← All Netgraph solutions
EDR / EPPDetect & Respond

One agent. Thirteen modules. Every platform.

Netgraph's Unified Endpoint Agent is a single cross-platform Rust binary for macOS, Linux and Windows, built from 13 composable modules, telemetry, netcollect, osquery-bridge, dspm, uem, yara and more. It streams rich open-schema OCSF telemetry, scores behaviour on-host with an ONNX model, runs EPP anti-malware and YARA scans locally, and inventories the whole machine, while its detections land in the same central alert queue the rest of the platform triages.

macOSLinuxWindows13 Rust modules2,600+ YARA rulesOCSF open telemetryOn-host ONNX scoringEDR + EPP + UEM in one

What is EDR (Endpoint Detection & Response)?

EDR continuously records what happens on laptops, servers, and workloads, processes, network connections, file and registry changes, detects malicious behaviour on-host, and gives responders remote containment: isolate the machine, kill the process, quarantine the file. Netgraph's unified agent combines EDR telemetry, on-host behavioural scoring, and EPP anti-malware in one install, and streams everything into the same knowledge graph the rest of the SOC queries, so an endpoint alert arrives already connected to the identity, network, and vulnerability context around it.

What ships in the module

EDR, EPP and UEM, one binary, no agent sprawl.

01

Open-schema telemetry

Process, file, network, audit and file-integrity monitoring (FIM) events, normalised to OCSF, plus local user-account discovery that feeds the identity registry. Your endpoint data, in an open schema you can query anywhere.

02

Behavioural scoring on-host

An ONNX behavioural model scores endpoint activity locally, with the runtime auto-provisioned via brew, apt or winget, no manual dependency chase per platform.

03

EPP anti-malware

ClamAV integration with auto-install and signature-DB management, optional Bitdefender alongside. Scan detections flow to central Alerts as source “EPP Scan”, and quarantined files sit in a 30-day-TTL queue managed from the Fleet Manager Quarantine tab.

04

2,600+ YARA rules

Rules imported from elastic/protections-artifacts are compiled and tested server-side, deployed to endpoints over a dedicated yara channel, and scanned on-host with yara-x, content-managed, not hard-coded.

05

OSQuery, for real

Real osqueryi execution with query packs, results come back as task rows and fold into the security knowledge graph, so a fleet-wide SQL question becomes graph context.

06

On-host DSPM

Path-scoped sensitive-data discovery runs on the endpoint itself, only classification labels leave the host, never the data. Out-of-box recognizers cover Aadhaar, PAN, bank, passport and health identifiers.

07

Full UEM inventory

Hardware, software, patch, kernel, application, plug-ins, dependencies and licenses, per-asset profiles reused by the Asset Register (incremental 30-minute sync) and as a UEBA posture risk factor.

08

Process-tree forensics

Reconstruct the full parent–child process tree behind any detection, with ATT&CK technique tagging, so triage starts from lineage, not a lone event.

09

Fleet management

Enrollment tokens, policy, tasking and stale-endpoint lifecycle, plus ad-hoc actions, scan · isolate · inventory · live response, all from the Endpoint Fleet Manager.

Signal quality, engineered

Detections that survive restarts, upgrades, and Monday morning.

EDR detections write straight into the central alerts table and get auto-triaged by the L1 autopilot. Before they ever reach an analyst, the EDR Rules & Suppression console shapes the volume: per-rule enable / aggregate / threshold / suppress config, with alerts aggregated per (rule, window) and unique hosts tracked, one aggregate alert instead of a flood.

  • Per-rule config that survives upgrades, enable, aggregate, threshold, suppress.
  • Aggregation per (rule, window) keeps unique-host context in a single alert.
  • Resilient comms: heartbeat with timeout and pool hygiene self-heals after manager restarts; an offline spool covers the gaps.
  • Upgrade-in-place preserves endpoint identity, no re-enrollment churn.

Functionality map

Module functions at a glance

FunctionWhat it doesWhere it lives
Endpoint telemetryOCSF process / file / network / audit / FIM streams plus local user-account discoveryEDR ▸ Telemetry
Analysis & forensicsProcess-tree reconstruction with ATT&CK technique tagging and behavioural verdictsEDR ▸ Analysis
VisibilityFleet-wide endpoint visibility over the same open telemetryEDR ▸ Visibility
Rules & SuppressionPer-rule enable / aggregate / threshold / suppress; aggregation per (rule, window) with unique-host trackingEDR ▸ Rules & Suppression
YARA rules2,600+ rules compiled and tested server-side, deployed over the yara channel, scanned on-host with yara-xEDR ▸ YARA Rules
Fleet ManagerEnrollment tokens, policy, tasking, stale lifecycle, ad-hoc actions (scan · isolate · inventory · live response), Quarantine tabFleet ▸ Endpoint Fleet Manager
EPP anti-malwareClamAV auto-install + signature-DB management, optional Bitdefender; detections → central Alerts (“EPP Scan”)Agent EPP module + central Alerts
UEM inventoryHardware / software / patch / kernel / app / plug-in / dependency / license profiles, synced to the Asset Register every 30 minutesAgent UEM module → Asset Register

Common questions

EDR / EPP, asked and answered

Does the Netgraph EDR agent cover Windows, Linux, and macOS?+

Yes, one cross-platform agent for all three, shipping rich telemetry, on-host behavioural scoring, AV/EPP with quarantine, 2,600+ YARA rules, OSQuery, file-integrity monitoring, live response, and centralised fleet management.

Can I use Netgraph EDR without the full SIEM?+

Netgraph modules are licensed individually with module-level gating, but they gain the most value together: EDR detections land in the same alert queue and knowledge graph that the agentic SOC, NDR, and UEBA read, which is what makes cross-domain correlation automatic.

How does EDR data feed incident response?+

Every endpoint event becomes a node with edges on the security knowledge graph. When an alert fires, the L1/L2 SOC agents traverse from the alert to the host, the identity, the CVE, and the technique in one query, and containment actions (isolate host, kill process) run as gated playbooks with human-in-the-loop approval.

See it live

Enroll one endpoint. Retire three agents.