← Managed SOCXDR

Managed XDR

ELASTIC SECURITY · MICROSOFT DEFENDER XDR · CROWDSTRIKE FALCON

Managed XDR is our correlation scope: endpoint, identity, cloud, email and network in one data model, from a single platform or cross-vendor. Examples are Elastic Security, Microsoft Defender XDR or CrowdStrike Falcon.

What sets this service apart: a case is built across domain boundaries, with one timeline and one response path. Attacks that look like three harmless alerts in separate tools become visible as one chain.

Typical detections

  • Attack paths across domain boundaries
  • Phishing to token theft to endpoint execution as one chain
  • Cloud persistence after identity compromise
  • Mailbox rules and consent grants correlated with endpoint activity
  • BEC chains across mail, identity and cloud
  • Multi-stage campaigns spanning days or weeks

Response actions within mandate

  • Coordinated response in one playbook: session revoke, host isolation, mail purge and blocklisting in a single step
  • One case, one timeline, one mandate check across all affected domains
  • Example mandate: automated combined response on critical verdicts for standard assets, approval for tier-0

Limits of this service

  • Detection depth depends on the integration depth of each individual source
  • Compliance retention and custom parsing usually run through Managed SIEM
  • Without network onboarding there is no visibility into agentless zones, that is Managed NDR

SLAs

Minutes
Cross-domain case escalation
minutes
Automated containment (pre-authorised)
< 60 min (24/7)
Critical incident response time (contractual)

Included

  • Cross-domain correlation and case building across endpoint, identity, cloud, email and network
  • Cross-domain response playbooks with one shared mandate check
  • Attack path review and coverage reconciliation per domain

Not included

  • Platform and agent licences (yours, or passed through at cost)
  • Anti-ransomware (e.g. Halcyon) as a separate add-on module
  • Eradication and recovery inside your systems, executed by your IT with our coordination
  • Use case/playbook development and log source integration, those come with a Managed SIEM or Managed NDR scope

Process

  1. Assess

    Domain inventory across endpoint, identity, cloud, email and network, integration paths and API availability.

  2. Integrate

    Connect all signal sources into a normalised schema, build and test cross-domain correlation cases.

  3. Automate

    Combined response playbooks across several domains, pre-authorised in the mandate matrix.

Deliverables

  • Cross-domain coverage matrix per connected domain
  • Attack path review with prioritised hardening recommendations
  • Case timelines across domain boundaries, documented per incident

FAQ

Single vendor or best of breed?

Both work. Single-vendor XDR integrates faster, best of breed gives more detection depth. We base our recommendation on your existing landscape.

Do we still need a SIEM alongside it?

For detection and response often not. For compliance retention, custom parsing of your own applications and long-term forensic search, many customers add Managed SIEM or a data lake.

Included in every ANOMAL managed service

  • 24/7 threat monitoring: every alert is picked up, enriched with context and documented in the ticket system
  • Incident triage on every severity from low to critical, classified as false positive, benign true positive or true positive
  • Further analysis on every suspected true positive, including log, telemetry and asset context
  • Incident response along NIST: containment and first response within your mandate. A full IR engagement for a major incident is billed separately.
  • SOC platform operations: backend, updates and health monitoring of the SOC stack
  • Automated incident response: SOAR enrichment, automated queries, pre-authorised response actions per mandate
  • Threat hunting and threat intelligence (e.g. MISP plus external feeds) feeding back into detections
  • Effectiveness testing once a year, e.g. together with an external purple team
  • Service management: monthly service efficiency report, quarterly optimisation meeting, live view in ANOVIEW
  • Ongoing operations: continuous tuning, detection maintenance and quarterly service optimisation

Scope, service level (e.g. business hours for low to high, 24/7 for critical) and volumes differ per environment. That is why there is no list price: every customer gets a dedicated quote with defined scope, service level and response mandate. With Managed SIEM and Managed NDR the scope additionally covers use case and playbook development as well as log source integration and management.

Let's talk about Managed XDR.

30 minutes with our SOC team. You describe your situation, we tell you clearly whether and how we can help.