EDR

Endpoint Detection and Response

Endpunkt-Erkennung und -Reaktion

EDR continuously monitors endpoints — workstations, servers, mobile devices — records their behaviour and detects suspicious activity by patterns rather than only by known signatures. Unlike classic antivirus, EDR enables investigation and targeted response, such as isolating a compromised host. Forensic endpoint telemetry is a core ingredient of modern detection.

History. The term Endpoint Detection and Response was coined in 2013 by Gartner analyst Anton Chuvakin — initially as „Endpoint Threat Detection and Response“. The background was the realisation that signature-based antivirus systematically misses targeted attacks: what matters is not the known file but the anomalous behaviour.

Facts. EDR collects process, file, registry and network events at the endpoint, evaluates them behaviourally and provides investigation and response functions. The telemetry also supplies the raw material for forensics — timelines, persistence mechanisms, lateral movement. EDR is the foundation on which the broader approaches Extended Detection and Response (XDR) (multiple domains) and Managed Detection and Response (MDR) (operated as a service) build.

Outlook & recommendation. EDR is no longer a luxury today but a minimum standard for the Network and Information Security Directive 2 (NIS2) measure „attack detection“ at the endpoint. The common mistake is to license EDR but have nobody evaluating the alerts at night — the telemetry is only as valuable as its analysis. In the Extended Security Incident and Event Management (XIEM) model, the forensic endpoint function is already included in the base tier, Sentry.

EDR — Endpoint Detection and Response