How Field Effect MDR Works

Introduction

Field Effect MDR is a cybersecurity solution that includes endpoint, cloud, and (for MDR Complete customers) network monitoring. When a cybersecurity situation is detected that requires action or follow-up, you will be notified via our core reporting mechanism - an ARO (Action, Recommendation, or Observation).


This article covers how Field Effect MDR's various components work and communicate with each other across the following topics:



How Field Effect MDR's Monitoring Works

The following sections outlines the various aspects of our MDR service and how they interoperate.


The MDR SIEM

The MDR SIEM (formerly called the primary appliance) acts as the service's main controller. Field Effect usually hosts this but in some cases you can choose to host it on your network (physically or virtually). 


Endpoint Monitoring

Field Effect MDR includes a powerful endpoint agents for Windows, Mac, and Linux hosts. This agent generate telemetry for reporting and ARO creation and is capable of taking active response actions to protect the host.


Our endpoint agent (see availability here) communicates with the primary appliance either directly (when on the same network) or through an encrypted relay connection. Depending on how the service is configured, the agent can intervene (isolate, block, etc.) when a threat is detected.


Installers can be downloaded from the primary appliance and the MDR Portal, and they support several installation types including GPO, RMM, etc. See our Installer Guides for more on this.


Cloud Monitoring

Field Effect MDR integrates with several cloud services, which are set up in the MDR Portal. Once a cloud service is enrolled, we will monitor and analyze the service's telemetry and user activity for reporting and ARO creation as well taking active response actions to protect accounts, when appropriate. See our Cloud Monitoring Overview and integration guides for more.


Network Monitoring

Field Effect MDR monitors network activity, generating telemetry for reporting and ARO creation. You will require network sensors for each site you want included in Field Effect's network monitoring. Your appliance type depends on your service tier and network requirements, but our sales and support teams will help ensure that your select the appropriate appliance(s) for your deployment.


Other Monitoring

  • MDR Complete customers can use the Field Effect MDR DNS Firewall to monitor DNS traffic. This will take action to block connections to malicious or deny list sites.
  • The Suspicious Email Analysis Service (SEAS) allows your users to report suspicious email and receive guidance on how to handle it.
  • Monthly Dark web monitoring, which will report on any sensitive data we’ve observed across the dark web.
  • MDR Complete customers can choose to send syslog to their MDR SIEM. This allows for log aggregation.
  • Antivirus Management allow you to manage AV on hosts with endpoint agents.


Add-ons

Field Effect MDR offers some additional add-ons to address customer needs, including:

  • Log Retention from our MDR SIEM for customers with data retention requirements exceeding 90 days
  • Security Awareness training to educate and test user cybersecurity awareness.


How Field Effect Notifies About Cybersecurity Issues

Most users will log into the MDR Portal (https://my.fieldeffect.net) to control and use Field Effect MDR. This will allow them to see their AROs, Field Effect's structured alerts that provide security teams with a recommended action, prioritized next step or contextual observation to accelerate response and reduce uncertainty. AROs are how Field Effect MDR delivers low-false positive alerts to clients and provides the mechanism for coordinating activities between our MDR analysts and clients.


For MDR Complete customers that want to dive deeper into the telemetry, alerts, and data that determine when we generate AROs, you can access the MDR SIEM (formerly called the Appliance Dashboard). Partners users may choose to use Vision to dig deeper across all of their clients.


Organizations can also choose to route their AROs to their PSA tools so that they can integrate AROs with the rest of their ticketing systems.


How Field Effect MDR Components Communicate

Field Effect must perform initial configuration of the MDR SIEM and network sensors.

Agent Configuration

Field Effect automatically configures each endpoint agent during installation with the information required to locate and securely connect to its assigned MDR SIEM. The agent continuously validates the identity of the appliance using certificates and will only establish communications with trusted Field Effect infrastructure.


Identity Server (epid.fieldeffect.net)

Immediately after an endpoint agent is installed, it connects to the Identity Server to retrieve its configuration (for your organization). If the agent loses its connection for more than a week, it will reconnect to in an attempt to restore the connection and reconfigure the agent. 


Log Server (installogs.fieldeffect.net)

This server collects data used for debugging. Following an installation, the agent provides a one-time report that includes basic host telemetry to help investigate failures. The Log Server can also request remote diagnostics via this connection.

When an agent has an unexpected issue or disruption, it is reported to the Log Server. If it detects that the agent not running, it can automatically force the agent to restart.


Endpoints Communication with the MDR SIEM

The endpoint agent communicates with the MDR SIEM using secure encrypted connections over TCP port 443. The agent can connect to the MDR SIEM in the following ways:

  • Direct Network Connection – When the endpoint is on the same network as the MDR SIEM, communication occurs directly.
  • Internet-Based Connection – When the endpoint is outside the local network (for example, remote users working from home or travelling), the agent securely connects to the MDR SIEM over TCP port 443.


This approach allows endpoints to maintain communication with the MDR SIEM regardless of their location while using a commonly permitted outbound port.


Field Effect Communication with the MDR SIEM

Field Effect MDR analysts and analytic processes communicate using secure encrypted connections from Field Effect datacenters over TCP/443 with the MDR SIEM to analyze data and determine the need to generate AROs.


Communication Security

Our configurations are signed by our root of trust, which is hard coded into the agent. All messages sent from an agent to the appliance are additionally encrypted with a client-specific key using X25519. Messages sent from the appliance to the agent are ED25519 signed with this key. Further, sensitive messages such as those related to our EDR rules are separately ED25519 signed with keys that are not present on the MDR SIEM, minimizing the impact of an MDR SIEM compromise.


Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article