Just Published! Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

EDR: What is the order of priority for event ingestion?

EDR: What is the order of priority for event ingestion?

Environment

  • EDR Server: All Supported Versions

Question

How does EDR prioritize incoming data from sensors?

Answer

The order of priority for event ingestion is as follows:
  1. Tamper Events 
  2. Events data (regmods, netconns, etc.) 
  3. Binary data 

Labels (1)
Tags (2)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎03-04-2021
Views:
325
Contributors