inklap

METHODOLOGY FOR TESTING THE CAPABILITIES OF SOFTWARE SOLUTIONS ENDPOINT DETECTION AND RESPONSE (EXTENDED DETECTION AND RESPONSE)

Roman Shtonda, Oleksii Cherednychenko, Denys Fomkin, Olena Bokii, Pavlo Kutsaiev · Cybersecurity: Education, Science, Technique · 2025

In the conditions of modern cyberspace, Endpoint Detection and Response (Extended Detection and Response) software solutions are the key to cyber protection. These solutions play a key role in the cyber protection of end devices operating in information and communication systems and electronic communication networks. However, the effectiveness of these solutions can vary significantly. That is why a comprehensive approach to testing their capabilities is necessary, which will allow them to be effectively evaluated. This article discusses the methodology for testing the capabilities of Endpoint Detection and Response (Extended Detection and Response) software solutions. Testing Endpoint Detection and Response (Extended Detection and Response) software solutions is carried out according to the following methods proposed by the authors of the article: checking organizational issues; checking the capabilities of installation, removal, and operation in the system; checking the configuration, editing of policies and rules; checking console functions; checking the management of threat indicators, detection, response and blocking of threats; checking the capabilities of analysis and data

📖 افتح في inklap 🔗 DOI 📮 اطلب بحثاً