Components
Components
Section titled “Components”XDR Forensics is a cloud-based, client-server solution that allows you to remotely perform various tasks on assets such as collecting forensic evidence and performing threat hunts with YARA, Sigma, or osquery.
1. Management Console
Section titled “1. Management Console”Management Console is a web-based application that can be viewed from any device with an up-to-date browser.
2. XDR Forensics Responders
Section titled “2. XDR Forensics Responders”Assets are connected to the management console via a lightweight “passive” responder that can be deployed manually or via other mechanisms such as SCCM.
2.1. Passive Responder Explained
Section titled “2.1. Passive Responder Explained”XDR Forensics responders;
- DO NOT scan anything on the asset that may cause slowdowns (e.g. your Antivirus),
- DO NOT block anything on the asset that may cause false positives (e.g. your DLP),
- DO NOT create any alerts that may cause “alert fatigue”.