Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Endpoint detection and response (EDR) monitors activity on computers and servers, looks for suspicious behavior, and helps security teams investigate and contain threats. Its typical workflow is to collect endpoint signals, generate alerts from detections, investigate the evidence, take response actions, and verify the outcome. The exact data collected, how long it is retained, and which actions run automatically depend on the product and its configuration.

How does endpoint detection and response work?

EDR combines endpoint telemetry with detection logic and response tools. A sensor or built-in security component sends activity data to a security service, where detections can raise alerts for investigation. Analysts or automated workflows examine the available evidence and may take action to stop a threat from continuing or spreading.

Three terms help distinguish what happens along the way:

  • Detection: The system identifies behavior or an indicator it considers suspicious.
  • Alert: A record of a detection that can be investigated.
  • Incident: A related collection of alerts, grouped to help explain a broader event.

For example, Microsoft says Defender for Endpoint can group alerts into an incident when they are linked by techniques or an attributed attacker. That describes Microsoft’s product, not a universal requirement for every EDR platform. Microsoft’s EDR overview

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
SonicWall TZ270W Wireless Gen7 Firewall | SMB Wi-Fi Security Appliance with 2 Gbps Firewall Speed, Integrated Wireless Radios, Threat Protection, and Cloud Management (02-SSC-2823)
  • SonicWall TZ270W Appliance Only - No Service Subscription (02-SSC-2823) - Combines enterprise-grade firewalling with integrated 802.11ac Wave 2 Wi-Fi to deliver secure wired and wireless connectivity in one compact device for small offices and clinics.
  • Blocks zero-day threats and ransomware with Capture ATP sandboxing enhanced by RTDMI, plus IPS and anti-malware scanning for layered protection.
  • Eliminates the need for separate access points in smaller spaces thanks to built-in high-speed wireless that is simple to deploy and manage.
  • Supports VPN, SD-WAN, and TLS 1.3 decryption to secure hybrid cloud access and remote workers while maintaining usability and performance.
  • Delivers gigabit performance with up to 750,000 concurrent connections to handle growth in users, devices, and SaaS applications.

What does EDR collect from an endpoint?

EDR relies on signals that provide context about what a device is doing. In Microsoft Defender for Endpoint, documented examples include process and network activity, logins, and changes involving memory, the kernel, the registry, and file systems. Microsoft says its service stores behavioral telemetry for six months; that is a product-specific retention figure, not an industry standard. Microsoft’s telemetry documentation

EDR data should not be treated as a complete audit trail of every operation. Microsoft says Defender for Endpoint is not intended to record every endpoint activity and throttles repeated identical events. Investigations therefore depend on the evidence the product collected and retained, along with any other records the organization has available.

How does EDR investigate an alert?

Investigation turns an alert into a clearer account of what happened, how far it may have spread, and what may be affected. An analyst reviews the alert and related evidence, examines process and network context, and follows connections among the available endpoint records to build a timeline and assess impact.

Microsoft documents tools such as advanced hunting and live response for Defender for Endpoint on Windows. Other products may provide different investigation views or capabilities. Automation can also examine evidence and produce a verdict, but organizational policy determines whether proposed actions happen automatically or wait for review. Microsoft Defender for Endpoint documentation

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Firebox X20E Wireless
  • Watchguard Tech WG50021 Firebox X20e-Wireless

Can EDR isolate an infected computer?

Many EDR response workflows can isolate a device from the network to limit ongoing activity or prevent an attacker from moving laterally. The precise capabilities depend on the product, operating system, permissions, and security policy. Microsoft’s documentation also describes actions such as stopping or quarantining files, collecting files or investigation packages, and using live response. CISA describes endpoint isolation or containment as a response option governed by agency policy. CISA’s CDM technical capabilities

Containment and remediation are related but different. Isolation restricts a device’s connectivity to limit an active threat. Remediation addresses malicious artifacts or changes, for example by stopping a process or quarantining a file. Some platforms can perform certain remediation automatically; others require approval.

What happens after EDR detects a threat?

After a response action, the security team checks whether the threat was contained, whether remediation completed, and whether other devices or accounts may also be affected. In Microsoft Defender for Endpoint, pending and completed actions are tracked in the Action center, and Microsoft says some completed remediation can be undone. Treat that as an example of a product workflow rather than a standard interface across EDR tools. Microsoft’s response and remediation documentation

How does Microsoft Defender’s investigation automation work now?

Microsoft’s documentation says that, as of September 1, 2026, Automated Investigation and Response (AIR) no longer runs as a separate investigation experience or remains available for manual triggering from Microsoft Defender for Endpoint alerts and remediations. Microsoft says AIR detection and response capabilities are included in the default antivirus protection stack and run automatically; an on-demand investigation can use a full antivirus scan. This is a Microsoft Defender for Endpoint change, not a description of EDR products generally or Defender for Office 365. Microsoft’s AIR documentation

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sophos XGS 88 (Gen2) Network Security Appliance with 3 Years Standard Protection (XT88ZZ36ZZPCUS) | 4 x 2.5 GE Ports | Advanced Threat Protection, SD-WAN, Secure VPN, Centralized Management
  • XGS 88 with 3 Years Standard Protection - Next-generation firewall appliance with Standard Protection subscription providing firewall, VPN, intrusion prevention, web security, and application control, managed through Sophos Central for unified policies and reporting.
  • Equipped with 4 x 2.5 GE copper ports, supporting up to 9.9 Gbps firewall performance for small offices and branch deployments.
  • Protects users from ransomware, malware, phishing, and intrusion attempts before they reach endpoints or applications.
  • SD-WAN features deliver reliable, optimized application performance and intelligent multi link failover.
  • Includes Standard Protection – Comprehensive security package with firewall, intrusion prevention, VPN, web security, and application control to defend against everyday threats and keep business operations safe.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What to check when evaluating an EDR deployment

EDR features vary by product and configuration, so compare the capabilities that affect your environment and response process:

  • Endpoint and operating-system coverage: Which workstations, servers, and other endpoint types are supported?
  • Telemetry and retention: What activity is collected and searchable, and for how long?
  • Investigation workflow: Can the team correlate alerts, inspect timelines and process activity, run hunting queries, or investigate remotely?
  • Response controls: Can the product isolate a device, quarantine a file, or stop a process? Are actions reversible?
  • Automation governance: Which findings trigger automatic actions, which require approval, and how are exceptions handled?
  • Integration and deployment: How are devices onboarded, and how does EDR connect with the organization’s other security tools?

Configuration and licensing can change what a feature can do. For example, Microsoft’s EDR in block mode documentation says the feature can remediate malicious artifacts detected by EDR while Defender Antivirus is passive, but protections that require Defender Antivirus active mode are unavailable; the feature also specifies Plan 2 licensing. This is a Microsoft-specific example, not a general EDR rule. Microsoft’s EDR in block mode documentation

Onboarding is not the same as configuring a full security program. Microsoft says its Intune EDR onboarding configures devices to send telemetry to Defender for Endpoint; onboarding alone does not configure attack surface reduction, firewall, or antivirus policies, threat-hunting rules, or response workflows. Microsoft’s Intune EDR deployment documentation

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.