← All articles

Endpoint detection versus antivirus: what changed

·2 min read·By Adrian

Also available in ES, RO

Antivirus works by comparing files against a list of known-bad signatures. That model was sound when malware was a file you downloaded. Increasingly, it is not.

What signature matching misses

  • Living off the land. Attackers use tools already on the machine — the scripting engine, the remote management utility, the archiving tool. Every file is legitimate and correctly signed.
  • Fileless execution. The payload never touches disk, running entirely in memory.
  • Stolen credentials. A valid login from an unexpected place involves no malware at all.
  • Novel samples. Ransomware is frequently recompiled per victim, so the signature does not exist yet.

None of these produce a file on a list.

What detection and response adds

Endpoint detection watches behaviour rather than files, and keeps a record of it:

  • The chain of what launched what — a document spawning a script spawning a network connection is suspicious regardless of the files involved
  • Encryption patterns across many files in a short window
  • Credential access attempts against the operating system
  • The ability to isolate a machine from the network remotely, immediately
  • A timeline afterwards, so you can answer what was reached and when

That last capability is the one people underestimate. After an incident, the difference between "we contained it" and "we cannot tell what was taken" is whether anything was recording.

The part vendors omit

Detection generates alerts, and alerts need a human. A tool that emails a warning at two in the morning to an unmonitored mailbox has not improved your position.

Either someone watches the console during working hours and accepts the limits of that, or you buy a managed service where somebody watches it continuously. Both are defensible. Buying the tool and watching nothing is not.

A reasonable position for a smaller company

  • Detection and response on every endpoint and server
  • Alerts routed somewhere with a named owner
  • Automatic isolation enabled for high-confidence detections, so containment does not wait for a human
  • Thirty days of telemetry retained, minimum

We deploy and monitor this as part of cybersecurity.

← Blog