<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/">
	<channel>
		<title><![CDATA[GETOVERX FORUM Community Support - EDR]]></title>
		<link>https://forum.getoverx.com/</link>
		<description><![CDATA[GETOVERX FORUM Community Support - https://forum.getoverx.com]]></description>
		<pubDate>Wed, 10 Jun 2026 09:35:54 +0000</pubDate>
		<generator>MyBB</generator>
		<item>
			<title><![CDATA[Help configuring the Corporate EDR Version]]></title>
			<link>https://forum.getoverx.com/showthread.php?tid=140</link>
			<pubDate>Wed, 18 Feb 2026 00:58:11 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://forum.getoverx.com/member.php?action=profile&uid=4110">thomasb4083</a>]]></dc:creator>
			<guid isPermaLink="false">https://forum.getoverx.com/showthread.php?tid=140</guid>
			<description><![CDATA[<img src="https://i.postimg.cc/mr9qy3pP/edrconfig.png" loading="lazy"  alt="[Image: edrconfig.png]" class="mycode_img" /><br />
<br />
Hello community,<br />
I’m configuring the EDR module and I see it supports rule lists (import/export). I’d like to expand the baseline rules safely without causing false positives or system instability.<br />
<br />
Where do you recommend sourcing reliable rule ideas or detection guidance?<br />
<br />
For example: CISA advisories, NIST recommendations, MITRE ATT&amp;CK mappings, or other reputable public resources that can be translated into EDR rules.<br />
Any suggestions or rule pack structures you’ve tested in real endpoints would be appreciated.<br />
Thanks!]]></description>
			<content:encoded><![CDATA[<img src="https://i.postimg.cc/mr9qy3pP/edrconfig.png" loading="lazy"  alt="[Image: edrconfig.png]" class="mycode_img" /><br />
<br />
Hello community,<br />
I’m configuring the EDR module and I see it supports rule lists (import/export). I’d like to expand the baseline rules safely without causing false positives or system instability.<br />
<br />
Where do you recommend sourcing reliable rule ideas or detection guidance?<br />
<br />
For example: CISA advisories, NIST recommendations, MITRE ATT&amp;CK mappings, or other reputable public resources that can be translated into EDR rules.<br />
Any suggestions or rule pack structures you’ve tested in real endpoints would be appreciated.<br />
Thanks!]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[What does the EDR module monitor and where can I see its logs?]]></title>
			<link>https://forum.getoverx.com/showthread.php?tid=89</link>
			<pubDate>Fri, 05 Dec 2025 00:28:23 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://forum.getoverx.com/member.php?action=profile&uid=7795">VilleTai</a>]]></dc:creator>
			<guid isPermaLink="false">https://forum.getoverx.com/showthread.php?tid=89</guid>
			<description><![CDATA[Hey,<br />
I enabled the EDR module but I’m not sure what exactly it does. Is it just another scanner, or does it give me more detailed information about my system? <img src="https://forum.getoverx.com/images/smilies/angel.png" alt="Angel" title="Angel" class="smilie smilie_10" /> <img src="https://forum.getoverx.com/images/smilies/angel.png" alt="Angel" title="Angel" class="smilie smilie_10" />]]></description>
			<content:encoded><![CDATA[Hey,<br />
I enabled the EDR module but I’m not sure what exactly it does. Is it just another scanner, or does it give me more detailed information about my system? <img src="https://forum.getoverx.com/images/smilies/angel.png" alt="Angel" title="Angel" class="smilie smilie_10" /> <img src="https://forum.getoverx.com/images/smilies/angel.png" alt="Angel" title="Angel" class="smilie smilie_10" />]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Unusual process detected – is this malware?]]></title>
			<link>https://forum.getoverx.com/showthread.php?tid=1</link>
			<pubDate>Sat, 20 Sep 2025 17:42:51 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://forum.getoverx.com/member.php?action=profile&uid=2">mrwebfeeder</a>]]></dc:creator>
			<guid isPermaLink="false">https://forum.getoverx.com/showthread.php?tid=1</guid>
			<description><![CDATA[Author: alfred@04a3cf8d | Forum: edr-lite-endpoint-detection-response<br />
<br />
Hello community, EDR Lite flagged a process named msworkerupdate.exe running from AppData\\Roaming. I don’t recognize it. Has anyone else seen this behavior? Could this be a new type of malware or just a false positive?]]></description>
			<content:encoded><![CDATA[Author: alfred@04a3cf8d | Forum: edr-lite-endpoint-detection-response<br />
<br />
Hello community, EDR Lite flagged a process named msworkerupdate.exe running from AppData\\Roaming. I don’t recognize it. Has anyone else seen this behavior? Could this be a new type of malware or just a false positive?]]></content:encoded>
		</item>
	</channel>
</rss>