Skip to content

Resource

EDR versus traditional antivirus

Traditional antivirus compares files against a list of known bad ones, which is why it misses anything new. Endpoint detection and response watches behaviour instead. That difference matters, but it comes with a condition most businesses miss: the tooling only works if somebody reads what it says.

What each approach detects

The gap is not marginal. Most modern attacks are specifically designed to defeat the first column.

Detection capability compared between antivirus and EDR
Threat typeAntivirus
Known malware fileDetectedDetected
Newly created variantUsually detected by behaviourUsually missed
Fileless attack in memoryDetectedMissed
Legitimate tool used maliciouslyDetected by contextMissed
Stolen credential used normallyDetected by anomaly, if reviewedMissed
Bulk file encryption startingDetected and can be haltedSometimes detected late

What EDR adds beyond detection

The recording capability matters as much as the blocking.

  • A timeline of what a process did, which is how you learn what was actually reached
  • The ability to isolate a device from the network while leaving it reachable for investigation
  • Rollback of changes on some platforms, including certain encryption events
  • Evidence that survives the incident, which several compliance frameworks require
  • Visibility across every managed endpoint from one place rather than machine by machine

The condition nobody mentions

EDR generates alerts continuously, most of them benign. Its value appears only when somebody with the experience to tell the difference reviews them promptly.

Businesses of this size rarely have anyone rostered to look at a security console at two in the morning, which is exactly when the interesting alerts arrive. Attacks are timed for Friday evenings and public holidays deliberately.

This is why the honest comparison is not antivirus against EDR. It is antivirus against EDR with somebody watching it, which is a managed service rather than a licence purchase.

Common questions

Answered before you ask.

Is the EDR in our Microsoft licence good enough?

The tooling in the higher Microsoft tiers is genuinely capable and for many businesses there is no need to buy something else. The question is not whether the product is adequate, it is whether anyone reviews its output. A capable platform generating alerts nobody reads provides compliance evidence rather than protection.

Do we still need antivirus if we have EDR?

EDR platforms include the signature based detection that antivirus performs, so running both is usually duplication rather than defence in depth. Consolidating to one is normally cheaper and avoids the conflicts that come from two products both trying to inspect the same activity.

Will EDR slow our machines down?

Modern agents are considerably lighter than the antivirus suites people remember. Where a genuine conflict occurs, usually with line of business software doing something unusual, it is resolved with a scoped exclusion rather than by disabling protection.

Start with the assessment, not the contract.

We document what you have, test whether your backups restore, and give you the findings in writing. Yours to keep either way.

CallFree assessment