Reviewed September 2026CISA defensive guidance

Operate endpoint security as a detection-and-response system, not merely an installed agent.

An EDR platform only creates defensive value when coverage is known, prevention settings are controlled, telemetry reaches analysts, detections are tested, investigators can reconstruct activity, and containment actions work when an endpoint is compromised. Agent deployment is the beginning of the program, not the finish line.

CISA’s StopRansomware guidance recommends application allowlisting and/or EDR across assets, and CISA red-team findings show the operational value of endpoint telemetry for detecting and investigating malicious activity. This guide focuses on the operating practices required to make that visibility dependable.

Coverage assurance

Know which endpoints are protected, which are reporting, and which are missing.

Reconcile EDR inventory with endpoint management, directory, vulnerability management, cloud workloads, virtualization, server inventory, and asset records. Track workstations, laptops, servers, virtual desktops, developer systems, administrative workstations, and supported cloud instances. A device absent from the EDR console may be decommissioned—or it may be the highest-risk unmanaged system in the environment.

Separate installed, healthy, stale, unsupported, and intentionally excluded states. “Agent installed” is not the same as “telemetry current.” Monitor last check-in, policy assignment, engine version, signature or intelligence freshness, sensor health, tamper-protection state, and whether the endpoint can receive response commands.

Document exclusions with owner, reason, affected controls, compensating protections, and expiration. Performance-sensitive applications and legacy servers often accumulate broad exclusions that quietly eliminate meaningful protection.

Preventive controls

Use endpoint prevention without assuming prevention will catch everything.

Anti-malware and behavior protection

Enable supported prevention capabilities centrally, keep detection content current, and manage policy through controlled configuration. Test that representative malicious or simulated behaviors produce the expected prevention or alert outcome.

Application control

CISA recommends application allowlisting and/or EDR in ransomware defenses. Use application-control policy where operationally feasible, beginning with administrative systems, servers with narrow software profiles, or high-consequence environments.

Tamper protection

Prevent ordinary users and local attackers from disabling sensors, changing policy, unloading protections, or altering security services. Alert on tamper attempts because the event may be an early indication of attacker preparation.

Exploit and script controls

Use platform controls for suspicious scripting, credential theft, office-child-process behavior, exploit mitigation, and known living-off-the-land abuse where supported. Roll out carefully and measure exceptions instead of disabling broad classes of protection after one compatibility issue.

Telemetry

Collect enough endpoint context to reconstruct an attack chain.

Useful telemetry commonly includes process creation and ancestry, command line, file activity, network connections, authentication context, registry or configuration changes, script execution, persistence mechanisms, security-control changes, device identity, user identity, and timestamps. Exact fields depend on platform and product.

Forward high-value EDR events into the central detection platform where correlation with identity, network, cloud, email, and application data adds value. Preserve native console access for endpoint-specific investigation detail that may not be practical to export.

Define retention based on investigation needs and cost. A compromise discovered today may have begun weeks earlier. If endpoint telemetry ages out before analysts can establish initial access and lateral movement, the organization loses one of EDR’s primary benefits.

Detection engineering

Validate endpoint detections against behavior you actually care about.

Credential access

Test coverage for suspicious credential-store access, dumping behavior, token theft, LSASS access where relevant, browser credential abuse, and attempts to obtain privileged material. Map the alert to an investigation path and containment authority.

Execution and persistence

Validate alerts for suspicious PowerShell or shell execution, scheduled tasks, services, startup mechanisms, remote administration abuse, unsigned binaries in sensitive locations, and unusual parent-child process relationships.

Ransomware behaviors

Use safe simulations to test mass file modification, shadow-copy or recovery inhibition, security-control tampering, suspicious remote execution, and precursor malware behavior. Never wait for a real ransomware event to discover isolation or alerting does not work.

Lateral movement

CISA has highlighted EDR’s value for visibility into endpoint network connections. Correlate unusual remote-service use, administrative shares, remote shells, RDP, SMB, WinRM, SSH, or management tooling with identity and network context.

Investigation

Give analysts a repeatable endpoint triage workflow.

Start with alert context, process tree, user, device, observed command line, file hashes, network destinations, prevalence, parent process, signer, and nearby events. Determine whether the activity is expected administration, authorized testing, commodity malware, credential compromise, hands-on-keyboard intrusion, or another condition requiring escalation.

Expand beyond the single endpoint. Search for the same hash, domain, command, account, persistence mechanism, remote connection, or parent-child pattern across the fleet. A detection on one host can be the visible edge of a broader intrusion.

Preserve evidence before destructive remediation where incident severity requires it. Coordinate forensic collection, volatile evidence, disk or memory acquisition, legal requirements, and business continuity with the incident-response process rather than letting an analyst erase the only useful artifacts while trying to clean the host.

Containment and recovery

Pre-authorize the response actions analysts need under pressure.

Network isolation

Test endpoint isolation and document what communication remains possible afterward. Ensure security tooling, management, forensics, and emergency business requirements still work as designed while attacker-controlled traffic is restricted.

Process and file response

Define when analysts may terminate malicious processes, quarantine files, block hashes or indicators, remove persistence, or initiate scans. High-impact automated actions should account for false-positive and availability risk.

Identity response

Endpoint containment does not invalidate stolen credentials or sessions. Coordinate password reset, token revocation, account disablement, privilege review, and phishing or identity investigation when endpoint evidence indicates credential access.

Rebuild criteria

Define when cleaning is insufficient and a trusted rebuild is required. For high-confidence attacker persistence, administrative compromise, root-level access, or uncertain system integrity, restoring from a known-good baseline may provide stronger assurance than piecemeal remediation.

Program measures

Measure defensive coverage and response reliability.

90-day implementation

Prove the endpoint control loop before adding more dashboards.

Days 1–30

Reconcile endpoint inventory, fix missing or unhealthy sensors, define core prevention policy, review exclusions, and identify the endpoint classes with the highest business consequence.

Days 31–60

Validate credential-access, persistence, ransomware, and lateral-movement detections; integrate high-value telemetry with the SIEM; and test isolation, evidence collection, and identity-response handoffs.

Days 61–90

Measure sensor health, detection-test coverage, response time, exception aging, and repeat compromise. Tune noisy detections and document rebuild criteria and analyst authority.

Continue learning

Related guides after Endpoint Security & EDR Operations

Follow the next implementation topic without returning to search.

Put this guide to work

Turn Endpoint Security & EDR Operations Program Guide | Zeph Tech into a decision-ready next step.

Use the source-backed research to pressure-test assumptions, then build a reusable evaluation brief before you compare products, scope implementation, or request a fit review.