Back to glossary
Glossary
EDR (Endpoint Detection and Response)
Security software on laptops and servers that watches for suspicious behaviour, not just known viruses.
Traditional antivirus mostly matches files against a list of known-bad signatures. EDR goes further: it watches what's actually happening on a device — unusual process behaviour, suspicious network connections, attempts to disable security tools — and can isolate a compromised device automatically before an incident spreads. It's the backbone of most modern SOC monitoring.
Related terms
Got a question that's not in the glossary?
Ask us directly — no jargon, straight answers.
Get in touch