Protecting infrastructure endpoints (workstations, servers, mobile devices, etc.) is becoming a major pillar of cybersecurity, where traditional antivirus software struggles to keep up on its own: when EDR agents step in to effectively combat today’s technical threats…
For several decades, we have seen a surge in the sophistication of offensive methods and tools used to breach IT infrastructure endpoints: endpoints. In many large infrastructures, defensive efforts are often primarily focused on perimeter security to counter threats head-on: firewalls, WAFs, proxies, etc. However, much like a Maginot Line bypassed by specialized forces, these elements are increasingly avoided in attacks that occur behind these initial defenses. We find ourselves overwhelmed by nuisances: malware, backdoors, internal lateral movement, etc. How can we fight back and defend ourselves? Local security features in operating systems and applications, along with specific tools like traditional antivirus, are ready for the challenge. But what happens when the threat is new, unknown, stealthy, aggressive, persistent, intelligent, or even adaptive? Let’s recall a few public examples: Wannacry, NotPetya, etc. In this article, we will explore the topic of EDR agents and their complementary methods for detection, protection, and response: defense in depth.
- The difference between a traditional approach and a holistic approach to cybersecurity
- Weaknesses in developing a comprehensive cybersecurity strategy
- Lack of structure
- Lack of clarity
- Lack of consistent real-time data
- Steps for developing a holistic cybersecurity strategy
- Gain an overview from leadership
- Focus on high-priority risks
- Eliminate silos
- Foster collaboration
- Ensure that cybersecurity is not a barrier to innovation
- Invest in cybersecurity
- Prerequisites for a holistic approach to cybersecurity
- Holistic technologies for a comprehensive approach
About EDRs
Context
It would be impossible to cover every aspect of protecting IT infrastructure endpoints in a single article. However, to whet the appetite of those looking to dive deeper, we will focus primarily on EDR agents to introduce readers who may not yet be familiar with these tactically and strategically significant points.
For those who are already well-versed in this subject, please forgive the humble author for not being able to go into every detail.
Do you want to equip your SOC/CSIRT with tools that go far beyond simple log collection (SIEM) or flow analysis (NIDS), to start engaging with the enemies hiding in your OS? If so, EDRs might interest you, and we will try to provide you with some key insights. Some results-oriented managers are starting to prefer deploying EDR (HIPS++) rather than NIDS or SIEM, thereby shifting their efforts toward the entities that are currently vulnerable and targeted.

About endpoints
But what are the endpoints where it is highly recommended to install security agents? The terminology is evolving and becoming blurred. We often refer to components that process data at the edge of an infrastructure and feature a processor: laptops, workstations, servers, mobile phones, tablets, connected objects, industrial controllers, etc.
Unifying security across an Industry 4.0 factory component, a connected car, the latest smartphone, a corporate web server, and the laptops moving in and out of offices is a massive undertaking. Threats naturally vary depending on the context. Current operating systems do not host applications and data cleanly, not to mention the risks at the hardware level. A low-level software presence seems necessary to ensure detection, protection, or even the technical management of incidents.
EDR Infrastructure
This mission will be handled by EDR agents. These are generally linked to a client-server infrastructure, with agents on the endpoints to be protected and an appliance component to manage them and/or collect their alerts: Cloud, On-Premise, or hybrid solutions mixing both, or even an Air Gap mode for closed networks.
The institute [AV-TEST] currently identifies 350,000 new pieces of malware every day. Writing all the generic, daily antivirus rules would therefore be complex. Faced with such a vibrant offensive landscape, many live infrastructures based on EDR arrive in SaaS mode, with interactivity sometimes starting from the workstation and extending to centralized security services. For example, all unknown binaries can be sent to Cloud-based sandboxes via software robots.
