Huntress explains how EDR telemetry powers managed security investigations, contrasting managed vs. unmanaged EDR approaches. The post walks through real-world investigation examples: a tech support scam caught via browser history and notepad artifacts, an Akira ransomware incident traced back four days via Windows Defender logs, and a RedCurl APT campaign spanning three Canadian organizations discovered through historical telemetry. Key themes include how human-led SOC teams derive meaning from telemetry, the value of forensic artifacts like browser history and Windows event logs, and how investigations answer questions about attack origin, extent, and broader impact.
Table of contents
The role of telemetry data in managed versus unmanaged EDRWhat leads up to an investigation?The value of investigations for you1 Impression