Endpoint detection and response
Also known as EDR
Security software on each device that records behavior, detects attacker activity, and lets a responder investigate and isolate remotely.
Antivirus asks whether a file is known to be bad. EDR asks whether the behavior on this machine looks like an attack, which is what catches fileless techniques, abuse of legitimate tools, and brand-new malware no signature exists for yet.
The response half matters as much as the detection half. Being able to isolate a machine from the network in seconds, from anywhere, while keeping your own access to investigate, is what stops one infection becoming an estate-wide event.
Where this comes up
Endpoint detection and response sits inside our cybersecurity and threats work. If you are trying to work out what this means for your own environment rather than in the abstract, that is the page worth reading next, and a short call will get you a straight answer faster than either.