Environment
- EDR Server: 7.5.0 and Higher
Question
Why does an alert for an IOC trigger for one endpoint when multiple endpoints are affected?
Answer
Only one alert triggers so that the Triage Alerts page of the EDR UI is not cluttered with the same alert, thereby increasing the opportunity that a more significant alert would be missed.
Additional Notes
The additional endpoints that received the alert can be found in the details of the process in the Process Analysis page.