# Stop the attack. *Fix how it got in.* EDR response and remediation that takes endpoints *from attack to recovery* Shrink attacker dwell time and contain the blast radius before an active incident spreads. Isolate compromised endpoints, terminate malicious activity, recover affected files, and use built-in UEM to patch vulnerabilities, remove risky software, and close the same exposure across your endpoint fleet. **Live response** Malicious document found vendor_form.docm carries an embedded macro dropper. Incident: incident-2841 ## Detection finds the threat. Response contains it. Remediation removes it. Once an incident is confirmed, Endpoint Central EDR gives analysts the actions needed to isolate affected endpoints, terminate malicious processes, remove malicious files, and recover from ransomware activity. Response does not end when the process stops. Remediation continues until the threat is removed, the endpoint is recovered, and it is safe to return to operation. ## Find with EDR. Fix with UEM. Investigate what happened, contain the affected endpoint, neutralize malicious activity, and complete remediation without breaking the response workflow. Endpoint Central brings the actions analysts need into the same incident context. ```text incident-2841 · response.log 00:00.012 [EDR] Attack chain reconstructed 00:00.024 [RESPONSE] Endpoint isolated 00:00.038 [RESPONSE] Malicious process terminated 00:00.061 [RESPONSE] Malicious file removed 00:00.940 [RECOVERY] Protected files restored 00:01.310 [VALIDATE] Endpoint returned to operation 00:02.140 [UEM] Exploited vulnerability patched ``` ### See the whole attack, not just the alert **EDR · Find** - Hunt across endpoint telemetry for suspicious activity - Reconstruct the attack chain and identify its root cause - Correlate behavioral analytics, IoCs, and MITRE ATT&CK TTPs - Determine which endpoints and assets are affected Telemetry window · 30 days ### Cut the attack off at attack speed **EDR · Contain** - Isolate compromised endpoints in one click - Terminate malicious processes remotely - Remove confirmed malicious files - Interrupt ransomware before further encryption Time to isolate · < 30ms ### Close the door the attacker walked through **UEM · Fix** - Patch exploited vulnerabilities across the fleet - Update, uninstall, or restrict risky applications - Correct insecure endpoint configurations - Deploy custom scripts for environment-specific fixes Fleet reach · 1 → many ## Respond at every stage of the incident Endpoint Central maintains the path from the first suspicious signal to a remediated and operational endpoint. 1. **Detect** — Identify suspicious behavior, malicious files, and ransomware activity. 2. **Investigate** — Reconstruct the attack chain, establish root cause, and assess impact. 3. **Contain** — Isolate compromised endpoints before the attack moves laterally. 4. **Neutralize** — Terminate malicious processes and remove confirmed malicious files. 5. **Remediate** — Patch vulnerabilities, remove risky software, and harden configurations. 6. **Recover** — Restore affected files using protected backup copies. 7. **Validate** — Confirm that remediation is complete before returning the endpoint to normal operation. ## Contain the threat. Remediate the endpoint Isolate compromised endpoints, terminate malicious activity, remove confirmed malicious files, and interrupt ransomware before the attack can progress further. ### Isolate compromised endpoints Cut affected devices off from the wider network to restrict lateral movement and attacker communication while remediation is carried out. ### Terminate malicious processes Stop active processes associated with the incident before they can execute additional payloads, establish persistence, or continue encryption. ### Remove malicious files Eliminate confirmed malicious files from affected endpoints and prevent the same artifact from continuing to operate. ### Recover ransomware-affected files Interrupt malicious encryption, then restore the files it reached so the endpoint comes back with its data intact rather than merely contained. ## Turn threat hunting findings into response. When a hunt uncovers suspicious activity, turn the finding into an incident and move directly into investigation, containment, and remediation. Schedule validated hunting conditions to surface recurring behavior for analyst action. ### Detect recurring attacker behavior Turn validated hunting conditions into scheduled monitoring so similar suspicious activity is surfaced for investigation without repeating the hunt manually. 1. Search telemetry 2. Identify suspicious activity 3. Create an incident 4. Investigate 5. Respond and remediate ## Go beyond cleanup. Fix what made the attack possible. Containment stops what the attacker is doing now. UEM-powered remediation closes the endpoint weakness that allowed the attack to happen. Endpoint Central connects security investigation with the endpoint controls needed to complete the fix. | What the incident revealed | Immediate EDR response | Endpoint Central remediation | |---|---|---| | A specific CVE was exploited | Isolate the endpoint and stop malicious activity | Deploy the applicable CVE patch and enforce relevant Attack Surface Reduction (ASR) rules across exposed endpoints | | Vulnerable or unauthorized software enabled execution | Terminate associated processes | Update, uninstall, or restrict the application | | An insecure configuration enabled persistence | Remove the malicious artifact | Deploy a hardened configuration | | A removable device introduced the threat | Remove the malicious file | Restrict the device or enforce the required removable-media policy | | Environment-specific changes require cleanup | Contain the affected endpoint | Execute a custom remediation script or configuration | | Ransomware began encrypting files | Stop the responsible process and isolate the device | Restore protected files and validate endpoint recovery | EDR tells you how the attacker succeeded. *UEM helps ensure the same path is not left open.* ## Remediate beyond the compromised endpoint. An incident on one endpoint can expose the same weakness across many more. Use what the investigation revealed to find similarly exposed devices, apply the required remediation at scale, and verify that the exposure has been closed. ### Find exposed endpoints Identify devices affected by the same vulnerability, application, configuration, or endpoint condition. Respond to the compromised endpoint. Remediate every endpoint exposed to the same attack path. ## EPP prevents. EDR investigates. UEM remediates. Endpoint Central unifies EPP protection, EDR threat hunting, and UEM remediation through a single lightweight agent. Instead of treating prevention, response, and endpoint operations as separate workflows, every layer contributes to one coordinated security outcome. ### Prevent **EPP · Layer 1** Prevent threats before execution. Block known and unknown malware, ransomware, exploits, and malicious behavior. ### Detect & investigate **EDR · Layer 2** Detect and investigate threats that require deeper analysis. Collect endpoint telemetry, correlate behavioral analytics and TTPs, hunt for suspicious activity, reconstruct attacks, and contain incidents. ### Remediate **UEM · Layer 3** Remediate the endpoint conditions behind the incident. Patch specific CVEs, update or remove risky software, enforce ASR rules, harden configurations, and apply the fix across the fleet. ### One lightweight agent All three layers ship through a single endpoint agent and console. Prevent with EPP. Find and contain with EDR. *Fix and harden with UEM.* ## What is EDR response and endpoint remediation? EDR response and endpoint remediation is the process of containing an active endpoint threat, eliminating the malicious files and processes involved, fixing the weakness that enabled the attack, and safely restoring the device to operation. Containment limits immediate damage. Threat neutralization removes malicious activity. Endpoint remediation addresses vulnerabilities, risky software, insecure configurations, and other underlying conditions so the endpoint is not left exposed to the same attack path. ## Frequently asked questions. ### What response actions can Endpoint Central EDR perform? Endpoint Central EDR can isolate compromised endpoints, terminate malicious processes, remove confirmed malicious files, contain ransomware activity, and restore affected files. Analysts can then use built-in UEM capabilities to patch vulnerabilities, remediate applications, harden configurations, restrict endpoint resources, and deploy custom remediation scripts.