{"id":682,"date":"2026-08-13T11:42:44","date_gmt":"2026-08-13T11:42:44","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=682"},"modified":"2026-08-13T11:42:44","modified_gmt":"2026-08-13T11:42:44","slug":"edr","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/edr\/","title":{"rendered":"EDR Explained: Endpoint Detection and Response"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: EDR\n     Shared glossary design system. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">EDR watches what actually happens on laptops and servers, records it, and lets you detect and shut down an attack that has already got past prevention.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Endpoint<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>EDR stands for endpoint detection and response. An agent on each device records process launches, file changes, registry edits and network connections, then flags behaviour that looks like an attack. Unlike antivirus, which blocks known bad files, EDR assumes something will get through and gives you the recording plus the ability to isolate the device.<\/p>\n<\/div>\n\n<p>The shift is from matching signatures to watching behaviour. A legitimate tool used the wrong way, such as PowerShell reaching out to an unknown host, has no signature to match but a very clear behavioural pattern.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#antivirus\">EDR compared with antivirus<\/a><\/li>\n    <li><a href=\"#does\">What EDR does<\/a><\/li>\n    <li><a href=\"#xdr\">EDR, MDR and XDR<\/a><\/li>\n    <li><a href=\"#osto\">How Osto covers the endpoint<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"antivirus\">EDR compared with antivirus<\/h2>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 240\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Antivirus blocks known bad files at the door, while EDR records behaviour and detects an attack already running.\">\n  <defs><marker id=\"edA\" markerWidth=\"8\" markerHeight=\"8\" refX=\"6\" refY=\"4\" orient=\"auto\"><path d=\"M0,0 L8,4 L0,8 z\" fill=\"#4a52a8\"\/><\/marker><\/defs>\n\n  <rect x=\"12\" y=\"40\" width=\"356\" height=\"182\" rx=\"18\" fill=\"#f4f5fd\"\/>\n  <text x=\"34\" y=\"70\" font-family=\"Inter,sans-serif\" font-size=\"14.5\" font-weight=\"700\" fill=\"#4a52a8\">Antivirus<\/text>\n  <text x=\"34\" y=\"92\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">Blocks what it already recognises<\/text>\n  <rect x=\"34\" y=\"106\" width=\"312\" height=\"34\" rx=\"9\" fill=\"#ffffff\"\/>\n  <text x=\"190\" y=\"128\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">Known malware file &#8594; blocked<\/text>\n  <rect x=\"34\" y=\"148\" width=\"312\" height=\"34\" rx=\"9\" fill=\"#ffffff\"\/>\n  <text x=\"190\" y=\"170\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">Stolen password used to log in &#8594; nothing<\/text>\n  <text x=\"190\" y=\"204\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-style=\"italic\" fill=\"#0f1538\">No file, no signature, no alert<\/text>\n\n  <rect x=\"392\" y=\"40\" width=\"356\" height=\"182\" rx=\"18\" fill=\"#eef4f9\"\/>\n  <text x=\"414\" y=\"70\" font-family=\"Inter,sans-serif\" font-size=\"14.5\" font-weight=\"700\" fill=\"#25547a\">EDR<\/text>\n  <text x=\"414\" y=\"92\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">Records behaviour, detects the pattern<\/text>\n  <rect x=\"414\" y=\"106\" width=\"312\" height=\"34\" rx=\"9\" fill=\"#ffffff\"\/>\n  <text x=\"570\" y=\"128\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">Unusual process spawns a shell &#8594; alert<\/text>\n  <rect x=\"414\" y=\"148\" width=\"312\" height=\"34\" rx=\"9\" fill=\"#1c267a\"\/>\n  <text x=\"570\" y=\"170\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"600\" fill=\"#ffffff\">Device isolated, timeline preserved<\/text>\n  <text x=\"570\" y=\"204\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-style=\"italic\" fill=\"#25547a\">You can answer what happened, and when<\/text>\n<\/svg>\n<\/div>\n<figcaption><span class=\"swipe\">Swipe to see the full diagram. <\/span>Most organisations run both. Prevention stops the noise, EDR handles what prevention misses.<\/figcaption>\n<\/figure>\n\n<h2 id=\"does\" class=\"c-sage\">What EDR does<\/h2>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Capability<\/th><th>Why it matters<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><strong>Continuous recording<\/strong><\/td><td>Process, file, registry and network activity kept so an incident can be reconstructed after the fact<\/td><\/tr>\n    <tr><td><strong>Behavioural detection<\/strong><\/td><td>Flags patterns rather than files, catching legitimate tools used maliciously<\/td><\/tr>\n    <tr><td><strong>Device isolation<\/strong><\/td><td>Cuts a compromised laptop off the network in one action while keeping your access to investigate<\/td><\/tr>\n    <tr><td><strong>Threat hunting<\/strong><\/td><td>Lets you search every endpoint for an indicator when a new threat is published<\/td><\/tr>\n    <tr><td><strong>Rollback and remediation<\/strong><\/td><td>Kills the process, quarantines the file and, in some cases, reverses the changes made<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">The question EDR answers<\/p>\n  <p>After an incident, someone will ask what the attacker touched and whether customer data was reached. Without endpoint recording, that answer is a guess, and a guess is not something you can put in a breach notification.