Skip to content
Skip to main content
Logs, Records & Provider Evidence Technical Explainer

What is an endpoint-security log?

An endpoint-security log contains selected device telemetry and product assessments from antivirus, EDR, host firewall or application-control tools. It is not a complete forensic history or definitive malware attribution.

Agent and policy define visibility

Telemetry can include processes, files, command lines, network connections, user sessions, detections, quarantine and remediation. Agent version, policy, connectivity and collection affect gaps and delay. A detection label is a product classification, and the named user may only be the logged-in account.

Preserve the process and response context

Identify product, agent, policy and whether the item is raw telemetry, detection, alert or analyst conclusion. Retain process trees, hashes, commands, network events and remediation history.

Correlate forensic, authentication and network evidence and use specialists for process ancestry or malware behaviour where necessary.

The point to remember

Endpoint-security records provide valuable selected telemetry whose coverage, classification and attribution must be independently tested.

Reference: LOG-027Logs, Records & Provider Evidence