166 terms · 75/46/45
Defense № 001 · class: endpoints

Endpoint Protection

Endpoint protection encompasses software solutions that protect computers, servers, and mobile devices from malicious software and unauthorized activities. It combines classic signature-based malware detection with heuristic analysis and behavior-based detection.

Term

description · examples · notes

Endpoint protection encompasses software solutions that protect computers, servers, and mobile devices from malicious software and unauthorized activities. It combines classic signature-based malware detection with heuristic analysis and behavior-based detection.

Description

Modern solutions include application control, exploit protection, on-device web traffic filtering, and the ability to isolate suspicious processes. They often serve as the foundation upon which more advanced tools like EDR systems are built.

This technology is necessary but not sufficient on its own. It covers a broad range of known threats and provides a baseline level of protection that should be supplemented with network and identity controls.

What people often say

  • Antivirus alone is sufficient for complete system protection.
  • If the antivirus does not flag a threat, the system is safe.
  • Endpoint protection eliminates the need for software patching.

Covers / does not cover

Covers

  • Detection and blocking of known malware based on signatures
  • Heuristic analysis of suspicious files and behavior
  • Application and script execution control
  • Basic protection against exploitation of known vulnerabilities

Does not cover

  • Advanced threats using novel, unknown techniques (zero-day exploits)
  • Attacks operating entirely in memory without writing to disk
  • Network-based attacks that do not touch the endpoint
  • Social engineering that does not involve malicious software

Mentioned in the news

Composite

Threats

reduces 14

Techniques

neutralizes 10