IronSights

Detection & response

Endpoint Detection and ResponseEDR

A security solution that continuously monitors endpoint activity — processes, network connections, file changes — and provides detection, investigation, and response capabilities for advanced threats that evade traditional antivirus.

Also known asEDRendpoint detection and response

In plain English

EDR is next-generation endpoint protection. Unlike traditional antivirus that only scans for known malware signatures, EDR watches what programs actually do — and alerts when something behaves suspiciously, even if it's never been seen before. Microsoft Defender for Endpoint is a leading EDR platform built into Microsoft 365 Business Premium.

Keep learning

More terms in the IronSights Glossary.