Cybersecurity definition
What is EDR?
EDR stands for Endpoint Detection and Response.
By Cyber Tool Stack Editorial TeamUpdated
Definition
Software that continuously records what happens on endpoints (processes, files, network connections) and detects, investigates, and responds to malicious behavior.
Where EDR fits in the security landscape
These beginner lessons use this term while explaining the surrounding security control.
Related cybersecurity terms
XDRExtended Detection and ResponseExtends endpoint detection and response by correlating telemetry from identity, email, and cloud systems alongside endpoint activity, so a single attack spanning multiple systems appears as one connected incident instead of scattered alerts.EndpointAny laptop, server, or mobile device that runs software and connects to a network — the place where most attacks ultimately execute.AgentA small piece of software installed on a device that collects activity data and can take local action, such as blocking a process or isolating the machine from the network.EPPEndpoint Protection PlatformThe baseline security agent installed on laptops and servers that blocks known malware, enforces device and application control policy, and reports fleet-wide compliance from one console.