Endpoint Detection and Response
What Is Endpoint Detection and Response?
Endpoint Detection and Response (EDR) is a security technology that enables organizations to detect, investigate, and respond to malicious activity on their endpoints. EDR solutions are typically deployed on endpoints such as laptops, desktops, and servers, and use a combination of machine learning, behavioral analytics, and threat intelligence to detect and respond to malicious activity. EDR solutions can detect malicious activity such as malware, ransomware, and malicious file downloads, as well as suspicious user behavior such as privilege escalation and lateral movement. EDR solutions can also provide organizations with the ability to investigate and respond to malicious activity, such as by blocking malicious files or isolating compromised endpoints.
Description
Endpoint Detection and Response (EDR) is a security technology that enables organizations to detect, investigate, and respond to malicious activity on their endpoints.
Usage and Examples
EDR solutions are typically deployed on endpoints such as laptops, desktops, and servers, and use a combination of machine learning, behavioral analytics, and threat intelligence to detect and respond to malicious activity. For example, an EDR solution may detect a malicious file download, or detect suspicious user behavior such as privilege escalation or lateral movement. EDR solutions can also provide organizations with the ability to investigate and respond to malicious activity, such as by blocking malicious files or isolating compromised endpoints.