ESET Endpoint Security
KHCOLO deploys ESET Endpoint Security as the foundation of your organisation’s defence. ESET is a globally recognised endpoint protection platform trusted by over 110 million users, combining low system overhead with multi-layered threat detection that goes far beyond traditional signature-based antivirus.What ESET Protects Against
Ransomware Shielding
ESET’s ransomware shield monitors file system behaviour in real time. It detects mass encryption attempts and halts the process immediately, preserving your data before the attack completes.
Zero-Day Malware
The ESET LiveGrid cloud reputation system and heuristic engine identify previously unseen threats based on behaviour, not just known signatures.
Phishing & Web Threats
Web access protection scans URLs and downloads in real time, blocking phishing sites, malicious scripts, and drive-by downloads before they execute.
Network Attack Prevention
Detects and blocks network-level exploits, brute-force attacks, and vulnerability scanning directed at your endpoints.
Removable Media Control
Enforce policies on USB drives and external storage — prevent unauthorised devices from introducing malware or exfiltrating data.
Email Client Protection
Scans incoming and outgoing email attachments within mail clients (Outlook, Thunderbird), adding a local layer of protection on top of gateway-level filtering.
Enterprise EDR Monitoring
Beyond traditional antivirus, KHCOLO’s service includes Endpoint Detection and Response (EDR) capabilities that give your IT team (or KHCOLO’s managed IT team) deep visibility into what is happening on every device.EDR Capabilities
- Continuous behavioural monitoring — records process execution, network connections, file system changes, and registry modifications on each endpoint
- Threat hunting — query historical endpoint telemetry to identify indicators of compromise (IOCs) that may have been missed at the time of execution
- Automated response actions — isolate a compromised endpoint from the network with a single click, preventing lateral movement while you investigate
- Incident timeline reconstruction — trace the full chain of events for any detected threat, from initial execution to any files dropped or network connections made
- Alert triage — KHCOLO’s managed IT team reviews EDR alerts as part of the daily maintenance workflow, escalating confirmed incidents immediately
EDR monitoring is included in KHCOLO’s per-user managed IT pricing tier. If you are managing your own IT team, ESET’s PROTECT Cloud console gives your administrators direct access to all EDR telemetry and response tools.
Centralised Management Console
All ESET-protected endpoints are managed through a single ESET PROTECT console — either cloud-hosted or deployed on your own server. This gives administrators a unified view of your entire endpoint estate.Console Capabilities
Daily AV Log Review Workflow
Endpoint security is only effective if someone is actively reading what it finds. KHCOLO’s managed IT maintenance checklist includes a daily antivirus log review as a core task — ensuring no detection goes unnoticed.1
Morning Log Pull
Each business day, the KHCOLO IT team (or your designated administrator) opens the ESET PROTECT console and reviews the prior 24 hours of detection and scan logs across all endpoints.
2
Threat Classification
Detections are classified by severity. Informational items (PUPs, tracking cookies) are noted. High-severity detections (ransomware, trojans, exploit attempts) trigger immediate escalation.
3
Remediation Actions
For confirmed threats, remediation steps are executed: quarantine confirmation, file deletion, endpoint isolation if required, and password resets for affected user accounts.
4
Root Cause Investigation
EDR telemetry is reviewed to determine how the threat arrived (phishing email, USB device, malicious download) and whether other endpoints may have been exposed to the same vector.
5
Log & Report
All findings and actions are recorded. Monthly security summary reports are provided to your management team, covering threat counts, response times, and any recommended policy adjustments.
Deployment Process
1
Endpoint Inventory
KHCOLO audits all devices in your organisation — workstations, laptops, and servers — to establish a baseline and remove any conflicting AV software before deployment.
2
ESET PROTECT Console Setup
The management console is provisioned (cloud or on-premises) and configured with your organisational structure, device groups, and initial security policies.
3
Agent Rollout
The ESET agent is deployed to all endpoints via remote push, GPO (for domain-joined environments), or manual installation on standalone devices.
4
Policy Configuration
Scan schedules, real-time protection settings, web filtering rules, and device control policies are customised to your business requirements.
5
Initial Full Scan
A full system scan is run across all endpoints to establish a clean baseline and identify any pre-existing threats before the managed monitoring service begins.
6
Handover & Training
Your team receives a walkthrough of the console. If KHCOLO is managing monitoring, we confirm the daily log review schedule and escalation contact procedures.