Antivirus watches files. This watches behaviour.
EDR sits on every endpoint and server, watching what processes do rather than what they are named — and isolating a machine the moment it starts behaving like an attacker. XDR joins that telemetry with mail, firewall and identity into one timeline.
Signature antivirus is a list of yesterday’s attacks. Useful, and twenty years out of date as a defence.
Modern intrusions rarely arrive as a known-bad file. They arrive as a legitimate tool doing something illegitimate — PowerShell pulling credentials, a signed binary encrypting shares, a stolen session moving sideways. Behavioural detection exists because the file scan cannot see any of that. It is the difference between checking IDs at the door and noticing someone is carrying the furniture out.
Behaviours, not signatures.
The honest version of what this layer does and does not do. Every row is a behaviour we have seen blocked in real environments — none requires the malware to be previously known.
| The behaviour | What EDR does | Without it |
|---|---|---|
| 01Mass file encryption begins | What EDR doesKills the process, isolates the machine, rolls back encrypted files from local cache | Without itRansomware finishes the disk, then finds the shares |
| 02Credential theft from memory | What EDR doesBlocks the access attempt and flags the account for review | Without itAttacker leaves with domain credentials, returns at leisure |
| 03Legitimate tool, hostile use | What EDR doesBehavioural rules catch PowerShell or PsExec doing attacker work | Without itInvisible — the tool is signed and “trusted” |
| 04Lateral movement between machines | What EDR doesXDR correlates the hops into one incident instead of three alerts | Without itThree separate alerts nobody joins together until later |
| 05Phish followed by odd sign-in | What EDR doesMail and identity telemetry land in the same timeline | Without itTwo consoles, two vendors, no story |
| 06Machine goes quiet to the console | What EDR doesTamper protection alerts when an agent is disabled or blinded | Without itFirst sign of trouble is the ransom note |
What it does not do: watch it overnight. Detection is automatic; judgement is human. That is the gap MDR closes, with analysts on the same telemetry around the clock. The plain-English version of the difference is in antivirus versus EDR, and the practices around it in six endpoint practices that block ransomware. Sectors that buy this first: dental clinics, law firms and healthcare.
The ones people actually ask.
If yours isn’t here, ask it directly — you’ll get an answer from an engineer, not a form letter.
It includes antivirus, but the point is behavioural: processes are judged by what they do, not what they are named. A brand-new, never-seen ransomware strain gets caught mid-encryption because encrypting a thousand files in a minute is behaviour, not a signature.
EDR watches endpoints. XDR joins that with mail, firewall and identity telemetry so one attack reads as one timeline instead of four unrelated alerts. Practically: it is the difference between an alert and an explanation.
Not noticeably on anything built in the last several years. The agent is a few percent of CPU under scan and near-idle otherwise — a fair trade against a machine that spends a day being reimaged.
Yes. The volume of macOS malware is lower; the value of what walks around on MacBooks — partner credentials, finance sessions — is not. Same agent, same console, same policy.
Included in the baseline stack of every managed engagement, along with mail filtering, DNS filtering and firewall management. The tier above it is MDR — human analysts on this telemetry, 24/7 — which is quoted separately per endpoint.
Next
Caught mid-behaviour, not post-mortem.
Twenty minutes. Tell us what endpoint protection you run today and we will tell you honestly whether it is enough.