EDR Connect
The EDR Connect feature opens a console that provides direct access to an EDR-protected device running a v5.2 Windows Collector through a remote Shell connection. This enables you to respond to incidents immediately and to perform in-depth investigation by running commands and scripts on the device, collecting and downloading forensic data from the device, remediating threats, and so on.
An EDR Connect console can be accessed from various EDR pages that list devices, such as the Threat Hunting tab and the Investigation View.
- A Connect to Device button appears at the top of these pages, which enables you to connect to the device that is selected in the list.
- You can only connect to a single device in each EDR Connect session. See Connecting to an EDR-protected device.
- A device can only be connected to a single session at a time.
- Each EDR user can have up to ten EDR Connect sessions open and connected at the same time – each to a different device.
- Multiple users in your organization can open up EDR Connect sessions (on the EDR Manager), but no more than 30 sessions can be opened at the same time.