Legal (LPM, etc.), financial (licensing, etc.), and technical arguments will enter into infrastructure considerations before EDR deployments can proceed. Do you have multiple small branches with many small DSL lines around the world, necessitating a Cloud mode rather than placing appliances at every small site? Do you have a factory or a strategic site in a remote location with a risk of outages, requiring an appliance On-Premiseto remain operational during outages? Do you have bandwidth constraints, via satellite or otherwise, that also require thinking about the placement and configuration of elements to limit and optimize the traffic to be sent back (alerts, analyses, etc.)?
Regarding the most commonly requested operating systems, although the list could be longer, we find the classics: Microsoft Windows, Linux, and Apple macOS, but also at least Android for mobile devices. Generally, with Apple iOS—for example on iPhones and iPads—the possibilities for coding protections are limited because Apple aligns with a philosophy of selling a product that is already clean and secure, thus offering few development opportunities: on a standard iOS fleet (without jailbreak), it is difficult to perform a live, remote autopsy of each device.
On Windows, EDR agents must keep up with, or even prepare for, Microsoft's new features so as not to be disrupted by new layers. For example, on a future Windows 10 that might have part of the disk in MS Cloud mode with so-called hydration mechanisms, it would be difficult to tolerate an EDR (or antivirus) scanning (and thus downloading) the disk, which is actually remote, via these mounts that are fairly transparent to the user. And beyond recent Windows versions, many companies actually need to continue covering legacy versions like Windows XP or Windows 2003 Server: these are still very present in factories and operational production environments that cannot tolerate updates or specific shutdowns. As you can see, EDR agents are expected to be: as all-terrain as possible, highly effective even against unknown threats, easy to deploy and configure, inexpensive, and trustworthy.
Detection
Antivirus and/or EDR?
Antivirus software already provides the most effective barrier possible using known and proven traditional methods. Thanks in particular to their signature databases and even certain auxiliary features like heuristics, the antivirus software present on endpoints manages to filter out a huge percentage of attacks by detecting known threats, or even variations close to known threats. These barriers are the best way to fight against what we call the "run-of-the-mill" threats, such as the current Dridex, the ransomware of the month, a foolishly infected USB drive, etc.
When looking at antivirus product tests, some achieve impressive scores around 100%. But when talking to offensive experts or pentesters, they reiterate that antivirus software can generally be easily bypassed. Nevertheless, everyone will say to keep them, as they are a practical way to eliminate basic threats.
Furthermore, some antivirus programs possess hyper-advanced features like the complete cleanup of tools such as harmful Adware and everything that isn't necessarily "black" but operates in the "grey" area to remain hidden, particularly on Windows stations. The question that often arises is: should we choose between an Antivirus or an EDR?
This is certainly highly debatable, and many answers are possible, but to simplify, we believe here—following numerous penetration tests—that it is better to keep both technologies (for now). The antivirus will filter out a maximum of basic threats, and the EDR will have the mission of pushing detection and incident response very far to answer complex questions: who executed what, when, how, why, with what behavior, across all or part of the fleet, etc.
Conscientious system administrators will wonder what footprint an EDR will have on a system, knowing that antivirus software is sometimes heavy on the CPU: so paying for a license in addition to the antivirus that was previously considered sufficient, while also paying in CPU and RAM, would start to add up. In reality, EDR agents usually look at fewer things than antivirus software regarding input/output, for example on the hard drive. Where an antivirus will actually compare hundreds of thousands of signatures with many blocks being written, the EDR agent will use finer, yet still effective, analyses, or it will use intelligent, low-resource blocking modes.
Process monitoring
One of the main missions of an EDR agent is to monitor all executions. There are generally several methods, such as mechanisms like Load Library, regular process polling, system call tracking functions, or even low-level interception, sometimes with options to suspend any suspicious execution while a more in-depth analysis is completed. EDRs must also focus on process migration and execution tracking to determine who launched what and in what context, in order to simplify neutralization or analysis operations.
Process migrationFrom: C:UsersAdminTempcarbanak.exe (3572)To: C:WindowsSystem32svchost.exe (2036)Remediation taken: Remote thread terminated
Memory analysis
Who hasn't dreamed of being able to find Mimikatz, Meterpreter, or even [PUPY] and other weapons in the RAM of processes across their entire Windows fleet? Some EDRs can perform these analyses, which are CPU-intensive but useful for combating "fileless" attacks.
