What is XDR? Extended Detection and Response explained
Extended Detection and Response (XDR) is a detection platform that correlates telemetry from endpoint, identity, email, cloud and network in one data model. XDR replaces many functions of a classic SIEM, but it does not replace a team. Only combined with a SOC or MDR does it turn into security.
How this compares to neighbouring topics
This page defines XDR as a platform. For the difference between a platform and a team, read SOC vs. SIEM. For MDR as a service, see What is MDR. For the fundamentals of the operating unit, read What is a SOC. As a full offering, SOC as a Service Switzerland covers platform, team and response together.
Short definition
XDR unifies telemetry from endpoint, identity, email, cloud and network in a single data model. It correlates events across system boundaries and bundles individual alerts into prioritised cases. Native XDR comes from one vendor; Open XDR integrates telemetry from multiple vendors.
XDR is a modern replacement for many SIEM functions, not a replacement for the team.
XDR vs. SIEM vs. EDR
| Criterion | EDR | SIEM | XDR |
|---|---|---|---|
| Data sources | Endpoint only | All logs, generic | Endpoint, identity, cloud, email, network |
| Correlation | Within endpoint | Rule-based, high maintenance | Model-based, cross-source |
| Response capability | Endpoint isolation | None, alerts only | Response on endpoint and identity |
| Operating without a team | Little value | No value | No value |
What XDR delivers
- Fewer alerts through cross-source correlation
- Cases instead of raw alerts, prioritised by impact
- Shorter investigations thanks to pre-joined context
- Response actions directly from the platform (endpoint, identity)
- Lower SIEM licence and storage cost with the right architecture
XDR in Switzerland
Swiss customers increasingly retire legacy SIEM in favour of XDR plus a data lake, often combined with a managed SOC. The critical question stays the same: who works the cases every day. Without a team, XDR is an expensive console. If you do not run it in-house, combine the platform with SOC as a Service Switzerland or consume MDR as an outcome service.
Frequently asked questions
Is XDR just a better EDR?
No. EDR sees endpoint; XDR correlates endpoint with identity, cloud, email and network in one data model.
Does XDR fully replace a SIEM?
Often yes for detection and response, often not for compliance logging and long-term retention. Many customers pair XDR with a data lake.
What is the difference between native and open XDR?
Native XDR uses one vendor's telemetry and response; open XDR integrates sources from multiple vendors. Native goes live faster; open is more flexible when a stack already exists.
Do I still need a SOC alongside XDR?
Yes. XDR produces cases, but someone has to work them. Without a SOC or MDR the platform stays unused.
What does XDR cost in Switzerland?
Cost depends on endpoint count, integrated sources, data volume and the vendor's licence model. Team operating cost is separate unless you consume managed SOC.
Related terms
- XDR Extended Detection and Response (XDR) connects security signals from endpoints, identities, email, cloud and network in one platform.
- EDR Endpoint Detection and Response (EDR) monitors activities on devices like laptops and servers, enabling intervention during attacks.
- NDR Network Detection and Response (NDR) analyses network traffic to detect attacks, without needing an agent on the systems.
- SIEM A Security Information and Event Management (SIEM) system collects logs from many sources, makes them searchable and analyses them with detection rules.
- MDR Managed Detection and Response (MDR) is a service that detects threats and actively contains them.
- Correlation Rule A correlation rule links events from various sources and triggers an Alert when a defined pattern is matched.