Parameter

What is EDR?

Endpoint detection and response

What EDR is, how it records and responds to activity on laptops and servers, and which attacks it can't see.

01Introduction

Signature antivirus looked for known-bad files. Attackers moved on to living off the land: legitimate tools, stolen credentials and in-memory payloads. EDR was built for that shift, and it is now standard on most corporate laptops and servers.

02What is EDR?

Endpoint detection and response (EDR) is software installed on endpoints that continuously records process, file, network and registry activity, detects malicious behavior using rules and models, and lets responders investigate and contain a device remotely.

EDR data is often the richest source in a SIEM, and EDR is the foundation that XDR extends to other telemetry. Teams without in-house staff often have it watched by an MDR provider.

03How EDR works

An EDR agent sits between the operating system and everything that runs on it.

  1. 1.

    Record

    The agent logs process trees, command lines, file writes, network connections and privilege changes.

  2. 2.

    Detect

    Behavioral rules flag patterns such as an Office document spawning PowerShell or credential dumping from memory.

  3. 3.

    Investigate

    Responders replay the timeline on one device or search for the same indicator across the fleet.

  4. 4.

    Respond

    The console can kill processes, quarantine files, isolate the host from the network or roll back changes.

04Threats and risks

EDR covers devices it is installed on, and little else.

  • Unmanaged assets

    Containers, serverless functions, contractor laptops and appliances often can't run an agent.

  • Application-layer attacks

    An attacker abusing a broken authorization check in your API never touches an endpoint the EDR watches. That is the gap application security fills.

  • Evasion and tampering

    Attackers target EDR itself with driver exploits and unhooking techniques to blind it before acting.

  • Cloud control plane

    A leaked access key used against a cloud API leaves no process on any laptop. That falls to cloud security.

05How Parameter helps

Parameter covers the layers EDR can't: the application and the cloud.

  • Application attack paths

    The pentesting agents test authentication, authorization and business logic in your running app and APIs.

  • Cloud misconfigurations

    Cloud Security maps how IAM, network and data settings chain into a path to sensitive data.

  • Credentials in code

    Secrets detection finds the keys that let an attacker skip the endpoint entirely. Read the secrets detection explainer.

[ AI Pentesting ]

See how Parameter AI Pentesting fits your EDR program.

Autonomous agents that find, prove and fix what matters. Every finding ships with evidence.