Endpoint Detection and Response (EDR), also referred to as Endpoint Detection and Threat Response (EDTR), is an endpoint security solution that continuously monitors end-user devices to detect and respond to cyber threats like ransomware and malware.
EDR security solutions record the activities and events taking place on endpoints and their workloads, providing security teams with the visibility they need to uncover incidents that might otherwise be missed. An EDR solution needs to provide continuous and comprehensive visibility into what is happening on endpoints in real-time.
An EDR tool should offer advanced threat detection, investigation, and response capabilities; including incident data search and investigation alert triage, suspicious activity validation, threat hunting, and malicious activity detection and containment.