EDR (Endpoint Detection and Response)
Endpoint detection and response (EDR) is a security technology that continuously monitors endpoints such as laptops, servers and workstations, recording their activity to detect, investigate and respond to threats. EDR goes beyond traditional antivirus by capturing detailed behavioural telemetry, enabling detection of novel attacks and providing tools to contain them, such as isolating a compromised device.
Endpoint detection and response is a category of security technology focused on the devices where most attacks land and unfold: laptops, desktops, servers and workstations. An EDR agent runs on each endpoint, continuously recording activity such as process execution, file changes, network connections and registry modifications, then uses that telemetry to detect suspicious behaviour, support investigation, and enable response.
EDR arose because traditional antivirus, which relies on matching files against signatures of known malware, could not keep up with modern attacks. Adversaries increasingly use fileless techniques, legitimate system tools turned to malicious ends, and novel malware that no signature yet covers. By recording behaviour rather than only scanning files, EDR can detect the actions an attacker takes even when the specific tool is unknown, and it preserves a detailed history that analysts can review after the fact.
The core capabilities are continuous monitoring and recording, behavioural detection that flags suspicious sequences of activity, investigation tools that let an analyst trace exactly what happened on a device, and response actions such as killing a process, quarantining a file or isolating the endpoint from the network to stop an attack spreading. That combination of visibility and control is what distinguishes EDR from passive antivirus.
EDR is powerful but it is a tool, not a complete service. It generates alerts and telemetry that still need skilled humans to investigate and act upon around the clock. Many organisations deploy EDR and then find they lack the staff to monitor it continuously, which is why EDR is frequently delivered as part of a managed detection and response service, where a provider’s analysts operate the technology on the customer’s behalf.
EDR also sits within a family of related technologies. Extended detection and response broadens the same idea beyond the endpoint to correlate signals across network, identity, email and cloud. Network detection and response focuses on network traffic. Managed variants add the human operation. Choosing between them depends on where an organisation needs visibility and how much of the operating burden it wants to carry itself.
EDR is a foundational input to broader detection strategies rather than a complete answer on its own. Its deep endpoint visibility is most powerful when correlated with network and identity signals, which is the premise of extended detection and response, and when operated continuously by analysts, which is the premise of managed detection and response. Deployed without that operation, EDR becomes another source of alerts that no one has the capacity to investigate.
Because so many attacks ultimately act on an endpoint, EDR provides some of the richest telemetry available to defenders, but that telemetry only becomes protection when it is watched and acted upon continuously. Deployed and left to generate alerts that no one reviews, EDR offers little defence; operated by analysts around the clock, whether in-house or through a managed service, it becomes one of the most effective controls an organisation can run.
Within its managed detection and response service, Precursor operates EDR, so the telemetry is watched and acted upon by CREST-accredited analysts 24/7 rather than generating alerts that no one reviews.