[![](https://1.bp.blogspot.com/-02gmDwssX6I/X7NeUmSof6I/AAAAAAAAUZM/DsK-gF0mowYMB78XRA12uNh2Nj4ChbV-gCNcBGAsYHQ/w640-h142/openedr_1.jpeg)]()
We at OpenEDR believe in creating a [cybersecurity]( “cybersecurity” ) platform with its source code openly available to public, where products and services can be provisioned and managed together. EDR is our starting point. OpenEDR is a full blown EDR capability. It is one of the most sophisticated, effective EDR code base in the world and with the communitys help it will become even better.
OpenEDR is free and its source code is open to public. OpenEDR allows you to analyze whats happening across your entire environment at base-security-event level. This granularity enables accurate root-causes analysis needed for faster and more effective remediation. Proven to be the best way to convey this type of information, process hierarchy tracking provide more than just data, they offer actionable knowledge. It collects all the details on endpoints, hashes, and base and advanced events. You get detailed file and device trajectory information and can navigate single events to uncover a larger issue that may be compromising your system.
OpenEDRs security architecture simplifies _breach detection, protection and visibility_ by working for all threat vectors without requiring any other agent or solution. The agent records all telemetry information locally and then will send the data to locally hosted or cloud hosted ElasticSeach deployments. Real-time visibility and continuous analysis are the vital elements of the entire endpoint security concept. OpenEDR enables you to perform analysis into what’s happening across your environment at base event level granularity. This allows accurate root cause analysis leading to better remediation of your compromises. Integrated Security Architecture of OpenEDR delivers Full Attack Vector Visibility including MITRE Framework.
The Open EDR consists of the following components:
* Runtime components
* Core Library the basic framework;
* Service service application;
* Process Monitor components for per-process monitoring;
* Injected DLL the library which is injected into different processes and hooks API calls;
* Loader for Injected DLL the driver component which loads injected DLL into each new process
* Controller for Injected DLL service component for interaction with Injected DLL;
* System Monitor the genetic container for different kernel-mode components;
* File-system mini-filter the kernel component that hooks I/O requests file system;
* Low-level process monitoring component monitors processes creation/deletion using system callbacks
* Low-level registry monitoring component monitors registry access using system callbacks
* Self-protection provider prevents EDR components and configuration from unauthorized changes
* Network monitor network filter for monitoring the network activity;
* Installer
Generic high-level interaction diagram for runtime components
[![](https://1.bp.blogspot.com/-PvAlgzyFxjk/X7NeeA8DyNI/AAAAAAAAUZQ/35JaD8oS6gIolXM8T7fSPy7bdjX92ifyACNcBGAsYHQ/w640-h326/openedr_4.png)]()
[]( “Open EDR public repository (5)” )For details you can refer here :
**Build Instructions**
You should have Microsoft Visual Studio to build the code
* Microsoft Visual Studio Solution File is under /openedr/edrav2/build/vs2019/
* All OpenEDR Projects are in /openedr/edrav2/iprj folder
* All external Projects and Libraries are in /openedr/edrav2/eprj folder
**Libraries Used:**
* AWS SDK AWS SDK for C++ : ()
* Boost C++ Libraries ([https://www.boost.org/]( “https://www.boost.org/” ))
* c-ares: asynchronous resolver library ()
* Catch2: a unit [testing framework]( “testing framework” ) for C++ ()
* Clare : Command Line parcer for C++ ()
* Cli: cross-platform header only C++14 library for interactive command line interfaces ()
* Crashpad: crash-reporting system ()
* Curl: command-line tool for transferring data specified with URL syntax ()
* Detours: for monitoring and instrumenting API calls on Windows. ()
* Google APIs: Google APIs ()
* JsonCpp: C++ library that allows manipulating JSON values ()
* libjson-rpc-cpp: [cross platform]( “cross platform” ) JSON-RPC (remote procedure call) support for C++ ()
* libmicrohttpd : C library that provides a compact API and implementation of an HTTP 1.1 web server ()
* log4cplus: C++17 logging API ()
* MadcHook, MadcHookDrv : Hooking
* NetFilter SDK & ProtocolFilter: Network filtering toolkit ()
* nlohmann JSON: JSON library for C++: ()
* OpenSSL Toolkit ([https://www.openssl.org/]( “https://www.openssl.org/” ))
* Tiny AES in C: implementation of the AES ECB, CTR and CBC [encryption algorithms]( “encryption algorithms” ) written in C. ()
* Uri: C++ Network URI ([https://www.boost.org/]( “https://www.boost.org/” ))
* UTF8-CPP: UTF-8 with C++ ()
* xxhash_cpp: xxHash library to C++17. ()
* Zlib: Compression Libraries ()
**Roadmap**
Please refer here for project roadmap :
**Installation Instructions**
OpenEDR is single agent that can be installed on Windows endpoints. It generates extensible telemetry data over all security relevant events. It also use file lookup, analysis and verdict systems from Comodo, . You can also have your own account and free license there.
