# What is Endpoint Detection and Response (EDR)?

> Endpoint detection and response (EDR) is a security capability that continuously records and analyzes activity on endpoint devices so defenders can detect suspicious behavior, investigate what happened, and take response actions.

- Canonical URL: https://yellowcube.eu/glossary/endpoint-detection-and-response/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

Endpoints commonly include workstations and servers, although supported device types and depth of visibility vary by product and operating system.

An EDR agent can observe activity such as process creation, file changes, logons, persistence mechanisms, and network connections. Depending on policy and product capability, responders may isolate a host, terminate a process, quarantine a file, or collect investigation evidence.

### Key points

- **Primary purpose:** Provide host-level visibility and response during security investigations.
- **Operational value:** Helps reconstruct attack chains, hunt for related activity, and contain affected machines.
- **Deployment dependency:** Agents must be installed, healthy, correctly configured, protected from tampering, and monitored by people or automation.
- **Important limitation:** EDR cannot see every device or attack path and does not replace secure configuration, identity controls, network monitoring, or recoverable backups.

### Related terms

[Extended detection and response (XDR)](<https://yellowcube.eu/glossary/extended-detection-and-response/>) · [Network detection and response (NDR)](<https://yellowcube.eu/glossary/network-detection-and-response/>) · [Managed detection and response (MDR)](<https://yellowcube.eu/glossary/managed-detection-and-response/>) · [Ransomware](<https://yellowcube.eu/glossary/ransomware/>) · [Indicator of compromise (IoC)](<https://yellowcube.eu/glossary/indicator-of-compromise/>)

### Sources

[CISA CDM Technical Capabilities, Volume 2](https://www.cisa.gov/sites/default/files/2023-08/CDM_Tech%20Volume2_v2.5.pdf) · [NIST SP 800-83 Rev. 1: Guide to Malware Incident Prevention and Handling for Desktops and Laptops](https://csrc.nist.gov/pubs/sp/800/83/r1/final)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

