Endpoint detection and response
EDR · Security software that continuously watches behaviour on computers and servers, detects suspicious activity, keeps records and can isolate a device from the network when needed.
- 01
Why it matters
Classic antivirus looks for known malicious files; EDR looks at behaviour such as legitimate tools being misused, unexpected encryption or unusual network connections. Its records make it possible to understand how an incident started. Someone, a team or a service, has to follow up on its alerts.
- 02
Example
On a laptop, hundreds of files start being renamed and encrypted within moments. EDR recognises the behaviour as ransomware, stops the process and isolates the device, preventing spread to other computers.
- 03
Common mistake
Installing EDR without assigning anyone to look at its alerts. Alerts nobody follows let the signs of a serious attack go unnoticed.
- 04
Let's talk about your project.
Tell us what you need; we will define the scope together.