Endpoint and infrastructure sources

Endpoint and infrastructure sources are host-based systems that generate security telemetry through an installed agent or supported host-level integration. These sources form the primary signal surface for Kaseya MDR, enabling the managed SOC to detect, investigate, and respond to threats across user endpoints, servers, and infrastructure hosts.

Use this article to understand how real systems (endpoints and servers) participate in MDR detection and investigation, not how agents are installed, deployed, or configured on individual machines.

This article explains:

  • What endpoint and infrastructure sources represent in Kaseya MDR

  • How these sources become active after agent deployment or host integration

  • Where endpoint and server activity appears in the MDR interface

  • What types of telemetry these sources contribute, including default Windows Event Log monitoring

  • How to tell, based on alerts and investigations, that endpoint ingestion is working

What are endpoint and infrastructure sources?

Endpoint and infrastructure sources typically include:

  • User endpoints (workstations and laptops)

  • Servers (physical or virtual)

  • Infrastructure hosts running monitored workloads or services

Once active, these systems generate continuous security-relevant telemetry that is evaluated by MDR detection logic and reviewed by the managed SOC.

Endpoint and infrastructure sources form the primary signal surface for Kaseya MDR.

How endpoint and infrastructure sources become active

Endpoint and infrastructure sources become active in Kaseya MDR after a host successfully reports telemetry. Unlike application‑ or integration‑based sources:

  • There is no Add Application workflow

  • There is no application‑level connection status

  • Visibility is established when the agent begins reporting

Association with an organization occurs during agent deployment or assignment. Once the endpoint checks in successfully, it becomes an active MDR data source for that organization.

For deployment methods, platform requirements, and onboarding procedures, see the agent deployment articles referenced from this section.

Where endpoint and infrastructure activity appears

Endpoint and infrastructure systems do not appear as configurable applications or services. Their presence is reflected through alert context and investigation evidence.

You will encounter endpoint and infrastructure activity in:

  • Alert details: Host‑based process, file, network, or operating‑system activity is included when an endpoint contributes to a detection.

  • Analysis > Investigations: Activity from endpoints, servers, identity signals, and network sources is correlated to support investigation and validation.

Endpoint visibility in Kaseya MDR is alert‑driven, not inventory‑driven. Systems become visible through the alerts and investigations they participate in, not through an asset list.

How endpoint and infrastructure sources differ from other MDR data sources

Endpoint and infrastructure sources differ from other MDR telemetry in important ways:

  • They are host‑centric, not service‑centric

  • They generate continuous behavioral telemetry

  • They are the primary basis for process‑ and behavior‑based detections

By contrast:

  • Identity and cloud activity contribute authentication and account‑level context

  • Network and log‑based sources contribute infrastructure and traffic signals

  • MSP and IT operations tools provide operational and workflow context

Endpoint telemetry anchors MDR investigations in observable system behavior.

What telemetry endpoint and infrastructure sources provide

Endpoint and infrastructure sources commonly contribute:

  • Process creation and execution activity

  • File system and registry activity

  • Network connections originating from the host

  • Operating system and security‑relevant events

  • Behavioral indicators associated with common attack techniques

This telemetry is evaluated alongside data from identity, network, and log‑based sources to validate risk and scope. Endpoint detections may include contextual metadata such as mapped attack techniques (TTPs) or operating system event identifiers derived from host activity.

Windows Event IDs

Kaseya MDR uses the same Windows Event Log monitoring set documented for the RocketCyber agent's Endpoint Event Log Monitoring capability. The following Windows Event IDs are collected by default:

Event ID Log Description
104 System Security log was cleared
1100 System Event logging was shut down
1102 Security Audit log was cleared

4625

Security

An account failed to log in

4649

Security

A replay attack was detected

4698

Security

A new scheduled task was created

4702

Security

A scheduled task was modified

4720

Security

Test user account created

4722

Security

A user account was enabled

4724

Security

An attempt was made to reset an account's password

4735

Security

Local Group Changed

4738

Security

User account password was changed

4740

Security

A user account was locked out

5142

Security

A network share object was added

5143

Security

A network share object was modified

5144

Security

A network share object was deleted

5145

Security

A network share object was checked by PsExec

7031

System

Service terminated unexpectedly

7034

System

Services Terminated Unexpectedly

7036

System

A defensive service was stopped

7040

System

Service was changed from auto start to disabled

64004

System

Windows File Protection was unable to restore file to its original version

NOTE  The monitored Event IDs represent the default Windows event monitoring set. Additional telemetry may be collected through integrated security products and endpoint detection platforms.

What you will see when endpoint ingestion is working

When endpoint and infrastructure ingestion is functioning correctly:

  • Alerts include host‑based activity and context

  • Endpoint activity appears consistently in investigations

  • Process, network, and operating‑system details are attached to detections

There may not be a single “connected” indicator. Successful ingestion is confirmed through ongoing alert and investigation visibility, not a status badge.

Relationship to other data source workflows

Endpoint and infrastructure sources fit into the broader MDR ingestion model as follows:

  • Connecting data sources and integrations explains how sources are associated with organizations

  • Identity and cloud security activity explains how account and authentication context complements endpoint detections

  • Network and log‑based ingestion explains how infrastructure telemetry extends visibility

  • Application Configurations explains how certain MDR behaviors are tuned after ingestion

Each source type contributes a different layer of signal.

Key takeaway

Endpoint and infrastructure sources are where real systems, endpoints and servers, become visible in Kaseya MDR. They appear through alerts and investigation context, not as configurable applications or inventories, and their presence is confirmed through continuous host‑based telemetry.

Integration‑specific endpoint sources

Endpoint and infrastructure telemetry in Kaseya MDR often originates from deployed agents or supported endpoint security platforms. For tool‑specific deployment and setup instructions, see the relevant integration articles: