All Posts

EDR vs Antivirus: Why Signature Scanning Stopped Working

Most small businesses have antivirus and assume the endpoint is handled. It is a reasonable assumption and it has been wrong for about a decade.

How does traditional antivirus work?

Signature-based antivirus keeps a list of known-bad files. When a file arrives, it is compared against that list. Match found, file blocked. No match, file allowed.

The flaw is structural rather than a matter of quality. A signature can only exist for malware somebody has already caught, analysed and catalogued. Something written last week has no signature anywhere, so a signature scanner will wave it through no matter how good it is at its job.

Attackers know this. Modern ransomware kits generate a fresh variant per target for exactly this reason. The file that hits your network may be the only copy of it that has ever existed.

What does EDR do differently?

Endpoint detection and response ignores what a file is and watches what it does. It builds a picture of normal behaviour on the machine and flags departures from it:

  • A process spawning other processes in a pattern that does not match how that program normally behaves
  • Something reading a browser's stored credentials
  • A program suddenly opening and rewriting hundreds of files in sequence — the signature of encryption in progress
  • Legitimate administrative tools being driven in ways an administrator never would
  • An account signing in from two places far enough apart that nobody could have travelled between them

None of that requires knowing what the malware is called. It requires knowing what the machine normally does.

What happens when EDR detects something?

The important part is not the alert, it is the response. Good EDR can isolate the machine from the network automatically while a human investigates — the infected laptop can still talk to the security tooling and nothing else.

That containment window is the whole game. Ransomware is only catastrophic when it reaches the file server and the backups. Contained on one laptop, it is an afternoon of work. Left to spread for four hours overnight, it is the business.

Many EDR tools can also roll back the changes a process made, which turns some incidents into a non-event.

Do I still need antivirus if I have EDR?

In practice you get both. Modern EDR products include signature scanning as one input among several — there is no reason to stop catching known threats cheaply just because you can now catch unknown ones. The distinction is not “either/or,” it is whether behaviour is being watched in addition.

Is Microsoft Defender enough?

Defender has become genuinely good, and if the alternative is nothing, it is a real improvement. Two caveats worth being honest about.

First, the behavioural and response capabilities sit in the higher Microsoft 365 tiers. The Defender that ships with Windows is not the same product as Defender for Endpoint, and people routinely conflate them.

Second, and this is the part that catches small businesses: a tool that detects something and nobody reads the alert has not protected you. The gap in most small offices is not the software. It is that no human is watching the console, and the isolation that should have happened at 2am happens at 9:15 when someone opens their laptop.

What about the machine that cannot be updated?

Almost every office has one — the workstation running imaging software, a legacy line-of-business application, or a piece of equipment whose vendor certified one specific operating system version and never revisited it.

You cannot patch it, so the honest answer is compensating controls: isolate it on its own network segment, restrict what it is allowed to talk to, and put EDR on it so its behaviour is watched even though its vulnerabilities cannot be closed. Not as good as patching. Considerably better than hoping.

Where this leaves you

If your endpoint protection is a signature scanner and nobody is watching it, you are protected against threats that were catalogued before the attack was written. That is a meaningful category, and it is not the category that closes businesses.

We include EDR and identity threat detection in Endpoint Protection at $32 per device per month, with automatic isolation and a phone call rather than a ticket.

Want this handled for you?

Fix It Mobile manages endpoints, patching, and threat detection for South Florida businesses — and sells prepaid support hours when you just need a hand.