Endpoint Detection and Response

Also known as:EDR

Endpoint DetectionDetectionThe capability to identify suspicious activity, attacks, or policy violations in time. and Response: Continuously monitors endpointsEndpointA user or server device that communicates with a network and runs workloads or applications. and supports detection, investigation, and containmentContainmentActions that limit the scope, spread, and impact of an active security incident.. The focus is on endpoints, serversServerA system that provides applications, data, or network services to other systems., or device-level technology. Typical measures include hardening, centralized managementCentralized ManagementAdministration of distributed systems or controls from a common management plane., telemetryTelemetryAutomatically collected measurements and events that describe the state and behavior of systems., rapid isolationIsolationThe separation of a system, process, or resource to limit access and prevent spread., and controlled updates.

How it works and where it fits

Endpoint Detection and Response connects data sources to detection or assessment logic. Raw records become security-relevant only when timing, identity, system context, and expected behavior are considered. Rules, correlations, statistical models, and analyst decisions may work together; no single method reliably covers every attack pattern.

Practical security relevance

Operational quality is reflected in coverage, data completeness, detection time, and false-alert workload. Data sources need owners, time synchronization, retention, and quality controls. Detections should be tested, versioned, and improved using real incidents. Every meaningful alert also requires triage guidance, escalation, and possible response actions.

  • Endpoint Protection PlatformEndpoint Protection PlatformBundles preventive security functions such as malware protection, firewalls, and device control.: Bundles preventive security functions such as malware protection, firewalls, and device control.
  • Extended Detection and ResponseExtended Detection and ResponseCorrelated detection and response across endpoints, identities, email, networks, and the cloud.: Correlated detection and response across endpoints, identities, email, networks, and the cloud.
  • Managed Detection and ResponseManaged Detection and ResponseOutsourced service for continuous monitoring, analysis, and response to threats.: Outsourced service for continuous monitoring, analysis, and response to threats.
  • Incident ResponseIncident ResponseA structured process for the preparation, detection, containment, eradication, and post-incident review regarding security incidents.: A structured process for the preparation, detection, containment, eradication, and post-incident review regarding security incidents.