Antivirus, EDR, XDR and MDR: what each one actually does
KINNEX Team5 min read
Endpoint protection vocabulary is confusing, partly because vendors keep inventing new labels.
Antivirus (AV)
Detects known malware by signatures and basic behaviour. It still helps, but attackers routinely avoid it, and modern attacks use legitimate tools that signatures do not flag.
Next-generation antivirus (NGAV)
Adds machine-learning detection, exploit protection and behaviour analysis. A reasonable minimum today.
EDR: endpoint detection and response
Records activity on each device, such as processes, network connections and file changes, so suspicious chains of behaviour can be detected, investigated and stopped. EDR lets you answer “what happened, and where else?”
XDR: extended detection and response
Pulls signals from endpoints, email, identity, network and cloud into one view, to correlate attacks across layers.
MDR: managed detection and response
A team watches the alerts for you, around the clock or during agreed hours, investigates and responds. For organisations without a security team, this is often the practical way to get value from EDR.
How to choose
- Do you have people to review alerts daily? If not, consider MDR.
- Which devices do you protect: laptops, servers, mobile, cloud workloads?
- Does it integrate with your identity, email and firewall?
- What are the response actions, and can they run automatically?
Whichever you choose, deploy it everywhere and keep it updated. A tool on half the devices protects half the network.