2022-04-25T21:05:00Z
  • 8
  • 287

What to choose: an endpoint antivirus, an EDR solution or both?

Hi community professionals,

I am looking for your advice on whether it makes sense to use both an endpoint antivirus and an EDR solution simultaneously? What are the pros and cons of using each one or both simultaneously?

*In terms of products, I've been looking at CrowdStrike Falcon, Microsoft Defender for Endpoint, and ESET Endpoint Security.

Thanks for the help!

9
PeerSpot user
9 Answers
ChandanMunshi - PeerSpot reviewer
Chief Technical Officer at Provision Technologies LLP
Real User
Top 5
2022-04-27T13:18:43Z
Apr 27, 2022

EDR (or XDR) is the new coinage for endpoint security technology. 


Although those good old days antivirus software were doing the same thing, signature-based detection and response against that defection. But the modern threat vector has changed a lot and everything is quite complicated these days. So, the protection mechanism also. 


Almost all leading cyber security software vendors have come up with newer versions of endpoint protection, sometimes with AI as well. 


So, if there is an option, it is always better to go with EDR of anything "*DR". But keep in mind that cyber security has to be implemented in every layer of ISO. 

Search for a product comparison in EPP (Endpoint Protection for Business)
MK
Deputy Technical Manager (SOC Operations) at a tech services company with 1,001-5,000 employees
Real User
Top 5
2022-04-28T05:31:48Z
Apr 28, 2022

Next-Generation Antivirus (NGAV) uses a combination of artificial intelligence, behavioral detection, machine learning algorithms, and exploit mitigation, so known and unknown threats can be anticipated and immediately prevented.


Endpoint detection and response (EDR) is a solution that combines data collection, data analysis, forensics, and threat hunting, with the end goal of finding and blocking any potential security breaches in due time.


For the current attack landscape, you need both NGAV + EDR in a single product for better protection & remediation.


but the current trend is


XDR (Extended Detection and Response) collects and automatically correlates data across multiple security layers – email, endpoint, server, cloud workload, and network. This allows faster detection of threats and improved investigation and response times through security analysis.

NavcharanSingh - PeerSpot reviewer
Senior Seo Executive at Real Time Data Services
Real User
Top 20
2022-09-15T12:44:58Z
Sep 15, 2022

The benefits of EDR over an antivirus solution are:


1. Behavior-based detection blocks advanced threats
2. Forensic analysis capabilities help with detailed investigations
3. Sandboxing capabilities safeguard your network environment
4. Automated remediation and instant threat removal
5. Threat pattern identification for easy detection in the future
6. Centralized security and enhanced endpoint visibility

Managed EDR exceeds traditional antivirus in multiple ways. It can detect the unknown and emerging threats missed by AV solutions. With real-time responses and extensive forensic analysis capabilities, managed EDR is, without a doubt, the superior endpoint security solution.

Read more: Managed EDR Over Antivirus

Real User
Top 20
2022-04-27T13:30:38Z
Apr 27, 2022

Antivirus lifeline (as a separate tool) is limited now. 


All the products are now combining EPP and EDR into a single solution. I would rather prefer to go with XDR solutions which will help to detect and as well as remove the existing one from the system.

AS
Principal Consultant at 1net
User
2022-04-27T01:35:57Z
Apr 27, 2022

The “Antivirus” protection technology is replaced by EDR which does include a modern version of “antivirus” along with other ways of device protection. 


Multiple vendors provide EDR: Trend Micro, Cisco, etc.


The more current technology is XDR.

2022-09-19T06:01:33Z
Sep 19, 2022

I agree with most of the responses. SentinelOne, CrowdStrike, and Carbon Black are solutions that most enterprises use but if you are looking at a comparison/necessity of an endpoint solution vis-à-vis an EDR/XDR solution I believe the endpoint solution is as good as a dead investment. The current EDR / XDR is capable to replace the av. Keeping both solutions together will lead to issues with end-user performance and productivity loss. Obviously, it is your choice to judge security and productivity but keeping both solutions in an extremely critical environment can help you someday as well in a zero-day sort of attack which the AV OEM detects, and all these sophisticated solutions won't. So my take is you are the best judge of your environment. It's your choice.

Learn what your peers think about Cisco Secure Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: January 2023.
670,400 professionals have used our research since 2012.
MB
Client Solution Services Manager at 2TS
User
2022-09-16T11:53:23Z
Sep 16, 2022

I can recommend Carbon Black, an award-winning next-gen anti-virus (NGAV) and endpoint detection and response (EDR) security solution. The CB Predictive Security Cloud platform combines multiple high-powered endpoint security modules into a single, cloud-based security platform.

JB
Technical Director - RPA at Diversified Robotic
User
2022-07-31T23:57:25Z
Jul 31, 2022

Most EDR solutions are EDR + EPP (Endpoint Protection, formerly called antivirus).


My opinion is: never run 2 different vendors in real-time (antivirus and/or endpoint security solutions) on the same machine, as either conflicts will most likely arise or CPU usage will go high.

