OpenEDR is an open-source endpoint detection and response platform developed by OpenShield. It provides real-time monitoring of endpoints across Windows, Linux, and macOS using lightweight agents that collect system activity data for behavioral analysis. The platform features automated threat detection through customizable YARA-based rulesets, integrated malware sandboxing, and forensic timeline reconstruction capabilities. Key technical components include a centralized cloud management console for policy enforcement, prebuilt playbooks for common attack scenarios like ransomware, API integrations with SIEM/SOAR systems, and low-resource agent architecture optimized for legacy hardware support.