openskills.info
Course Preview

Endpoint Detection and Response

Endpoint detection and response, or EDR, is a security capability that records activity on computers and other endpoints, detects suspicious behavior, and gives defenders tools to investigate and contain it.

itDefensive security and security operations

Endpoint Detection and Response

Endpoint detection and response, or EDR, is a security capability for observing and acting on activity at endpoints. Endpoints include employee computers, servers, and other managed devices where processes run, files change, users sign in, and network connections begin. An EDR platform records selected activity, analyzes it for suspicious behavior, presents evidence for investigation, and provides response actions.

Traditional antivirus focuses on preventing known malicious files from running. Endpoint protection platforms add broader preventive controls. EDR addresses the part that remains after prevention: suspicious activity must still be detected, reconstructed, investigated, and contained. Many commercial platforms combine prevention and EDR in one endpoint agent and console, but the functions remain distinct. A block is a preventive result. A process tree, historical event trail, hunt query, and host-isolation action are detection-and-response functions.

Architecture and data flow

Most EDR deployments have four logical parts:

  1. Endpoint sensor or agent: observes operating-system activity and applies local policy. Depending on the platform and operating system, observations can include process creation, file activity, network connections, logon sessions, services, modules, and registry changes.
  2. Collection and storage service: receives selected telemetry and retains it for detection and investigation. Retention, filtering, connectivity, and licensing determine how much history is available.
  3. Analytics and detection service: evaluates events against indicators, behavioral rules, statistical models, and correlations. A detection becomes an alert when its evidence meets the configured logic.
  4. Analyst console and response channel: groups evidence into investigations and sends authorized actions back to endpoints.

Continue the course

This section is part of the paid course.

See pricing to subscribe, or log in if you already have access.

Where this skill leads

Relevant careers

See how this topic contributes to broader role-level skill maps.

Sources