Five terms vendors use interchangeably. They're not the same. Here's the difference - with real attack examples - and the exact products from CrowdStrike, Fortinet, Sophos, Palo Alto Networks and Trellix that deliver each one.
Stops known burglars on a list. Useless against the new one.
Lock + alarm + window grilles + USB-control. Hardens every device.
Records every action inside. Spots strange behaviour. Lets you replay.
Connects CCTV from endpoint, network, email, cloud - one storyline.
Real humans watching the cameras at 2 AM Saturday. They call you.
Traditional antivirus has one job: take the file, generate its hash/signature, and check it against a database of known malware. If it matches - block it. If not - let it run.
What it CAN'T do:
Accountant downloaded an "invoice.pdf.exe" from a phishing email. The endpoint had only basic free antivirus. The malware was a 4-day-old LockBit 3.0 variant - no signature in the AV database yet. Result: 2 servers + 18 desktops encrypted overnight. AV scanned the file, said "clean", let it run. EDR (which doesn't care about signatures) would have flagged the PowerShell + mass file-rename behaviour in seconds.





Modern Endpoint Protection Platform (EPP) is what people mean when they say "antivirus" today. One agent on every laptop, desktop and server doing many jobs:
A finance executive plugged in a USB stick from a vendor at a trade show. The stick had a USB-loaded keylogger. Their endpoint security (Sophos Intercept X) was set to block unknown USB devices by default - the stick was greylisted, the IT helpdesk was alerted, and the exec called for approval before plugging in. Zero infection. Pure antivirus would never have stopped the USB at all - it would only have scanned files after they ran.





EPP prevents what it knows. EDR watches for what slips through - by recording behaviour: what process started what, who it called, what file it touched, which IP it talked to.
A salesperson opened a Word document attached to a "purchase order" email. The macro silently launched PowerShell, downloaded a Cobalt Strike beacon, and attempted to dump credentials with Mimikatz. AV saw a normal Word.exe - nothing to block. CrowdStrike Falcon Insight (EDR) flagged the WINWORD.EXE → POWERSHELL.EXE → unusual outbound chain in 4 seconds, killed the process tree, isolated the laptop, and pulled a full timeline. The attacker never got to lateral movement. Without EDR, this would have been a 30-day silent breach ending in ransomware.





EDR sees only the laptop. XDR pulls in signals from every other security tool you own - firewall, email, Microsoft 365, AWS, identity provider, IoT - and stitches them into one attack timeline.
A senior analyst's Microsoft 365 password was phished from a personal device at home. EDR saw nothing - no file ran on the work laptop. Palo Alto Cortex XDR correlated three weak signals: (1) login from a new ASN in Vietnam, (2) impossible-travel from Hyderabad 30 min earlier, (3) sudden mailbox-rule creation forwarding finance emails outside. XDR auto-disabled the account and locked the session within 6 minutes. Standalone EDR or AV would have missed every single one of those signals - none happened on the endpoint.





EDR/XDR generates alerts. Someone still has to look at them, decide if they're real, and act fast enough to stop the attack. MDR is a service: the vendor's (or our) SOC analysts watch your environment 24/7/365 and act on your behalf.
Friday 23:42. An admin's stolen RDP credentials were used to log in over a forgotten port-forward. The customer had Sophos Intercept X EDR deployed but no in-house security team. The EDR alert sat unread. Their Sophos MDR SOC analyst saw it, called the IT manager on his mobile at 23:48, isolated the affected server, killed the attacker's session, blocked the source IP at the FortiGate via API, and sent a 1-page incident report by 02:30. Total damage: zero. Time to detection without MDR: typically 30+ days.





SmartSoft also delivers MDR on top of CrowdStrike, Sophos and Fortinet - so you get one local point of contact instead of an offshore vendor SOC.
If you only print one slide for the management meeting, print this one.
| Capability | Antivirus | Endpoint Security | EDR | XDR | MDR |
|---|---|---|---|---|---|
| Stops known malware (signature) | Yes | Yes | Yes | Yes | Yes |
| Stops unknown / new malware (behaviour) | No | Yes | Yes | Yes | Yes |
| Catches file-less / "living-off-the-land" attacks | No | Partial | Yes | Yes | Yes |
| Records every process for forensic replay | No | No | Yes | Yes | Yes |
| One-click device isolation | No | Limited | Yes | Yes | Yes |
| Correlates with firewall, email, cloud, identity | No | No | No | Yes | Yes |
| Threat hunting on historical data | No | No | Yes | Yes | Yes |
| 24/7 human analysts watching for you | No | No | No | No | Yes |
| Active response on your behalf (kill, isolate, block) | No | No | Manual | Auto-playbook | Yes |
| Written response SLA / breach warranty | No | No | No | No | Yes (15-min) |
| Skill required from your IT team | Low | Low | High | Very High | None - outsourced |
Each leads in a different niche. We help you pick the one that actually matches your business - not the loudest sales pitch.





Honest answers to the questions every IT manager asks us.
Book a free 30-minute audit. We map your current stack against the 5 layers and tell you which vendor & tier actually fits your business and budget. Written report, no sales pitch.