Endpoint detection and response (**EDR**) is an application that *monitors an endpoint for malicious activity*. EDR tools are installed on endpoints. An endpoint is any device connected on a network. Examples include end-user devices, like computers, phones, tablets, and more. EDR tools *monitor, record, and analyse endpoint system activity to identify, alert, and respond to suspicious activity*. Unlike [[Intrusion Detection System|IDS]] or [[Intrusion Prevention System|IPS]] tools, EDRs collect endpoint activity data and perform behavioural analysis to identify threat patterns happening on an endpoint. Behavioural analysis *uses the power of machine learning and artificial intelligence* to analyse system behaviour to identify malicious or unusual activity. EDR tools also use automation to stop attacks without the manual intervention of security professionals. For example, if an EDR detects an unusual process starting up on a user’s workstation that normally is not used, it can automatically block the process from running.