Dear community,
We are expanding the Automated actions feature in Elements EDR to help partners respond to endpoint threats faster and at scale. With this update, you can now create automated rules that trigger six new EDR response actions whenever a Broad Context Detection (BCD) is created or updated to a medium, high, or severe risk level.
What is changing?
Automated Actions for endpoint rules already supported Device Isolation as an automated response. We are now adding six new response actions, giving you greater flexibility to automate incident response across your customer organisations.
With this update, six new response actions are available for automation:
- Retrieve files - collects files from endpoints based on path patterns,
- Enumerate services - lists all installed services on Windows endpoints,
- Retrieve browser artefacts - collects browser history and data from major browsers,
- Netstat - retrieves network connection information,
- Enumerate scheduled tasks - lists Windows scheduled tasks,
- Enumerate processes - lists all running processes.
How rules work
When creating a rule with one of the new response actions, you choose a risk level trigger (Medium, High, or Severe) and a device scope. Rules set to "All Devices" can span multiple customer organisations; rules scoped to "Devices with specific labels" apply to a single organisation only. Schedule options remain Continuous or Custom, and the rule type is fixed to Endpoint. As with existing rules, the rule type and response type cannot be changed after creation, all other fields remain editable.
With automated EDR response actions, you can:
- Reduce manual effort when responding to endpoint threats,
- Ensure consistent, policy-driven responses to similar risk levels,
- Scale security operations across many customer organisations,
- Focus expert attention on complex investigations rather than repetitive tasks.
We believe this improvement will meaningfully reduce the manual burden on partners managing high volumes of endpoint detections, and bring the power of EDR response actions into your automated workflows.