Cyber Hunting - How do I hunt ?

Need to look at your network as WEB (web site and cloud presence) or LAN (office).

LAN(OFFICE): If you want to do Cyber Hunting in your LAN then https://edr.cwatch.comodo.com download this free tool and watch your network and identify what is happening, when…what is bad, what is good and who did what…

WEB: If you want to Monitor and do Cyber Hunting and protect your WEB then enable Cwatch WEB https://www.comodo.com/managed-security-as-a-service/cwatch.php for your website. This will combine a WAF, SIEM, SOC, CDN and Security Analysts watching, protecting and providing intelligence.

@melih I wanted to look at the EDR but when I attempted to install it, it said it wasn’t compatible with Comodo Security. How is it meant to be utilized?

Hi,

Comodo security tools and EDR compatibility is something that we are currently working on. It is planned to be available with the upcoming release. When completed, you will be able to fully benefit EDR along with other Comodo tools you currently utilize.

Thanks for the feedback.

Are we going to be able to run EDR in C1? =)

Yes we will. This is already in the roadmap. I think this feature will be implemented in one of the 2018 Q2 releases.

Cool… But is it possible to try EDR now? Or do I have to install some other agent for that solution?

There is a 2nd agent and reg edit entry, I’m going to wait until its part of C1:)

Yes it’s possible to try it.

You should:

  1. Visit https://edr.cwatch.comodo.com
  2. Get yourself an account.
  3. Log in to the portal and download the agent.
  4. Install the agent and like @dittoit remarked you should do the registry pack installation (Registry installation will vanish with the future releases BTW)
  5. Make sure the “cwagtsrv” is running (Windows/Services)

Then your agent starts sending events to our servers. You can enjoy world’s first EDR solution.

Always keep in mind that you can post your questions here or you can reach us at edrsupport@comodo.com

  1. Install the agent and like @dittoit remarked you should do the registry pack installation (Registry installation will vanish with the future releases BTW)

“It already has, was an EXE when I installed the new agent today”