EDR: Your Security Tools Are Only as Good as What They Can Find
25 September
The problem isn’t always stopping an attack. It’s knowing when something has got through.
Most organisations have invested heavily in cybersecurity. Firewalls, email security, identity protection, vulnerability management, endpoint protection and security awareness are all designed to prevent an attacker from getting in.
But no security control is perfect.
Eventually, something may get through. It could be a compromised account, a vulnerable application, a malicious attachment, stolen credentials or an attacker using legitimate tools already available within the environment.
When that happens, prevention is no longer the only concern.
The question becomes: can you see what’s happening quickly enough to stop it?
This is where Endpoint Detection and Response (EDR) becomes an important part of the security strategy.
EDR isn’t just another antivirus solution
Traditional antivirus has an important role to play, but today’s attacks don’t always involve obvious malware.
Attackers increasingly use legitimate applications, stolen credentials, scripts and built-in operating system tools to move around an environment. Their activity can look very different from the traditional image of a virus or malicious file.
That makes simply asking “Is this file malicious?” less useful than it once was.
Security teams need to understand the wider context.
Why did this process run? Which user initiated it? What did it access? What did it communicate with? Did anything happen immediately before or afterwards? Is the same behaviour appearing on other endpoints?
EDR provides the visibility needed to start answering those questions.
Instead of simply identifying a suspicious file, security teams can investigate the behaviour and sequence of events surrounding it.
And that context can be critical.
The problem isn’t always a lack of security data
In fact, many organisations have the opposite problem.
They have too much.
Every endpoint can generate huge amounts of telemetry covering processes, applications, network connections, users, files and system activity. Multiply that across hundreds or thousands of devices and security teams can quickly find themselves dealing with an enormous amount of information.
The challenge becomes separating the important signals from the background noise.
This is where alert fatigue becomes a serious issue.
If analysts are constantly investigating low-priority alerts, genuinely suspicious activity can become harder to identify. Even when the right information exists within the environment, finding it quickly enough can be difficult.
Visibility is only valuable if you can turn it into action.
What happens when an attacker looks like a legitimate user?
One of the biggest challenges facing security teams is that attackers don’t necessarily need to use obviously malicious software.
They can use legitimate credentials, standard administrative tools and applications that employees already use every day.
This makes behaviour increasingly important.
An unusual login, a suspicious process chain or an unexpected connection might not look significant in isolation. But when those events are connected together, they can tell a very different story.
EDR can help security teams build that picture.
It allows analysts to investigate questions such as:
- What happened immediately before the suspicious activity?
- Which user, device or process initiated it?
- Did the activity spread to other endpoints?
- What systems or data could have been accessed?
- Does the behaviour match known attacker techniques?
The objective isn’t simply to generate more alerts.
It’s to provide the context needed to understand what those alerts actually mean.
What if the threat hasn’t triggered an alert?
This is where threat hunting becomes particularly important.
Traditional security monitoring is often reactive. A security tool generates an alert, an analyst investigates it and the organisation responds.
Threat hunting takes a different approach.
Instead of waiting for the technology to tell you that something is wrong, security teams proactively search for suspicious activity that may have gone unnoticed.
This could involve looking for unusual processes, unexpected connections, suspicious account behaviour or patterns associated with known attacker techniques.
EDR can provide a valuable source of information for this activity.
And this raises an uncomfortable question for many organisations:
What activity is happening in your environment that you haven’t detected yet?
Detection is only the beginning
Finding suspicious activity is important, but it is only the first step.
Once a potential threat has been identified, the security team needs to establish what happened and decide what to do next.
Was the endpoint compromised? Has the attacker moved elsewhere? Are other accounts involved? Does the device need to be isolated? Has sensitive information been accessed?
The faster those questions can be answered, the faster the organisation can move from detection to containment.
This is why EDR should not be viewed as simply another security product sitting on an endpoint.
Its real value comes from how it supports the wider process of detection, investigation and response.
Having EDR doesn’t automatically mean you’re protected
This is an area that can easily be overlooked.
An organisation can have EDR deployed across its entire estate and still have gaps in its security.
The technology might be there, but is it configured correctly? Are alerts being investigated? Are analysts using the available data effectively? Is threat hunting taking place? Are response processes understood and tested?
There is a significant difference between having EDR and getting value from EDR.
Before investing in another security product, organisations should consider whether they are fully utilising the capabilities they already have.
Test your security controls before an attacker does
One of the most effective ways to understand whether your security controls are working as expected is to test them.
Controlled threat emulation can simulate realistic attacker behaviour and allow organisations to see how their existing security controls respond.
This can reveal gaps that aren’t necessarily obvious from dashboards or configuration reviews.
For example, you may discover that:
- An attack technique isn’t being detected.
- An alert is generated but isn’t investigated quickly enough.
- An endpoint is detected but isn’t automatically contained.
- Multiple alerts exist but aren’t being connected into a wider attack story.
- Your technology works, but the processes around it need improvement.
These findings aren’t failures. They’re opportunities to improve before a genuine incident exposes the same weakness.
Your EDR should help answer three questions
Ultimately, effective endpoint security should help your team answer three fundamental questions.
What is happening?
You need sufficient visibility across endpoints to identify suspicious activity.
What does it mean?
You need the ability to investigate that activity, understand the context and determine whether it represents a genuine threat.
What do we do about it?
You need the processes and capabilities to contain and respond before the threat develops further.
If your current security strategy can’t confidently answer those questions, it may be time to look more closely at how your EDR is being used.
Don’t wait for an incident to discover the blind spot
Cybersecurity isn’t about how many security products you have.
It’s about whether those controls work together to prevent, detect and respond to an attack.
EDR can provide security teams with valuable visibility into endpoint activity, helping them investigate suspicious behaviour and respond to threats that make it past preventative controls.
But technology alone isn’t enough.
You need the right configuration, the right processes, the right expertise and, importantly, the ability to test whether your controls actually work when faced with realistic attack techniques.
Because the most dangerous threat isn’t necessarily the one your security tools detect.
It’s the one they don’t.
Is your EDR giving you the visibility you think it is?
ANSecurity helps organisations assess, optimise and test their endpoint security capabilities — from EDR implementation and health checks through to threat hunting, security validation and controlled threat emulation.
Don’t just assume your security controls are working. Test them.