Managed endpoint detection and response — behavioural threat detection backed by human analysis and containment, included on the Standard and Enterprise plans.
Why antivirus stopped being sufficient
For roughly two decades, endpoint protection worked by recognising files. A researcher found a piece of malware, extracted a signature, and every machine running the product learned to block it. That model works precisely as well as its list is current, and it fails completely against three things that now dominate: malware nobody has catalogued yet, attacks that use no malicious file at all, and attackers who log in with valid credentials and use the tools already installed on your machines.
The last of those is the important one. An attacker who has your password does not need malware. They need PowerShell, which is already there, and the same remote access tools your IT provider uses.
What EDR does instead
EDR watches what happens on the endpoint rather than what arrives on it. Process creation chains, credential access, network connections, file operations, registry changes — recorded continuously and evaluated against patterns of attacker behaviour.
That is why it catches things a signature never will: an ordinary process suddenly enumerating credentials, encryption beginning simultaneously across a mapped drive, a legitimate administration tool being run at 2am from an account that has never used it.
The word that matters is “managed”
Detection technology is broadly commoditised. Every serious EDR product will spot the obvious cases. The variable that actually determines outcomes for a business of 20 to 200 staff is whether anybody looks at the detection.
An unmanaged EDR deployment generates alerts into a console that nobody has opened since the week it was installed. That is not a security control, it is a subscription.
We run Huntress specifically because it includes a security operations team reviewing detections around the clock. For a business of your size, a competent human reviewing a moderate sensor beats an excellent sensor reporting to an empty room, every time.
Containment without a site visit
When a machine is confirmed compromised, the priority is stopping lateral movement. EDR allows an endpoint to be network-isolated remotely — cut off from everything except the management channel — within minutes, wherever it is, including a laptop on a home connection in another state.
That single capability is frequently the difference between one rebuilt machine and an environment-wide incident.
What it costs
Nothing additional. EDR is included in the Standard and Enterprise plans at no per-device charge on top of the plan rate. It is not available on Basic, which covers monitoring and reporting only.
That is worth stating plainly because EDR is commonly sold as a per-endpoint add-on. Bundling it reflects a straightforward view: a managed fleet without endpoint detection is not one we want to be responsible for.