Home Glossary What is EDR (Endpoint Detection and Response)?
Glossary · Cybersecurity 101

What is EDR (Endpoint Detection and Response)?

EDR deploys behavioral sensors on every endpoint — capturing telemetry that signature-based antivirus is completely blind to.

Glossary · Endpoint Detection and Response

EDR is a generational upgrade from antivirus — and the foundation of every serious endpoint security program.

Endpoint Detection and Response (EDR) is a category of security software that deploys lightweight agents on individual devices — workstations, laptops, servers — and continuously captures detailed telemetry about every process, network connection, file write, and registry modification. That telemetry is analyzed in real time using behavioral detection engines that identify suspicious activity patterns regardless of whether the specific threat has been seen before.

The "detection" half of EDR surfaces threats that signature-based antivirus misses. The "response" half provides the tools analysts use to investigate confirmed threats — process trees, timeline reconstruction, memory analysis, and endpoint isolation. Without analysts operating the response capability, EDR is a sophisticated alarm system with no one listening.

How EDR differs from antivirus

  • Antivirus: Compares files against a database of known-malicious signatures. If a file matches a known signature, it's blocked. If it doesn't, it passes. Novel malware, fileless attacks, and living-off-the-land techniques all evade signature detection.
  • EDR: Monitors behavior — what processes are doing, what they're connecting to, what files they're modifying — and flags behavior that deviates from baseline regardless of whether the specific file is in any signature database. A PowerShell script that dumps LSASS memory gets flagged because of what it does, not because the script has been seen before.

What EDR monitors

  • Process execution: what processes are running, what spawned them, and what they're doing
  • Network connections: where endpoints are connecting, on what ports, with what frequency
  • File system activity: what files are being created, modified, or deleted
  • Registry modifications: changes to Windows registry keys, especially run keys and service entries
  • User and account activity: logins, privilege escalations, account modifications
  • Script execution: PowerShell, WMI, VBScript, and other scripting activity with encoded command detection

Managed EDR vs. self-managed EDR

EDR deployed without human analysts reviewing its alerts provides limited protection — the tool generates alerts, but no one investigates them. Managed EDR wraps the technology with a team of analysts who review, investigate, and respond to every alert. SignalPoint's managed EDR service handles the entire lifecycle: deployment, tuning, 24/7 monitoring, investigation, and response.

EDR focuses on detection and response; EPP focuses on prevention. Modern platforms often combine both, but EDR capabilities require human analysts to be effective.

Yes. EDR provides a strict superset of antivirus capabilities — signature matching plus behavioral detection. SignalPoint's managed EDR replaces antivirus as part of the service.

Stop the next attack before it starts.

Free 30-minute consultation — no commitment, no jargon, no sales pressure.

Schedule nowView pricing
Free monthly threat briefing
Chattanooga-specific threat intelligence, delivered to your inbox. No spam, unsubscribe anytime.