SOC, SIEM, EDR, XDR, MDR: the terms explained

SOC is the function; SIEM, EDR and XDR are tools; MDR is a service. The label matters less than whether response happens and in whose mandate. At ANOMAL, SOC as a Service covers detection and response and is often called MDR; a managed SIEM is part of the SOC with analysts and response in the mandate. Customers keep their existing tools.

All

What each term means

The five terms sit on different levels. A SOC is the function: people, processes and tools that investigate alerts every day and respond when incidents occur. A SIEM is a tool: it collects logs, evaluates rules and produces alerts. EDR is an endpoint tool: it detects and can isolate processes. XDR widens the view beyond endpoints to identity, cloud and email. MDR is a service: a provider runs detection and handles response in its own mandate.

The short version

The label matters less than whether response happens and in whose mandate.

The terms side by side

TermWhat it isWho runs itDoes it respond?When it fits
SOCFunction: team, processes, toolsRun in-house or externallyYes, when response sits in the mandateWhen alerts are investigated daily and incidents are owned
SIEMTool: logs, correlation, alertsIn-house or as a managed SIEMNo, it alerts; response needs peopleWhen many log sources need central evaluation
EDREndpoint tool: detection, isolationRun in-house or by a partnerPartly, isolation can be automatedAs baseline protection on laptops and servers
XDRTool beyond endpoints: identity, cloud, emailRun in-house or by a partnerPartly, depending on playbooks and approvalWhen telemetry from several layers is merged
MDRService: detection and response outsourcedBy the provider in its own mandateYes, agreed contractuallyWhen no in-house team can respond around the clock

How the terms fit together at ANOMAL

SOC as a Service Switzerland covers detection and response in one mandate. Many providers call exactly that promise MDR; the name is secondary. A managed SIEM is part of the SOC at ANOMAL: the platform runs with us, analysts investigate in the mandate and response is included. You keep your existing tools; we remove nothing and bolt nothing on.

Frequently asked questions

Is MDR just a SOC under a different name?

SOC names the function; MDR names a service that delivers it. The label matters less than whether response happens and in whose mandate. Ask for evidence of exactly that, whatever the name.

Can a SIEM run without a SOC?

Technically yes. Without a team investigating alerts every day, the evidence stays paper-only and detections contribute little to security.

What do I need as an SME?

Usually detection and response from one mandate, meaning a service that investigates and contains around the clock. Whether the offer is called MDR or SOC as a Service is secondary; check the scope.

Does a modern SOC even need a SIEM?

Often not in the classic sense. XDR platforms and data lakes take over many SIEM functions. What counts is detection connected to analysts and response.

How does MDR differ from a managed SIEM?

A managed SIEM runs the platform and delivers alerts; response stays with the customer or moves into an extended mandate. MDR includes response as a service. At ANOMAL, the managed SIEM is part of the SOC, with analysts and response in the mandate.