← All services
Service · Security

EDR & threat response

Detection on every endpoint, with someone actually watching it at 3 a.m.

Typical timeline
2–4 weeks
Ongoing cadence
24/7 monitored
Delivered by
ClearPath engineers

Endpoint detection only works if a human responds to it. We deploy and tune EDR across your estate, wire the alerts into our on-call rotation, and write the containment steps in advance so response does not depend on improvisation.

How we do the work

01 · Assess

We inventory endpoints and servers, including unmanaged devices.

02 · Architect

We define detection policy, isolation authority, and escalation.

03 · Deploy

We deploy agents by group and reconcile coverage.

04 · Configure

We tune policies and exclusions, and write and rehearse containment runbooks.

05 · Maintain

The NOC monitors 24/7, investigates, contains, and reports.

What the engagement includes

  • Estate-wide agent deployment and coverage reconciliation
  • Detection policy and exclusion tuning
  • Documented isolation and containment authority
  • 24/7 monitoring and investigation
  • Post-incident reporting and root cause

What you are left holding

  • Coverage report against asset inventory
  • Detection and response runbook
  • Monthly detection and action summary
  • Incident reports with root cause

Documentation is yours to keep, whether or not we keep working together.

You probably need this if…

  • Antivirus with no detection or response layer
  • Alerts arriving in an inbox nobody watches overnight
  • No agreed authority to isolate a machine

How you engage us

Same engineers either way. The difference is how much of the ongoing work stays with your team.

Option 01 · Project

Fixed scope, fixed outcome. We assess, architect, deploy, and hand over with documentation. Your team runs it from there.

Option 02 · Most common · Co-managed

We own the design, the hard changes, and after-hours cover. Your team keeps day-to-day control with our engineers on call.

Option 03 · Fully managed

End-to-end ownership against an SLA: monitoring, maintenance, and reporting, with a named engineer who knows your environment.

Let's scope EDR & threat response against your environment.

An hour with one of our engineers gets you a realistic scope, a timeline, and an honest read on what to do first.