Wider attack surface coverage powered by hundreds of integrations and deeper threat visibility powered by thousands of detections.
Version: Comodo Endpoint Protection
Comodo Endpoint Protection (EP) is a powerful event analysis tool that provides real-time monitoring and detection of malicious events on Windows Endpoints. Endpoint Protection allows you to view the threats in a detailed timeline and instantly alerts about an attack.
Comodo Endpoint protection agent writes events automatically on Windows event viewer. Netsurion agent picks logs and sends to Netsurion. Comodo sends events like antivirus scan, HIPS, HIDS, containment, file rating, autorun, and configuration changes. Generates reports on potentially unwanted applications, antivirus scan detail, file rating, intrusion activities, configuration changes on Endpoint, alerts, threats detected, and unwanted files removed, etc. It contains username, client IP address, status, action, file path, file name, and hash. Graphically displays threat detected by file name, device name, device IP, file management Intrusion detected by filename, etc.
After Comodo EP is configured to deliver events to Netsurion, then alerts, dashboards, and reports can be configured into Netsurion.
The configuration details are consistent with Netsurion version 9.2 and later, and Comodo Endpoint Protection.
Download Integration Guide and How-to Guide for more information and to configuration instructions.