EDR

Endpoint Detection and Response (EDR) is security software on servers and workstations that detects suspicious behaviour. It sends telemetry to a central analytics layer and can execute response actions such as host isolation.

Context

EDR is a tool, not a service. The operating unit above EDR is MDR or a full SOC, as described on SOC as a Service Switzerland. For the full tool-versus-service comparison see EDR vs. MDR. When EDR is correlated with identity, cloud and network telemetry, it becomes XDR.

Related terms

    Want to see this term in a real SOC context? Talk to us →