Managed XDR
ELASTIC SECURITY · MICROSOFT DEFENDER XDR · CROWDSTRIKE FALCON
Managed XDR is our correlation scope: endpoint, identity, cloud, email and network in one data model, from a single platform or cross-vendor. Examples are Elastic Security, Microsoft Defender XDR or CrowdStrike Falcon.
What sets this service apart: a case is built across domain boundaries, with one timeline and one response path. Attacks that look like three harmless alerts in separate tools become visible as one chain.
Typical detections
- Attack paths across domain boundaries
- Phishing to token theft to endpoint execution as one chain
- Cloud persistence after identity compromise
- Mailbox rules and consent grants correlated with endpoint activity
- BEC chains across mail, identity and cloud
- Multi-stage campaigns spanning days or weeks
Response actions within mandate
- Coordinated response in one playbook: session revoke, host isolation, mail purge and blocklisting in a single step
- One case, one timeline, one mandate check across all affected domains
- Example mandate: automated combined response on critical verdicts for standard assets, approval for tier-0
Limits of this service
- Detection depth depends on the integration depth of each individual source
- Compliance retention and custom parsing usually run through Managed SIEM
- Without network onboarding there is no visibility into agentless zones, that is Managed NDR
SLAs
Included
- Cross-domain correlation and case building across endpoint, identity, cloud, email and network
- Cross-domain response playbooks with one shared mandate check
- Attack path review and coverage reconciliation per domain
Not included
- Platform and agent licences (yours, or passed through at cost)
- Anti-ransomware (e.g. Halcyon) as a separate add-on module
- Eradication and recovery inside your systems, executed by your IT with our coordination
- Use case/playbook development and log source integration, those come with a Managed SIEM or Managed NDR scope
Process
- Assess
Domain inventory across endpoint, identity, cloud, email and network, integration paths and API availability.
- Integrate
Connect all signal sources into a normalised schema, build and test cross-domain correlation cases.
- Automate
Combined response playbooks across several domains, pre-authorised in the mandate matrix.
Deliverables
- Cross-domain coverage matrix per connected domain
- Attack path review with prioritised hardening recommendations
- Case timelines across domain boundaries, documented per incident
FAQ
Single vendor or best of breed?
Both work. Single-vendor XDR integrates faster, best of breed gives more detection depth. We base our recommendation on your existing landscape.
Do we still need a SIEM alongside it?
For detection and response often not. For compliance retention, custom parsing of your own applications and long-term forensic search, many customers add Managed SIEM or a data lake.
Included in every ANOMAL managed service
- 24/7 threat monitoring: every alert is picked up, enriched with context and documented in the ticket system
- Incident triage on every severity from low to critical, classified as false positive, benign true positive or true positive
- Further analysis on every suspected true positive, including log, telemetry and asset context
- Incident response along NIST: containment and first response within your mandate. A full IR engagement for a major incident is billed separately.
- SOC platform operations: backend, updates and health monitoring of the SOC stack
- Automated incident response: SOAR enrichment, automated queries, pre-authorised response actions per mandate
- Threat hunting and threat intelligence (e.g. MISP plus external feeds) feeding back into detections
- Effectiveness testing once a year, e.g. together with an external purple team
- Service management: monthly service efficiency report, quarterly optimisation meeting, live view in ANOVIEW
- Ongoing operations: continuous tuning, detection maintenance and quarterly service optimisation
Scope, service level (e.g. business hours for low to high, 24/7 for critical) and volumes differ per environment. That is why there is no list price: every customer gets a dedicated quote with defined scope, service level and response mandate. With Managed SIEM and Managed NDR the scope additionally covers use case and playbook development as well as log source integration and management.
Let's talk about Managed XDR.
30 minutes with our SOC team. You describe your situation, we tell you clearly whether and how we can help.
More managed services
We run your SIEM and keep it sharp: we connect new log sources, build detection rules and maintain them.
We monitor your endpoints around the clock and step in immediately during an attack. It works with all leading EDR platforms.
We monitor traffic inside your network and detect lateral movement and connections to attacker infrastructure. The signals flow straight into our cases.
We protect your accounts in Entra ID, Okta and Active Directory. We detect suspicious sign-ins and stolen credentials early and revoke affected sessions automatically.