Managed EDR
CROWDSTRIKE FALCON · MICROSOFT DEFENDER · ELASTIC DEFEND
Managed EDR is our endpoint scope: policy and prevention tuning, behavioural detections at process and memory level, endpoint hunting and active response up to isolation. Examples are CrowdStrike Falcon, Microsoft Defender for Endpoint or Elastic Defend.
What sets this service apart: this is where the fastest response levers live. A host can be taken off the network in minutes, a process killed, a file rolled back. That is exactly why the mandate matrix matters most here.
Typical detections
- Abuse of legitimate system tools (LOLBins)
- Ransomware precursors: shadow copy deletion, mass encryption, backup sabotage
- Credential dumping directly on the host
- Persistence established right after initial access
- EDR tampering and sensor deactivation
- Hands-on-keyboard activity following initial access
Response actions within mandate
- Host isolation within minutes
- Process kill and file quarantine
- Rollback where the platform supports it
- Blocklisting of hashes and binaries
- Example mandate: auto isolation on critical verdicts for standard clients, analyst-in-the-loop for servers and OT-adjacent systems
Limits of this service
- Managed endpoints with an agent only, OT, IoT, printers and BYOD stay invisible, that is Managed NDR
- No view of the cloud control plane or identity layer, that is Managed IDR or Managed XDR
- Without a SIEM scope there is no long-term retention and no custom parsing of your own applications
SLAs
Included
- Policy and prevention tuning on the endpoint platform, including hardening against known bypass techniques
- Custom behavioural detections on endpoint telemetry plus targeted endpoint hunting
- Agent coverage management: deployment gaps, outdated sensors, tamper protection status
Not included
- Platform and agent licences (yours, or passed through at cost)
- Anti-ransomware (e.g. Halcyon) as a separate add-on module
- Eradication and recovery inside your systems, executed by your IT with our coordination
- Use case/playbook development and log source integration, those come with a Managed SIEM or Managed NDR scope
Process
- Assess
Deployment coverage, policy review, prevention baseline against known bypass techniques.
- Integrate
Rollout to remaining endpoints, policy hardening, custom behavioural detections, connection to the SOC pipeline.
- Automate
Isolation and process kill pre-authorised by asset criticality, playbook per detection, SOAR enrichment.
Deliverables
- Endpoint coverage report: agent distribution, gaps, sensor health
- Policy and prevention hardening report with open recommendations
- Root cause analysis per true positive including kill chain
FAQ
Do you isolate endpoints without asking?
Only within the mandate you define. Asset criticality and pre-authorised actions are agreed during onboarding, for example automatic isolation on critical verdicts for standard clients and analyst-in-the-loop for servers.
Do you work with our existing EDR licence?
Yes. We take over the existing platform, review coverage and policy maturity and say openly when a switch delivers more value than further tuning.
Included in every ANOMAL managed service
- 24/7 threat monitoring: every alert is picked up, enriched with context and documented in the ticket system
- Incident triage on every severity from low to critical, classified as false positive, benign true positive or true positive
- Further analysis on every suspected true positive, including log, telemetry and asset context
- Incident response along NIST: containment and first response within your mandate. A full IR engagement for a major incident is billed separately.
- SOC platform operations: backend, updates and health monitoring of the SOC stack
- Automated incident response: SOAR enrichment, automated queries, pre-authorised response actions per mandate
- Threat hunting and threat intelligence (e.g. MISP plus external feeds) feeding back into detections
- Effectiveness testing once a year, e.g. together with an external purple team
- Service management: monthly service efficiency report, quarterly optimisation meeting, live view in ANOVIEW
- Ongoing operations: continuous tuning, detection maintenance and quarterly service optimisation
Scope, service level (e.g. business hours for low to high, 24/7 for critical) and volumes differ per environment. That is why there is no list price: every customer gets a dedicated quote with defined scope, service level and response mandate. With Managed SIEM and Managed NDR the scope additionally covers use case and playbook development as well as log source integration and management.
Let's talk about Managed EDR.
30 minutes with our SOC team. You describe your situation, we tell you clearly whether and how we can help.
More managed services
We run your SIEM and keep it sharp: we connect new log sources, build detection rules and maintain them.
We monitor traffic inside your network and detect lateral movement and connections to attacker infrastructure. The signals flow straight into our cases.
We correlate signals from endpoint, identity, cloud, email and network. Everything lands in one case with one response path.
We protect your accounts in Entra ID, Okta and Active Directory. We detect suspicious sign-ins and stolen credentials early and revoke affected sessions automatically.