Skip to main content
StandardCurrent

EDR

Also known as: Endpoint Detection and Response

Following adds this technology to your private workspace so related learning is easier to organise and revisit.

Technology explained

What is EDR?

Endpoint detection and response combines endpoint telemetry, behavioural detection, investigation and containment capabilities. This profile connects the concept to KBY's practical engineering guidance.

EDR agents record process, file, identity and network activity so suspicious behaviour can be correlated beyond traditional malware signatures. Operational value depends on coverage, tuned detections, retention and a rehearsed response path for isolating or remediating devices.

Primary purpose

Detect, investigate and contain malicious activity on endpoint devices.

Typical environments
WindowsmacOSLinux
Typical use cases
  • Detecting malware and ransomware
  • Investigating security incidents
  • Isolating compromised endpoints
Connected knowledge

1 resource for EDR

Browse by purpose, from definitions and learning through operations, diagnostics and controlled recovery.

Technology journey

Learn and operate with EDR

Ordered as a reader progression -- from core definitions through to operational reference -- using only the content already connected in the technology registry.

Lexicon Definitions(1)

Start here: understand the core vocabulary.