CP
Partner Account Manager 🔆 at SEC DataCom A/S
Reseller
2022-04-26T07:14:32Z
Apr 26, 2022

If you look at a product like SentinelOne, it is both EPP and EDR (and much more...). In that case you only need this single product.

You could take a look at this short explanaition on YouTube: EDR? EPP? Both?!? See how to explain SentinelOne in just 2 minutes

Related Questions
PJ
CIO & Information manager at a leisure / travel company with 501-1,000 employees
Jan 24, 2023
Hi peers,   I work as the CIO & Information Manager in the gaming and gambling industry. The company has 650 employees and >30.000 customers. I'm not able to find a study where Darktrace is compared against Crowdstrike Falcon (or other solutions for endpoint security, e.g. Sentinel One).  Can anyone help and share their insights?  Thanks, Regards from the Netherlands
2 out of 3 answers
HF
Consultant at a computer software company with 51-200 employees
Mar 31, 2022
Hi @reviewer1799568, Most of these comparisons are opinions and some tests are done in specific conditions that might not suit or reflect your organization's needs and roadmap. Ultimately, the cost of a mistake is a data breach and not just an audit finding or operational discomfort. I mention this because there are no viable shortcuts. I suggest you test the solutions thoroughly in your own environment to see what works for you. The gaming floor is hopefully "air-gapped" and the solution should respect that segregation and still provide great security and visibility. One of the challenges is security updates. For such an environment you would need comprehensive AI and machine learning. I suggest you look at the difference between IOC and IOA. IOA vs IOC: Defining & Understanding The Differences | CrowdStrike. (Please also check other sources). Good luck and stay safe!  
CP
Partner Account Manager 🔆 at SEC DataCom A/S
Apr 26, 2022
Hi. I am told that Darktrace is a complimentary product that doesn't do any endpoint protection.
EB
Director of Community at PeerSpot (formerly IT Central Station)
Feb 23, 2022
Hi, What are the top trends that you predict about the Endpoint Protection Platform (EPP) solutions for this year?
2 out of 3 answers
BH
IT Security Coordinator at a healthcare company with 10,001+ employees
Feb 22, 2022
More regular a/v collapsed into endpoint protection, move from console to cloud, maybe even more consolidation btwn vendors.
SG
Owner at a security firm with 1-10 employees
Feb 22, 2022
1) Crowdstrike, 2) SentinelOne, 3) Carbon Black
Related Articles
Ariel Lindenfeld - PeerSpot reviewer
Director of Community at PeerSpot
Aug 21, 2022
We’re launching an annual User’s Choice Award to showcase the most popular B2B enterprise technology products and we want your vote! If there’s a technology solution that’s really impressed you, here’s an opportunity to recognize that. It’s easy: go to the PeerSpot voting site, complete the brief voter registration form, review the list of nominees and vote. Get your colleagues to vote, too! ...
SB
Regional Manager/ Service Delivery Manager at ASPL INFO Services
Aug 9, 2022
If you’re weighing your options for endpoint security solutions, there are many options out there. However, solutions vary greatly in terms of how effectively they can protect your network. I want to help you make the best decision possible, so here are some questions to ask before buying an endpoint security solution, and why they are important. 1) Does the solution employ Foundational Tech...
EB
Director of Community at PeerSpot (formerly IT Central Station)
Feb 4, 2022
Hi dear community members, This is our latest community digest. It helps you catch up on recent contributions by community members. Comment below with your feedback and suggestions! Trending What are the Top 5 cybersecurity trends in 2022? What are the main benefits of modern IT Asset Discovery tools? Tip Post an educational article from your Home feed and receive 20 point...
See 1 comment
reviewer1577907 - PeerSpot reviewer
Manager at PeerSpot
Feb 4, 2022
Thank you, these community Spotlights are very handy!
EB
Director of Community at PeerSpot (formerly IT Central Station)
Nov 19, 2021
Hi community members, Spotlight #2 is our fresh bi-weekly community digest for you. It covers cybersecurity, IT and DevOps topics. Check it out and comment below with your feedback! Trending What are the pros and cons of internal SOC vs SOC-as-a-Service? Join The Moderator Team at IT Central Station (soon to be PeerSpot)! Questions Share your experience with other peers by ans...
Related Articles
Ariel Lindenfeld - PeerSpot reviewer
Director of Community at PeerSpot
Aug 21, 2022
PeerSpot User's Choice Award 2022
We’re launching an annual User’s Choice Award to showcase the most popular B2B enterprise technol...
SB
Regional Manager/ Service Delivery Manager at ASPL INFO Services
Aug 9, 2022
8 Questions to Ask While Selecting an Endpoint Security Solution for Your Business
If you’re weighing your options for endpoint security solutions, there are many options out there...
Download Free Report
Download our free Cisco Secure Endpoint Report and get advice and tips from experienced pros sharing their opinions. Updated: January 2023.
DOWNLOAD NOW
670,400 professionals have used our research since 2012.