October 1, 2026
Introduction to EDR: Visibility, Detection, Response, and Endpoint Telemetry
Introduction

By Jonathan Sanfer
10 min read
Introduction
Welcome to my walkthrough of Introduction to EDR! This is the first room in the Core SOC Solutions module of the SOC Level 1 path. In my previous article, I covered SOC Metrics and Objectives, which closed out the SOC Team Internals module by looking at how SOC performance is measured through metrics like False Positive Rate, MTTD, MTTA, and MTTR.
With the team side of the SOC covered, this module shifts focus to the tools analysts rely on every day. We start with Endpoint Detection and Response (EDR), one of the most widely adopted security solutions for protecting laptops, workstations, and servers wherever they happen to be.
Catch up on my previous article, SOC Metrics and Objectives, by clicking the banner below.
What we will cover
- The three pillars of an EDR: visibility, detection, and response
- How an EDR goes beyond a traditional antivirus, step by step through a real attack chain
- The EDR architecture of agents and a central console
- The telemetry an EDR collects and the detection and response capabilities built on top of it
- A hands on investigation of several detections in a simulated EDR dashboard
Room Information
Before we dive into the tasks, here is a quick overview of the room details.
- Room Name: Introduction to EDR
- Path: SOC Level 1
- Module: Core SOC Solutions
- Topic: Endpoint Detection and Response (EDR)
- Difficulty: Easy
- Room Link: TryHackMe โ Introduction to EDR
Task 1: Introduction
Endpoint Detection and Response (EDR) is a security solution designed to monitor, detect, and respond to advanced threats at the endpoint level. Because it is so widely adopted, understanding how an EDR works is an essential skill for any SOC analyst.
This room covers how an EDR differs from a traditional antivirus, what data it collects from endpoints, and what detection and response capabilities it offers, before finishing with a realistic alert investigation. The only prerequisites are a basic understanding of common endpoints (Windows, Linux, and Mac) and the attacks against them, and an awareness of the SOC team's role.
Task 2: What is an EDR?
Most organisations protect their devices with network level defenses, but remote work has pushed many of those devices outside the perimeter. An EDR solves this by protecting each endpoint directly, so devices stay monitored no matter where they are. Popular examples include CrowdStrike Falcon, Symantec EDR, SentinelOne EDR, and Microsoft Defender for Endpoint, and while their features vary, their underlying architecture is largely the same.
Every EDR is built on three pillars. Visibility comes from collecting detailed data such as process, registry, and file modifications and user actions, then presenting it as structured process trees and activity timelines so every detection arrives with full context. Detection combines signature based and behavior based techniques, uses machine learning to flag deviations from a baseline, catches fileless malware in memory, and accepts custom IOCs. Response lets analysts isolate an endpoint, terminate a process, quarantine files, or connect to a host remotely, all from the central EDR console.
The room illustrates visibility with a CrowdStrike Falcon process tree. Each node is a process and each connecting line shows a parent and child relationship, so finding which process launched another is simply a matter of following the line from the child node back to the node on its left. One caveat worth remembering is that an EDR is a host only solution and does not detect network level threats.
Questions and Answers
Which feature of EDR provides a complete context for all the detections?
Answer:
VisibilityVisibilityWhich process spawned sc.exe?
Answer:
cmd.execmd.exeTask 3: Beyond the Antivirus
A common question is why an EDR is needed when endpoints already run an antivirus. The room answers with an airport analogy. An antivirus is like the immigration check at the entrance, comparing passports against a list of known criminals, which works well until someone with a clean record walks through. An EDR is like the security officers inside the airport watching cameras and motion sensors, who notice when someone roams near restricted areas or leaves a bag unattended, and who can act or escalate with full details.
The room then walks through an attack chain to show the gap in practice. A user opens a phishing Word document whose macro spawns PowerShell, an obfuscated command downloads a second stage payload, the payload is injected into a legitimate svchost.exe, and the attacker gains remote access. A signature based antivirus sees nothing wrong at most of these stages and may even mark the activity as clean. The EDR, on the other hand, flags the unusual winword.exe to PowerShell.exe parent and child relationship, the obfuscated script, the process injection, and the unexpected outbound connection, then raises one alert containing the full attack chain.
