What is EDR (endpoint detection and response)?

Endpoint detection and response (EDR) is a security technology that continuously records activity on endpoints, detects suspicious behavior, and gives security teams the tools to investigate and respond — isolating hosts, killing processes and rolling back changes. EDR assumes some attacks will execute and optimizes for finding and containing them quickly, rather than preventing them outright.

Also known as: endpoint detection and response · EDR security · EDR solutions · EDR tools

How EDR works

An agent on each endpoint streams telemetry — process launches, file activity, network connections, registry changes — to a platform where detection logic and analysts identify malicious patterns, then trigger response actions. The category’s strengths are fleet-wide visibility, historical threat hunting and a deep integration ecosystem; for a staffed SOC, EDR is the backbone of investigation work.

The limits of detect-and-respond

EDR tolerates a window between detection and response, and that window is where encryption finishes and data leaves. Its value also scales with analyst capacity: alert triage is a staffing commitment, not a feature. And because detection runs largely in the vendor cloud, disconnected and sovereignty-constrained environments keep the agent but lose much of the product. These limits are why prevention-first platforms enforced inside the operating system — 1stProtect in the Cyberdis portfolio — are deployed either alongside EDR or in its place for lean teams.

// In the Cyberdis portfolio

1stProtect closes the response window EDR leaves open — distributed by Cyberdis.

// FAQ

Common questions.

What is the difference between EDR and antivirus?

Antivirus blocks known-bad files at the point of execution. EDR watches behavior over time across the estate, detects what file-scanning misses, and provides investigation and response tooling. EDR is a superset in visibility, not necessarily in prevention.

What is the difference between EDR and XDR?

XDR (extended detection and response) widens EDR correlation beyond the endpoint to identity, email, network and cloud signals. The operating model is the same: detect, triage, respond — with the same dependence on analyst capacity.

Do I need EDR if I have real-time prevention?

They answer different questions. Prevention closes the damage window; EDR provides fleet telemetry, hunting and compliance visibility. Mature SOCs typically run both; lean teams sometimes run prevention-first. Our EDR vs real-time prevention comparison covers the decision in depth.

Related explainers: What is endpoint security?How does endpoint security work in air-gapped environments?What is data exfiltration?

Weighing approaches? Real-time endpoint prevention vs EDR: stop the attack, or investigate it?