Malicious process found
Memory rule triggered: hacking_tool_mimikatz
C:WINDOWSsystem32csrss.exe
NT AUTHORITYSYSTEM
Persistent threats
The famous APTs (Advanced Persistent Threats) have been at the heart of numerous commercial and technical publications in recent years, given that many companies and individuals have been hacked using methods that allow remote control without being easily detected. Some corporate backdoors are detected years after the initial infection. But why didn't the antivirus see this backdoor hidden for so long? Because that is not its job, and we must stop asking it to cover all of security when faced with offensive tools that sometimes combine intrusive and stealthy technological components. How can these threats be detected? Quite simply, it is like performing forensics: you have to look at all the entry points on a machine to be present at boot, at the next login, or in a list of items launched occasionally or regularly, etc.
Office-level threats
EDRs will often have multiple features to combat classic threats related to office environments.
Regarding USB, you might want to track port usage across the entire fleet, or even the serial numbers of certain devices; directly prohibit USB storage features, or leave them accessible only in read-only mode; or attempt to combat the classic connection of a personal mobile phone that is supposed to be just charging, but is actually sharing its 4G bridge and thus connecting an internal endpoint to the Internet without the company's official proxy.
Mobile device “GT-N7100” detected !
Samsung Electronics Co., Ltd
GT-I9300 Phone [Galaxy S III] (debugging mode)
Serial: 6&21ab38g3&0&0000
Install Date: 2017-11-10 14:35:39
In terms of office software, tools like web browsers, Office or Adobe suites, and even products like Java or Flash are very useful for hackers, as they are widely deployed and often contain many vulnerabilities that can be exploited remotely, either directly or through vulnerable modules.
In large, heterogeneous, and distributed infrastructures with complex permissions and sometimes a lack of IT unification, you must scan the network to identify machines running risky versions of these products. An EDR can perform this task and provide a comprehensive view of security. It can generally also detect risky behaviors: why is Java launching a PowerShell script that attempts to obfuscate its code? Why is Outlook launching Word, which launches CMD.EXE, which launches POWERSHELL.EXE to attempt to download and run an unknown .EXE from the internet? And why does this Word document contain highly risky macros that try to interact with system components? These questions should be addressed at the EDR level, not to mention TCP/IP process traces (e.g., Word communicating with a C&C server).
Fighting ransomware
No one wants to be a victim of a major worm-style ransomware that infects an entire company. Recent months have shown shifts in the structure of criminal groups and even the number of attacks, with growth recorded in other threats like cryptojacking. But how can we fight these tools that, even in 2018, manage to paralyze segments of cities, hospitals, and various companies?
EDRs capable of blocking unknown binaries by intercepting execution can prevent such software from launching. EDRs with behavioral analysis capabilities can detect when software is systematically destroying files, or even decoy files on the disk. Sometimes, it is the combination of several defensive technologies that will successfully combat the most malicious or stealthy versions of ransomware (or various logic bombs used not for financial gain, but for sabotage).
Neutralizing a PowerShell ransomware (Windows sees software signed by Microsoft):
Honeyfile c:userstestappdatafakepathfakefile1.docx is being modified,
Parent Folder listing:
c:userstestappdatafakepath:
— fakefile1.docx
— fakefile2.xlsx
Source process information:
Sha256: 65554b6cabe23a726eadcb72b09204e63afc6a76277c997528ca28ea084c4b3d
Verify Status: Signed
Signatures: Microsoft WindowsMicrosoft Windows Production PCA 2011Microsoft Root Certificate Authority 2010
– (EVILtest) C:Windowsexplorer.exe (3232)
— (EVILtest) C:WindowsSystem32WindowsPowerShellv1.0powershell.exe (4216)
Remediation:
ApplicationPolicy/Ransomware activity, not authorized by application policy
Killed processes –> 4216
Attacks via third-party tools (PowerShell, etc.)
