Company Partners Our Teams Contact Blog
Services
Industries
Talk to an expert

What is EDR (Endpoint Detection and Response)?

DefinitionEDR (Endpoint Detection and Response) is a solution that continuously monitors the behavior of endpoints, such as workstations and servers, records their activity and makes it possible to detect, investigate and contain attacks directly on those devices.

How it works

An agent installed on each endpoint records events such as started processes, file and registry changes, network connections and credential use. This telemetry is analyzed for malicious behavior, not just known files. Typical capabilities are:

  • Behavioral detection, such as an Office document spawning PowerShell or a process starting to encrypt files in bulk.
  • Investigation with a timeline of what happened on the machine.
  • Response: isolating the host from the network, killing processes, quarantining files.
  • Search for indicators across the entire fleet, useful for threat hunting.

EDR vs antivirus

Traditional antivirus relies mainly on signatures of known threats and focuses on prevention. EDR assumes something may get past prevention and provides visibility and response capability. Many current solutions combine both functions in the same platform.

EDR, XDR and MDR

XDR extends the EDR approach to network, cloud, identity and email. MDR is the service in which analysts operate these tools 24/7. This point matters: an EDR generates alerts all the time, and without someone to analyze them and act quickly, much of its value is lost, especially against attacks such as ransomware that move fast.

Network Secure integrates EDR telemetry into the monitoring of its 24/7 SOC.

Frequently asked questions

Does EDR replace antivirus?

Generally yes, in modern solutions that combine prevention and EDR in the same agent. The key point is that EDR adds visibility and response, which traditional antivirus does not offer.

What is the difference between EDR and XDR?

EDR works on endpoints. XDR correlates endpoint data with other layers, such as network, cloud, identity and email.