XDR
Extended Detection and Response (XDR) connects security signals from endpoints, identities, email, cloud and network in one platform.
Extended Detection and Response (XDR) connects signals from endpoints, identities, email, cloud and network in one platform. The goal is to view an attack across all areas as one cohesive incident.
How it works
XDR usually builds on an EDR solution, extending it with additional data sources. The platform automatically links related alerts into a single incident. Response actions like isolating a device or blocking an account can be triggered directly from the same interface.
For example, a phishing email leads to a login with a stolen password. Shortly afterwards, a suspicious script runs on a laptop. XDR shows the email, login and process as a single attack chain. The SOC blocks the account and isolates the laptop in one step.
What to look out for
- Vendor lock-in: Many XDR solutions work best with products from the same vendor.
- Open integration: Check if firewalls and applications from other vendors can be integrated.
- XDR vs. SIEM: An XDR does not always replace a SIEM. Long-term storage and custom rules are often limited.
- Human operation: XDR still needs people to assess incidents around the clock.
Classification
XDR is more of a product category than a fixed standard. Its capabilities differ greatly between providers. The key factor is which sources the platform correlates.
Questions to ask a provider
Ask which data sources the platform correlates natively and which are only ingested as raw data. Ask for a demonstration of how an incident is displayed across identity, email, and endpoint. Clarify how long data is retained and what longer retention costs. Also check whether you can write your own detection rules. Without this capability, you remain dependent on the vendor's rules.
How we implement it
We operate Managed XDR on top of your existing platform, for example Microsoft Defender or CrowdStrike. We supplement signals not covered by XDR using our SIEM and NDR capabilities.