TrustRadius: an HG Insights company

IBM Security QRadar EDR

Score7.2 out of 10

44 Reviews and Ratings

Top Performing Features

-11%

Malware Detection

Detection and blocking of zero-day file and fileless malware.

Cat avg: 9.1

-18%

Endpoint Detection and Response (EDR)

Continuous monitoring and response to advanced internet threats by endpoint agents.

Cat avg: 9.2

-15%

Centralized Management

Centralized management supporting multi-factor authentication, customized views, and role-based access control.

Cat avg: 8.7

-17%

Anti-Exploit Technology

In-memory and application layer attack blocking (e.g. ransomeware)

Cat avg: 8.9

Worst Performing Features

-9%

Hybrid Deployment Support

Administrators should be able to choose endpoint security on-premise, cloud, or hybrid.

Cat avg: 8

-14%

Infection Remediation

Capability to quarantine infected endpoint and terminate malicious processes.

Cat avg: 8.6

IBM Security QRadar EDR Features from Reviews

Endpoint Security

Endpoint security software protects enterprise connected devices from malware and cyber attacks.

7.5-14%
  • Anti-Exploit Technology

    In-memory and application layer attack blocking (e.g. ransomeware)

    Category average: 8.9

  • Endpoint Detection and Response (EDR)

    Continuous monitoring and response to advanced internet threats by endpoint agents.

    Category average: 9.2

  • Centralized Management

    Centralized management supporting multi-factor authentication, customized views, and role-based access control.

    Category average: 8.7

  • Hybrid Deployment Support

    Administrators should be able to choose endpoint security on-premise, cloud, or hybrid.

    Category average: 8

  • Infection Remediation

    Capability to quarantine infected endpoint and terminate malicious processes.

    Category average: 8.6

  • Malware Detection

    Detection and blocking of zero-day file and fileless malware.

    Category average: 9.1

IBM Security QRadar EDR Features from the Vendor

Endpoint Security

Vendor-reviewed
  • Anti-Exploit Technology

    In-memory and application layer attack blocking (e.g. ransomeware)

  • Endpoint Detection and Response (EDR)

    Continuous monitoring and response to advanced internet threats by endpoint agents.

  • Centralized Management

    Centralized management supporting multi-factor authentication, customized views, and role-based access control.

  • Hybrid Deployment Support

    Administrators should be able to choose endpoint security on-premise, cloud, or hybrid.

  • Infection Remediation

    Capability to quarantine infected endpoint and terminate malicious processes.

  • Malware Detection

    Detection and blocking of zero-day file and fileless malware.

Additional Features

Vendor-contributed
  • Pre-execution prevention: Reviews file source code prior to full execution and stop files from running if malicious code is detected.

  • NanoOS: Each endpoint agent includes dual AI engines and NanoOS technology, which allows certain detection and autonomous operation capabilities even when endpoints are offline.

  • Attack visibility: Detects and correlates alert information, including an attack’s root cause, risk assessment, and MITRE ATT&CK framework.

  • Anti-ransomware: Analyzes file behaviors for detecting imminent attacks and stop malicious processes from executing.

  • Signature scanning: Uses heuristics and signature-based prevention.

  • Threat insights: Identifies potential threats with metadata-based analysis to expedite triaging and enable detection of an alert’s artifacts to discover new binaries as soon as they’re activated.

  • AI-driven Threat hunting: Enables real-time search for indicators of compromise (IOC), binaries and behaviors to facilitate the discovery of dormant threats.

  • Forensics: Enables remote gathering of forensic information to reconstruct an attacker’s activities.

  • Custom playbook: Creates custom-built detection response and remediation playbooks.

  • API access: Automates workflows and integrate with external platforms with Direct API access to ReaQta.