CrowdStrike Falcon EDR (endpoint detection and response) with the new behavioral detection (BSD) module has the ability to find anomalies in endpoint behavior and alert the administrator for further investigation.
The importance of the BSD module is that it can detect never before seen attacks, such as zero-day malware. It can even detect malicious behavior from trusted applications and cloud services. Another benefit of the BSD module is that it can help to reduce the number of false positives. This is because the BSD module is based on machine learning, which means that it can learn from the data it collects and improve its accuracy over time.