Let's talk about your project
01 / Knowledge hub

EDR or antivirus?

Short answer: antivirus focuses on recognising and blocking known malware; EDR continuously monitors behaviour on devices, makes the suspicious chain of events visible and allows responses such as isolating a device from the network. Because ransomware and targeted attacks do not carry known signatures, EDR becomes necessary as the number of employees and the value of data grow; but if nobody watches the alerts, EDR loses half its value.

At a glance
CriterionAntivirusEDR
Detection methodMainly known signatures and heuristic rules.Behavioural analysis: process, file, network and session activity are monitored together.
VisibilityA list of blocked files and alerts.A timeline of the incident: what ran, what it launched, where it connected.
ResponseDeleting or quarantining the file.Isolating the device, stopping processes, remote investigation and rollback.
Unknown attacksLimited; may miss attacks without signatures or those abusing system tools.Stronger; a suspicious chain of behaviour can be spotted even without a signature.
Operating effortLow; install it and keep it updated.Requires a team or managed service to assess alerts and respond.
Who is it for?Very small teams, basic protection; not sufficient on its own.Companies of any size with customer data, remote staff and ransomware risk.
  1. 01

    What does antivirus miss?

    Classic antivirus is good at recognising malicious files that have been seen before. A significant share of today's attacks, however, use new or modified malware, or abuse the operating system's own tools without dropping any file at all: signing in remotely with a stolen password, deleting backups with administrative commands. Each of these actions looks legitimate on its own, but when they follow one another they form the trail of an attack. Antivirus does not see this chain; EDR is designed to see it.

  2. 02

    How does EDR make a difference against ransomware?

    A ransomware attack often starts days before encryption: the attacker gets in, gathers privileges, finds the backups and only then starts encrypting. EDR can catch unusual behaviour in these early steps, such as activity resembling mass file encryption on an accounting computer or backup deletion commands, and stop the spread by isolating the device from the network. After the incident, records showing where the attacker got in and what they touched are also needed for investigation and notification obligations.

  3. 03

    Who will watch the alerts?

    EDR is most useful when the alerts it produces are assessed in time. If a critical alert that arrives at midnight is looked at the next morning, the attacker may already have finished. For companies without their own security team, a managed detection and response (MDR) service provides a team that watches EDR around the clock and responds when needed. Buying licences and leaving a console nobody looks at is the most common wasted investment.

  4. 04

    Are built-in protections enough?

    Modern operating systems come with built-in, updated malware protection, and for basic protection it is often unnecessary to buy a separate antivirus. But built-in antivirus is not the same as a centrally managed EDR that offers an incident timeline and response capabilities. Many providers offer EDR as a separate licence or a higher-tier package. Seeing from one central place which protection is actually active on which device matters more than the product name.

  5. 05

    EDR alone is not security

    EDR protects devices, but on its own it does not solve problems such as stolen passwords, remote access services left open and backups sitting on the same network. Multi-factor authentication, patch management, the principle of least privilege and immutable backups kept separate from the network complement EDR. If attack evidence needs to be collected and kept for a long time, forwarding EDR data to a SIEM should also be considered.

  6. 06

    Doki's impartial note

    For a team of a few people working with cloud applications and not holding sensitive data, up-to-date built-in protection, multi-factor authentication and good backups are often enough to start with. In any company that processes customer data, has remote staff or would come to a halt in an attack, EDR should be considered together with a team that monitors it. We can determine together which level is enough for your number of devices and your risk.

Let's begin

Let's talk about your project.

Tell us what you need; we will define the scope together.