Endpoint Detection and Response
What is EDR (Endpoint Detection and Response)?
EDR is a security technology that records what happens on a computer and detects and responds to threats by their behaviour, catching attacks that signature antivirus never sees. Lavawall® adds endpoint detection, application control, and ransomware hunting around the antivirus or EDR you already run.
Start free, no credit card See how it works
Endpoint telemetry · behavioural detection · threat hunting · isolate and remediate
Definition
EDR came out of a simple problem: antivirus only stops what it already recognizes. The term was coined in 2013 to describe tools that continuously record endpoint activity, the processes that run, the files they touch, the registry keys they change, the network connections they open, and then look at that record for the behaviour of an attack rather than for a known file.
That shift matters because most serious intrusions no longer arrive as a virus file. An attacker signs in with stolen credentials, runs built-in Windows tools such as PowerShell, and moves quietly. There is nothing for signature antivirus to match. EDR catches the pattern instead: the unusual parent-child process, the credential-dumping tool, the script reaching out to an unfamiliar host.
When something is found, EDR does more than alert. A responder can isolate the machine from the network, kill the offending process, pull the timeline of what happened, and in some products roll the endpoint back to a known-good state.
Core components
- Continuous endpoint recording. A lightweight agent logs process, file, registry, and network events so there is a timeline to investigate after the fact.
- Behavioural detection. Rules and models flag the actions of an attack, credential theft, privilege escalation, lateral movement, rather than a specific file.
- Threat hunting. Analysts query the recorded telemetry to find intrusions that never tripped an automated rule.
- Response actions. Isolate the host, terminate a process, quarantine a file, or remediate a change, from the console.
- Rollback and forensics. A recorded timeline supports clean-up, evidence preservation, and, in some tools, reverting the machine to its prior state.
Why it matters
The endpoint is where ransomware actually detonates and where a stolen login turns into real damage. If you can only see the endpoint after the fact, you are cleaning up instead of stopping the attack. EDR gives you the live behaviour and the record to act on it.
It is also becoming table stakes on paper. Cyber-insurance applications now ask whether you run endpoint detection, not just antivirus, and CMMC 2.0 and NIST CSF assessments expect behavioural detection and a response capability. Answering yes, with evidence, is part of getting covered and passing an audit.
How Lavawall® helps with EDR
Lavawall® is not trying to be the EDR you already trust. It works around one. It watches the state and health of the antivirus or EDR on every machine, so a disabled or out-of-date agent shows up before an attacker relies on it. It adds application control, elevation, allowlisting, and ringfencing as a single agent with no kernel driver, so a foothold has fewer ways to run in the first place. And its Akira ransomware indicator hunting looks for the ransom notes, exfiltration tools, and remote-access utilities that mark a dormant or missed intrusion.
Because Lavawall® also reads Microsoft 365, identity, and network activity, an endpoint signal does not sit alone. A risky sign-in that lines up with a new admin account and an odd process on a laptop becomes one correlated alert instead of three you have to connect yourself. When you want a managed layer on top, Huntress, Blackpoint, and Microsoft Defender integrate, so their incidents surface in the same console.
Frequently asked
- Is EDR the same as antivirus?
- No. Antivirus blocks known-bad files by signature. EDR records what a program actually does on the endpoint and flags the behaviour of an attack, so it catches fileless and living-off-the-land activity that has no signature to match.
- Is EDR the same as XDR or MDR?
- No. EDR watches the endpoint. XDR extends that detection across identity, email, network, and cloud and correlates the signals. MDR is a service where a provider's analysts operate the detection-and-response for you. They are layers, not competitors.
- Does Lavawall® replace my EDR?
- Lavawall® is not a classic EDR and does not ask you to remove one. It monitors the antivirus or EDR you already run, adds application control and Akira ransomware indicator hunting, and correlates endpoint signals with Microsoft 365 and network events.