🌙
 

Subscribe to the Taegis™ XDR Documentation RSS Feed at .

Learn more about RSS readers or RSS browser extensions.

Endpoint Watchlists

detectors


Endpoint watchlists serve two purposes:

Alert Consolidation

XDR consolidates alerts from endpoint integrations into the following detector names:

Note

Red Cloak™ Endpoint Agent alerts are produced directly in XDR and display in the Secureworks® Taegis™ Watchlist detector.

XDR Watchlist

Regardless of which endpoint agent is utilized within an environment, XDR applies CTU curated watchlists to normalized endpoint telemetry. This watchlist identifies adversary tactics and techniques within normalized endpoint telemetry.

Detector Requirements

 

On this page: