Endpoints are where users — and therefore attackers — actually land, so the endpoint agent is the defender's richest sensor and fastest kill-switch. EDR (Endpoint Detection & Response) records what happens on a machine, detects malicious behaviour from it, and lets a responder isolate the host with one click. This page is how it works under the hood, and it is the direct counterpart to the Defense Evasion and in-memory tradecraft pages, which are about beating exactly this.
How EDR works, end to end
[ Endpoint ]
kernel + user-mode sensors collect:
- process creation + full command line
- file / registry writes
- network connections
- image/DLL loads, driver loads
- API/syscall + AMSI + ETW events
|
v (stream telemetry)
[ EDR cloud backend ]
- behavioural analytics / ML / detection rules
- correlate into a process-tree 'story'
- threat-intel + cross-machine context
|
v
[ Console / SOC ] ---response---> isolate host, kill process,
quarantine file, collect forensics
The key idea is behaviour over signatures. Classic antivirus asked “does this file match known-bad?” EDR asks “does this sequence of actions look like an attack?” — Word spawning PowerShell spawning a network connection that injects into another process is malicious regardless of file hashes. That process-tree reconstruction is what lets it catch novel and fileless attacks.
The alphabet soup: EPP vs EDR vs XDR vs MDR
| Term | What it is |
|---|---|
| EPP / NGAV | Endpoint Protection Platform / next-gen antivirus — prevention (block known & ML-classified bad). The gate. |
| EDR | Detection & response — records behaviour, detects, enables investigation and host isolation. The eyes + kill-switch. |
| XDR | Extended DR — correlates endpoint with identity, email, network, and cloud telemetry for one cross-domain story. |
| MDR | Managed DR — a vendor/MSSP operates the EDR/XDR and responds on your behalf (24×7 coverage without the headcount). |
Leading platforms: CrowdStrike Falcon (premium default), Microsoft Defender for Endpoint (compelling with E5 licensing), SentinelOne, Palo Alto Cortex XDR. Open-source/DFIR adjacents: Wazuh, osquery, and Velociraptor for hunting and forensics.
The detection surfaces
EDR watches several layers at once — and each is a surface attackers try to blind. These map directly to the evasion content on this site:
| Surface | What EDR does | What attackers do |
|---|---|---|
| Static | Hash/signature/ML on files on disk | Pack, obfuscate, or go fileless entirely |
| Behavioural | Process-tree & action sequences | Live-off-the-land (LOLBins), mimic normal tools |
| In-memory | Scan for injected/unbacked executable memory | In-memory-only payloads, injection, module stomping |
| Userland hooks | Hook ntdll APIs to see calls | Unhook / direct syscalls to bypass the hooks |
| AMSI / ETW | In-process instrumentation of scripts & runtime | Patch AMSI, blind ETW in-process |
| Kernel / driver | Protected sensor, tamper protection | BYOVD — bring a vulnerable driver to kill the sensor |
This is an arms race, and that's the point of running Defense Evasion and telemetry as companion pages: the defender's job is to make evasion expensive and noisy, and to catch the evasion itself (an unhook, an AMSI patch, a driver load) as a high-fidelity signal.
Running EDR at fleet scale
Buying EDR is easy; operating it across 150,000 endpoints is the hard part, and where real posture is won or lost:
- Coverage & agent health. An unmonitored 2% is thousands of blind endpoints — fleet health (install %, agents reporting, version drift) is its own ops discipline.
- Tamper protection. The agent must resist being disabled by an attacker who gains local admin.
- Performance. A heavy sensor on latency-sensitive systems (trading, DBs) gets exclusions — and exclusions are exactly what attackers hunt for.
- Tuning. Out of the box, EDR is noisy; detections are tuned to the environment or analysts drown (see the SOC).
- Single-vendor & update risk. One agent on every machine is a systemic dependency — a bad sensor update can take the fleet down, so staged rollout rings matter.
Response & integration
EDR's “R” is what makes it more than a fancy AV: network-isolate a host (it can still talk to the EDR cloud, nothing else), kill a process, quarantine a file, and collect forensic artefacts remotely. In a mature shop these are driven by SOAR playbooks — an alert auto-isolates the host while a human investigates — and the telemetry feeds the detection-engineering loop and the XDR correlation across identity and cloud.
Red team ↔ blue team
Nearly every post-exploitation technique on this site is, from the defender's chair, an EDR detection problem: C2 implants must run code and call home (behaviour + network), LSASS dumping (T1003.001) is a hallmark EDR detection, and fileless tradecraft exists specifically to dodge the static surface. Understanding what EDR sees is what tells an attacker — and a defender — where the real friction is.
Key takeaways
- EDR = behaviour-based endpoint telemetry + detection + remote response (isolate/kill/quarantine).
- It detects the sequence of actions, which is why it catches novel and fileless attacks AV misses.
- Know the surfaces (static, behavioural, memory, hooks, AMSI/ETW, kernel) — each is an evasion battleground.
- At scale the challenge is coverage, tamper protection, tuning, and single-vendor/update risk.