What separates EDR from classic antivirus, what to look for when selecting, and why most deployments fail on operations rather than technology.
Endpoint protection is the area where most organisations believe they are fine because something is installed. Yet the gap between classic signature-based antivirus and EDR is an order of magnitude in what it sees and what it can do.
| Antivirus | EDR | |
|---|---|---|
| What it looks for | Known malware signatures | Suspicious behaviour |
| Against zero-days | No protection | Partial protection |
| What it can do | Quarantine | Kill processes, isolate hosts |
| Investigation | None | Retrospective search |
| Fileless attacks | Invisible | Visible from the process chain |
A significant share of modern attacks brings no file: they use legitimate system tooling (shells, scripting engines, administrative utilities). Signature-based protection cannot see these, because there is nothing to recognise.
Whether it covers the whole estate. Windows, macOS, Linux servers, and legacy systems where present. A product covering only workstations is half a solution.
Whether retrospective search exists. If a new indicator of compromise emerges in three weeks, can it tell you whether it occurred in your environment? That requires retaining telemetry, not just alerts.
How many false positives. Only a pilot reveals this. Ask for a 30-day trial in your own environment, not a demo.
Whether it integrates with your SIEM. EDR is one of the densest signal sources. If it cannot export, it remains an isolated island. We covered this in our SIEM deployment article.
Who responds to alerts. The most important question, and not a technical one. If nobody is available to watch, you need a managed service (MDR) rather than a standalone product.
1. Inventory. How many endpoints, running which operating systems? Deployment coverage is the key metric: 85 percent coverage means the attacker works on the remaining 15.
2. Monitoring mode. The first 2-4 weeks: the EDR logs and alerts without blocking. This reveals which legitimate tools trigger alerts.
3. Tuning. Every false positive requires a decision: exception, rule refinement or acceptance. Exceptions should be narrow, documented and periodically reviewed.
4. Gradual blocking. Starting with high-confidence detections, then widening.
5. Response process. Who receives the alert, what they do with it, when they escalate, and what happens at night and at weekends.
Post-deployment verification. Coverage must be reviewed regularly in the console. A new machine, a restored system, a forgotten server: something always slips through.
Tamper protection. An attacker's first act is disabling the EDR. Enabling tamper protection and alerting on disable attempts is a baseline requirement.
Servers. Many deployments stop at workstations, yet the attack continues on servers. EDR on the domain controller and file server is disproportionately valuable.
Legacy systems. Where no agent can be installed, compensating controls are needed: strict segmentation, enhanced network monitoring. In industrial environments this is the rule rather than the exception.
If coverage is below 98 percent, every other metric is theoretical. Our IT security services include designing and deploying endpoint protection architecture.
Comprehensive IT security services including firewalls, WAF, IPS, SIEM, DLP and endpoint protection from…
When an organisation needs a SIEM, which log sources to start with, how to avoid alert flooding, and what…
How a modern ransomware attack actually unfolds, which controls genuinely stop it, and what to do in the…
Our specialists are happy to discuss what this means in your organisation's environment.