Endpoint Detection and Response (EDR) protects systems by monitoring behavioral patterns rather than scanning for known malicious code, making it effective against novel and emerging threats. Extended and managed variants—XDR and MDR—broaden that coverage across entire networks and through third-party security providers.
Endpoint Detection & Response
Another piece of software that can help protect our endpoints would be an endpoint detection and response, or EDR.
Essentially, an anti-malware is looking at files and code to determine if there's any kind of malware incorporated into that. But it doesn't detect everything. It really has to know what it's looking for — it's looking for some specific pieces of code. Well, that doesn't cover anything, because what if somebody generates new code? Then this anti-malware is not going to catch it.
Endpoint detection and response isn't looking necessarily for a piece of code. Instead, it's looking more for behavior. What it's going to do is monitor what's happening on the machine and take a look at a few different aspects of this machine to see if they're off. For instance, maybe it's the traffic that's coming in and out of this machine. It could have very consistent traffic, and then when it gets compromised, that traffic can look differently. So it's looking for those types of patterns that are different.
We call this user behavior analytics, or UBA. Essentially what it's doing is it's setting trend lines. It's trying to figure out what is the behavior it typically sees on this machine, and once it understands what its typical behavior is, then it can look for anomalies. So it's like you kind of program it. It's like an AI, where it's looking for these trends and for what's happening, and then anything that goes beyond what is typical and how this machine responds, then it will start flagging that and say, hey, this is something to be concerned about. So if we suddenly have a big burst of traffic that's going out of this machine where it typically wouldn't be happening, then it will identify — hey, something is off here, something's going awry.
There is something called an extended endpoint detection response, or XDR. XDR extends it beyond just this machine. So we'd have EDR running on this machine looking at the specific behaviors on that machine; XDR extends it across the network. So maybe we have an email server here and it's analyzing that as well, and maybe some other services here. So it's looking at the big picture, the extended picture, and analyzing the behavior across multiple elements within this network.
Another term you may hear is a managed endpoint detection and response, or MDR. Essentially what this is is we set up an EDR system on here, but we are hiring a managed service provider, or MSP. We're hiring some other entity to be able to manage all of this.
The thing is that if we're a smaller company, we might not be able to see everything that's happening on our network. So by hiring an external company to help manage this and monitor this, we can better protect our systems and look for trend lines across even other companies. They'll see trends in other companies and come and identify if there are any issues within our company.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →