What are the differences between antivirus software and EPP?
In addition to focusing primarily on file signatures, antivirus/EPP solutions do not allow for investigation or forensics. Similarly, remediation (file deletion, quarantine, process termination) is also automatic.
Modern attacks are more subtle and difficult to detect than in the days of antivirus software. It is therefore essential to give human operators the opportunity to investigate, classify, and document alerts before making a decision on remediation. EDR gives SOC operators the power to decide what action to take. However, depending on the rules, types, criticality of alerts, or configuration, it is still possible to take immediate action without waiting for human intervention.
Are EDRs magical?
While essential, EDRs are neither sufficient nor foolproof. Increasingly intelligent malware and threat databases that are not always updated quickly enough to prevent attacks mean that multiple additional layers of protection are needed to deal with the barrage of cyber threats we face today.
Filtering solutions, such as Olfeo SaaS, help block threats upstream before they reach workstations and are a powerful complement to EDRs in ensuring employee security.
Who are the major French players in EDR?
- Tehtris:
Tehtris offers a comprehensive cybersecurity solution that includes an EDR (Endpoint Detection and Response) platform. Their approach focuses on detecting and responding to advanced threats. The Tehtris EDR solution provides real-time monitoring of endpoint activity, behavioral detection, and automated response capabilities to counter sophisticated attacks. The integration of artificial intelligence and machine learning helps to strengthen threat detection capabilities.
- HarfangLab:
HarfangLab offers a comprehensive security solution for businesses, including an EDR solution for detecting and responding to incidents on endpoints. HarfangLab's EDR solution focuses on early threat detection using behavioral detection mechanisms and advanced analysis techniques. It aims to provide in-depth visibility into endpoint activities to enable rapid response to security incidents.
- Stormshield:
Stormshield offers a range of cybersecurity solutions, including an EDR solution called Stormshield Endpoint Security. This solution aims to protect endpoints against a wide range of threats, including targeted attacks. It incorporates behavioral detection, exploit prevention, and incident response features. Stormshield also emphasizes visibility into endpoint activities to help organizations better understand and counter threats.


