EDR vs XDR vs MDR: The Real Difference | Tech Fortress
Tech Fortress Book a Call
← All articles
Security 22 July 2026 · 7 min read

EDR, XDR, MDR and plain antivirus: what the acronyms actually mean

Four acronyms, sold by everyone, explained by almost nobody. Here is the version we give clients before they spend money.

Security dashboard showing a detected attack chain across endpoints

Security vendors have a habit of renaming things faster than anyone can learn them. If you are trying to work out whether you need EDR or XDR or MDR, and whether the antivirus you already pay for is enough, the honest answer is that these solve different problems and the names describe roughly what they do.

Antivirus: does this file match something known to be bad?

Traditional antivirus works from signatures. It has a list of known-bad files, it checks what lands on your machine against that list, and it blocks matches. This works well for known threats, which is not a small category.

The weakness is obvious once you say it out loud. If a threat is new, or has been altered slightly to change its signature, or doesn't involve a file at all because it runs entirely in memory, there is nothing to match. Attackers have known this for years and build accordingly.

EDR: is this behaviour consistent with an attack?

Endpoint Detection and Response changes the question. Instead of asking whether a file is on a list, it continuously records what is actually happening on the device — processes launching, files being modified, network connections opening — and looks for patterns that indicate an attack in progress.

That is why EDR catches things antivirus misses. Mass file encryption looks like ransomware regardless of which variant is doing it. A legitimate Windows tool being used to move laterally across the network is suspicious even though the tool itself is signed and trusted.

The response half matters as much as the detection. EDR can isolate an affected machine from the network automatically, kill the process, and roll changes back, then hand your team a full forensic timeline of what happened.

XDR: what if we looked at more than the endpoint?

Extended Detection and Response takes the same idea and widens the lens. Attacks rarely stay in one place. A phishing email leads to stolen credentials, which are used to sign in from an unfamiliar location, which leads to data being pulled out of a cloud file share.

Looked at separately, each of those events is a shrug. Correlated together, they are obviously one attack.

XDR pulls telemetry from endpoints, email, identity and cloud applications into one place and correlates it, so you see the attack chain rather than three unrelated alerts in three consoles.

MDR: who is actually watching all this?

Here is where most businesses quietly come unstuck. EDR and XDR are technologies. They generate alerts. Alerts need someone to triage, investigate and act on them, at 3am on a Sunday as much as at 11am on a Tuesday.

Managed Detection and Response is the people layer. A Security Operations Centre monitors your environment around the clock, investigates what the tooling surfaces, and responds on your behalf. You are buying analysts and process, not another dashboard.

So which do you need?

If you have no in-house security team, MDR built on EDR or XDR is usually the right shape. You get the detection technology and the humans to act on it, without hiring a team you can't realistically staff around the clock.

If you do have a security function, EDR or XDR alone may be enough, and MDR becomes a question of whether you want out-of-hours coverage. What almost never works is buying the tooling, switching it on, and assuming someone will notice the alerts. That is how breaches get discovered weeks late.

Want a straight answer for your environment?

Tell us what you're running and we'll tell you what's worth adding, and what isn't.

Book a Call

Related services

EDR XDR MDR Endpoint Security