Endpoint Detection and Response
Endpoint detection and response, or EDR, is a security capability that records activity on computers and other endpoints, detects suspicious behavior, and gives defenders tools to investigate and contain it.
itDefensive security and security operations | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Don't Panic
Don't Panic — Endpoint Detection and Response
Endpoint detection and response, or EDR, is the security capability that watches activity on managed computers and gives people controlled ways to act when the activity becomes suspicious. It exists because prevention is useful but not omniscient. A malicious file can be blocked, which is splendid. A suspicious process chain that already ran needs explaining, which is where the paperwork becomes a detective story.
The useful mental model is a loop: observe, transmit, retain, analyze, alert, investigate, respond, and verify. An endpoint sensor notices selected operating-system events. A collection service keeps enough of them to search. Analytics turns some patterns into alerts. The console presents the evidence and, where authorized, sends an action back to the host. Each step is necessary. A magnificent alert cannot investigate itself, despite the confidence with which some dashboards arrange their gradients.
The small vocabulary matters because the words are not interchangeable. An event is one recorded action. A detection is logic that finds something suspicious. An alert asks for review. An incident groups related evidence into a case. The first alert is a starting point, not a signed affidavit describing the entire intrusion. Context does the heavier work: process ancestry, user identity, files, destinations, times, and the role of the affected device.
The surprise is that empty search results are not a comforting proof of absence. The event may be outside retention, the sensor may not have recorded it, the endpoint may be offline, or the question may be wrong. Similarly, host isolation can limit communication but cannot remove persistence, rotate stolen credentials, repair the original weakness, or certify the neighboring hosts as clean. Containment is a useful brake, not a time machine.
Read the Intro when you need the architecture and its limits. Use the Slides for the control loop and the decisions around response. Keep the Cheatsheet nearby when an alert needs a triage order, a response check, or a way to describe a coverage gap. The Quiz is for checking the distinctions before a vendor console turns them into a much larger set of buttons. EDR is not a complete security program. It is the endpoint evidence and response part of one, which is already plenty of responsibility for a single acronym.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://csrc.nist.gov/glossary/term/endpoint_detection_and_response
Supports
- Endpoint detection and response terminology and authoritative linked publications
- Novice definition, introduction, quiz, and reference-path foundation
- https://www.cisa.gov/sites/default/files/publications/cdm-technical-capabilities-vol2-v24.pdf
Supports
- EDR endpoint agents, centralized administration, collection, analytics, alerting, response actions, and management requirements
- Architecture, control loop, operational health, response, limits, quiz answers, and infographic factual base
- https://www.cisa.gov/stopransomware/ransomware-guide
Supports
- EDR and application allowlisting as parts of layered ransomware defense
- EDR ecosystem limits and Reference rationale
- https://www.nist.gov/publications/incident-response-recommendations-and-considerations-cybersecurity-risk-management-csf
Supports
- Incident response integrated with cybersecurity risk management
- Investigation, containment, recovery, coordination, and improvement context
- https://nvlpubs.nist.gov/nistpubs/specialpublications/nist.sp.800-61r3.pdf
Supports
- Analysis under incomplete information, incident scoping, containment tradeoffs, recovery, evidence, and improvement
- Response decision content and quiz explanations
- https://attack.mitre.org/resources/faq/
Supports
- ATT&CK purpose, behavior vocabulary, endpoint telemetry research origin, and 2013 start
- ATT&CK limits, quiz answer, Reference rationale, and timeline research decision
- https://attack.mitre.org/datasources/
Supports
- Endpoint evidence subjects including process, file, network traffic, logon session, service, sensor health, and Windows Registry
- October 2025 deprecation of legacy data sources in favor of newer detection objects
- https://attack.mitre.org/resources/attack-data-and-tools/
Supports
- ATT&CK Navigator, structured data, STIX, TAXII, and programmatic coverage analysis
- Reference rationale and validation-path quiz answer
- https://github.com/sindresorhus/awesome
Supports
- Required starting catalog and discovery of Awesome Incident Response
- https://github.com/meirwah/awesome-incident-response
Supports
- Discovery of Velociraptor, osquery, GRR Rapid Response, and Fleet as relevant endpoint investigation tools
- https://docs.velociraptor.app/
Supports
- Endpoint visibility, targeted collection, continuous monitoring, and threat hunting
- Velociraptor Awesome Links rationale
- https://osquery.readthedocs.io/en/stable/
Supports
- Operating-system instrumentation through SQL tables, scheduled queries, fleet telemetry, and platform coverage
- osquery Awesome Links rationale and empty-query quiz context
- https://grr-doc.readthedocs.io/en/latest/
Supports
- Remote live forensics, clients and servers, hunts, artifacts, approvals, and scale
- GRR Awesome Links rationale
- https://fleetdm.com/docs/get-started/why-fleet
Supports
- osquery-based device visibility, policy, inventory, audit evidence, and management workflows
- Fleet Awesome Links rationale
- https://learn.microsoft.com/en-us/defender-endpoint/
Supports
- Prevention, post-breach detection, investigation, hunting, response, platforms, APIs, and portal integration
- Microsoft Defender for Endpoint Landscape placement
- https://www.crowdstrike.com/en-us/platform/endpoint-security/
Supports
- Falcon endpoint sensor, EDR, behavioral detection, investigation, threat hunting, response, and managed-service context
- CrowdStrike Falcon Insight XDR Landscape placement
- https://www.sentinelone.com/platform/endpoint-security/
Supports
- Combined EPP, EDR, local operation, automated containment, remediation, and rollback
- SentinelOne Singularity Endpoint Landscape placement
- https://www.paloaltonetworks.com/cortex/cortex-xdr
Supports
- Endpoint, network, and cloud evidence correlation, behavioral analytics, investigation, and containment
- Cortex XDR Landscape placement
- https://docs-cortex.paloaltonetworks.com/p/XDR
Supports
- Cortex XDR incident analysis, enforcement integration, endpoint agent, and response model
- https://docs.broadcom.com/doc/Carbon-Black-EDR-Datasheet
Supports
- Continuous endpoint visibility, hunting, incident response, remote investigation, retention, and hybrid or on-premises deployment
- Carbon Black EDR Landscape placement
- https://www.trendmicro.com/en_us/business/products/endpoint-security.html
Supports
- Integrated endpoint prevention, EDR, response, and cross-domain correlation
- Trend Vision One Endpoint Security Landscape placement
- https://www.elastic.co/docs/reference/integrations/endpoint
Supports
- Endpoint prevention, telemetry, process trees, investigation, response, Elastic Agent architecture, and licensing tiers
- Elastic Defend Landscape placement and process-tree quiz context
- https://engineering.fb.com/2014/10/29/security/introducing-osquery/
Supports
- October 2014 osquery open-source milestone considered during timeline research
- https://news.microsoft.com/videos/announcing-windows-defender-advanced-threat-protection/
Supports
- March 2016 Windows Defender Advanced Threat Protection announcement considered during timeline research
- https://www.cisa.gov/topics/cybersecurity-best-practices/executive-order-improving-nations-cybersecurity
Supports
- 2021 federal government-wide EDR direction considered during timeline research
- https://attack.mitre.org/resources/attackcon/october-2023/
Supports
- ATT&CKcon 4.0 session on validating ATT&CK technique coverage with EDR telemetry through data components, functional tests, and cross-sensor comparison
- Field Notes guidance on treating expected telemetry as testable evidence rather than a coverage label