Many attackers are adept at skillfully using malicious tools or legitimate tools repurposed for harm. In recent years, there has been a race where aggressors constantly innovate to find ways to carry out offensive operations without their actions being too visible.
To this end, an effective method on Windows is to use third-party tools such as wmic, mshta, rundll32, regsvr32, msbuild, or PowerShell. The latter is well-known (distributed with Windows) and recognized as coming from a trusted company (Microsoft). It can be difficult to restrict its presence, especially for remote administration, even though signing mechanisms exist to refine its usage.
So, how can you discover that a .ps1 file is actually a pure PowerShell ransomware, or a tool for injecting malicious code into memory? With a behavioral engine, an EDR can identify malicious usage. The best EDRs will not only detect but also block these attacks, preventing a simple detection from escalating.
Complex phases
The boot phase is dangerous if you need to address local attacks (physical access by the hacker) or even remote attacks. An EDR alone will struggle to plug every hole. A machine without minimal protection (such as FDE) would likely be at risk of certain compromises regardless.
On a server platform, FDE is not commonly used, and such machines are often found in Cloud infrastructures where many unknown administrators could illegally tamper with the machine's confidentiality or integrity. On a workstation platform, everything depends on the situation, and security concerns can extend to BIOS and/or UEFI aspects.
Windows also offers the ELAM mechanism (Early Launch Anti-Malware), which can, in some cases, cover the few seconds during machine startup when security is not always immediately perfect.
Once an attacker has control of a machine, they will surely try to delete, disable, or suspend EDR tools. This makes effective agent protection essential for survival. Its resilience is therefore a key point, even if 100% protection cannot be guaranteed when the underlying system is already compromised.
Artificial Intelligence
Entire articles could be written about AI and cybersecurity. Let’s summarize the concept here. AI tools are capable of identifying that a photo of a tiger represents a cat with a 71% confidence level, after being trained on enough photos of dogs and cats. By breaking down the photo, the AI analyzes numerous input elements: edges of different zones, colors, shapes, sizes, etc. This goes beyond traditional mathematics where, via algorithms—sometimes bordering on weighted systems or Bayesian filters—one eventually builds effective recognition methods, particularly with neural networks. These mechanisms also exist for recognizing abnormal or malicious activity.
Many EDRs incorporate these features locally or in the cloud to recognize malware. You provide a Windows PE file as input, and the artificial intelligence indicates whether it is malware, along with a confidence score.
AI has become a controversial subject, fueling debates ranging from the scientific to the fantastical, with some hailing it as a magic solution. In reality, for those accustomed to digital counter-espionage, AI is seen as an additional tool, but not the absolute solution.
An antivirus says, "I see this specific virus in this binary," and you get two pieces of information: something seems malicious + the name of the threat. Sometimes, the antivirus even knows the specific cleaning mechanism required for that threat.
AI says, "I think this binary is malicious with this level of confidence." Unfortunately, some AI developers are the biggest generators of false positives, unlike antivirus software, which is more precise but blinder when it comes to unknown threats (zero-day viruses).
What can we conclude about these topics? AI, when integrated into EDRs, certainly has its place, but it shouldn't be put on a pedestal: it can be bypassed and makes mistakes too. It doesn't know the specific procedure to follow because it won't identify the exact name of the virus. What is it for, then? It serves as an additional virtual teammate to help fight threats and catch what traditional signature-based solutions might miss. It is better to use a belt-and-suspenders approach, combining AI with antivirus software (not to mention the full range of EDR capabilities: behavioral analysis, heuristics, detection of lateral movement, zero-day exploits, privilege escalation, etc.).
Responding to threats
Neutralization
Basic responses naturally involve neutralizing an infected or high-risk application or family of applications. For example, if a user launches Word and gets infected by a malicious document that downloads and executes a backdoor, Windows will see EXPLORER launching WORD, which then launches a BINARY. An EDR aiming to clean the machine will need to kill the BINARY: but why not kill WORD as well, since it is already compromised? There is a risk of data loss for the user who may have been working on a document; they shouldn't have opened that INVOICE31337.DOC sent by a stranger. Some EDRs also offer quarantine operations to prevent a binary from constantly restarting.
