What can you do with the data from the EDR Tool?
- Historical Searching, Scoping, and Remediation.
- Real-time visibility
- Pattern Analysis and IOC matching
All the data can also be sent to SIEM Application like Splunk, Humio, or ELK Stack. Choice of the free text search depends on a budget of the team. EDR tools are great and offer visibility across the organization. Visibility is critical during an event of intrusion.
One key thing to remember is EDR is not a forensic tool. It'll not collect the complete data set. EDR tools are Proactive, and Forensic tools are Reactive.