EDR (endpoint detection and response) works by deploying sensors on protected endpoints to continuously collect selected behavioral telemetry, forwarding that telemetry to a centralized analytics layer, commonly cloud-hosted, that applies detection rules, behavioral analytics, machine learning and threat intelligence, and surfacing prioritized incidents in a console where analysts can investigate and respond.