Offline and online investigations
The recent article [ARCHAEOLOGY] from MISC perfectly recapped all the concepts related to Threat Intelligence and Analysis, and also covered several products, both commercial and otherwise, designed to assist with investigations. Many cybersecurity firms have had to manage intense crises where they needed to intervene remotely on thousands of machines to clean up a fleet contaminated by one or more threats. In this context, the article [MEMENTO] highlights the specificities of EDRs: they are an essential weapon for fighting large-scale attackers, depending on their strengths and embedded features.
However, some sensitive issues should be noted: if an EDR is capable of copying a machine's RAM to conduct an in-depth digital investigation elsewhere, what happens if the SOC team using that memory dump decides to snoop for other information? This is not a trivial question. It is frequently raised by major corporate clients who use EDRs to protect sensitive workstations. Think of administrators with excessive privileges, or members of an executive committee, and you will quickly see that there are complex scenarios where no one would want a strategic presentation to be copyable via a cybersecurity tool meant to fight espionage. Some products have unlimited rights in this regard (or require end-user authorization, which can be difficult to explain to non-technical staff), while others intentionally omit this feature to prevent such misuse.
Debates will certainly continue in the future, especially as Indicators of Compromise (IOCs) seem to be becoming a commercial and/or technical goldmine. The question to ask will then be: should I pay a certain (very large) sum to subscribe to more or less exclusive IOC feeds? Or can I limit myself to open-source intelligence? Can I rely on systems so autonomous that they can discover attacks on their own, building IOC databases without human intervention for actions that are ultimately obvious (at an ITIL level 1 sense)? Money, time, and strategy will be key factors in making your choice.
Isolation
A technology that tends to be highly valued, especially since the arrival of certain well-known worms (WannaCry, NotPetya), involves isolating one or more endpoints from the entire network. The EDR is instructed to cut off traffic to the rest of the fleet, except for communication with the EDR management servers. This eliminates the risk of a malicious program spreading, particularly during massive infections involving lateral movement. You can then work on the infected machine(s) remotely with near-total peace of mind to perform security analysis, cleaning, etc., without creating additional risk, while keeping the machine powered on and available for further investigation.
Conclusion
Some are beginning to think that the absence of an EDR in an IT environment is equivalent to the absence of antivirus software several decades ago. The need for advanced protection is obvious when you see the damage caused by fairly basic tools that are unknown and stealthy enough to damage infrastructure. But using an EDR also proves powerful for continuous security improvement, whether by searching for strange logs on workstations, identifying existing vulnerabilities, or simply adopting a highly reactive remote approach for verifying alerts and conducting forensic-oriented analysis. Depending on your resources, you might start by looking at, or even contributing to, open-source solutions that resemble EDRs or could be adapted to provide similar functionality ([OSQuery][OSSEC]). Most of the more robust offerings are now commercial and provide numerous options, with varying costs and real technical effectiveness that is well worth validating.
References
Article licensed under (CC BY-NC-ND) – published in MISC magazine issue #99 – November 2018
[OSQUERY] Performant Endpoint Visibility: https://osquery.io
[OSSEC] Official OSSEC project website, Open Source HIDS SECurity: http://www.ossec.net
[AV-TEST] Malware statistics: https://www.av-test.org/en/statistics/malware/
[PUPY] Official PUPY website, for your penetration tests: https://github.com/n1nj4sec/pupy
[ARCHAEOLOGY] Guillaume Arcas, "DIGITAL ARCHAEOLOGY", MISC #97, May-June 2018
[MEMENTO] LinkedIn article "Memento Mori. Forensics Strategy.": https://www.linkedin.com/pulse/memento-mori-strat%C3%A9gie-forensics-laurent-oudot/


