166 terms · 75/46/45
Defense № 004 · class: endpoints

XDR

XDR (Extended Detection and Response) unifies data from endpoints, network, email, and cloud.

Term

description · examples · notes

XDR (Extended Detection and Response) unifies data from endpoints, network, email, and cloud.

Description

It extends EDR capabilities by correlating signals from multiple sources into one platform.

It automates detection of complex attacks that traverse multiple infrastructure layers.

It reduces alert fatigue through centralized analysis instead of separate consoles.

It covers everything EDR covers, plus network and cloud visibility.

What people often say

  • XDR is not a replacement for EDR — it encompasses and extends it with network and cloud layers.
  • It is not the same as SIEM: XDR automates response, SIEM is an analytical tool.

Covers / does not cover

Covers

  • Correlation of events from endpoints, network, email, and cloud
  • Detection of multi-stage attacks spanning multiple infrastructure layers
  • Automated incident response coordinating actions across multiple systems
  • Centralized visibility over the entire security environment

Does not cover

  • Systems and data sources not integrated into the XDR platform
  • Threats that do not generate sufficient telemetry in any covered layer
  • Identity and access management (XDR detects, it does not manage)

Mentioned in the news

Composite

Threats

reduces 15

Techniques

neutralizes 18