How EDR works
An EDR agent runs on each laptop and server and records activity such as running processes, file changes and network connections. That data is sent to a central console, where detection rules and behavioural analysis flag patterns that look like an attack, for example ransomware encrypting files or a tool stealing credentials. From the console, the security team can investigate what happened, isolate the device from the network and remove the threat.
EDR vs antivirus
Traditional antivirus compares files against a list of known malware and blocks the matches. EDR also looks at behaviour, so it can detect threats that have not been seen before, and it keeps a record of activity that makes investigation possible. Most modern EDR products include antivirus capabilities.
EDR, XDR and MDR
XDR extends detection beyond endpoints to email, cloud and network data. MDR is a service in which an external team monitors the alerts and responds on your behalf. In short, EDR is the technology and MDR is the team that watches it.
Where EDR shows up in compliance
EDR supports the malware protection and monitoring controls in ISO 27001 (Annex A 8.7 and 8.16), the protection and monitoring measures of the ENS, and the cybersecurity risk management measures required by NIS2.




