Endpoints commonly include workstations and servers, although supported device types and depth of visibility vary by product and operating system.
An EDR agent can observe activity such as process creation, file changes, logons, persistence mechanisms, and network connections. Depending on policy and product capability, responders may isolate a host, terminate a process, quarantine a file, or collect investigation evidence.
Key points
Primary purposeProvide host-level visibility and response during security investigations.
Operational valueHelps reconstruct attack chains, hunt for related activity, and contain affected machines.
Deployment dependencyAgents must be installed, healthy, correctly configured, protected from tampering, and monitored by people or automation.
Important limitationEDR cannot see every device or attack path and does not replace secure configuration, identity controls, network monitoring, or recoverable backups.