Classic antivirus mainly "sees" known malicious files. EDR (Endpoint Detection and Response) watches how a device behaves: for example, when a program starts encrypting files en masse or runs an unusual script, EDR stops the activity and alerts the administrator.
EDR is usually managed from a central console, where the status of every computer, alerts and incidents are visible in one place.
At night EDR notices a program mass-encrypting files on a laptop and automatically isolates the device from the network.