> ## Documentation Index
> Fetch the complete documentation index at: https://doc.khcolo.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Endpoint Security and ESET Antivirus for Businesses

> Protect every device in your organisation with ESET antivirus, enterprise EDR monitoring, and KHCOLO's centralised security management in Cambodia.

Every laptop, desktop, and server in your organisation is a potential entry point for malware, ransomware, and data theft — and attackers are counting on at least one device slipping through the cracks. KHCOLO's endpoint security service deploys and centrally manages **ESET Endpoint Security** across your entire fleet, pairs it with enterprise-grade EDR monitoring, and integrates daily log review into your managed IT maintenance workflow so that threats are caught and remediated before they cause damage.

<Warning>
  **Unmanaged endpoints are a critical risk in Cambodia's threat landscape.** Cambodia consistently ranks among the regions with high rates of malware infection and targeted phishing campaigns, particularly against SMEs and financial services firms. Devices running expired antivirus, consumer-grade software, or no AV at all are actively exploited — often going undetected for weeks. A single compromised endpoint can expose your entire network, client data, and financial systems. Do not operate business devices without actively managed, enterprise-grade endpoint protection.
</Warning>

***

## ESET Endpoint Security

KHCOLO deploys **ESET Endpoint Security** as the foundation of your organisation's defence. ESET is a globally recognised endpoint protection platform trusted by over 110 million users, combining low system overhead with multi-layered threat detection that goes far beyond traditional signature-based antivirus.

### What ESET Protects Against

<CardGroup cols={2}>
  <Card title="Ransomware Shielding" icon="lock">
    ESET's ransomware shield monitors file system behaviour in real time. It detects mass encryption attempts and halts the process immediately, preserving your data before the attack completes.
  </Card>

  <Card title="Zero-Day Malware" icon="bug">
    The ESET LiveGrid cloud reputation system and heuristic engine identify previously unseen threats based on behaviour, not just known signatures.
  </Card>

  <Card title="Phishing & Web Threats" icon="fish">
    Web access protection scans URLs and downloads in real time, blocking phishing sites, malicious scripts, and drive-by downloads before they execute.
  </Card>

  <Card title="Network Attack Prevention" icon="network-wired">
    Detects and blocks network-level exploits, brute-force attacks, and vulnerability scanning directed at your endpoints.
  </Card>

  <Card title="Removable Media Control" icon="usb-drive">
    Enforce policies on USB drives and external storage — prevent unauthorised devices from introducing malware or exfiltrating data.
  </Card>

  <Card title="Email Client Protection" icon="envelope-open-text">
    Scans incoming and outgoing email attachments within mail clients (Outlook, Thunderbird), adding a local layer of protection on top of gateway-level filtering.
  </Card>
</CardGroup>

***

## Enterprise EDR Monitoring

Beyond traditional antivirus, KHCOLO's service includes **Endpoint Detection and Response (EDR)** capabilities that give your IT team (or KHCOLO's managed IT team) deep visibility into what is happening on every device.

### EDR Capabilities

* **Continuous behavioural monitoring** — records process execution, network connections, file system changes, and registry modifications on each endpoint
* **Threat hunting** — query historical endpoint telemetry to identify indicators of compromise (IOCs) that may have been missed at the time of execution
* **Automated response actions** — isolate a compromised endpoint from the network with a single click, preventing lateral movement while you investigate
* **Incident timeline reconstruction** — trace the full chain of events for any detected threat, from initial execution to any files dropped or network connections made
* **Alert triage** — KHCOLO's managed IT team reviews EDR alerts as part of the daily maintenance workflow, escalating confirmed incidents immediately

<Info>
  EDR monitoring is included in KHCOLO's per-user managed IT pricing tier. If you are managing your own IT team, ESET's PROTECT Cloud console gives your administrators direct access to all EDR telemetry and response tools.
</Info>

***

## Centralised Management Console

All ESET-protected endpoints are managed through a single **ESET PROTECT** console — either cloud-hosted or deployed on your own server. This gives administrators a unified view of your entire endpoint estate.

