🔴 Under active attack? Get connected to an incident response team now — Get Emergency Help →
EDR isn't a silver bullet: the ransomware detection gaps it leaves open
Defense & Hardening

EDR isn't a silver bullet: the ransomware detection gaps it leaves open

ERD Research TeamJul 2, 20266 min read

Key takeaways

  • EDR is necessary but not sufficient — living-off-the-land tradecraft and unmanaged hosts routinely slip past it.
  • The biggest gap is coverage: the servers, appliances, and OT devices where EDR often can't be installed are exactly where attacks land.
  • Pair EDR with identity, network, and egress telemetry so an attack that evades the endpoint is still caught somewhere.

What EDR does well — and where it stops

Endpoint detection and response is one of the most valuable controls you can deploy: it catches malware, flags suspicious process behavior, and gives responders the telemetry to reconstruct an intrusion. But it is frequently sold as a complete answer, and attackers plan around it. The gap isn't that EDR is bad; it's that a defense resting entirely on one layer has predictable seams.

Gap one: living off the land

Modern intrusions increasingly avoid malware entirely, using tools already present and trusted on the system — PowerShell, PsExec, RDP, legitimate remote-management software. To an endpoint agent, an admin using PowerShell to reach another machine looks a lot like an attacker using PowerShell to do the same thing. Behavioral detection helps, but this tradecraft is specifically designed to live in the gray zone where blocking generates too many false positives.

Gap two: the machines EDR never reaches

The more consequential gap is coverage. EDR often can't be installed on network appliances, hypervisors, storage arrays, legacy servers, or OT devices — and those are exactly the systems attackers target, because encrypting a hypervisor takes down every VM on it at once. An attacker who reaches an unmonitored host has effectively stepped out of your field of view. Knowing which of your systems EDR does not cover is as important as deploying it.

Defense in depth, not defense in one place

The fix isn't a better endpoint agent; it's layered telemetry so an attack that evades one control trips another. Identity monitoring catches the anomalous admin login, network monitoring catches the lateral movement across segments, and egress monitoring catches the exfiltration — none of which depend on an agent being present on the compromised host. EDR should be one strong signal among several, not the only place you're watching.

We respect your privacy

We use analytics cookies to understand how visitors use this site and improve our defense resources. No advertising or cross-site tracking. Privacy Policy