What is Endpoint Detection and Response (EDR)? Print

  • 0

  • EDR (Endpoint Detection and Response) is an active, endpoint security solution that does real-time continuous monitoring correlating different events that happen on an endpoint level to detect malicious activity, compromised processes and suspicious behavior on end-user devices. The purpose is to identify in-progress attacks, potential security incidents, compromises or breaches – and then acting as a response system, providing capabilities to remediate it.

    The primary EDR capabilities as defined by Gartner are:

    • Detect security incidents
    • Contain the incident at the endpoint
    • Investigate security incidents
    • Provide remediation guidance

Was this answer helpful?

« Back