antivirus software is suitable if you have a limited number of devices that need protection and a small budget to protect them. 

On the other end, endpoint detection and response (EDR) may be your best option for securing numerous devices with a larger budget. 

EDR is also preferable if you need to monitor your endpoint security from a higher vantage point. 

Endpoint protection platforms (EPPs) are somewhat in the middle in terms of capabilities and scale and are often combined with EDR to create the perfect endpoint security cocktail.

Typical antivirus software scans a user’s computer for malware such as worms, trojans, adware, ransomware, and others. It accomplishes this by using three types of detection:

  • Signature comparison, which monitors a device for evidence of known threats and blocks them from taking further action
  • Heuristic analysis, which examines new programs for suspicious source code or behavior by comparing it to viruses that are already known from a heuristic database
  • Integrity checking, which inspects system files for evidence of corruption