What it is
Endpoints Are Where Most Compromises Actually Begin.
Workstations, laptops and servers run the browsers, email clients, user sessions, local credentials, scripts and remote-access tools an attacker needs. That makes the endpoint the place where a phishing click, a stolen password or a malicious document turns into something running inside your network.
Endpoint detection and response, or EDR, continuously observes what happens on those machines. Instead of only matching known bad files, it watches behaviour: a process encrypting files rapidly, a script pulling code from an unfamiliar host, an administrative tool being used in a way nobody would use it during normal work. When that behaviour looks like compromise, it can be blocked, the machine can be isolated from the network, and the activity is recorded for investigation.
No endpoint product prevents everything. What EDR changes is how early malicious behaviour is noticed and how much is known about it afterwards.