For the complete documentation index, see /llms.txt. Markdown version of this page: /en/insights/endpoint/edr-and-antivirus-what-the-difference-is.md.
Endpoint Security ↗

EDR vs antivirus, and why you need both

Yes, you need EDR even with antivirus running. Antivirus blocks known bad files, EDR records what the attacker does next.

CrowdStrike logo and EDR vs Antivirus, FM CyberSecurity branded cover

Antivirus answers one question: was this file already known to be bad? EDR answers the question that decides an incident: what did the attacker do next?

Most intrusions no longer start with a bad file. CrowdStrike reports that 82 percent of its detections in 2025 involved no malware at all, up from 51 percent in 2020 (CrowdStrike, 2026 Global Threat Report). A file scanner has nothing to look at in those cases.

I spend most weeks in the Falcon console. Across the CrowdStrike onboardings I ran this year, the antivirus alert was the start of a trail, never the end of it. The questions that mattered came after. How did it get in, what ran from it, which account did it touch, did anything reach a second machine. Plain antivirus answered none of them.

Short version: keep antivirus, add EDR, then put someone on the signal EDR produces.

CrowdStrike logo and EDR vs Antivirus, FM CyberSecurity

What antivirus does, and where it stops

Antivirus compares files on your machines against a list of known-bad signatures. A signature is a fingerprint of malware someone has already seen and catalogued. Match the fingerprint, and the file gets blocked or quarantined. That is fast, it is cheap, and it is still worth running.

The limit sits in the word “known”. Someone has to see the threat, fingerprint it, and ship the update before your scanner can catch it. Attackers build around that window. They run inside legitimate tools like PowerShell, so no file exists to fingerprint. They use software already installed on the machine instead of dropping malware. And they sign in with stolen credentials, which looks like a normal Tuesday morning.

CrowdStrike describes 2025 intrusions as moving through authorized pathways and trusted systems, where they blended into normal activity (same report). I have watched that from the console side. The antivirus dashboard was green. The attacker was already inside, using tools the scanner had no reason to flag.

What EDR adds that antivirus cannot

EDR records. CrowdStrike defines endpoint detection and response as a tool that “continuously monitors end-user devices to detect and respond to cyber threats like ransomware and malware”, and says these tools “record the activities and events taking place on endpoints and all workloads” (CrowdStrike, What is EDR).

The recording changes what you can answer. Instead of “a file was blocked”, you get the chain. This attachment started PowerShell, PowerShell reached that address, this account then signed in to a second machine. EDR also detects on behaviour rather than signatures alone, so the pattern fires when nothing matches a fingerprint.

You get a way to act, too. From the console you can cut a machine off the network while the recording keeps running, or kill the process outright. On the Falcon platform that layer is Falcon Insight XDR, which keeps EDR at its core and adds Real Time Response for direct access to the host (CrowdStrike, Falcon Insight XDR). It runs from the same agent as the rest of CrowdStrike’s endpoint security modules.

In one composite case from this year’s onboardings, the behavioural detection fired on the lateral-movement step, well after the scanner had cleared the file that started it. That step is where the incident stopped.

Do I need EDR if I have antivirus

Yes. Prevention is never perfect, and every hour after it fails goes unrecorded unless something is recording.

CrowdStrike puts the layers in order: “If the NGAV is a first line of defense, then the EDR is a safety net which catches any threats that may slip past.” The same page warns that “without proper threat detection tooling in place, silent failures allow attackers to move around the environment freely for days, weeks or even months” (CrowdStrike, EDR vs NGAV).

The clock says the same thing. CrowdStrike measured average eCrime breakout time, meaning the gap between first access and movement onto a second system, at 29 minutes in 2025, with the fastest observed at 27 seconds (2026 Global Threat Report). eCrime is CrowdStrike’s label for financially motivated attackers. Antivirus on its own means nobody sees minute 30.

One practical note before you buy anything. Check what you already own. In several onboardings I have found EDR sitting unenabled inside an endpoint suite the customer was already paying for. That is the cheapest EDR you will ever deploy.

Where NGAV fits, and what endpoint security covers now

NGAV is the prevention layer after signatures. CrowdStrike defines next-generation antivirus as a combination of “artificial intelligence, behavioral detection, machine learning algorithms, and exploit mitigation, so known and unknown threats can be anticipated and immediately prevented” (CrowdStrike, What is NGAV).

So endpoint security today is three jobs rather than three purchases. Signature matching handles the known files. NGAV widens what counts as recognisable. EDR records the rest and gives you a response option. On the Falcon platform all three run through one lightweight agent, which matters more than it sounds. Three separate agents on the same PC is how endpoint projects quietly die.

EDR produces signal, someone has to read it at 02:00

Tooling on its own does not close the gap. Signal needs a person reading it the minute it fires, and few Norwegian SMBs staff a night shift.

FM CyberSecurity delivers managed detection and response through CrowdStrike Falcon Complete Next-Gen MDR. CrowdStrike’s own analysts staff that 24/7 bridge and run the detection, investigation and remediation. CrowdStrike describes the service as acting “on your behalf”, including “isolating systems, removing persistence, and restoring you to a known-good state” (CrowdStrike, Falcon Complete). FM CyberSecurity handles onboarding, the tuning that makes alerts match your stack, and local escalation in Norwegian when a decision has to come from you. We do not staff that bridge ourselves. CrowdStrike does.

Three questions to answer this quarter

Would anyone see the second step of an attack on your machines today, the part after the file?

Does your endpoint tool keep a searchable record of process starts, sign-ins and network connections, and how far back does it go?

When an alert fires at 02:00 on a Saturday, whose phone rings?

If the answers are no, no, and nobody’s, the gap is recording and response, not prevention.

If this resonates

← Back to all insights
Questions or inquiry? hello@fmcybersecurity.com Contact us →