Connect your EDR / XDR
Endpoint detection and response platforms hold the ground truth of your endpoint posture — agent coverage, detections, response actions. TruSecure's EDR/XDR connector pulls that posture into the governance record, so 'do we monitor our endpoints?' becomes a query, not a claim.
What the connector pulls
| Source system | What TruSecure pulls | Feeds governance |
|---|---|---|
| Agent fleet | Deployment status, agent versions, stale agents | Evidence Automation · coverage controls |
| Detection events | Detections, severity, MITRE tactics | Incident and Resilience Workflows · NIS2 Art. 23 triggers |
| Response actions | Isolations, kills, restores, by whom and when | Audit Trail · response-effectiveness evidence |
| Policy state | Prevention policies, exclusions, tamper protection | Control Library · hardening measures |
Evidence produced from EDR / XDR data
One control test pulled from live EDR / XDR state — not a manual export, not a screenshot, but a verified query result with provenance:
- Control tested
- NIS2 Art. 21(2)(d) — detection on all managed endpoints
- EDR source
- CrowdStrike · sensor: windows/7.16.0-1709
- Test
- re-perform · fleet coverage and sensor health
- Sample
- 1,082/1,102 endpoints · 98.2% covered
- Result
- pass with exceptions · 3 stale sensors, 17 cloud-shadow hosts
- Evidence
- EDR API query · timestamped 2026-08-22T08:04:41Z
- Export
- sealed · sha256:e1c9...4b7f
Setup and scope model
- Read-only, scoped permission
Connector requires read-only access to detection events, response logs, and agent status. No write permissions, no ability to isolate hosts or change policies.
- Data filtered by entity
Pull is scoped to the TruSecure entity context — your endpoints only, no cross-tenant data. Coverage percentages match your fleet, not the tenant-wide number.
- Continuous sync
Coverage re-computed on every control test. A stale sensor shows as a stale sensor the day it goes stale, not at quarter-end.
Commercial packaging
EDR / XDR connectors are part of the paid TruSecure Fabric subscription. The connector itself, the continuous sync, the evidence provenance tracking, and the mapping to NIS2, DORA, ISO 27001, SOC 2 and other frameworks are all included — no per-connector fees, no usage tiers. Pricing is scoped in the conversation, not a price list.
How integration works
A demo with your actual EDR / XDR environment shown in preview mode — your data pulling into governance, feeding controls and evidence. Then a Resilience Sprint that configures the connector for production, scopes the entity context, and validates the first evidence pull. No self-serve checkout, no per-connector pricing.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.