EDR

Endpoint detection and response gives you telemetry from the machine, a way to investigate it and a remote hand to act.

That last part is the underrated one: being able to isolate a machine from a console, at three in the morning, without anybody attending, changes what a response looks like. Its coverage depends entirely on the agent being installed and running, which is less universal than dashboards suggest.

Checked against the primary source.

More on Malware & ransomware