EDR
EDR (Endpoint Detection and Response) is a technology that continuously monitors endpoint activity, records events, and enables detection, investigation, and response to threats that bypassed preventive controls.
Term
description · examples · notesEDR (Endpoint Detection and Response) is a technology that continuously monitors endpoint activity, records events, and enables detection, investigation, and response to threats that bypassed preventive controls.
Description
Unlike traditional endpoint protection that focuses on prevention, EDR emphasizes visibility and response capability. It records detailed telemetry about processes, network connections, file changes, and registry activity.
EDR enables security teams to investigate incidents, understand the scope of compromise, and take corrective actions such as device isolation, process termination, and removal of malicious artifacts.
What people often say
- EDR automatically stops all threats without human involvement.
- Simply installing the EDR agent is sufficient for protection without tuning and monitoring.
Covers / does not cover
Covers
- Continuous monitoring and recording of endpoint activity
- Real-time detection of suspicious behavioral patterns
- Forensic investigation of incidents at the process and file level
- Ability to isolate compromised devices and terminate malicious processes
Does not cover
- Network attacks that generate no activity on the endpoint
- Threats in cloud environments and SaaS applications beyond agent reach
- Attacks on devices where the EDR agent is not installed
Mentioned in the news
- 19. JUN 2026. Ransomver banda Gentlemen svoje saradnike snabdeva sa alatima za gašenje naprednih mehanizama zaštite →
- 20. MAR 2026. ESET: EDR killer alati su postali predvidiva faza modernih ransomware upada →
- 5. MAR 2026. Microsoft pokreće Windows Resilience Initiative za jačanje bezbednosti sistema →
Threats
reduces 19Techniques
neutralizes 22Techniques it neutralizes. Select one to open its page.
- Exploitation→
- Data Exfiltration→
- Malware Delivery→
- Lateral Movement→
- Command & Control→
- Privilege Escalation→
- Impair Defenses→
- Persistence→
- Automation & Scripting→
- Encrypted C2 Channels→
- Living off the Land→
- Process Injection→
- Payload Obfuscation→
- In-Memory Execution→
- DLL Sideloading→
- Supply Chain Compromise→
- Data Destruction→
- Drive-by Download→
- Indicator Removal→
- Timestomping→
- Rootkit Installation→
- Watering Hole→