Key Takeaways
Fidelis EDR uses a single lightweight agent to deliver detection, response, and forensic visibility without requiring multiple endpoint tools
Continuous telemetry collection captures process execution, file changes, registry activity, and network connections in real time
Local detection capabilities ensure threats are identified even when endpoints are offline or disconnected from the network
Detection logic combines behavioral analytics with indicators mapped to MITRE ATT&CK for faster and more accurate threat classification
Built-in automated response actions such as process termination and endpoint isolation reduce containment time during active incidents
Endpoint Collector enables deep forensic investigation by querying historical endpoint data without reimaging or disrupting systems
Integrated threat intelligence including YARA and OpenIOC improves detection accuracy and reduces reliance on external tools
How Does Fidelis EDR Agent Work
Endpoint agents are the foundation of any effective endpoint detection and response strategy. Fidelis Endpoint® deploys a single lightweight agent per endpoint device. No separate AV process, no secondary forensic collector, no additional endpoint security tools stacked on top of each other. One agent handles prevention, detection, investigation, forensics, and automated response across Windows, macOS, and Linux operating systems, through the same management interface.
Every process and child process is monitored continuously. Behavioral patterns, registry changes, file operations, and network activity are captured in real time and stored in the Endpoint Collector, a centralized behavioral metadata store retaining 30, 60, or 90 days of history by default, with longer retention available. This gives security teams comprehensive visibility into endpoint environments without deploying separate tools for each function.
Detection logic and threat intelligence run locally on each endpoint device. Managed devices operating outside corporate networks, including remote workers, air-gapped segments, and field devices, maintain full detection coverage. Cached data synchronizes back to the management platform once connectivity resumes, supporting consistent off-site device management without gaps in endpoint monitoring.
For enterprise security teams replacing fragmented endpoint security solutions with a consolidated approach, the single-agent architecture reduces attack surface introduced by agent conflicts and simplifies endpoint management across large fleets.
Organizations running unified endpoint management (UEM) or mobile device management (MDM) programs alongside a traditional EDR will find the Fidelis agent fits within existing endpoint device management workflows. It does not require replacing current mobile device management or device management infrastructure; it layers endpoint detection and response on top of whatever management tooling is already in place.
Fidelis EDR Prevention Features
Prevention in the Fidelis Endpoint® security platform runs through three independent mechanisms. Each operates regardless of whether the others are active, giving security teams layered coverage to secure endpoints without mandatory dependencies.
Fidelis Antivirus (optional, Windows only):
Powered by Bitdefender, covering signature, heuristic, and behavioral defenses including boot sector protection. Detected malware samples go automatically to a Global Quarantine. From any AV alert, analysts can pivot directly into the endpoint process tree to see the execution context, turning a raw alert into an immediately actionable investigation.
Process Behavior Blocking:
Scores process execution in real time across multiple behavioral dimensions using machine learning. When a process crosses the malicious behavior threshold, it is terminated before it can exfiltrate sensitive data or move laterally. Unlike sandboxing, which can be evaded by malware that delays execution, this mechanism acts on live endpoint behavior. Requires the Fidelis AV option; Windows only.
Process Blocking via Hashes and YARA Rules:
Runs independently of whichever AV engine is deployed, giving security teams an open AV engine choice without sacrificing process-level controls. Hash-based blocks are added immediately on new threat indicators. YARA rules using modules such as the PE module inspect executable structure before a file runs. Hash rotation by attackers does not defeat YARA-based blocks, because the rules evaluate structural properties rather than static signatures, reducing security vulnerabilities introduced by signature-only prevention.
Fidelis Endpoint Detection Capabilities
How Does Fidelis Behavioral Threat Detection Work
Fidelis Insight, maintained by the Fidelis Threat Research Team, drives threat detection by pushing continuously updated behavioral indicator feeds to every endpoint. Behavior Rules run against endpoint activity in near-real time. Triggered rules carry MITRE ATT&CK technique mappings where applicable, giving security teams immediate attacker tactic context at the moment of alert without additional lookup steps.
External threat intelligence in STIX, XML, JSON, and delimited file formats is normalized and ingested alongside Insight feeds. Atomic indicators including IPs, DNS hostnames, URLs, and file hashes are correlated continuously against live process and network activity. Internally developed indicators are supported in the same pipeline as commercial and open-source feeds, so organizations can enforce security policies built on their own intelligence alongside vendor-provided data.
The Scanning Indicator Library ships with hundreds of OpenIOC and YARA rules from community sources. ThreatScan jobs execute these against file systems and memory across multiple connected devices simultaneously, covering the full managed fleet rather than individual endpoints.
Behavioral analytics run continuously in the background. The platform identifies anomalous endpoint behavior, such as processes executing from non-standard directories or unexpected outbound network connections to unknown destinations, without requiring a known-bad signature to match.
