Skip to content

EDR assessment

April 2024–January 2025

I assessed endpoint detection, incident response and forensic investigation capabilities, along with integrations and performance. The aim was to understand how each product would support the SOC in daily use.

Assessment scope

Area Review question
Visibility What endpoint activity is available to an analyst, and what is missing?
Investigation Can an analyst follow a process, user and host across the incident?
Forensic collection Which artifacts can be collected, under which permissions and constraints?
Integration How does the product connect with case management and the wider monitoring stack?
Performance What overhead and operational dependencies need to be considered?

These questions describe the assessment scope; they are not a product ranking or a published benchmark.

Related experience · Other projects