Netskope LogoNetskope Logo
  • Security Services
  • AI Services
  • Networking Services
  • Analytics Services
  • Integrations
  • getting-started.svgGetting Started
    • Support
    • Community
    • Netskope.com
    © 2026 All Rights Reserved. Netskope Inc.
    Home
    Threat Protection
    Endpoint Detection and Response

    Endpoint Detection and Response

    Netskope will now only support Endpoint Detection and Response integrations with Netskope Threat Exchange. The in-tenant EDR integration will no longer be available after December 1, 2025. To learn more: Netskope Product EOL Announcements.
    Next Generation API Data Protection will not support any 3rd party Endpoint Detection & Response (EDR). When you configure a severity-based remediation action for threat quarantine, there will be no option to select a remediation endpoint. You cannot configure a remediation profile under Policies > Threat Protection. As an alternative, you can leverage and perform the same actions using Netskope Cloud Exchange. For more information, see:
    – Carbon Black Plugin for Threat Exchange
    – CrowdStrike Plugin for Threat Exchange

    Certain applications allow admins to query and collect data, like clients installed on each individual system in your network. The applications also have the capability to protect and mitigate against threats by performing actions on your systems. These applications provide indicators of compromise (IOC) data and trigger remediation to protect integrated systems from getting infected from attacks found by Netskope Threat Protection. 

    Endpoint Detection and Response (EDR) applications monitor endpoints for suspicious activity and provide visibility into malware and other cyber threats. Netskope supports Carbon Black and CrowdStrike for EDR integrations. A Standard Threat Protection license is required.

    Upon detection, EDR alerts appear in the Netksope UI on the Skope IT Pages.

    In this Topic
    • Endpoint Detection and Response