GlossarySOC and monitoring

Antivirus and EPP

Short answer

Antivirus software detects and blocks known malicious files on computers and servers. An EPP (Endpoint Protection Platform) extends this with behaviour based detection, exploit protection, firewall and device control. Both focus on prevention, while EDR adds detection and response. Many products now combine EPP and EDR in a single agent.

From signatures to behaviour

Traditional antivirus compared files against signatures of known malware. That still blocks many common threats, but attackers change their code constantly. Modern antivirus and EPP products add machine learning models, behaviour analysis, protection against exploits and malicious scripts, and cloud lookups to block new and modified threats.

What an EPP includes

Typically: anti malware, a host firewall, web filtering, control of USB and other devices, application control, and central management with policies and reports for all endpoints. Microsoft Defender, built into Windows, is a capable EPP when it is properly configured and centrally managed.

EPP and EDR

An EPP tries to stop threats before they run. EDR assumes some will get through: it records endpoint activity, detects suspicious behaviour and lets analysts investigate and contain an attack, for example by isolating a laptop. Most vendors now sell both in a single agent. XDR extends the same idea across email, identity and cloud, and MDR adds a team that monitors and responds.

Is antivirus still enough?

For most companies, no. Ransomware groups often use legitimate administration tools that antivirus does not flag. Antivirus remains a necessary baseline on every device, but it should be combined with EDR, patch management, hardening and monitoring. ISO 27001 requires protection against malware (Annex A 8.7).

Related terms

Keep reading on this topic

Continuous monitoring and response: EDR, SIEM, SOC operations, detection engineering and incident handling.

Go to the topic hub