The telemetry data is stored locally on the endpoint itself. You can use any log streaming solution and analysis platform. Here we will present, how can you do remote streaming and analysis via open source tools like [Elasticsearch]( “Elasticsearch” ) and Filebeat.
**OpenEDR :**
OpenEDR project will release installer MSIs signed by Comodo Security Solutions, The default installation folder is C:Program FilesOpenEdrEdrAgentV2, currently we dont have many option to edit/configure the rule set, alerts etc. Those will be coming with upcoming releases.
The agent outputs to C:ProgramDataedrsvclogoutput_events by default, there you will see the EDR telemetry data where you should point this to Filebeat or other log streaming solutions you want.
**Elasticsearch:**
There are multiple options to run Elasticsearch, you can either install and run it on your own machine, on your data center or use Elasticsearch service on public cloud providers like AWS and GCP. If you want to run Elasticsearch by yourself. You can refer to here for installation instructions on various platforms
Another option is using Docker, this will also enable a quick start for PoC and later can be extended to be production environment as well. You can access the guide for this setup here :
**Filebeat:**
Filebeat is very good option to transfer OpenEDR outputs to Elasticsearch, you need to install Filebeat on each system you want to monitor. Overall instructions for it can be found here :
We dont have OpenEDR Filebeat modules yet so you need to configure custom input option for filebeat
**Releases**
**Screenshots**
How OpenEDR integration with a platform looks like and also a showcase for openedr capabilities
Detection / Alerting []( “Open EDR public repository (44)” )
[![](https://1.bp.blogspot.com/-Ibk5lXTblmA/X7Nenpi9EiI/AAAAAAAAUZY/1rHcpMd5bnYknTfpCFv1JRryvJVSAOShQCNcBGAsYHQ/w640-h294/openedr_7_Screenshot_1.jpeg)]()
Event Details []( “Open EDR public repository (45)” )
[![](https://1.bp.blogspot.com/-XmwRMADikg8/X7NeuSRjECI/AAAAAAAAUZg/yCPQ3U2VbboTDwfPHgKecxwmlrFgB8MWQCNcBGAsYHQ/w640-h308/openedr_8_Screenshot_2.jpeg)]()
Dashboard []( “Open EDR public repository (46)” )
[![](https://1.bp.blogspot.com/-65pupGQSZJQ/X7Ne0MRMI5I/AAAAAAAAUZk/u5sKiTZg3dEJEu9kgYuiTiKKEPN4M8n9wCNcBGAsYHQ/w640-h304/openedr_9_Screenshot_3.jpeg)]()
Process Timeline []( “Open EDR public repository (47)” )
[![](https://1.bp.blogspot.com/-_2QSxaBExw4/X7Ne5M9eOzI/AAAAAAAAUZs/aGOb7sOa-MU6aTd1KhexVi9nQ8NdA021QCNcBGAsYHQ/w640-h280/openedr_10_Screenshot_4.jpeg)]()
Process Treeview []( “Open EDR public repository (48)” )
[![](https://1.bp.blogspot.com/-dPPGvCpVNd0/X7Ne8VaN-oI/AAAAAAAAUZw/aCrpApC9p6IqeqQdqWwvW-oygy2ZJJ7hgCNcBGAsYHQ/w640-h306/openedr_11_Screenshot_5.jpeg)]()
Event Search []( “Open EDR public repository (49)” )
[![](https://1.bp.blogspot.com/-96VubWx6W68/X7Ne_9IXGOI/AAAAAAAAUZ4/xb-vYxmSk6Qkf_o1dfq6rYbEALx6Du48wCNcBGAsYHQ/w640-h310/openedr_12_Screenshot_6.jpeg)]()
**[Download Openedr]( “Download Openedr” )**Read More
References
Back to Main