Evidence for Antivirus and EDR
Evidence Type Description / Example Location / Format Retention Period Agent Status Report Snapshot of all endpoints with agent status = “Active” and “Connected” from EDR console (e.g., CrowdStrike Falcon, Microsoft Defender for Endpoint). Filtered by last 24–48 hours. PDF or CSV export from console; stored in secure SharePoint or GRC platform 3 years Signature […]
Evidence for Antivirus and EDR Read Post »