Terminology Index
Glossary
1801 terms
Showing 577-608 of 1801 terms
EDR
Endpoint Detection and Response: software on endpoints that continuously records activity, detects malicious behavior, and lets responders investigate and act, such as isolating a host, giving deep visibility and control over what happens on each device.
EDR agents collect rich endpoint telemetry, processes, file and registry changes, network connections, and apply behavioral detection to surface threats that signature antivirus misses, while giving responders tools to investigate and remediate, including remote isolation. As a hardening and detection control, EDR is a cornerstone of endpoint defense, providing both the visibility detections rely on and the response capability to contain compromised hosts quickly.
Introduced in: System Hardening Fundamentals
Examples
- An EDR agent flagging a process behaving like ransomware.
- A responder remotely isolating an infected endpoint through EDR.
- Investigating an alert using the detailed activity EDR recorded on the host.
No related terms linked yet.
