From signatures to behaviour
Traditional antivirus compared files against signatures of known malware. That still blocks many common threats, but attackers change their code constantly. Modern antivirus and EPP products add machine learning models, behaviour analysis, protection against exploits and malicious scripts, and cloud lookups to block new and modified threats.
What an EPP includes
Typically: anti malware, a host firewall, web filtering, control of USB and other devices, application control, and central management with policies and reports for all endpoints. Microsoft Defender, built into Windows, is a capable EPP when it is properly configured and centrally managed.
EPP and EDR
An EPP tries to stop threats before they run. EDR assumes some will get through: it records endpoint activity, detects suspicious behaviour and lets analysts investigate and contain an attack, for example by isolating a laptop. Most vendors now sell both in a single agent. XDR extends the same idea across email, identity and cloud, and MDR adds a team that monitors and responds.
Is antivirus still enough?
For most companies, no. Ransomware groups often use legitimate administration tools that antivirus does not flag. Antivirus remains a necessary baseline on every device, but it should be combined with EDR, patch management, hardening and monitoring. ISO 27001 requires protection against malware (Annex A 8.7).




