THREAT-WATCH logo

THREAT‑WATCH

Glossary

Endpoint Detection and Response (EDR)

Software that monitors laptops, servers, and other devices for malicious activity and can respond automatically or via a SOC.

EDR agents run on individual devices (endpoints) and continuously record activity (process execution, network connections, file changes) looking for signs of compromise. When something suspicious is found, EDR can alert, and in a managed setup, a SOC can isolate the device from the network to stop an attack from spreading.