Assessing Your Security Posture Prior to an Incident
How Can Decision Makers Use the MITRE ATT&CK Framework?
Beyond the MITRE Evaluation
How Fidelis Collects Executable Files and Scripts
Every binary and script executed on a managed endpoint is captured the first time it appears and stored centrally. Attackers routinely delete tools after use to remove evidence from compromised endpoints. Because capture happens at execution time, those samples are preserved regardless of subsequent file deletion.
Each collected file is accessible through a built-in hex or text editor, sendable to the Fidelis Insight sandbox for behavioral scoring, or checkable against Threat Lookup for multi-scanner results. Security teams can search the collection by hash, path, or behavior metadata to surface every occurrence across the environment alongside full execution context.
This capability directly addresses increasingly sophisticated attacks that rely on fileless techniques and living-off-the-land execution, where traditional file-based detection misses the threat entirely.
What is Fidelis Endpoint Collector
The Fidelis Endpoint® Collector stores the full behavioral record per endpoint, enabling continuous monitoring with depth:
Process starts and exits, with complete parent-child relationships
Registry reads and writes
File creation, modification, and deletion
Network connections, DNS queries, HTTP and HTTPS traffic
Windows Event Log data
Loaded DLLs and remote threads
Queries run with Boolean logic, supporting network security investigations alongside host-based analysis. Complex searches are saved for recurring monitoring workflows. The event timeline shows the complete process tree around any detection, making it possible to reconstruct a full attack chain back to initial access. Security teams handling incident response on corporate data breaches get a complete activity record without needing to preserve volatile state manually.
Fidelis EDR Forensic Analysis Capabilities
Security teams investigating compromised endpoints need forensic data collected at the right depth, at the right time. Data security during collection matters; Fidelis Endpoint® covers the full forensic range without requiring separate tooling.
Live Response:
Running processes, open network connections, recently contacted DNS hostnames, and recently executed applications are collected in minutes, capturing volatile state before it changes. No full disk image required for initial triage.
Full Disk Imaging:
Remote full disk image collection in E01 or S01 forensic container formats for deep forensic investigation of compromised endpoints.
File Collection:
Filter-based collection by creation date, path, extension, hash, or file content. Files are retrieved in native format or AD1 logical forensic container format, which preserves filesystem metadata for evidentiary use when investigating corporate data incidents.
Memory Acquisition and Live Memory Analysis:
Full system memory is collected in RAW or AFF4 format for offline analysis. Before committing to a full dump, analysts run live memory analysis on the target machine through an integrated Volatility framework instance. Results return process listings with memory addresses, privileges, sockets, open handles, DLLs, and VADs, surfacing hidden processes or injected DLLs without the time cost of a full memory collection.
Process Dumps and Cerberus Binary Analysis:
Memory dumps for specific processes include selectable artifacts: handle data, thread information, and more. For unknown executables without multi-scanner coverage, Cerberus inspects binary structure including digital signature validity, packing indicators, and OS function imports, then produces a maliciousness score to prioritize triage before sandbox submission.
Endpoint Isolation:
An isolated endpoint retains communication with the Fidelis management console and designated investigator systems. Investigation and remediation continue on the isolated machine. Lateral movement to other systems on the corporate network is blocked without interrupting the investigation.
Fidelis EDR Automated Threat Response and Remediation
Security teams operating at enterprise scale cannot manually respond to every alert. Automated responses in Fidelis Endpoint® trigger from agent-level detections or from external SIEM and SOAR alerts, closing the gap between detection and containment without waiting for analyst availability.
Over 100 response scripts ship for Windows, Linux, and macOS across three categories:
CategoryWhat It Does
InvestigativeCaptures user session data, process ownership, and event logs at detection time, before analyst loginForensicCollects files, network logs, and volatile artifacts at the exact moment of detectionDestructiveIsolates the endpoint, deletes specified files, or modifies registry entries to contain the threat
Playbooks chain actions on trigger rules. A single confirmed alert can isolate the endpoint, collect forensic data, check the process against threat intelligence, and route a notification, all without analyst intervention. Any endpoint action can be scripted and pushed to the full enterprise fleet from the central console. Security tasks and security measures that previously required hours of manual work execute in seconds.
Bidirectional SIEM integration via syslog covers IBM QRadar, Micro Focus ArcSight, and McAfee Enterprise Security Manager. Response templates launch from SIEM alerts; results push back to the SIEM interface automatically. The REST API handles SOAR workflows and integrations with existing it infrastructure outside the built-in set.
Fidelis EDR Use Cases
How Fidelis EDR Stops Ransomware
A malicious script executes on a managed endpoint. Fidelis captures it as a first-time-seen file and stores a copy immediately. Process Behavior Blocking scores the child processes; when the behavioral threshold is crossed, the process is terminated. An automated playbook isolates the endpoint and runs forensic scripts within seconds, collecting process data, network connections, and file artifacts before any attacker cleanup can occur. Corporate data on the affected system is protected from exfiltration while the investigation runs, providing an effective data loss prevention outcome without a dedicated DLP layer.