<\/p>\n<\/div>\n\n<h2 id=\"xdr\" class=\"c-apri\">EDR, MDR and XDR<\/h2>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Term<\/th><th>What it means<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><strong>EDR<\/strong><\/td><td>The technology on the endpoint. You operate it and respond to its alerts<\/td><\/tr>\n    <tr><td><strong>MDR<\/strong><\/td><td>A service. Someone else monitors your EDR and responds on your behalf<\/td><\/tr>\n    <tr><td><strong>XDR<\/strong><\/td><td>Detection extended beyond the endpoint to identity, cloud, network and email, correlated together<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>For a small team the practical question is who reads the alerts. EDR without anyone watching it becomes a recording nobody plays back.<\/p>\n\n<h2 id=\"osto\">How Osto covers the endpoint<\/h2>\n\n<p>Osto provides endpoint protection, device control and content filtering through a managed agent, with macOS support. The same agent underpins access: through <a href=\"https:\/\/www.osto.one\/resources\/glossary\/ztna\/\">ZTNA<\/a>, internal resources stay unreachable unless that agent is installed and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/mfa\/\">MFA<\/a> is satisfied, so a device that falls out of policy loses access rather than just generating an alert. Endpoint events feed the same <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">SIEM<\/a> as identity, cloud and network activity, which is what turns an isolated device alert into a full picture of an incident.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Free security assessment<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Detection that does not need a security team<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Endpoint protection and device control with the agent that also gates access, so a device out of policy loses access rather than just alerting.<\/p>\n  <a href=\"https:\/\/osto.one\/contact\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 30px;border-radius:12px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Get a free security assessment<\/span><\/a>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:transparent;color:#ffffff;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:600;font-size:16px;text-decoration:none;border:1.5px solid rgba(255,255,255,.5);border-radius:12px;padding:13px 28px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#ffffff;\">Book a platform walkthrough<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:14px 0 0;\">macOS agent &middot; Access tied to device state &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What does EDR stand for?<\/summary>\n  <p>Endpoint detection and response. An agent records activity on laptops and servers, detects behaviour that indicates an attack, and provides the tools to investigate and contain it.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the difference between EDR and antivirus?<\/summary>\n  <p>Antivirus blocks files it recognises as malicious. EDR assumes something will get past that and focuses on detecting attacker behaviour, preserving a timeline and letting you isolate the device. Most organisations run both.<\/p>\n<\/details>\n\n<details>\n  <summary>Is EDR the same as MDM?<\/summary>\n  <p>No. MDM manages device configuration: encryption on, screen lock set, OS current. EDR detects and responds to threats running on the device. They answer different questions and are usually deployed together.<\/p>\n<\/details>\n\n<details>\n  <summary>Do small teams need EDR?<\/summary>\n  <p>They need the outcome: detection of what prevention missed, and enough recording to answer what happened. A full EDR product assumes someone is watching alerts. Teams without that capacity are better served by endpoint protection integrated with the rest of their stack.<\/p>\n<\/details>\n\n<details>\n  <summary>Do frameworks require EDR?<\/summary>\n  <p>None name the technology. ISO 27001:2022 covers malware protection in Annex A 8.7 and monitoring in A 8.16, and SOC 2 expects <a href=\"https:\/\/osto.one\/resources\/blog\/soc-2-controls-cc1-cc9\/\" target=\"_blank\" rel=\"noopener\">evidence of detection and incident response<\/a>. Enterprise questionnaires often ask about endpoint detection specifically.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> MDM &middot; SIEM &middot; ZTNA &middot; DLP &middot; MFA &middot; Incident Response<\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>EDR watches what actually happens on laptops and servers, records it, and lets you detect and shut down an attack\u2026<\/p>\n","protected":false},"author":8,"featured_media":683,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[262,264,265,263],"class_list":["post-682","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-edr","tag-edr-vs-antivirus","tag-mdr-and-xdr","tag-what-is-edr"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/682","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=682"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/682\/revisions"}],"predecessor-version":[{"id":684,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/682\/revisions\/684"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/683"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=682"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=682"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=682"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}