SOC, SIEM, EDR, XDR, MDR: the terms explained
SOC is the function; SIEM, EDR and XDR are tools; MDR is a service. The label matters less than whether response happens and in whose mandate. At ANOMAL, SOC as a Service covers detection and response and is often called MDR; a managed SIEM is part of the SOC with analysts and response in the mandate. Customers keep their existing tools.
What each term means
The five terms sit on different levels. A SOC is the function: people, processes and tools that investigate alerts every day and respond when incidents occur. A SIEM is a tool: it collects logs, evaluates rules and produces alerts. EDR is an endpoint tool: it detects and can isolate processes. XDR widens the view beyond endpoints to identity, cloud and email. MDR is a service: a provider runs detection and handles response in its own mandate.
The label matters less than whether response happens and in whose mandate.
The terms side by side
| Term | What it is | Who runs it | Does it respond? | When it fits |
|---|---|---|---|---|
| SOC | Function: team, processes, tools | Run in-house or externally | Yes, when response sits in the mandate | When alerts are investigated daily and incidents are owned |
| SIEM | Tool: logs, correlation, alerts | In-house or as a managed SIEM | No, it alerts; response needs people | When many log sources need central evaluation |
| EDR | Endpoint tool: detection, isolation | Run in-house or by a partner | Partly, isolation can be automated | As baseline protection on laptops and servers |
| XDR | Tool beyond endpoints: identity, cloud, email | Run in-house or by a partner | Partly, depending on playbooks and approval | When telemetry from several layers is merged |
| MDR | Service: detection and response outsourced | By the provider in its own mandate | Yes, agreed contractually | When no in-house team can respond around the clock |
How the terms fit together at ANOMAL
SOC as a Service Switzerland covers detection and response in one mandate. Many providers call exactly that promise MDR; the name is secondary. A managed SIEM is part of the SOC at ANOMAL: the platform runs with us, analysts investigate in the mandate and response is included. You keep your existing tools; we remove nothing and bolt nothing on.
Placement in SOC operations
The SOC as a Service Switzerland page describes how detection and response run in a shared mandate.
Frequently asked questions
Is MDR just a SOC under a different name?
SOC names the function; MDR names a service that delivers it. The label matters less than whether response happens and in whose mandate. Ask for evidence of exactly that, whatever the name.
Can a SIEM run without a SOC?
Technically yes. Without a team investigating alerts every day, the evidence stays paper-only and detections contribute little to security.
What do I need as an SME?
Usually detection and response from one mandate, meaning a service that investigates and contains around the clock. Whether the offer is called MDR or SOC as a Service is secondary; check the scope.
Does a modern SOC even need a SIEM?
Often not in the classic sense. XDR platforms and data lakes take over many SIEM functions. What counts is detection connected to analysts and response.
How does MDR differ from a managed SIEM?
A managed SIEM runs the platform and delivers alerts; response stays with the customer or moves into an extended mandate. MDR includes response as a service. At ANOMAL, the managed SIEM is part of the SOC, with analysts and response in the mandate.
Related terms
- SOC A Security Operations Center (SOC) is the team that constantly monitors an organisation's IT for attacks and intervenes during incidents.
- SIEM A Security Information and Event Management (SIEM) system collects logs from many sources, makes them searchable and analyses them with detection rules.
- EDR Endpoint Detection and Response (EDR) monitors activities on devices like laptops and servers, enabling intervention during attacks.
- XDR Extended Detection and Response (XDR) connects security signals from endpoints, identities, email, cloud and network in one platform.
- MDR Managed Detection and Response (MDR) is a service that detects threats and actively contains them.
- SOCaaS SOC as a Service (SOCaaS) is a SOC operated by an external provider and delivered as an ongoing service.