← All Netgraph solutions
EDR / EPPDetect & Respond

One agent. Thirteen modules. Every platform.

Netgraph's Unified Endpoint Agent is a single cross-platform Rust binary for macOS, Linux and Windows, built from 13 composable modules — telemetry, netcollect, osquery-bridge, dspm, uem, yara and more. It streams rich open-schema OCSF telemetry, scores behaviour on-host with an ONNX model, runs EPP anti-malware and YARA scans locally, and inventories the whole machine — while its detections land in the same central alert queue the rest of the platform triages.

macOSLinuxWindows13 Rust modules2,600+ YARA rulesOCSF open telemetryOn-host ONNX scoringEDR + EPP + UEM in one

What is EDR (Endpoint Detection & Response)?

EDR continuously records what happens on laptops, servers, and workloads — processes, network connections, file and registry changes — detects malicious behaviour on-host, and gives responders remote containment: isolate the machine, kill the process, quarantine the file. Netgraph's unified agent combines EDR telemetry, on-host behavioural scoring, and EPP anti-malware in one install, and streams everything into the same knowledge graph the rest of the SOC queries — so an endpoint alert arrives already connected to the identity, network, and vulnerability context around it.

What ships in the module

EDR, EPP and UEM — one binary, no agent sprawl.

01

Open-schema telemetry

Process, file, network, audit and file-integrity monitoring (FIM) events, normalised to OCSF — plus local user-account discovery that feeds the identity registry. Your endpoint data, in an open schema you can query anywhere.

02

Behavioural scoring on-host

An ONNX behavioural model scores endpoint activity locally, with the runtime auto-provisioned via brew, apt or winget — no manual dependency chase per platform.

03

EPP anti-malware

ClamAV integration with auto-install and signature-DB management, optional Bitdefender alongside. Scan detections flow to central Alerts as source “EPP Scan”, and quarantined files sit in a 30-day-TTL queue managed from the Fleet Manager Quarantine tab.

04

2,600+ YARA rules

Rules imported from elastic/protections-artifacts are compiled and tested server-side, deployed to endpoints over a dedicated yara channel, and scanned on-host with yara-x — content-managed, not hard-coded.

05

OSQuery, for real

Real osqueryi execution with query packs — results come back as task rows and fold into the security knowledge graph, so a fleet-wide SQL question becomes graph context.

06

On-host DSPM

Path-scoped sensitive-data discovery runs on the endpoint itself — only classification labels leave the host, never the data. Out-of-box recognizers cover Aadhaar, PAN, bank, passport and health identifiers.

07

Full UEM inventory

Hardware, software, patch, kernel, application, plug-ins, dependencies and licenses — per-asset profiles reused by the Asset Register (incremental 30-minute sync) and as a UEBA posture risk factor.

08

Process-tree forensics

Reconstruct the full parent–child process tree behind any detection, with ATT&CK technique tagging — so triage starts from lineage, not a lone event.

09

Fleet management

Enrollment tokens, policy, tasking and stale-endpoint lifecycle, plus ad-hoc actions — scan · isolate · inventory · live response — all from the Endpoint Fleet Manager.

Signal quality, engineered

Detections that survive restarts, upgrades — and Monday morning.

EDR detections write straight into the central alerts table and get auto-triaged by the L1 autopilot. Before they ever reach an analyst, the EDR Rules & Suppression console shapes the volume: per-rule enable / aggregate / threshold / suppress config, with alerts aggregated per (rule, window) and unique hosts tracked — one aggregate alert instead of a flood.

  • Per-rule config that survives upgrades — enable, aggregate, threshold, suppress.
  • Aggregation per (rule, window) keeps unique-host context in a single alert.
  • Resilient comms: heartbeat with timeout and pool hygiene self-heals after manager restarts; an offline spool covers the gaps.
  • Upgrade-in-place preserves endpoint identity — no re-enrollment churn.

Functionality map

Module functions at a glance

FunctionWhat it doesWhere it lives
Endpoint telemetryOCSF process / file / network / audit / FIM streams plus local user-account discoveryEDR ▸ Telemetry
Analysis & forensicsProcess-tree reconstruction with ATT&CK technique tagging and behavioural verdictsEDR ▸ Analysis
VisibilityFleet-wide endpoint visibility over the same open telemetryEDR ▸ Visibility
Rules & SuppressionPer-rule enable / aggregate / threshold / suppress; aggregation per (rule, window) with unique-host trackingEDR ▸ Rules & Suppression
YARA rules2,600+ rules compiled and tested server-side, deployed over the yara channel, scanned on-host with yara-xEDR ▸ YARA Rules
Fleet ManagerEnrollment tokens, policy, tasking, stale lifecycle, ad-hoc actions (scan · isolate · inventory · live response), Quarantine tabFleet ▸ Endpoint Fleet Manager
EPP anti-malwareClamAV auto-install + signature-DB management, optional Bitdefender; detections → central Alerts (“EPP Scan”)Agent EPP module + central Alerts
UEM inventoryHardware / software / patch / kernel / app / plug-in / dependency / license profiles, synced to the Asset Register every 30 minutesAgent UEM module → Asset Register

Common questions

EDR / EPP — asked and answered

Does the Netgraph EDR agent cover Windows, Linux, and macOS?+

Yes — one cross-platform agent for all three, shipping rich telemetry, on-host behavioural scoring, AV/EPP with quarantine, 2,600+ YARA rules, OSQuery, file-integrity monitoring, live response, and centralised fleet management.

Can I use Netgraph EDR without the full SIEM?+

Netgraph modules are licensed individually with module-level gating, but they gain the most value together: EDR detections land in the same alert queue and knowledge graph that the agentic SOC, NDR, and UEBA read, which is what makes cross-domain correlation automatic.

How does EDR data feed incident response?+

Every endpoint event becomes a node with edges on the security knowledge graph. When an alert fires, the L1/L2 SOC agents traverse from the alert to the host, the identity, the CVE, and the technique in one query — and containment actions (isolate host, kill process) run as gated playbooks with human-in-the-loop approval.

See it live

Enroll one endpoint. Retire three agents.