A technology that continuously monitors endpoints to detect, analyze and neutralize malicious behavior, beyond the traditional antivirus.
Endpoint detection and response, known by the acronym EDR, is a category of security tools that continuously monitor workstations and servers in order to spot suspicious behavior, analyze its context and react, for example by isolating a compromised machine. It goes beyond the traditional antivirus, based on recognizing known signatures, by focusing on behavior, which allows it to detect novel or stealthy attacks. Its extended variants, XDR and managed MDR services, broaden its scope to the whole information system or entrust its operation to a specialist provider. EDR reduces the dwell time of an attacker in the network, a decisive parameter of a loss's severity, and it has become an almost standard underwriting requirement in cyber insurance. This dependence carries, however, a concentration downside, because these tools, deployed at the heart of the systems of thousands of organizations, themselves become sensitive points, a faulty update to a very widespread EDR having already been enough to cause a worldwide IT outage, illustrating how the security tool can turn into a single point of failure.
An EDR detects that a workstation is attempting, in the middle of the night, to encrypt files en masse, behavior typical of ransomware. It automatically isolates the machine from the network, halting the attack before it spreads and drastically limiting the loss.
EDR, endpoint detection and response, détection et réponse sur les terminaux, XDR, MDR