AV, MDR, XDR, EDR
Verify antivirus, EDR, XDR, and MDR across every endpoint
Lavawall® confirms that anti-malware protection is actually present and healthy on each device, whatever the branding. It asks the operating system what it knows, then checks 70+ security services directly in case the OS missed something, recognizes 70+ vendors, and adds deep API integration with Huntress and Sophos so managed detections fold into one alerting picture.
Start free, no credit card See how it works
70+ vendors · OS plus service checks · Huntress and Sophos API · compliance-linked
How the detection works
Like your RMM, Lavawall® checks with Microsoft Windows and Apple macOS for what they understand about your antivirus, EDR, XDR, MDR, anti-malware, or whatever branding is trendy this year. That gives a baseline, but the operating system does not always report every product correctly.
So, as with everything Lavawall® does, it takes a step further and checks for 70+ security services directly, in case the operating system missed them. The result is a more reliable answer to a simple but important question: is this endpoint actually protected, right now? Coverage gaps that would otherwise hide behind a stale or missing OS report get surfaced instead.
Supported AV, EDR, XDR, and MDR vendors
Lavawall® recognizes 70+ antivirus and detection-and-response products across Windows and macOS, including:
- Microsoft Defender
- CrowdStrike
- SentinelOne
- Sophos
- ESET
- BitDefender
- Malwarebytes
- Trend Micro
- Trellix Endpoint Security
- Carbon Black
- Cybereason
- Rapid7 InsightIDR
- McAfee
- Symantec and Norton 360
- Kaspersky
- Webroot
- Avast, AVG, and Avira
- F-Secure and F-Prot
- FortiClient Endpoint Security
- G DATA
- Acronis Cyber Protect
- Elastic Security
- WatchGuard
- VIPRE
- Quick Heal and Seqrite
- Comodo
- Dr. Web
- Apple XProtect
This is a partial list. The full set spans 70+ products and their consumer and business editions.
Deep API integration where it counts
Detection tells you a product is present. Deep integration tells you what it is finding. Lavawall® integrates directly with the following vendors for enhanced reporting, notifications, and installation support:
- Huntress automatic organization correlation, open incident visibility, install-state and partial-install detection, and faster reporting access. See the Huntress integration.
- Sophos organization correlation, MDR case and incident search, simplified CSV installation keys, and licence tracking. See the Sophos integration.
More antivirus, EDR, and MDR integrations are currently in development. Products without deep API integration are still detected and reported, so your coverage verification is never limited to the integrated vendors.
Part of unified MDR alerting and compliance
Detection status is most useful when it sits beside everything else. Lavawall® unifies Sophos, Huntress, and Microsoft Defender detections into one ranked, de-duplicated queue, so managed detection and response alerts across your stack arrive together rather than in separate portals. See the unified MDR page for how that works.
Coverage also feeds compliance. Whether an endpoint runs healthy anti-malware maps directly to controls in CIS, NIST CSF, ISO 27001, CMMC, SOC 2, HIPAA, PCI DSS, and others, so verified protection becomes audit-ready evidence rather than a manual attestation. Endpoint hardening feeds the same console through configuration vulnerabilities.
Frequently asked
- How does Lavawall® detect antivirus and EDR on a device?
- Like an RMM, Lavawall® asks Windows and macOS what they know about the installed antivirus, EDR, XDR, or MDR product. It then goes a step further and checks for 70+ security services directly, in case the operating system missed or misreported the product, so coverage gaps are less likely to hide.
- Which antivirus and EDR vendors does Lavawall® recognize?
- Lavawall® recognizes 70+ vendors, including Microsoft Defender, CrowdStrike, SentinelOne, Sophos, ESET, BitDefender, Malwarebytes, Trend Micro, Trellix, Webroot, Kaspersky, Carbon Black, Cybereason, Rapid7 InsightIDR, WatchGuard, VIPRE, Apple XProtect, and many more across Windows, macOS, and their various brandings.
- Which vendors get deep API integration?
- Huntress and Sophos currently have deep API integration for enhanced reporting, notifications, and installation support. More antivirus, EDR, and MDR integrations are in development. Every other supported vendor is still detected and reported for coverage verification.
- Does Lavawall® replace my antivirus or EDR?
- No. Lavawall® does not replace your protection product. It verifies that the product is present and healthy, folds Huntress and Sophos detections into unified alerting, and correlates coverage with your compliance controls so you can prove endpoints are protected.