01Introduction
Signature antivirus looked for known-bad files. Attackers moved on to living off the land: legitimate tools, stolen credentials and in-memory payloads. EDR was built for that shift, and it is now standard on most corporate laptops and servers.
02What is EDR?
Endpoint detection and response (EDR) is software installed on endpoints that continuously records process, file, network and registry activity, detects malicious behavior using rules and models, and lets responders investigate and contain a device remotely.
03How EDR works
An EDR agent sits between the operating system and everything that runs on it.
- 1.
Record
The agent logs process trees, command lines, file writes, network connections and privilege changes.
- 2.
Detect
Behavioral rules flag patterns such as an Office document spawning PowerShell or credential dumping from memory.
- 3.
Investigate
Responders replay the timeline on one device or search for the same indicator across the fleet.
- 4.
Respond
The console can kill processes, quarantine files, isolate the host from the network or roll back changes.
04Threats and risks
EDR covers devices it is installed on, and little else.
Unmanaged assets
Containers, serverless functions, contractor laptops and appliances often can't run an agent.
Application-layer attacks
An attacker abusing a broken authorization check in your API never touches an endpoint the EDR watches. That is the gap application security fills.
Evasion and tampering
Attackers target EDR itself with driver exploits and unhooking techniques to blind it before acting.
Cloud control plane
A leaked access key used against a cloud API leaves no process on any laptop. That falls to cloud security.
05How Parameter helps
Parameter covers the layers EDR can't: the application and the cloud.
Application attack paths
The pentesting agents test authentication, authorization and business logic in your running app and APIs.
Cloud misconfigurations
Cloud Security maps how IAM, network and data settings chain into a path to sensitive data.
Credentials in code
Secrets detection finds the keys that let an attacker skip the endpoint entirely. Read the secrets detection explainer.

