EDR/XDR
Endpoint detection and response (EDR) is a security capability that monitors activity on endpoints, such as computers and servers. It detects suspicious behavior, helps security teams investigate incidents, and supports response actions.
Extended detection and response (XDR) extends this approach across endpoints and other security data sources, such as network, email, cloud, or identity systems. By combining related information, XDR can help to see connections between events that occur in different parts of an organization.
How EDR/XDR adds value beyond endpoint protection
Endpoint protection can prevent many threats, but some attacks can bypass prevention or require further investigation. EDR collects information about endpoint activity and uses behavioral analysis to help identify suspicious activity. Security teams can use this information to understand what happened, which systems are affected, and how the incident developed.
Detection, investigation, and response
EDR and XDR can use rules, behavioral analysis, indicators of compromise, and threat hunting to detect possible threats. Incidents group related events and provide context for investigation. After a security team confirms a threat, response actions can include isolating an endpoint from the network, stopping a process, blocking an executable, or using a remote shell to investigate and remediate the affected system.
Move beyond endpoint protection
ESET PROTECT brings EDR and XDR capabilities together in a central management platform. At the same time, ESET Security Services can add expert support when your team needs more time, skills, or coverage.
Explore the ESET Inspect On-Prem documentation, learn about the ESET PROTECT OpenXDR transition, and discover ESET Security Services.