Defense

EDR (Endpoint Detection and Response)

Solution for detecting and responding to threats on endpoints

EDR (Endpoint Detection and Response) is a category of security solutions that continuously monitor and collect data from endpoints (computers, servers, mobile devices) to detect and respond to cyber threats.

Key Capabilities

  • Real-time activity monitoring
  • Behavioral analysis
  • Threat Intelligence integration
  • Automated response
  • Forensic analysis

EDR vs Antivirus

| Criteria | Antivirus | EDR | |----------|-----------|-----| | Method | Signatures | Behavior | | Response | Block | Investigation | | Visibility | Low | High | | Forensics | No | Yes |

Popular Solutions

  • CrowdStrike Falcon
  • Microsoft Defender for Endpoint
  • Carbon Black
  • SentinelOne
  • Kaspersky EDR

Category

WAF, SIEM, SOC, EDR, protection and monitoring tools