Kandji EDR is an endpoint detection and response solution designed for Mac and Windows environments. The solution employs static file analysis, checksum-based detections, and behavioral detections that analyze process behaviors in real-time to identify potential threats. Behavioral detections utilize Apple's Endpoint Security framework to evaluate each process before execution, with the Kandji Agent processing these events in real-time for signs of suspicious or malicious behavior. Real-time process monitoring tracks process chains and command-line activity to detect novel attacks and prevent lateral movement. The solution includes AI-enhanced file analysis to identify malware and unwanted programs, with the ability to allow or block files by hash, path, or publisher. Blocked items trigger a detection and quarantine action. The solution provides controls for removable media and network volumes, including encryption and access permission controls for USB drives, DMGs, SD cards, and server shares. Kandji EDR operates on the Kandji Agent and is managed through a web application alongside device management capabilities. EDR events and tenant activity logs can be streamed to Amazon S3 buckets for SIEM ingestion and analysis.