Skip to main content
Offline·Progress is saved on this device and syncs the next time you open the app online.
Endpoint, Host & Application

EDR

Endpoint Detection and Response

Tooling that monitors endpoints for threats and supports investigation and response.

EDR continuously collects and analyzes endpoint telemetry such as process, file, and registry activity to detect threats that signature based antivirus misses. It supports investigation and response actions like isolating a host, killing a process, or rolling back changes, and it retains data for threat hunting. By focusing on behavior it catches fileless and novel attacks that evade static detection. XDR extends this concept across email, network, and cloud, while MDR adds a managed service layer.

Memory hook

Endpoint Detection and Response: deep visibility and response on endpoints.

Related terms

Looking EDR up is step one. Getting tested on it is step two.

A free account opens all 4 Domain 1 objectives, 271 exam-style questions with a lesson and a lab on each, a placement check that skips what you already know, and a dated plan. No card.

Not affiliated with or endorsed by CompTIA.