EDR IMPLEMENTATION

Selection of a high-quality solution considering infrastructure specifics

next

What issues were resolved

The company reached a point where it was necessary to obtain maximum information from workstations and servers, constantly improving protection. Standard telemetry was no longer enough, so the decision was made to select and install an EDR (Endpoint Detection and Response) solution with Vulnerability management and Sandbox modules.

How they were resolved

We analyzed the customer’s existing infrastructure and identified 2 solutions that meet their needs. After PoC on a demo and real infrastructure, the customer chose the solution that he was more comfortable working with. By connecting the necessary additional modules, we managed to exceed the customer’s expectations. It is worth noting that most EDR manufacturers have additional modules that can be very aptly applied for certain infrastructures.

«Extremely interesting projects with distributed infrastructure and highly specialized requests are rare, but this project was exactly like that. It is a pleasure when the customer actively participates in the pilot project»

«We received more than we hoped for when choosing EDR technology. We felt the company's commitment and customer-centric approach»

What problems were encountered

One of the most difficult stages of implementation was replacing the existing antivirus. Thanks to the successful choice of EDR and the customer’s active participation in the PoC, familiarization and training took place simultaneously. At the implementation stage, all personnel had already received basic training, and further training only consolidated the acquired skills.

Further strategy

After successful implementation and obtaining expertise in the use of EDR, the customer decided to move forward and develop its department in the direction of Threat Hunting, the basis of which will be additional EDR modules and new software tools.