CyberGlossary

Defense & Operations

EPP (Endpoint Protection Platform)

Also known as: Endpoint Protection Platform, Next-Gen Antivirus, NGAV

Definition

A preventive endpoint security suite that combines antivirus, anti-malware, host firewall and exploit protection to block threats before they execute on a device.

An Endpoint Protection Platform (EPP) is the preventive layer of endpoint defense, evolved from traditional antivirus into a multi-engine suite running on Windows, macOS, Linux and mobile devices. Typical capabilities include signature and ML-based malware detection, behavior-based blocking, exploit mitigation, application control, device control (USB), host-based firewall and disk encryption management. EPP focuses on stopping known and commodity threats at execution time, while EDR layers on continuous recording and post-compromise investigation; modern vendors combine EPP and EDR in a single agent. EPP is essential for meeting regulatory and insurance baseline controls.

Examples

  • Microsoft Defender Antivirus blocking a malicious .docm macro using ML-based behavior monitoring.
  • An EPP enforcing a USB device-control policy that prevents users from mounting unknown removable storage.

Related terms