The alert reaches the analyst’s Microsoft Teams channel with the MITRE ATT&CK technique mapping and pre-collected forensic data already attached. Fidelis Live Console connects to the isolated endpoint with full file system, registry, and process access. Detection, isolation, and evidence collection complete before the analyst logs in.
Enterprise Threat Hunting
ThreatScan jobs run OpenIOC or YARA rules from the Scanning Indicator Library against file systems and memory across the full endpoint fleet simultaneously. The Advanced Query Builder supports Boolean logic with saved queries for recurring workflows. The Executable File and Script Collection is searchable by hash, path, or behavioral metadata, returning every occurrence of a specific binary across all managed devices alongside execution context. Security teams can hunt for emerging threats across the full estate without running individual endpoint queries.
Patch Management and Vulnerability Remediation
Installed software is cataloged per endpoint and correlated against the MITRE CVE database and Microsoft KB articles. Software inventory updates automatically. When a new CVE affects software present in the environment, an alert is generated. Patch management scripts deploy from the central console across the enterprise without requiring physical access to endpoints, reducing the window of exposure on security vulnerabilities before attackers can exploit them.
Fidelis EDR Capability Fidelis EDR Features and Capabilities List
Prevention and Detection
The table below covers the key features across prevention and detection. Fidelis Endpoint® consolidates what would otherwise require multiple separate endpoint protection platforms into a single agent.
CapabilityDetail
Operating systemsWindows, macOS, LinuxAV preventionBitdefender-powered (optional add-on); open AV engine choice supportedProcess blockingHash-based and YARA-rule-based; independent of AV engineProcess behavior blockingMachine learning behavioral scoring; terminates malicious processes at executionBehavioral detection rulesCustom rules plus Fidelis Insight rules; mapped to MITRE ATT&CKScanning indicator libraryHundreds of OpenIOC and YARA rules from community sourcesThreat intelligence formatsSTIX, XML, JSON, delimited files; Fidelis Insight; third-party and internal feedsExecutable collectionFirst-time-seen binaries and scripts stored centrally at execution timeSandbox scoringFidelis Insight Content Analysis Platform; 0-100 malware score; active networking enabled
Investigation and Forensics
CapabilityDetail
Metadata retention30, 60, or 90 days default; longer retention configurableForensic collectionFull disk imaging (E01/S01), file collection (AD1), memory dump (RAW/AFF4), process dumpsLive memory analysisVolatility-based; runs on target machine; returns parsed process and memory detailsCerberus binary analysisStructural analysis of unknown executables; produces maliciousness score for triage
Response and Security Management
CapabilityDetail
Response scripts100+ out-of-the-box; investigative, forensic, destructive; fully customizableSIEM integrationIBM QRadar, Micro Focus ArcSight, McAfee ESM; bidirectional via syslogREST APISOAR workflows and custom integrationsOn/off-network coverageLocal detection logic; data cached offline and synced on reconnectAgent communicationTLS 1.2 encrypted, persistent WebSocketAlert notificationsEmail, Microsoft Teams, Slack; configurable by severityDynamic groupsAuto-update based on endpoint characteristicsRole-based access controls (security control)Scoped by endpoint group, script category, and system-level permissionsPatch managementCVE and KB correlation; patch deployment via central console scripts
Visibility and Detection
Forensics, Response and Prevention
Conduct Live Investigations
How Fidelis Endpoint Integrates With Elevate XDR
Fidelis Endpoint runs standalone or as a component of the Fidelis Elevate® XDR platform. Elevate integrates endpoint detection and response with network detection and response (NDR) and deception technology into a unified endpoint security environment.
Network detections trigger validation checks against endpoint data; endpoint detections correlate with network traffic analysis both in real time and retrospectively. Security teams get comprehensive protection across endpoint and network layers without switching between separate tools or management consoles.
Fidelis Deception® seeds corporate networks with decoys and breadcrumbs. When an attacker interacts with a decoy, endpoint response actions trigger directly through Fidelis Elevate®, giving security teams earlier visibility into lateral movement before it reaches production systems or data stores containing sensitive data.
Detection rules built by the Fidelis Threat Research Team drive automated alert context and one-click response across all three layers from a unified alert view. SOC analysts get the comprehensive visibility and rapid response capability needed to maintain a strong security posture against increasingly sophisticated cyber threats without expanding headcount or adding management tools to an already complex stack.
Key technical terms mentioned in this article are linked below for further exploration:
The post A Complete Guide to Fidelis EDR Agents and Their Core Security Roles appeared first on Fidelis Security.
No Responses