Skip to main content

IT security

What are EDR and XDR?

EDR monitors behaviour on PCs and servers and stops attacks that antivirus misses. Understand the difference between EDR, XDR and antivirus, and where to start.

In short

EDR (Endpoint Detection and Response) is a security technology that monitors the behaviour of a company's endpoints, that is PCs, laptops and servers, and automatically detects and responds to attacks that traditional antivirus misses.

Where antivirus looks for known signatures, EDR analyses suspicious behaviour in real time, for example processes encrypting large numbers of files or tools attempting to steal passwords, and can isolate an infected machine from the network immediately. XDR (Extended Detection and Response) extends the principle so that data from email, identities, cloud services and networks is analysed together, giving a far better picture of an attack across systems.

For Danish SMBs the point is simple: modern attacks use legitimate tools and are not detected by signatures alone, so EDR is today a minimum requirement for sensible security. MI Support IT implements and monitors EDR and XDR solutions based on Microsoft Defender for Danish businesses.

Back to the glossary

What are EDR and XDR?

EDR stands for Endpoint Detection and Response and is a security technology that monitors the behaviour of your endpoints, that is PCs, laptops and servers, and responds automatically when something looks wrong. An EDR solution continuously records which processes are running, which files are being changed and which connections are being opened, and can on that basis detect attacks as they happen. XDR (Extended Detection and Response) is the natural evolution, where the same principle is extended to the entire IT environment.

EDR vs. antivirus: what is the difference?

Traditional antivirus works with signatures: it recognises known malware from a catalogue and blocks it. That works fine against well-known threats, but modern attackers increasingly use legitimate tools such as PowerShell and remote access programs that do not match any signature.

EDR instead works with behaviour and response. If a process suddenly encrypts hundreds of files, or a program tries to read passwords out of memory, EDR raises the alarm, whether the tool is known or not. And where antivirus stops at blocking, EDR can respond: isolate the machine from the network, kill the process and give you a timeline of what actually happened. It is the difference between a lock and a guard keeping watch.

What is XDR?

XDR extends the EDR principle from endpoints to the entire attack surface: email, identities, cloud applications and networks. The advantage is coherence. A modern attack might start with a phishing email, continue with a compromised login and end up on a server. An XDR platform combines those three signals into one incident instead of three isolated alerts, so you see the entire attack chain and can stop it earlier. Larger setups also forward data to a SIEM, where logs from all systems are analysed together.

Microsoft Defender for Endpoint as EDR

For most Danish SMBs, the obvious choice is Microsoft Defender for Endpoint, which is Microsoft's EDR solution and part of the Microsoft 365 ecosystem. It is deeply integrated into Windows, shares threat data with the Defender products for email, identity and cloud apps (and thereby effectively becomes XDR via Microsoft Defender XDR) and requires no additional agents or servers. Microsoft's own documentation at learn.microsoft.com describes the features in detail, but the short version is: many companies already have the licence and simply are not using it.

An EDR solution only delivers value, however, if someone responds to the alerts. The technology must be backed by people who monitor, investigate and act.

How MI Support IT can help

We implement and configure Defender-based EDR and XDR as part of our IT security solutions, and with our 24/7 service desk there is always someone to respond when the alarm goes off. Contact us to hear what your current licences already cover.

Shall we talk about your business and your needs?

Real people talking to real people. We get back to you the same day.