An EDR also adds organisation wide visibility, so a suspicious file found on one endpoint is automatically checked across all others. Some modern antivirus products have improved, but an EDR still levels up detection and response well beyond them.
Questions and Answers
In the given analogy, what presents an AV?
Answer:
immigration checkimmigration checkWhich legitimate process was hijacked by the attacker in the scenario?
Answer:
svchost.exesvchost.exeWhich security solution might mark this activity as clean?
Answer:
AntivirusAntivirusTask 4: How an EDR works?
An EDR has two main components. Agents are deployed on every endpoint and act as the eyes and ears of the EDR, monitoring all activity and streaming detailed data to the central console in real time. They can also perform some basic signature and behavior based detections on their own. The EDR console is the brain, correlating everything the agents send using complex logic, machine learning, and threat intelligence, and connecting the dots into detections, more commonly called alerts.
When an alert arrives, the analyst acknowledges it and prioritises by the severity the EDR assigns (Critical, High, Medium, Low, or Informational). Opening the alert reveals the executed files and processes, network connections, registry changes, and more, which the analyst uses to decide whether it is a true or false positive before responding from the console. In a real environment, the EDR sits alongside firewalls, DLP, email security gateways, and IAM, all feeding into a SIEM that becomes the analyst's central point of investigation.
Questions and Answers
Which component of the EDR is responsible for collecting telemetry from the endpoints?
Answer:
AgentAgentAn EDR agent is also known as a?
Answer:
sensorsensorTask 5: EDR Telemetry
The data EDR agents collect and push to the console is called telemetry, which the room describes as the black box of an endpoint. Since most endpoint activity is legitimate, the more data collected, the easier it becomes to tell regular and malicious behavior apart.
Key telemetry includes process executions and terminations (revealing suspicious parent and child relationships), network connections (exposing C2 traffic, unusual ports, exfiltration, and lateral movement), command line activity in CMD and PowerShell (catching obfuscated scripts that antivirus often misses), file and folder modifications (tracking data staging, ransomware, and dropped files), and registry modifications, since the registry is a goldmine of Windows configuration data.
Advanced threats often rely on legitimate utilities so each action looks harmless on its own. Viewed together through detailed telemetry, those actions tell a different story, which helps both the EDR's detection engine and the analyst reconstructing the root cause and attack timeline.
Questions and Answers
Which telemetry data helps in detecting C2 communications?
Answer:
Network ConnectionsNetwork ConnectionsWhere are the configuration settings of a Windows system primarily stored?
Answer:
registryregistryTask 6: Detection And Response Capabilities
On the detection side, an EDR layers several techniques. Behavioral detection flags suspicious patterns like a Word document spawning PowerShell. Anomaly detection learns each endpoint's baseline and flags deviations, such as an unusual auto start registry change. IOC matching compares hashes and other indicators against threat intelligence feeds. MITRE ATT&CK mapping tags every detection with a tactic and technique, for example Persistence via Scheduled Task/Job. Finally, machine learning models trained on large datasets catch chains of individually harmless actions, which is how fileless and multi stage intrusions are often found.
On the response side, an EDR supports both automated policies and manual actions. Analysts can isolate a host to stop lateral movement, terminate a process when isolating a business critical machine would cause more harm than the threat, quarantine malicious files for later review, use remote access (such as CrowdStrike Falcon's Real Time Response console) to run commands and scripts directly on the endpoint, and perform artefact collection to pull memory dumps, event logs, specific folders, or registry hives for forensics without physical access to the device.
Questions and Answers
Which feature of the EDR helps you identify threats based on known malicious behaviours?
Answer:
IOC MatchingIOC MatchingTask 7: Investigate an alert on EDR
In this scenario, we play a SOC analyst at TECH THM with access to an EDR console holding several medium and high severity detections. The goal is to triage each detection using only the information the EDR provides. Acknowledging alerts and taking response actions is out of scope here, so the focus is entirely on reading and understanding the visibility the EDR offers.
Guided Walkthrough: Triaging Detections in the EDR Dashboard
Click the View Site button to open the static EDR dashboard in the split screen, or open the EDR Dashboard link from the URL section to view it in full screen. The Recent Detections table lists four detections, each with its severity, detection name, date, host, and acknowledgement status, plus an arrow in the Details column that opens the full detection.
The first two questions concern DESKTOP-HR01, so click the details arrow on the top row, the high severity Initial Access via Malicious Office Document detection.
