---
title: What is the difference between EDR and EPP (Antivirus)? Endpoint Security Measures and EDR Research Explained | AIでフォレンジック調査・eディスカバリを解決 | FRONTEO, Inc.
description: In today's information-oriented world, it is becoming increasingly difficult to respond to cyber-attacks against companies with conventional security products alone. In such an environment, EDR, which detects abnormalities in devices, is attracting attention. This article explains how EDR works, its functions, and how it differs from antivirus, as well as EDR surveys to understand virus intrusion routes and damage.
image: https://legal.fronteo.com/hubfs/Imported_Blog_Media/fllp-edr-security-1.png
---

# What is the difference between EDR and EPP (Antivirus)? Endpoint Security Measures and EDR Research Explained

2023年10月11日配信

In today's information-oriented world, it is becoming increasingly difficult to respond to cyber-attacks against companies with conventional security products alone. In such an environment, EDR, which detects abnormalities in devices, is attracting attention. In this article, we will explain how EDR works, its functions, and how it differs from antivirus, as well as EDR surveys to understand virus intrusion routes and damage.

![EDRとEPP（アンチウイルス）の違いは？エンドポイントのセキュリティ対策とEDR調査を解説](https://legal.fronteo.com/hubfs/Imported_Blog_Media/fllp-edr-security-1.png)

## EDR is a security solution that detects and responds to unauthorized activity at the endpoint

 EDR stands for Endpoint Detection and Response, a security measure that detects unauthorized activity on PCs, smartphones, servers, and other digital devices and notifies administrators. With changes in the way of working due to the spread of teleworking and other factors, EDR to enhance security of these digital devices, known as endpoints, has been attracting attention.

## Differences between EDR and other security products

 This section describes the differences between EDR and other security products such as EPP, NGAV, and NDR, as well as the features of each.

### Difference between EDR and EPP (Anti-Virus)

 EPP stands for Endpoint Protection Platform, also commonly referred to as antivirus software. The difference between EDR and EPP is that the main purpose of EDR is to minimize damage after a threat has entered the system, while the main purpose of EPP is to protect against threats before they enter the system.

### Differences between EDR and NGAV (Next Generation Anti-Virus)

 NGAV stands for Next Generation Anti-Virus and is a next-generation EPP. It uses machine learning technology to detect and eliminate anomalies that have movements and characteristics similar to malware (viruses and other malicious software). It is characterized by its ability to respond to unknown malware that is not in its database, but like EPP, its main purpose is to prevent threats before they enter the system, which is the difference between it and EDR.

### Differences between EDR and NDR

 NDR stands for Network Detection and Response, and refers to security measures that detect and respond to unauthorized activity on a network, The difference is that EDR is a measure for endpoints, i.e., devices such as PCs and servers, while NDR is a measure for the network, i.e., communication activity after an intrusion.

## Importance of EDR in Cyber Security and Reasons for Increased Attention to EDR

 This presentation will explain the importance of EDR, which approaches threats that cannot be prevented, rather than preventing them from entering the system, as well as the background to the growing attention to EDR.

### Increasing sophistication and sophistication of cyber attacks

 Cyber-attacks are becoming more advanced and sophisticated with the evolution of technology. Even if security measures are taken, attacks can quickly surpass them, making it nearly impossible to completely prevent intrusions. For this reason, EDR, a mechanism to minimize damage based on the assumption that an intrusion will occur, is becoming more and more important.

### Widespread use of mobile terminals

 The proliferation of mobile devices such as smartphones and tablets is also having an impact. There are an increasing number of cases of intrusion into corporate servers via employees' smartphones or through Wi-Fi environments in the city, and conventional security systems are finding it difficult to cope with such intrusion.

### Diversification of work styles such as telework

 Another factor is the diversification of work styles due to the Corona disaster. With the spread of remote work, there are more opportunities to work from home or outside the office, and attack routes have become more diverse. In such a network environment, perimeter-type defenses that separate internal and external networks have their limits. Therefore, it is necessary to strengthen security at endpoints in accordance with the zero-trust concept of "no unconditional trust.

## Key points when considering EDR products

 There are a wide variety of EDR products, and each product has different features and costs, so it is important to select the right product for your security situation. In addition, some of the tools that are widely used as EPPs also provide EDR, but some of these products may not have sufficient EDR functionality. If you need a full-fledged EDR function, select a product with EDR functions as its main feature.

## Subjects of EDR surveys and what can be learned from the surveys

 This section explains what EDR investigates and what can be learned as a result.

### Virus entry routes

 When EDR investigations detect suspicious behavior or suspicious programs, they can catch up lateral movement from the active endpoint (terminal) where the compromise originated. If you have an EDR license that retains logs for a certain period of time in the past, you can also identify intrusion routes by analyzing the process retroactively from the point of detection.

### Damage Situation

 EDR investigations can collect and analyze information such as the type of malware detected, the intrusion route, and whether or not information has been leaked, to identify the root cause of the security breach and visualize the damage situation.

