An endpoint is a device. EDR, or endpoint detection and response, is a cybersecurity technology that monitors and protects that device.

The distinction has 2 parts: the device and the security technology. A company laptop, desktop computer, server, smartphone, tablet, Internet of Things device or virtual machine can be an endpoint. EDR collects security telemetry from endpoints, detects suspicious activity, supports investigation and enables response actions.

Endpoint vs. EDR at a Glance

Term What it means Example
Endpoint A network-connected device that accesses digital resources Employee laptop, Windows server or company smartphone
Endpoint security The tools and policies used to protect endpoints Antivirus, firewall, encryption, application control and EDR
EDR A security capability that monitors endpoint activity and helps detect, investigate and respond to threats Microsoft Defender for Endpoint or CrowdStrike Falcon Insight

What Is an Endpoint?

An endpoint is a device that connects to or accesses resources on a network.

The National Institute of Standards and Technology, or NIST, includes laptops, desktops, mobile phones, tablets, servers, Internet of Things devices and virtual environments in its definition of an endpoint.

Endpoints are common attack targets because they provide access to company applications, accounts and data. Attackers may target an endpoint through:

  • A phishing attachment
  • A malicious download
  • Stolen login credentials
  • An infected USB drive
  • A vulnerable application
  • A malicious script or process

The word endpoint describes the asset itself. It does not describe the software or policies used to protect that asset.

What Is EDR?

Endpoint detection and response is a security technology that monitors endpoint activity to identify, investigate and respond to threats.

An EDR platform usually collects information about processes, files, user activity, network connections and other events on a device. Security teams can use that information to investigate suspicious behavior, search for related activity and contain an affected device.

Microsoft lists EDR functions such as advanced threat detection, threat hunting, device isolation, investigation packages and live response.

For example, suppose a laptop runs a suspicious script, creates a new user account and connects to an unusual server. EDR can record those events, connect them and alert a security analyst. Depending on the product and its configuration, the team may then isolate the laptop, stop the process or collect more evidence.

Is EDR the Same as Endpoint Security?

No. EDR is one part of endpoint security.

Endpoint security is the broader approach to protecting devices. It can include:

  • Antivirus and next-generation anti-malware
  • Endpoint detection and response
  • Host-based firewalls
  • Application control
  • Device and USB controls
  • Disk encryption
  • Vulnerability management
  • Attack surface reduction
  • Security configuration policies
  • Automated investigation and remediation

Microsoft Defender for Endpoint, for example, combines endpoint protection with EDR, vulnerability management, attack surface reduction and automated investigation and remediation.

Endpoint Security vs. EDR

The comparison buyers usually need is endpoint protection platform versus EDR, not endpoint versus EDR.

Capability Endpoint security or EPP EDR
Main purpose Prevent and reduce threats across devices Detect, investigate and respond to suspicious activity
Primary focus Prevention and overall device protection Visibility and incident response
Typical tools Antivirus, firewall, encryption, application control and device control Telemetry collection, behavioral detections, threat hunting and response actions
Best question answered "How do we stop threats from running?" "What happened, how far did it spread and what should we do now?"
Relationship Broad security category or platform A component within endpoint security platforms

Endpoint protection and EDR handle different jobs. Prevention controls try to block malware and risky behavior before damage occurs. EDR provides visibility when an attack bypasses those controls or uses legitimate tools in a suspicious way.

A Simple Example

Consider an employee's Windows laptop:

  1. The laptop is the endpoint.
  2. Antivirus blocks a known malicious file.
  3. EDR records the attempted execution and related process activity.
  4. If an attacker uses a legitimate tool instead of known malware, EDR can detect suspicious behavior.
  5. The security team investigates the event and may isolate the laptop or stop the process.

The laptop is the asset. EDR is the technology monitoring activity on that asset.

Do You Need EDR?

EDR is particularly useful when an organization needs to investigate attacks, detect suspicious behavior and contain affected devices.

Common reasons to use EDR include:

  • Investigating attacks that bypass antivirus
  • Detecting behavior rather than only known malware
  • Searching historical endpoint activity
  • Supporting a security operations center
  • Containing compromised laptops or servers quickly
  • Improving visibility across remote and hybrid-work devices

EDR also requires people, processes and appropriate configuration. A company that cannot monitor alerts or investigate incidents may need managed detection and response, often called MDR. MDR adds external security monitoring and expertise to the EDR technology.

Bottom Line

Use endpoint security and EDR for different jobs. When comparing products, check whether the solution can prevent threats, record endpoint activity, support investigation and let your team contain affected devices. Endpoint security provides the wider set of controls. EDR provides the activity data and response tools needed when something gets through.