VIPRE Endpoint EDR+MDR Overview

What is VIPRE EDR+MDR?

Written By Marissa Fegan (Super Administrator)

Updated at October 1st, 2024

VIPRE’s Endpoint EDR+MDR services offer comprehensive endpoint protection by combining advanced detection, response capabilities, and 24/7 monitoring. EDR brings AI-driven threat detection, next-gen antivirus, and remote forensic tools to quickly investigate and mitigate threats. MDR adds proactive incident response, offering continuous monitoring, network isolation, forensic analysis, and full incident remediation. Together, EDR+MDR ensures fast, coordinated defenses against evolving cyber threats, providing robust protection through user-friendly management consoles.

What is VIPRE EDR+MDR capable of?

EDR capabilities include:

  • All the next-generation anti-malware, anti-virus, and anti-threat capabilities included in VIPRE Endpoint Security Cloud and Server, including AI-driven malware detection, network intrusion detection, DNS protection, web exploit detection, and anti-spam engines
  • Additional advanced threat detection and correlation engines that combine raw events, security events, and contextual data to identify zero-day, living-off-the-land, and grey zone threats not detectable by classic next-gen AV
  • The VIPRE Endpoint Web Access Control add-on, which provides policy-based access control to selected website categories to address compliance and duty-of-care concerns
  • A clean and seamless incident investigation capability that surfaces relevant information and actionable data to first responders
  • Application scanning to determine the risk profile of the endpoint and any potential vulnerabilities
  • A remote shell that provides instant access to allow investigators to perform detailed forensic analysis on the endpoint; no installer required
  • Supplemental in-situ investigation with sandbox-based forensic threat analysis granting detailed insights into potential malware behavior.
  • The ability to quickly and easily isolate threats that may reside on endpoints by preventing all network access to/from the endpoint
  • Rapid response through built-in tools, including Vulnerability & Patch Management, remote process control, and remote file management

All of these capabilities are provided within a responsive console that can be used from anywhere, even while on the go, and supports the seamless exploration of all data through a deeply linked UI.

MDR includes:

  • 24/7 monitoring and incident coverage
    • Our team of security experts will monitor your console 24 hours a day, seven days a week, 365 days a year to react to any new incidents, and then will quickly triage, investigate, and provide remediation
  • Incident response
    • After your initial onboarding, we will handle proactive incident response, including forensic analysis, containment, and remediation by the VIPRE team leveraging our Remote Shell and other technologies; detected artifacts will be fully analyzed in sandbox environments to extract additional IoCs for further investigation and to support additional hardening
  • Quarterly security reports
    • We will keep you informed about longer-term trends in your organization's security and highlight the value of this solution while ensuring that your environment and security solution are kept in tip-top shape and operating effectively
  • IT security experts 
    • Our IT Security experts handle dozens of incidents daily, along with a friendly Support team to ensure you don’t run into problems

Leverage VIPRE's EDR+MDR solution to ensure no threat to your environment is missed and to help you reduce attack spread and dwell time while saving your internal team time and money.

Features and Benefits

Feature Benefit The VIPRE Difference
Onboarding We'll work with you to deploy VIPRE EDR+MDR to your environment and ensure that all agents are configured and operating correctly.
  • Verify agents at customer site
  • Test that incidents are detected and created correctly
  • Gather customer contact/escalation info
  • Gather information on baseline security posture
24x7x365 Monitoring and Tech Support

Our security analysts will monitor your instance of VIPRE EDR+MDR on a 24/7/365 basis for any new incidents.

 

We'll also provide support to you for all EDR+MDR product-related issues.

  • Monitoring and assignment of new Incidents to response teams
  • Reactive response to customer-reported product issues
  • Internal escalation for resolution as required
Incident triage Expert IT security personnel will review all incidents and ensure that they are properly handled, closing false positives or escalating any unhandled threats to the response team.
  • Handle and analyze new inbound Incidents
  • Perform a quick analysis to identify obvious FPs and potential threat impact
  • Internal assignment and escalation
False Positive/True Positive Analysis We'll establish if an alert is a false positive after analysis and close the alert; in case of a true positive, a ticket will be generated and escalated to you.
  • More intensive analysis by Tier 2 team to weed out false positives or clarify potential threat impact
  • Adjustments to incident status and severity, plus early identification of potential targets and threat artifacts 
Incident Enrichment We'll review incidents and attach contextual information gleaned from Open-source Intelligence (OSINT) sources.  
  • Pull indicators of compromise (IoCs) from the Incident and research within known threat databases to identify attack type, source, etc
  • Annotate the Incident with any significant findings
Analyst notes, remediation, and recommendations as needed Human analyst insight is added to each Incident as part of our initial triage and analysis.
  • Human review of Incident to identify significant malicious activity within processes, network connections, files, etc
  • Perform remediation to clean up any threat on the endpoint along with any further recommendations
  • Annotation of Incident with these insights
Quarterly Executive Reporting We'll provide a quarterly executive summary of activity within the EDR+MDR service, including incident summaries, environment changes, and long term trends.
  • Analyst reviews customer history and prepares report
  • Incident metrics and retrospectives
  • Overall threat trends and observations
  • Environmental recommendations
Service Level Agreements (SLA) The agreed time within which customers will be notified of any new incidents, broken out into separate SLAs for initial incident acknowledgment/assignment; for incident response, and for responding to customer requests for clarification.
  • SLAs are set based on Incident status and severity
  • SLAs fully defined in the Statement of Work associated with this service

 

Why VIPRE?

VIPRE Security Group puts more than twenty years of advanced security intelligence, cutting-edge machine learning, real-time behavioral analysis, and a comprehensive threat intelligence network to work defending against known and unknown attacks. Our supportive approach to EDR+MDR is suitable for all small to medium-sized businesses.

  • The Best Protection at the Best Price – VIPRE EDR+MDR is consistently ranked in the top tier alongside other market leaders in comprehensive independent tests
  • Ease of Use - VIPRE’s intuitive solutions make it easier to secure your endpoints from ransomware and other threats
  • Rapid Deployment - We can quickly deploy VIPRE EDR+MDR with minimal disruption to day-to-day activities
  • Reduced Downtime - VIPRE enables both speed and security, protecting you from malware without slowing down any processes
  • Industry leading Support - included with all of our solutions is access to our award-winning, highly qualified global tech support team with a consistent 90%+ CSAT rating.

VIPRE Endpoint EDR+MDR is an important solution to ensure that your endpoints are protected against malware, remote compromise, and insider threats. EDR solutions require expert attention to achieve the best value and provide complete protection. VIPRE EDR+MDR provides an outsourced management layer to ensure you get the best protection from your EDR solution. 

To detect and respond instantly to endpoint threats with next-generation EDR+MDR and antivirus technology built for SMEs and the partners that serve them, you can find more detailed information on the VIPRE website.

Onboarding - What to Expect

Our team of experts will work closely with you to ensure a seamless deployment and integration of our solution into your infrastructure. 

We'll verify all service agreements during the deployment call and review the product, including all options, with you. You'll also have the opportunity to address any questions or concerns you may have during our scheduled deployment call.

Important! 

Monitoring and incident response begins only once the onboarding session is completed. If you do not receive your onboarding email then reach out to our Support team for help.