Malware
EDR
Also called endpoint detection and response.
EDR is software installed on a computer or server that records process and file activity and can stop or isolate the machine when something looks wrong. It sees the endpoint itself, not just the network.
How it is measured
EDR agents collect events: process starts, command lines, file writes, registry changes, network connections. A console lets you search them and apply rules. Measure coverage by percent of machines with a healthy agent, and by mean time to detect and respond on test alerts.
Test it. Run a harmless detection test file on a machine and confirm an alert reaches the console within minutes.
Worked example
A 40-person design studio installs EDR on 38 of 40 laptops. One alert fires: Word launched PowerShell with an encoded command, which then connected to a server in a hosting range. The console isolates the laptop from the network in one click.
The owner finds a macro in an emailed brief. The two laptops without the agent were old machines from a partner; they get it that week.
How it differs
EDR watches a machine and acts on it. A WAF watches web requests in front of an application. EDR sees the process that wrote a webshell; a WAF sees the request that delivered it. Heuristic detection is one technique inside EDR, alongside signatures and behavior rules. Antivirus is the older, narrower cousin focused on file scanning.
Common errors
Installing it and never reading alerts. Leaving servers out because they are headless. Turning on exclusions for a noisy folder and forgetting them. Assuming EDR protects a hosted WordPress site when the agent cannot run on shared hosting. Relying on it with no response plan.
In practice
Count machines with and without an agent. Decide who reads alerts and what they do in the first 15 minutes. If your site runs on shared hosting where you cannot install an agent, use file-integrity monitoring and logs instead.