Endpoint Detection and Response
Endpoint detection and response, or EDR, is a security capability that records activity on computers and other endpoints, detects suspicious behavior, and gives defenders tools to investigate and contain it.
itDefensive security and security operations | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Intro
Endpoint Detection and Response
Endpoint detection and response, or EDR, is a security capability for observing and acting on activity at endpoints. Endpoints include employee computers, servers, and other managed devices where processes run, files change, users sign in, and network connections begin. An EDR platform records selected activity, analyzes it for suspicious behavior, presents evidence for investigation, and provides response actions.
Traditional antivirus focuses on preventing known malicious files from running. Endpoint protection platforms add broader preventive controls. EDR addresses the part that remains after prevention: suspicious activity must still be detected, reconstructed, investigated, and contained. Many commercial platforms combine prevention and EDR in one endpoint agent and console, but the functions remain distinct. A block is a preventive result. A process tree, historical event trail, hunt query, and host-isolation action are detection-and-response functions.
Architecture and data flow
Most EDR deployments have four logical parts:
- Endpoint sensor or agent: observes operating-system activity and applies local policy. Depending on the platform and operating system, observations can include process creation, file activity, network connections, logon sessions, services, modules, and registry changes.
- Collection and storage service: receives selected telemetry and retains it for detection and investigation. Retention, filtering, connectivity, and licensing determine how much history is available.
- Analytics and detection service: evaluates events against indicators, behavioral rules, statistical models, and correlations. A detection becomes an alert when its evidence meets the configured logic.
- Analyst console and response channel: groups evidence into investigations and sends authorized actions back to endpoints.
Continue the course
This section is part of the paid course.
See pricing to subscribe, or log in if you already have access.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://csrc.nist.gov/glossary/term/endpoint_detection_and_response
Supports
- Endpoint detection and response terminology and authoritative linked publications
- Novice definition, introduction, quiz, and reference-path foundation
- https://www.cisa.gov/sites/default/files/publications/cdm-technical-capabilities-vol2-v24.pdf
Supports
- EDR endpoint agents, centralized administration, collection, analytics, alerting, response actions, and management requirements
- Architecture, control loop, operational health, response, limits, quiz answers, and infographic factual base
- https://www.cisa.gov/stopransomware/ransomware-guide
Supports
- EDR and application allowlisting as parts of layered ransomware defense
- EDR ecosystem limits and Reference rationale
- https://www.nist.gov/publications/incident-response-recommendations-and-considerations-cybersecurity-risk-management-csf
Supports
- Incident response integrated with cybersecurity risk management
- Investigation, containment, recovery, coordination, and improvement context
- https://nvlpubs.nist.gov/nistpubs/specialpublications/nist.sp.800-61r3.pdf
Supports
- Analysis under incomplete information, incident scoping, containment tradeoffs, recovery, evidence, and improvement
- Response decision content and quiz explanations
- https://attack.mitre.org/resources/faq/
Supports
- ATT&CK purpose, behavior vocabulary, endpoint telemetry research origin, and 2013 start
- ATT&CK limits, quiz answer, Reference rationale, and timeline research decision
- https://attack.mitre.org/datasources/
Supports
- Endpoint evidence subjects including process, file, network traffic, logon session, service, sensor health, and Windows Registry
- October 2025 deprecation of legacy data sources in favor of newer detection objects
- https://attack.mitre.org/resources/attack-data-and-tools/
Supports
- ATT&CK Navigator, structured data, STIX, TAXII, and programmatic coverage analysis
- Reference rationale and validation-path quiz answer
- https://github.com/sindresorhus/awesome
Supports
- Required starting catalog and discovery of Awesome Incident Response
- https://github.com/meirwah/awesome-incident-response
Supports
- Discovery of Velociraptor, osquery, GRR Rapid Response, and Fleet as relevant endpoint investigation tools
- https://docs.velociraptor.app/
Supports
- Endpoint visibility, targeted collection, continuous monitoring, and threat hunting
- Velociraptor Awesome Links rationale
- https://osquery.readthedocs.io/en/stable/
Supports
- Operating-system instrumentation through SQL tables, scheduled queries, fleet telemetry, and platform coverage
- osquery Awesome Links rationale and empty-query quiz context
- https://grr-doc.readthedocs.io/en/latest/
Supports
- Remote live forensics, clients and servers, hunts, artifacts, approvals, and scale
- GRR Awesome Links rationale
- https://fleetdm.com/docs/get-started/why-fleet
Supports
- osquery-based device visibility, policy, inventory, audit evidence, and management workflows
- Fleet Awesome Links rationale
- https://learn.microsoft.com/en-us/defender-endpoint/
Supports
- Prevention, post-breach detection, investigation, hunting, response, platforms, APIs, and portal integration
- Microsoft Defender for Endpoint Landscape placement
- https://www.crowdstrike.com/en-us/platform/endpoint-security/
Supports
- Falcon endpoint sensor, EDR, behavioral detection, investigation, threat hunting, response, and managed-service context
- CrowdStrike Falcon Insight XDR Landscape placement
- https://www.sentinelone.com/platform/endpoint-security/
Supports
- Combined EPP, EDR, local operation, automated containment, remediation, and rollback
- SentinelOne Singularity Endpoint Landscape placement
- https://www.paloaltonetworks.com/cortex/cortex-xdr
Supports
- Endpoint, network, and cloud evidence correlation, behavioral analytics, investigation, and containment
- Cortex XDR Landscape placement
- https://docs-cortex.paloaltonetworks.com/p/XDR
Supports
- Cortex XDR incident analysis, enforcement integration, endpoint agent, and response model
- https://docs.broadcom.com/doc/Carbon-Black-EDR-Datasheet
Supports
- Continuous endpoint visibility, hunting, incident response, remote investigation, retention, and hybrid or on-premises deployment
- Carbon Black EDR Landscape placement
- https://www.trendmicro.com/en_us/business/products/endpoint-security.html
Supports
- Integrated endpoint prevention, EDR, response, and cross-domain correlation
- Trend Vision One Endpoint Security Landscape placement
- https://www.elastic.co/docs/reference/integrations/endpoint
Supports
- Endpoint prevention, telemetry, process trees, investigation, response, Elastic Agent architecture, and licensing tiers
- Elastic Defend Landscape placement and process-tree quiz context
- https://engineering.fb.com/2014/10/29/security/introducing-osquery/
Supports
- October 2014 osquery open-source milestone considered during timeline research
- https://news.microsoft.com/videos/announcing-windows-defender-advanced-threat-protection/
Supports
- March 2016 Windows Defender Advanced Threat Protection announcement considered during timeline research
- https://www.cisa.gov/topics/cybersecurity-best-practices/executive-order-improving-nations-cybersecurity
Supports
- 2021 federal government-wide EDR direction considered during timeline research
