<h2 style="margin-top: 0px; margin-bottom: 10px;">What is included in ESET Inspect?</h2>
<p style="margin-top: 0px; margin-bottom: 0px;"><strong>Detection rules engine</strong> – Over 800 ESET rules mapped to MITRE ATT&amp;CK techniques.<br /> <strong>Incident creator</strong> – Groups related detections into a single prioritised incident.<br /> <strong>One-click response actions</strong> – Isolate a machine, kill a process, block a hash.<br /> <strong>Terminal live response</strong> – Remote PowerShell session on the affected computer.<br /> <strong>Public REST API</strong> – Exports detections to SIEM, SOAR or ticketing systems.<br /> <strong>Important</strong> – Add-on module; requires ESET PROTECT Elite or Enterprise.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What are the main benefits of ESET Inspect?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">ESET Inspect is the XDR-enabling module of the ESET PROTECT platform, managed centrally from a web console next to the endpoints it monitors. It was previously sold as ESET Enterprise Inspector, so older quotes and internal documentation may still carry that name.<br /><br /> <strong>Root cause analysis</strong> – Full process tree shows how the attack started.<br /> <strong>Transparent rules</strong> – Every detection rule is readable and editable by your admins.<br /> <strong>Multiplatform connector</strong> – One agent covers Windows, macOS and Linux devices.<br /> <strong>EU data location</strong> – ESET private cloud data centres sit inside the EU.<br /> <strong>Existing agent reuse</strong> – Installs on top of your ESET endpoint products.<br /> <strong>Automatic remediation</strong> – Rules can trigger response actions without an analyst.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-defender-not-enough"><strong>Best antivirus? Why Windows Defender alone is not enough</strong><br />Explains where built-in prevention stops and why detection and response is a separate layer.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which company size is ESET Inspect suitable for?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">ESET Inspect is bought by organisations that already run ESET endpoint protection and now need to see what prevention did not stop. The deciding factor is not headcount but whether someone reviews detections regularly, because the tool produces incidents that a person has to read and close.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Requirement</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Small business</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Medium-sized company</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Large company</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Reporting obligation Switzerland</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">NIS 2 in the European Union</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Security questionnaire from large customers</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Occasional</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Someone reviews detections regularly</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Partial</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">This product fits</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Via provider</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does ESET Inspect meet the requirements of Swiss cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The reporting obligation under the revised Information Security Act applies to operators of critical infrastructure, for example energy and water supply, transport, healthcare and cantonal or municipal administrations, not to every Swiss company. Those organisations must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with a further period to complete the report. ESET Inspect supports that deadline in one specific way: the incident view collects the related detections with timestamps, the affected computers and the triggering processes, which is exactly the material an initial report needs, and the process tree answers the how and when question that follows. What it does not do is decide whether an incident is reportable, submit the report, or preserve evidence indefinitely, because raw events in the cloud version are deleted after seven days and an attack discovered late may no longer be reconstructable. It also covers only endpoints running an ESET security application, so attacks against network devices, cloud services or unmanaged systems remain outside its view. This text is general product information and not legal advice; have your own reporting duties assessed by qualified counsel.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does ESET Inspect meet the requirements of European cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No software product creates NIS 2 compliance, because the directive addresses management responsibility, risk processes and reporting rather than tools. NIS 2 requires measures in categories that include risk analysis, incident handling, business continuity, supply chain security, access control and the effectiveness review of security measures. ESET Inspect contributes to incident handling and to the effectiveness review: it records endpoint activity, raises prioritised incidents, allows response actions to be executed centrally and exports detections through a public REST API to a SIEM, which produces the audit trail an assessor asks for. It contributes nothing to business continuity, supply chain security, staff training, access control or governance, and it does not replace the human decision to escalate and report. Because the data is processed in ESET private cloud data centres located in the European Union, the data location question that European assessors raise can be answered directly.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does ESET Inspect help with security questionnaires from large customers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes, for the detection and response block of a supplier questionnaire, and for very little outside it. It answers concretely: an EDR or XDR solution is deployed on endpoints and servers, detections are centrally collected and prioritised, response actions such as network isolation and process termination are available, detections are mapped to MITRE ATT&amp;CK, logs can be exported to a SIEM through a documented API, access is role-based through the ESET PROTECT console, and data is processed inside the European Union. It does not answer the questions on patch and vulnerability management, disk encryption, multi-factor authentication, email filtering, backup and restore, mobile device management or round-the-clock monitoring, because none of those functions is part of this module. If a questionnaire fails on several of those points at once, the cheaper route is usually to move up within the same family rather than to add a second vendor: ESET PROTECT Elite already bundles ESET Inspect with full disk encryption, mail security, multi-factor authentication and vulnerability and patch management on the same console, which also means one supplier record instead of several. Continuous monitoring by named analysts is a separate matter and requires the managed service tiers.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What is the difference between ESET Inspect and ESET Inspect On-Prem?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The decisive difference is data retention and who holds the data. The cloud version runs in a lightweight collection mode with a fixed retention of seven days for raw events and 31 days for detections, while the on-premises version stores its data in your own SQL database, where retention and collection depth are configurable and limited mainly by disk space. The cloud version needs no server, no database maintenance and no upgrade planning, which is why smaller teams choose it. The on-premises version scales beyond the sizing ceiling of a single cloud instance and suits organisations that must keep forensic data inside their own infrastructure.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Property</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">ESET Inspect</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">ESET Inspect On-Prem</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Own server and database required</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Raw event retention</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">7 days</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Configurable</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Detection retention</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">31 days</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Configurable</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Full data collection depth</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Limited</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Data stays in your infrastructure</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">EU data centre</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which limitations should you know before buying?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">ESET Inspect is a module, not a standalone product: it needs ESET PROTECT Elite or Enterprise and a supported ESET security application on every monitored device, and the connector will not install without one. The web console interface is available in English, Chinese Traditional, Japanese and Ukrainian only, so German, French and Italian speaking teams work in an English console even though the underlying ESET PROTECT console is localised. Coverage is limited to Windows, macOS and Linux; Windows ARM and Linux ARM devices are not supported, and Android and iOS devices are not monitored at all, which surprises buyers who expect mobile telemetry from an XDR product. Some detection rules depend on ESET LiveGrid, which is mandatory in the cloud version and means reputation data leaves the endpoint. The short raw event retention in the cloud version is the limitation that most often triggers a follow-up purchase, either of the on-premises version or of a SIEM that keeps the exported detections longer.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="data-loss-backups-avoid-outages"><strong>Data loss is expensive: How backups help you avoid outages</strong><br />Explains why detection and response reduces damage but never replaces a working restore path.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Frequently asked questions about ESET Inspect</h3>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What is the difference between ESET Inspect and ESET MDR?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">ESET Inspect is the tool your own staff operate; ESET MDR is the service in which ESET analysts monitor and triage the same detections for you. MDR is not enabled by this module and requires the ESET PROTECT MDR or MDR Ultimate tier.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does ESET Inspect also monitor file servers and Exchange?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes. The connector is supported alongside ESET Server Security for Windows Server and for Linux, ESET Mail Security for Microsoft Exchange Server and for IBM Domino, and ESET Security for Microsoft SharePoint Server, so server-side activity appears in the same incident view as workstation activity.</p>
<div class="ke-block mceNonEditable" data-ke-block="blogteaser" data-topics="sec-edr,sec-endpoint,sec-console" data-audience="b2b" data-count="3"> </div>