Skip to main content
Incident Response

Your EDR Just Alerted: A Blunt Field Guide to Incident Response

When your EDR pings at 2 a.m., you need a plan. Here's how to run containment, eradication, and recovery without panicking—based on real-world numbers and guidance.

You're the security lead at a mid-sized firm, and at 2:14 a.m. your phone buzzes: an EDR alert on a finance laptop. The behavioral analytics flag shows a PowerShell process spawning from an Office document, and the user is in a different time zone—asleep, presumably. What do you do next? This is the moment incident response stops being a slide deck and becomes a fire drill. Here's the blunt, practical walkthrough you need, grounded in the numbers and frameworks that actually matter.

Step One: Don't Treat This Like an Antivirus Popup

First, resist the urge to dismiss it as a false positive. If you're still running legacy antivirus as your only defense, you're flying blind—AV only catches known signatures. (CISA) EDR, on the other hand, uses behavioral analysis and heuristics, so it catches fileless attacks and zero-days. The threat landscape has shifted: the CrowdStrike 2026 Global Threat Report found that 82% of detections in 2025 were malware-free, and average breakout time dropped to just 29 minutes. That means an attacker can move from initial compromise to domain-wide access in under half an hour. Your response speed matters more than ever.

Step Two: Contain Before You Investigate

Your first move should be to contain the endpoint. If your EDR platform supports it, isolate the device from the network immediately. This is where EDR shines—it can remotely isolate, terminate processes, and capture forensics. (CISA) Don't wait for a full picture; you can analyze later. In parallel, start your incident response lifecycle per NIST SP 800-61 Rev. 2, which breaks down into Preparation, Detection and Analysis, Containment, Eradication, and Recovery. (NIST) You're now in the Containment phase. Your goal is to stop lateral movement. Remember that the average cost of a data breach hit $4.99 million in 2026 (IBM), and a major factor is dwell time. Every minute you hesitate, the attacker gets closer to your crown jewels.

Step Three: Eradicate, But Don't Forget the Backups

Once contained, you need to eradicate the threat. This means removing the malicious files, registry keys, and scheduled tasks. But here's the trap: many ransomware variants target backups. So before you wipe and restore, verify your backups are intact and offline. CISA's StopRansomware guidance is explicit: maintain offline, encrypted backups and test them regularly. (CISA) If you don't have tested backups, you're one encryption event away from paying a ransom—and even then, there's no guarantee you'll get your data back. In fact, the Verizon 2026 DBIR notes that ransom payouts are shrinking as more businesses refuse to pay. (Verizon) That's a good trend, but it only works if you can recover on your own.

Step Four: Learn From the MITRE ATT&CK TTPs

As you analyze the incident, map the attacker's behavior to the MITRE ATT&CK framework. (MITRE) This isn't academic—it helps you understand the full kill chain. Was it initial access via a phishing email? Did they use credential dumping to move laterally? Each technique you identify tells you what security gap to close. For example, if the initial vector was a known vulnerability, check CISA's Known Exploited Vulnerabilities (KEV) catalog, which lists ~1,670 vulnerabilities known to be exploited in the wild. (CISA) If your system is in that catalog and you hadn't patched it, you've found a policy failure. Patch management is preventive maintenance—NIST SP 800-40r4 frames it as a way to prevent compromises and breaches. (NIST)

Step Five: The Human Factor—Phishing and MFA

Chances are, the entry point was a phishing email. The FBI IC3 2024 report shows phishing was the top crime type by complaint count, with over 193,000 complaints. (FBI) So your incident response plan must include user awareness. But you also need to enforce multi-factor authentication (MFA) everywhere. NIST SP 800-63B defines AAL2 as requiring two different authentication factors—something you know and something you have. (NIST) If you're not doing that, you're relying on passwords alone, which are easily phished. The CrowdStrike 2026 report notes an 89% increase in AI-enabled attacks, including deepfake impersonations. (CrowdStrike) So train your users to spot phishing, but don't expect perfection. MFA is your safety net.

Step Six: Post-Incident—Make It Hurt Less Next Time

After you've recovered, do a post-incident review. NIST SP 800-61 Rev. 2 calls this Post-Incident Activity, and it feeds lessons back into preparation. (NIST) Ask hard questions: Why did the alert fire? Were our detection rules adequate? Did we follow our runbook? Update your incident response plan accordingly. Also, consider adopting a zero-trust architecture, which assumes a breach and requires verification for every access request. (NIST SP 800-207) This isn't a one-time project—CISA's Zero Trust Maturity Model describes a journey through stages. (CISA) But every step you take reduces the blast radius of the next incident.

The takeaway? Incident response is not about being perfect—it's about being fast and methodical. When that 2 a.m. alert comes in, you need a plan that starts with containment, relies on tested backups, and uses frameworks like MITRE ATT&CK to learn. Don't underestimate the human element: train users, enforce MFA, and patch known exploited vulnerabilities. The numbers are stark—breaches cost millions, and attackers move in minutes. But with a solid EDR, a rehearsed response, and a commitment to continuous improvement, you can minimize the damage and get back to business.

Sources

  • CISA - https://www.cisa.gov/stopransomware
  • CrowdStrike 2025 Global Threat Report - https://www.crowdstrike.com/en-us/global-threat-report/
  • IBM Cost of a Data Breach Report 2026 - https://www.ibm.com/reports/data-breach
  • MITRE ATT&CK - https://attack.mitre.org/
  • NIST SP 800-61 Rev. 2 - https://csrc.nist.gov/pubs/sp/800/61/r2/final
  • Verizon 2026 Data Breach Investigations Report - https://www.verizon.com/business/resources/reports/dbir/

Share this article:

Comments (0)

No comments yet. Be the first to comment!