Finding gaps in endpoint protection
Many customers use runZero for a consolidated view of their assets. Once you integrate your endpoint protection platform with runZero, you can monitor the state of that deployment from inside runZero in several ways.
Who is this playbook for and why?
This playbook is for security and IT personnel who manage their organization’s endpoint protection platform. It can help you find gaps in your endpoint protection coverage and confirm that you’re getting full value from your investment.
How will runZero help?
runZero discovers assets on your network without an agent and imports asset information from your endpoint protection platform. With both in one inventory, you can identify gaps in coverage and other health information about your EDR implementation.
What will I need to do?
Start by scanning your entire network. Then, if applicable, configure a runZero integration with your endpoint protection platform to merge its data with the runZero data. Finally, query the asset data for assets that do not have the platform installed.
Prerequisites
- A complete asset inventory
- An endpoint protection platform supported by runZero
Steps to implement
- Configure your endpoint protection integration:
- (Optional) If your EDR is not among the native integrations, check the Custom Integrations Repository or create your own custom integration.
- Use the sample queries to search your inventory for assets missing endpoint protection.
- Set up alerts that notify you of gaps automatically or start a workflow.
Sample queries
Terms and operators combine in endless ways. Use these examples as they are or adjust them to your needs.
CrowdStrike Falcon
These queries monitor the state of your CrowdStrike deployment from inside runZero.
Identify assets that do not have CrowdStrike installed
(type:server OR type:desktop OR type:laptop) AND not edr.name:CrowdStrike
Identify assets running CrowdStrike in Reduced Functionality Mode (RFM)
(type:server OR type:desktop OR type:laptop) AND @crowdstrike.dev.reducedFunctionalityMode:yes
Identify assets running CrowdStrike where a protection policy has not been deployed
(type:server OR type:desktop OR type:laptop) AND @crowdstrike.dev.provisionStatus:NotProvisioned
Identify assets that are quarantined
(alive:true OR scanned:false) AND @crowdstrike.dev.status:Contained
SentinelOne
These queries monitor the state of your SentinelOne deployment from inside runZero.
Identify assets that do not have SentinelOne installed
(type:server OR type:desktop OR type:laptop) AND not edr.name:SentinelOne
Identify assets that have been decommissioned in SentinelOne
(alive:true OR scanned:false) AND @sentinelone.dev.isDecommissioned:true
Identify assets that are running an outdated agent
(type:server OR type:desktop OR type:laptop) AND @sentinelone.dev.isUpToDate:false
Identify assets that are quarantined
(alive:true OR scanned:false) AND @sentinelone.dev.networkQuarantineEnabled:true
Microsoft 365 Defender
These queries monitor the state of your Microsoft 365 Defender deployment from inside runZero.
Identify assets that do not have Defender installed
(type:server OR type:desktop OR type:laptop) AND not edr.name:"=Microsoft Defender for Endpoint"
Identify assets that are potentially running an outdated agent
(type:server OR type:desktop OR type:laptop) AND edr.name:"=Microsoft Defender for Endpoint" AND not @ms365defender.dev.defenderAVStatus:="Updated"
Identify assets that are not active
(alive:true OR scanned:false) AND edr.name:"=Microsoft Defender for Endpoint" AND not @ms365defender.dev.avMode:"=Active"
Outcome demo
This short video shows what the outcome of finding gaps in your EDR deployment may look like.
Getting help
For help building out this process, book a session with a runZero Customer Success Engineer.