The detection opens on the Summary tab, which gives a plain language overview of what happened. A macro enabled document called invoice.docm was opened in WINWORD.EXE, the document triggered CMD, and CMD launched a tool that downloaded a payload which was saved to disk but never executed. The tab also shows the affected user, host, timestamp, and severity, which is a quick way to get oriented before digging into the details.
Switch to the Process Info tab to see the Process Chain on the left. The chain starts at WINWORD.EXE, moves to CMD.EXE, and the process directly below CMD.EXE is the download tool the first question asks about, sitting just above the INSTALL.EXE payload it fetched. Clicking any node shows its path, command line, parent process, hash, user, and threat intel in the panel on the right.
For the second question, open the IOC/Indicators tab. The Associated Indicators of Compromise table lists every indicator tied to the detection, including the dropped file name, the C2 domain, the external IP address, and hashes. The first File Path row, sourced as a suspicious binary, holds the full absolute path where the payload was saved, which lines up with the summary's note about a public folder.
Questions three and four move to WIN-ENG-LAPTOP03. Head back to the dashboard and click the details arrow on the second row, the high severity Credential Dumping via LSASS Memory Access detection.
Open the Process Info tab and click the second node in the process chain, syncsvc.exe, which sits between explorer.exe and lsass.exe. Its command line shows it dumping the memory of lsass.exe to disk, it is unsigned, and threat intel matches it to a known credential dumping tool. The Path field near the top of the panel answers the third question, and the location alone is a red flag, since a legitimate service would not run from a user's temporary folder. For the fourth question, scroll down to the Network Activity section, where the Attempted exfil to entry shows the full URL. Notice how the domain imitates a well known file sharing service to blend in with normal traffic.
For the final question, return to the dashboard once more and click the details arrow on the third row, the medium severity Execution from AppData Directory detection on DESKTOP-DEV01.
Open the Process Info tab and click the second node in the process chain, UpdateAgent.exe. At first glance it looks suspicious: it is unsigned, runs from a user's AppData\Roaming folder, and makes an outbound HTTP connection. However, the connection goes to an internal IP address, and the Threat Intel field on the right tells us how the file has been labelled. This detection is a good reminder that not every alert is malicious, and that threat intelligence context can quickly help an analyst confirm a false positive.
Questions and Answers
Which tool was launched by CMD.exe to download the payload on DESKTOP-HR01?
Answer:
CURL.exeCURL.exeWhat is the absolute path to the downloaded malware on the DESKTOP-HR01 machine?
Answer:
C:\Users\Public\install.exeC:\Users\Public\install.exeWhat is the absolute path to the suspicious syncsvc.exe on the WIN-ENG-LAPTOP03 machine?
Answer:
C:\Users\haris.khan\AppData\Local\Temp\syncsvc.exeC:\Users\haris.khan\AppData\Local\Temp\syncsvc.exeOn which URL was the exfiltration attempt being made on WIN-ENG-LAPTOP03?
Answer:
https://files-wetransfer.com/upload/session/ab12cd34ef56/dump_2025.dmphttps://files-wetransfer.com/upload/session/ab12cd34ef56/dump_2025.dmpWhat was UpdateAgent.exe labelled by Threat Intel on DESKTOP-DEV01?
Answer:
Known internal IT utility toolKnown internal IT utility toolSummary & Key Takeaways
That wraps up Introduction to EDR, the first stop in the Core SOC Solutions module. EDR is often the tool an analyst opens first when an endpoint alert fires, so understanding its architecture, telemetry, and capabilities pays off in almost every investigation that follows.
Key lessons:
- An EDR protects endpoints wherever they are, built on the three pillars of visibility, detection, and response
- Unlike signature based antivirus, an EDR monitors behavior and can catch attacks that abuse legitimate processes
- Agents (also called sensors) collect telemetry on each endpoint, while the central console correlates it into alerts
- Process, network, command line, file, and registry telemetry together let analysts reconstruct the full attack chain
- Response actions like host isolation, process termination, quarantine, remote access, and artefact collection are all available from the console
- An EDR is a host only solution, so it works best alongside other tools feeding into a SIEM
Next up is Introduction to SIEM, where we see how a SIEM collects and correlates logs from across the network into a single place for investigation. Click the banner below to check it out!