root@thehacksparrow:~/writeups$ SYSTEM ONLINE
root@sparrow:~/writeups$ cat introduction-to-edr.md
// Blue Team & SOC

Introduction to EDR

17 Jul 2024 · 9 min read · user access
Overview — An introductory Blue Team & SOC room on EDR (Endpoint Detection and Response). It explains why EDR reaches far beyond traditional antivirus: continuous endpoint telemetry, behavioural and anomaly detection, IOC correlation, MITRE ATT&CK mapping, and powerful response actions (host isolation, process termination, file quarantine, remote shell, and artifact collection). It closes with a simulated triage in which you investigate real detections across several endpoints.
PlatformTryHackMe
CategoryBlue Team & SOC
DifficultyEasy
RoomIntroduction to EDR

Task 1 — Introduction

An EDR continuously monitors endpoints, detects advanced threats, and provides rich context through process trees, timelines, and historical visibility. That ability to reconstruct the full story behind a detection is what sets it apart from a simple point-in-time detector.

🔒 Free account required

This is USER ACCESS content — free to unlock, no payment. The rest of the write-up (and everything else at this level) opens up once you're signed in.

Create a free account