The reference desk / In practice

EDR

Telemetry and response capability on laptops and servers for process, file, and similar host activity.

Endpoint detection and response

What it means

EDR collects information from supported endpoints, such as laptops and servers, to help detect and investigate suspicious behavior. Depending on the product and operating system, it may record process activity, file changes, connections, or other events, and offer actions such as isolation or evidence collection. Those capabilities depend on deployment, permissions, configuration, and sensor health. EDR complements other defenses; it does not replace patching, identity controls, or application logging. A device that has an agent installed may still have stopped sending useful data.

AN ILLUSTRATIVE SCENARIO

A suspicious spreadsheet on a payroll laptop

An employee opens a spreadsheet and the endpoint sensor records an unusual child process making an outbound connection. The analyst examines the process chain, account, file details, and timing. This context helps distinguish ordinary spreadsheet use from suspicious execution. Before isolating the laptop, the analyst checks the response policy and business impact. The investigation also considers whether the same account was used elsewhere, beyond the endpoint sensor’s view.

Put it to work

  1. Inventory supported devices and deploy sensors in a measured rollout. Track current reporting and configuration, including devices that have been offline for extended periods.
  2. Define who can collect files, isolate hosts, or run response actions. Protect those permissions and account for operational impact on specialized or critical equipment.
  3. Test a harmless detection scenario and document the evidence produced. Route useful alerts to a staffed process, and investigate sensor failures as a coverage problem.

How to check your work

For a test device, confirm recent telemetry, expected event fields, alert delivery, and the approved response path. If testing isolation, verify both its intended restriction and the documented method for safely restoring connectivity.

Connect the ideas

  • XDR

    A vendor category for stitching multiple telemetry sources; it is not automatic coverage of every outcome.

  • NDR

    Detection and investigation based on network traffic or metadata rather than host agents alone.

  • Alert

    A notification that a rule or model wants a human to look at one or more records.

  • Coverage

    An explicit statement of which sources, time windows, and rows were actually collected, including truncation.

Explore a field lesson

Find your next idea.

Tip: press / to open search. Escape closes this window.