166 terms · 75/46/45
Defense № 003 · class: endpoints

EDR

EDR (Endpoint Detection and Response) is a technology that continuously monitors endpoint activity, records events, and enables detection, investigation, and response to threats that bypassed preventive controls.

Term

description · examples · notes

EDR (Endpoint Detection and Response) is a technology that continuously monitors endpoint activity, records events, and enables detection, investigation, and response to threats that bypassed preventive controls.

Description

Unlike traditional endpoint protection that focuses on prevention, EDR emphasizes visibility and response capability. It records detailed telemetry about processes, network connections, file changes, and registry activity.

EDR enables security teams to investigate incidents, understand the scope of compromise, and take corrective actions such as device isolation, process termination, and removal of malicious artifacts.

What people often say

  • EDR automatically stops all threats without human involvement.
  • Simply installing the EDR agent is sufficient for protection without tuning and monitoring.

Covers / does not cover

Covers

  • Continuous monitoring and recording of endpoint activity
  • Real-time detection of suspicious behavioral patterns
  • Forensic investigation of incidents at the process and file level
  • Ability to isolate compromised devices and terminate malicious processes

Does not cover

  • Network attacks that generate no activity on the endpoint
  • Threats in cloud environments and SaaS applications beyond agent reach
  • Attacks on devices where the EDR agent is not installed

Mentioned in the news

Composite

Threats

reduces 19

Techniques

neutralizes 22