GlossarySOC and monitoring

EDR

Short answer

EDR (Endpoint Detection and Response) is security software installed on laptops and servers. It records activity on each device, detects suspicious behaviour and lets a security team investigate, isolate the device and respond to an attack before it spreads.

How EDR works

An EDR agent runs on each laptop and server and records activity such as running processes, file changes and network connections. That data is sent to a central console, where detection rules and behavioural analysis flag patterns that look like an attack, for example ransomware encrypting files or a tool stealing credentials. From the console, the security team can investigate what happened, isolate the device from the network and remove the threat.

EDR vs antivirus

Traditional antivirus compares files against a list of known malware and blocks the matches. EDR also looks at behaviour, so it can detect threats that have not been seen before, and it keeps a record of activity that makes investigation possible. Most modern EDR products include antivirus capabilities.

EDR, XDR and MDR

XDR extends detection beyond endpoints to email, cloud and network data. MDR is a service in which an external team monitors the alerts and responds on your behalf. In short, EDR is the technology and MDR is the team that watches it.

Where EDR shows up in compliance

EDR supports the malware protection and monitoring controls in ISO 27001 (Annex A 8.7 and 8.16), the protection and monitoring measures of the ENS, and the cybersecurity risk management measures required by NIS2.

Related terms

Keep reading on this topic

Continuous monitoring and response: EDR, SIEM, 24/7 SOC operations, detection engineering and incident handling.

Go to the topic hub