Skip to content
Review Open access

An Overview of EDR Serviceability for Security Information and Event Management (SIEM)

Jul 2026 · Journal of Information Assurance and Security · Vol 21, pp. 52 - 88 · 0 citations · 122 references

TL;DR

This review synthesizes key developments and innovations in the EDR-SIEM domain, drawing from academic research, industry analysis, and real-world applications to contribute to higher quality, improved performance, effective cost management, better decision-making, and reduced risk.

Abstract

Abstract This review paper focuses on and addresses Endpoint Detection and Response (EDR) tools, providing an overview of their purpose, functions, operations, services, and benefits within the cybersecurity landscape. Specifically, EDR solutions are designed to detect, prevent, investigate, and respond to advanced cyber threats that often bypass traditional antivirus programs. To achieve this, these tools continuously collect and analyze data in real time using behavioral analytics, artificial intelligence (AI), and machine learning (ML). This enables the identification of anomalous activities and sophisticated attack patterns, such as zero-day exploits and fileless malware. Furthermore, the integration of open-source tools strengthens an organization's security posture by enhancing service capabilities, scalability, reliability, and availability. The paper also discusses the evolution of EDR from standalone tools to integrated, interoperable, automated, and intelligence-driven platforms that utilize behavioral and predictive analysis to counter increasingly sophisticated threats. Such integration, in turn, enables faster decision-making while reducing code complexity, operational costs, and response times. Ultimately, the sustainability of open-source tools contributes to higher quality, improved performance, effective cost management, better decision-making, and reduced risk. In summary, this review synthesizes key developments and innovations in the EDR-SIEM domain, drawing from academic research, industry analysis, and real-world applications.

Read PDF

Similar papers

Open access Jul 2026

SOAR Automation Platform for Cybersecurity Incident Response

Increasing numbers of cyberattacks led to increasing workload for Security Operations Centers (SOCs). SOC analysts are inundated with hundreds and thousands of alerts from SIEM, IDS/IPS, EDR, firewalls, and cloud/endpoint security systems. Manual investigation leads to alert fatigue, slow responses, and inconsistencies. This paper will focus on an AI-driven Security Orchestration, Automation and Response (SOAR) platform that involves: secure authentication, central monitoring, machine learning-based anomaly detection, Groq AI-driven incident analysis, threat intelligence enhancement, n8n workflow automation, AI chatbot, and automatic reporting. The unified platform increases efficiency, drastically reduce human effort to repetitive work, quick incident response times, enhances the quality of investigations, and provides a comprehensive view of an organizations security posture. The platform is also modular to further integrate with cloud security, SIEM, EDR, malware analysis and predictive analyses

Bhumika A R, Jhanavi H N, Prof. Thejaswini M N · 0 citations
Open access Jul 2026

Modern cybersecurity architecture for fraud prevention in administrative services

A cybersecurity architecture oriented toward fraud prevention in a service sector company in Lima, Peru, whose design is grounded in the documentary analysis of 385 technical incident records is proposed, forming a defense-in-depth capable of reducing residual exposure and sustaining a robust anti-fraud response in digitalized administrative environments.

Enrique Castellares Cuya, José Rengifo Espinal · 0 citations
Review Open access Jul 2026

Penetration Testing in System Security

This review's results show that penetration testing is an important part of improving cybersecurity because it helps identify weaknesses before they become problems and reduces risk.

Shruti Agarwal, Shilpi Sharma · 1 citation
Review Open access Aug 2026

A Survey on Cybersecurity Threats in Industrial and Information Technology Environments: Advancements and Resilience Through Network Steganographic Techniques

This paper analyzes eight major IT/OT threats in the view of their empowerment via steganography to anticipate the evolution of malicious software targeting IT/OT scenarios when endowed with advanced data hiding schemes, i.e., multi level steganography.

Przemysław Szary, Wojciech Mazurczyk, L. Caviglione · 0 citations
Review Open access Jul 2026

AIS Cybersecurity: Challenges, Vulnerabilities, and Mitigation Strategies

This survey provides an AIS-first, security-focused synthesis of AIS cybersecurity research, bringing together cybersecurity, maritime operations, and data-science perspectives, that provides practical guidance for securing AIS-based systems and highlights open problems for future standardization and implementation.

Silvie Levy, Ehud Gudess, Danny Hendler · 0 citations
Conference Aug 2026

Real-Time DDoS Detection by Integrated eBPF Telemetry and Machine Learning-enhanced SIEM

Distributed Denial-of-Service (DDoS) attacks remain one of the most disruptive threats to modern web services, overwhelming application resources and degrading service availability. This paper presents a lightweight, virtualized system architecture for real-time DDoS detection that combines kernellevel telemetry collection with machine learning (ML) based analysis. The proposed architecture enables fine-grained, lowoverhead log collection without modifying the web applications because the network and application-level events generated during normal and attack traffic are captured directly at the kernel layer by means of an extended Berkeley Packet Filter (eBPF). The collected logs are then processed within a Security Information and Event Management (SIEM) platform, where ML–based detection models analyze traffic patterns and behavioral features to identify DDoS attacks in near real-time. This architecture improves visibility into attack characteristics while maintaining minimal performance impact on the protected services. The proposed system demonstrates how eBPF-based observability, when integrated with SIEM and ML techniques, can provide an effective, scalable, and modular approach for DDoS detection in virtualized environments. The design is particularly suited for cloud and multi-VM deployments, offering enhanced security monitoring, faster attack detection, and improved operational resilience.

Zeeshan Ali, A. Marotta, W. Tiberti et al. · 0 citations