Antivirus blocks files that match known malware signatures. Endpoint detection and response watches behavior — processes, scripts, credential use, lateral movement — and can stop an attack that uses no malware at all. EDR also records what happened so the incident can be investigated and closed.