
CONSULT CIRCLE | ENDPOINT SECURITY
What signature-based antivirus still catches, what it structurally cannot, and how to evaluate EDR without being sold a dashboard.
Traditional antivirus is not useless and EDR is not magic. They work differently, and the difference matters because most damaging intrusions today do not involve a file that antivirus could have recognised.
This guide sets out the actual distinction, when antivirus alone is defensible, and how to evaluate EDR products on something more substantial than a demonstration.
How they differ
| Traditional antivirus | EDR | |
|---|---|---|
| Detection approach | Signatures and heuristics matched against known malicious files | Behavioural analysis of process activity, regardless of whether a file is involved |
| Catches | Known malware with a recognisable signature | Suspicious behaviour patterns, including techniques using legitimate tools |
| Misses | Novel malware, fileless techniques, misuse of legitimate administrative tools, hands-on-keyboard intrusion | Genuinely novel techniques that resemble normal activity |
| Response | Quarantine or delete the file | Isolate the host, kill processes, roll back changes, collect forensic data |
| Visibility after an event | Limited log of detections | Timeline of what happened, in what order, and what it touched |
| Operational requirement | Largely set and forget | Requires tuning and someone to triage alerts |
Table 1 — Antivirus and EDR compared.
When is antivirus alone defensible?
Rarely in an enterprise, but the honest answer is not never.
- Small, simple estates with no sensitive data, no regulatory obligation and low exposure.
- Fully locked-down single-purpose devices with no user interaction and no general-purpose software.
- As a layer alongside EDR, rather than instead of it. Many EDR products include preventative capability.
If your organisation holds personal data, has compliance obligations, has staff who receive email, or would suffer materially from several days of disruption, antivirus alone leaves a gap that is well understood by attackers. Our guide to the Chaos malware family shows how quickly that gap is exploited.
Evaluating EDR properly
Product demonstrations are optimised. These criteria are harder to stage.
| Criterion | What to ask |
|---|---|
| Detection quality | How does it perform against independent, published testing, and against techniques rather than samples? |
| False positive rate | What does a week of alerts look like in an estate like ours? Ask for realistic volumes, not a curated demo |
| Investigation experience | Can an analyst reconstruct what happened without needing the vendor? Ask to work through a real timeline |
| Containment | Can it isolate a host, kill a process and roll back changes, and how quickly |
| Coverage | Every operating system you run, including servers, older builds and any Linux or macOS |
| Performance impact | Measured on your standard build under normal load, not on a clean test machine |
| Managed response option | Is there a service that triages alerts, and what does it cost? Frequently the deciding factor |
| Data retention | How long is telemetry kept, and is that long enough for the way intrusions are actually discovered? |
| Integration | Does it feed your SIEM and ticketing, or create another console nobody watches? |
Table 2 — EDR evaluation criteria.
Deployment considerations
- Roll out in monitor-only mode first to establish a baseline and understand your normal.
- Tune before enabling automatic containment, or the first false positive will isolate a production server.
- Confirm coverage of every endpoint. Partial deployment leaves exactly the gap an attacker needs.
- Agree an incident process before you need it, including who can authorise isolating a machine.
- Retain telemetry long enough to be useful, given that intrusions are often discovered weeks after they begin.
- Test it. Run a controlled exercise and confirm detection and response work as expected.
Where to go next
Frequently Asked Questions
What is the difference between EDR and antivirus?
Antivirus matches files against signatures of known malware. EDR analyses behaviour on the endpoint, detecting suspicious activity even when no malicious file is involved, and provides investigation and containment capability.
Do we still need antivirus if we have EDR?
Most EDR products include preventative capability, so a separate traditional antivirus product is often unnecessary. Confirm what your EDR covers rather than assuming, and avoid running two agents that conflict.
Is EDR worth the cost for a mid-sized business?
If you hold personal data, have compliance obligations, or would suffer materially from days of disruption, the relevant comparison is against the cost of an incident. Also consider managed detection and response, which supplies the response capability most mid-sized organisations lack.
What is XDR?
Extended detection and response broadens the same approach beyond endpoints to include network, email, identity and cloud telemetry, correlating across them. It is an evolution of EDR rather than a different category.
How long does EDR deployment take?
Agent deployment is usually quick. The work is in tuning, establishing what normal looks like in your environment, and agreeing the response process. Budget several weeks before enabling automatic containment.
Talk to Consult Circle
We help organisations select, deploy and tune endpoint protection, including where a managed detection and response service is the more sensible route. Book a free 30-minute call - 0203 916 5593 - info@consultcircle.com