Skip to main content

EDR (Endpoint Detection & Response)

Overview​

EDR is Dralvia's endpoint detection and response capability. A signed agent runs on your endpoints, streams normalized telemetry to the EDR console, and lets your team start controlled host isolation from the console where supported. It is built around self-serve rollout and strong operator controls.

What it is for​

  • Get per-workspace visibility into endpoint activity, normalized and recorded.
  • Contain a suspicious or compromised host quickly by isolating it.
  • Keep response controls safe with two-person authorization for high-impact actions such as disabling the agent.

How to use it​

  1. Open EDR Agent Downloads (#/edr-agent) and download the signed agent for your platform (Linux, macOS, Windows, including a Windows EXE). Verify the published sha256 and the detached signature before distributing.
  2. Enroll the host. Agents enroll through the agent API; once enrolled the host appears in the EDR console (#/edr-console) with its current state.
  3. Review enrolled hosts and recent telemetry in the EDR console. Events are normalized and summarized per host, with severity.
  4. Isolate a host from the console when you need to contain it; the host state reflects the isolation.
  5. Disabling an agent uses a deliberate two-person flow: one operator authorizes and a second consumes the authorization. This prevents a single stolen session from turning protection off.

Evidence and privacy​

Telemetry and response actions are recorded per workspace and are workspace scoped. Host state, events, and isolation actions are stored so your reviewers can audit what happened and when. Isolation and decommission are explicit, recorded operator actions.

Where it appears​

  • EDR console (#/edr-console): enrolled hosts, recent telemetry, isolation.
  • EDR Agent Downloads (#/edr-agent): signed multi-platform agent, checksum, signature, and rollout notes.

Limits​

Boundary classification: add-on security module.

Dralvia expands this module only when customer demand, evidence quality, support readiness, and clear operating limits are in place.

EDR endpoints is an add-on, licensed separately from the core plans. Isolation and disable are operator actions with their own authorization model rather than fully automated responses. The agent reports the telemetry it is configured to collect; it is endpoint visibility and response, not a guarantee of detecting every possible threat.