0 / 4
Endpoint Detection and Response (EDR)
EDR is a security solution in which an agent installed on each PC or server keeps recording program runs, file changes, and network connections and sends them to the EDR server. When EDR finds an attack in these records and raises an alert, the security staff isolate the PC, find the cause, and return it to the state before infection.
Example: An employee opened a quote file received by mail and allowed the hidden commands inside it (macros) to run. The macros run PowerShell to download ransomware from the attacker server. The four boxes at the top of the figure are the main EDR functions named by Gartner.
1 / 4
Detect: finding a suspicious execution flow
The word processor (winword.exe) runs PowerShell (powershell.exe), a program that runs commands. PowerShell downloads a ransomware file (locker.exe) from the attacker server and runs it. The ransomware adds itself to the autorun list so it starts every time the PC is turned on, and it encrypts report.docx. The agent sends these execution records to the EDR server. This ransomware is a file never seen before, so it is not on any malware list. Even so, the EDR server raises an alert from the flow itself: the word processor went through PowerShell to download and run an outside file.
2 / 4
Contain: isolating the PC so the attack does not spread
Seeing the alert, the security staff send a response command from the management console. The agent that receives it isolates the employee PC from the network, cutting its connections to the attacker server and to other PCs in the company. Only the connection to the EDR server is kept, so response and investigation can go on. The agent stops locker.exe and moves the file to quarantine (a separate place where it cannot run). No more files get encrypted. Depending on product settings, EDR can also do this automatically without the security staff.
3 / 4
Investigate: tracing where it started and how far it spread
The security staff trace the execution records stored on the EDR server back from the ransomware. That shows quote.docm, received by the mail program, as the starting point of the attack. In the same records they find the attacker server address that PowerShell connected to, the encrypted file, and the entry added to the autorun list. They also check other PCs' records for the same flow to decide how far the damage goes.
4 / 4
Remediate: returning to the state before infection
Everything found in the investigation is undone one by one. The quarantined locker.exe is deleted, and so is the entry added to the autorun list. The copy of quote.docm saved on the PC is deleted too. The word processor and PowerShell are normal programs that were already there, so they are not deleted. The encrypted report.docx is restored from backup. The attacker server address and locker.exe are put on the blocklist, and then the PC's isolation is lifted.
In Gartner's definition, this function only goes as far as giving remediation guidance. Real products may also delete and block things themselves, and some restore files from snapshots (copies of files at a point in time) taken in advance.