Notifications
Clear all
Endpoint / EDR / XDR
1
Posts
1
Users
0
Reactions
4
Views
Topic starter
14/07/2026 2:29 pm
Hey everyone. I'm new to EDR and we're rolling out CrowdStrike in our manufacturing plants. The problem is we're getting flooded with IOA alerts from legacy equipment and specialized engineering workstations. It's mostly related to unsigned drivers and weird process chains from old proprietary software.
Our security team mentioned tuning IOA exclusions, but I'm not sure where to start without breaking detection. For those who've done this in OT/industrial environments, what's the best approach? Should we focus on path exclusions or process trust first? Also, how do you handle the risk vs. noise trade-off? Any examples would be super helpful!
Still learning