## For EDR investigation and other cyber attack damage response, FRONTEO's Cyber Security Investigation Package

 While EDR has many advantages as described above, there are also several disadvantages. One is that it is costly to implement. Another is the need to devote resources to operations. It is necessary to secure personnel with the knowledge and experience to respond to threats when they occur, and to establish an operational system that can respond quickly.

 FRONTEO's "Cyber Security Investigation Package" is recommended to eliminate such disadvantages, as FRONTEO has conducted more than 10,600 fraud investigations and is recommended by several insurance companies to provide high-quality cyber security investigations. We can investigate from a single PC.

 We provide not only EDR investigations, but also Dark Web investigations as a single package, and can conduct additional investigations such as Wi-Fi vulnerability investigations, NDR investigations, and penetration tests. For companies that do not have personnel with specialized knowledge, concerns remain about the speed and expertise of contingency response. Based on the know-how gained from our overwhelming experience, FRONTEO will support your initial response to cyber attack damage.

 → [[Related Article] Cyber Security Survey Package "Cyber Security Survey Package" service website](https://legal.fronteo.com/smaller-companies-package/?hsLang=en)<https://legal.fronteo.com/forensics/?hsLang=en>

 →For [inquiries about FRONTEO's EDR investigations, click here.](https://legal.fronteo.com/contact/?hsLang=en)

[![Prev](https://legal.fronteo.com/hubfs/raw_assets/public/p-chan-fronteo/assets/images/common/icon-arrow-slider-prev.svg)](https://legal.fronteo.com/en/legal-column/legal-affairs-ai?hsLang=en)

[一覧に戻る](https://legal.fronteo.com/en/legal-column)

[![Next](https://legal.fronteo.com/hubfs/raw_assets/public/p-chan-fronteo/assets/images/common/icon-arrow-slider-next.svg)](https://legal.fronteo.com/en/legal-column/ransomware-infection-routes?hsLang=en)

## 関連コンテンツ

[![What is support fraud? Actual conditions and effective countermeasures for damage such as sophisticated methods and remote control that start from warning screens.のサムネイル](https://legal.fronteo.com/hubfs/support-scam_image01.png)

2025年07月30日

### What is support fraud? Actual conditions and effective countermeasures for damage such as sophisticated methods and remote control that start from warning screens.

](https://legal.fronteo.com/en/legal-column/support-scam?hsLang=en)

[![How does a company investigate and collect evidence of suspected embezzlement? Explanation of the investigation process and response to employee embezzlement on the job.のサムネイル](https://legal.fronteo.com/hubfs/Imported_Blog_Media/w_AdobeStock_524231367-1.jpg)

2025年07月25日

### How does a company investigate and collect evidence of suspected embezzlement? Explanation of the investigation process and response to employee embezzlement on the job.

](https://legal.fronteo.com/en/legal-column/investigation-of-embezzlement?hsLang=en)

[![Cost of Forensic Investigations - Prices, Timeframes, Cautions and How to Choose an Investigation Companyのサムネイル](https://legal.fronteo.com/hubfs/Imported_Blog_Media/image-forensics-cost-1.jpg)

2024年10月29日

### Cost of Forensic Investigations - Prices, Timeframes, Cautions and How to Choose an Investigation Company

](https://legal.fronteo.com/en/legal-column/forensics-cost?hsLang=en)

[![What are some examples of cyber security measures taken by companies? Damage Impact Also Explainedのサムネイル](https://legal.fronteo.com/hubfs/Imported_Blog_Media/fllp-cyber-security-measures.png)

2023年12月06日

### What are some examples of cyber security measures taken by companies? Damage Impact Also Explained

](https://legal.fronteo.com/en/legal-column/cyber-security-measures?hsLang=en)

[![What are AI-based cybersecurity measures? Specific examples and benefitsのサムネイル](https://legal.fronteo.com/hubfs/Imported_Blog_Media/fllp-cyber-security-ai.png)

2023年12月06日

### What are AI-based cybersecurity measures? Specific examples and benefits

](https://legal.fronteo.com/en/legal-column/cyber-security-ai?hsLang=en)

[![What is NDR? Explaining its functions, advantages and disadvantages, and how it differs from EDRのサムネイル](https://legal.fronteo.com/hubfs/Imported_Blog_Media/fllp-about-ndr.png)

2023年11月30日

### What is NDR? Explaining its functions, advantages and disadvantages, and how it differs from EDR

](https://legal.fronteo.com/en/legal-column/about-ndr?hsLang=en)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "kaori_matsushita",
    "url" : "https://legal.fronteo.com/en/legal-column/author/kaori_matsushita"
  },
  "dateModified" : "2025-07-24T07:47:57.152Z",
  "datePublished" : "2023-10-11T03:00:00.000Z",
  "headline" : "What is the difference between EDR and EPP (Antivirus)? Endpoint Security Measures and EDR Research Explained",
  "image" : [ "https://legal.fronteo.com/hubfs/Imported_Blog_Media/fllp-edr-security-1.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://legal.fronteo.com/en/legal-column/edr-security",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject"
    }
  }
}
```