EDR tools, such as CrowdStrike, SentinelOne, or Microsoft Defender, generate alerts based on behavioral analysis and known threat signatures at the endpoint level. They give SOC analysts detailed visibility into what is happening on individual laptops, servers, and other devices. EDR is one of the primary alert sources in most SOC environments and is often the first tool analysts query when investigating a potential compromise.