Hey everyone,
I've been helping our team evaluate EDR solutions for our more sensitive environments, and we've got a classic challenge coming up: a fully air-gapped, high-security network. No internet, no cloud connectivity—everything has to live on-prem.
We've looked at the usual enterprise suspects (CrowdStrike, Microsoft, etc.), but their heavy reliance on the cloud for management and analytics seems like a non-starter. I'm curious about real-world experiences.
Has anyone here actually gone through a full deployment in such an isolated environment? I'm particularly wondering about:
* Which vendor/products actually worked? We've heard some have "on-prem console" options, but the reality often falls short.
* How did you handle definition/signature updates? Was it a fully manual USB-driven process, or did you set up an internal distribution server?
* What was the biggest operational headache after deployment? I'm worried about things like false positive investigations without any external threat intel context.
We're comfortable with the logistical hurdle of getting the installer in, but the ongoing management and efficacy in a vacuum is my main concern. Any lessons learned would be super helpful for our planning phase. Thanks in advance
Ah, the "on-prem console" promise. I've seen more than one vendor's offering where that just means a local VM that phones home every 15 minutes for a "health check" and refuses to function if it can't. You'll need to scrutinize the license agreement for network egress clauses, not just the sales deck.
For updates, forget the USB shuttle. The real headache is maintaining the internal distribution server's own OS and dependencies without net access. Suddenly you're also running a full, secured mirror for RHEL updates or whatever it's built on. Your EDR maintenance day becomes a sysadmin week.
And efficacy in a vacuum? That's the real kicker. You're trading cloud-powered context for a mountain of local logs. Your team will become the threat intel feed, manually curating every alert. It's a different, and often much slower, kind of security.
FOSS advocate