Saltar al contenido
03 · SOC Gestionado03 · Managed SOC

Gestión de EDR / XDREDR / XDR Management

CrowdStrike, Defender, SentinelOne.CrowdStrike, Defender and SentinelOne.

EDR · XDREDR · XDR 3.3 · Servicios Gestionados de Plataformas3.3 · Managed Platform Services

¿Qué es este servicio?What is this service?

Es la administración de la plataforma de detección en equipos —CrowdStrike, Defender, SentinelOne— por parte de un equipo externo: desplegar y mantener los agentes, endurecer las políticas, revisar las exclusiones, atender las detecciones y medir la cobertura real.

The administration of the endpoint detection platform — CrowdStrike, Defender, SentinelOne — by an external team: deploying and maintaining agents, hardening policies, reviewing exclusions, handling detections and measuring real coverage.

¿Para qué se usa?What is it used for?

Sirve porque comprar las licencias no es tenerlo. Es frecuente encontrar consolas de marcas excelentes corriendo en modo de solo detección desde el día de la instalación, con exclusiones de carpetas enteras que alguien agregó en 2021 para que dejara de molestar a un sistema contable. Y siempre hay un porcentaje de equipos sin agente: ahí es exactamente por donde entra el atacante.

It matters because buying the licences is not the same as having it. Consoles from excellent vendors are routinely found running in detect-only mode since installation day, with whole folders excluded because somebody added them in 2021 to stop it bothering an accounting system. And there is always a share of machines with no agent: that is exactly where the attacker gets in.

Qué beneficios traeBenefits it delivers

  • Mide la cobertura de agentes contra el inventario real y persigue los equipos que faltan, que es donde está el hueco.
  • Lleva las políticas de detección a bloqueo de forma gradual y controlada, en vez de dejarlas eternamente en observación.
  • Revisa y depura las exclusiones heredadas, que son el atajo favorito del que quiere evadir el control.
  • Convierte las detecciones en incidentes gestionados, no en una lista roja que nadie abre.
  • Measures agent coverage against the real inventory and chases the missing machines, which is where the gap sits.
  • Moves detection policies into blocking gradually and under control, instead of leaving them in observation forever.
  • Reviews and prunes inherited exclusions, the favourite shortcut for anybody wanting to evade the control.
  • Turns detections into managed incidents rather than a red list nobody opens.

¿En qué momentos es obligatorio?When is it mandatory?

Costa RicaCosta Rica

  • No hay obligación legal de tener EDR o XDR en Costa Rica.
  • El Acuerdo CONASSIF 5-24 exige a las entidades supervisadas capacidades de detección y respuesta, que en la práctica se sostienen sobre la telemetría de los equipos.
  • La nueva tabla de funciones de ciberseguridad del perfil tecnológico, de actualización anual, es donde esa capacidad se declara ante el supervisor.
  • There is no legal obligation to have EDR or XDR in Costa Rica.
  • CONASSIF Agreement 5-24 requires supervised entities to have detection and response capabilities, which in practice rest on endpoint telemetry.
  • The new cybersecurity functions table in the annually updated technology profile is where that capability is declared to the supervisor.

InternacionalInternational

  • PCI-DSS v4.0.1 exige protección contra software malicioso en los sistemas del alcance, mantenida al día y sin que el usuario pueda deshabilitarla.
  • ISO 27001 exige controles de protección contra malware y gestión de la configuración de los equipos.
  • NIS2 y DORA exigen capacidades de detección y respuesta, sin nombrar tecnología concreta.
  • PCI-DSS v4.0.1 requires anti-malware protection on in-scope systems, kept current and not disableable by the user.
  • ISO 27001 requires malware protection controls and endpoint configuration management.
  • NIS2 and DORA require detection and response capabilities, without naming a specific technology.

Requisitos mínimosMinimum requirements

  • Un inventario de equipos contra el cual medir cobertura: sin él, el porcentaje de despliegue es una adivinanza.
  • Un mecanismo de distribución de software para instalar y actualizar los agentes a escala.
  • Ventanas acordadas para endurecer políticas, porque el paso a bloqueo puede romper aplicaciones legítimas.
  • Decidir qué queda fuera de alcance y asumirlo por escrito: servidores viejos, sistemas industriales, equipos de terceros.
  • A device inventory to measure coverage against: without one, the deployment percentage is guesswork.
  • A software distribution mechanism to install and update agents at scale.
  • Agreed windows for hardening policies, because moving to blocking can break legitimate applications.
  • Deciding what stays out of scope and accepting it in writing: legacy servers, industrial systems, third-party devices.

Plazo típico de entregaTypical delivery time

Servicio continuo Ongoing service rango habitual del mercado usual market range

Es un servicio continuo. El despliegue inicial va de tres a ocho semanas según el tamaño del parque y la calidad del inventario. Lo que alarga el plazo casi nunca es instalar el agente sino el endurecimiento: pasar las políticas a bloqueo exige probar por grupos y aguantar las quejas de las primeras semanas.

This is a continuous service. Initial deployment runs from three to eight weeks depending on estate size and inventory quality. What stretches the timeline is almost never installing the agent but the hardening: moving policies into blocking requires testing by groups and absorbing the complaints of the first weeks.

NomenclaturaTerminology

Las siglas y estándares que aparecen en esta ficha, explicados. The acronyms and standards used on this page, explained.

EDREDR
Detección y respuesta en el equipo: registra el comportamiento de cada máquina y permite actuar sobre ella a distancia. Endpoint detection and response: records each machine behaviour and allows acting on it remotely.
XDRXDR
La misma idea extendida más allá del equipo: correo, identidad, nube y red en una sola consola correlacionada. The same idea extended beyond the endpoint: email, identity, cloud and network in a single correlated console.
AgenteAgent
El programa instalado en cada máquina que recoge la telemetría y ejecuta las acciones de bloqueo o aislamiento. The program installed on each machine that collects telemetry and executes blocking or isolation actions.
ExclusiónExclusion
Carpeta, proceso o ruta que la herramienta deja de inspeccionar. Necesaria a veces, peligrosa siempre que nadie la revise. A folder, process or path the tool stops inspecting. Sometimes necessary, always dangerous if nobody reviews it.
Modo bloqueoBlocking mode
La política que además de avisar impide la acción maliciosa. Sin ella, la herramienta solo documenta el ataque. The policy that not only alerts but prevents the malicious action. Without it, the tool merely documents the attack.