### Console Capabilities

| Feature                   | Description                                                                                                     |
| ------------------------- | --------------------------------------------------------------------------------------------------------------- |
| **Dashboard**             | Real-time overview of threat detections, update status, and device connectivity across all endpoints            |
| **Policy management**     | Push consistent security policies (scan schedules, exclusions, web filtering rules) to all devices or per-group |
| **Remote deployment**     | Install or update the ESET agent on new endpoints remotely without physical access                              |
| **Patch & update status** | Monitor ESET signature and engine update status — ensure every device is running the latest definitions         |
| **Scan log archive**      | Centralised repository of completed scan results with filtering by device, threat type, and date range          |
| **Reporting**             | Scheduled and on-demand reports on threat activity, device compliance, and policy violations                    |
| **Role-based access**     | Grant read-only access to department heads or auditors without exposing full admin controls                     |

***

## Daily AV Log Review Workflow

Endpoint security is only effective if someone is actively reading what it finds. KHCOLO's managed IT maintenance checklist includes a **daily antivirus log review** as a core task — ensuring no detection goes unnoticed.

<Steps>
  <Step title="Morning Log Pull">
    Each business day, the KHCOLO IT team (or your designated administrator) opens the ESET PROTECT console and reviews the prior 24 hours of detection and scan logs across all endpoints.
  </Step>

  <Step title="Threat Classification">
    Detections are classified by severity. Informational items (PUPs, tracking cookies) are noted. High-severity detections (ransomware, trojans, exploit attempts) trigger immediate escalation.
  </Step>

  <Step title="Remediation Actions">
    For confirmed threats, remediation steps are executed: quarantine confirmation, file deletion, endpoint isolation if required, and password resets for affected user accounts.
  </Step>

  <Step title="Root Cause Investigation">
    EDR telemetry is reviewed to determine how the threat arrived (phishing email, USB device, malicious download) and whether other endpoints may have been exposed to the same vector.
  </Step>

  <Step title="Log & Report">
    All findings and actions are recorded. Monthly security summary reports are provided to your management team, covering threat counts, response times, and any recommended policy adjustments.
  </Step>
</Steps>

For the complete daily IT maintenance procedure that incorporates AV log reviews alongside other tasks, see the [IT Maintenance Checklist](/it-management/maintenance-checklist).

***

## Deployment Process

<Steps>
  <Step title="Endpoint Inventory">
    KHCOLO audits all devices in your organisation — workstations, laptops, and servers — to establish a baseline and remove any conflicting AV software before deployment.
  </Step>

  <Step title="ESET PROTECT Console Setup">
    The management console is provisioned (cloud or on-premises) and configured with your organisational structure, device groups, and initial security policies.
  </Step>

  <Step title="Agent Rollout">
    The ESET agent is deployed to all endpoints via remote push, GPO (for domain-joined environments), or manual installation on standalone devices.
  </Step>

  <Step title="Policy Configuration">
    Scan schedules, real-time protection settings, web filtering rules, and device control policies are customised to your business requirements.
  </Step>

  <Step title="Initial Full Scan">
    A full system scan is run across all endpoints to establish a clean baseline and identify any pre-existing threats before the managed monitoring service begins.
  </Step>

  <Step title="Handover & Training">
    Your team receives a walkthrough of the console. If KHCOLO is managing monitoring, we confirm the daily log review schedule and escalation contact procedures.
  </Step>
</Steps>

<Tip>
  Ask your KHCOLO account manager about bundling endpoint security with **Enterprise Email Security** (secure email gateway and advanced threat filtering). Combining endpoint and email protection under a single managed service gives you coordinated detection — a threat blocked at the email gateway is automatically cross-referenced against endpoint telemetry.
</Tip>
