Hi WithSecure, one best method to detect any malicious actor in one network is the capacity to deploy decoy hosts and servers, and monitor for unauthorized access. After detect unauthorized access the EDR can be execute automatic playbook.
Thanks for the suggestion! The product team will review your request.