XDR
XDR (Extended Detection and Response) unifies data from endpoints, network, email, and cloud.
Term
description · examples · notesXDR (Extended Detection and Response) unifies data from endpoints, network, email, and cloud.
Description
It extends EDR capabilities by correlating signals from multiple sources into one platform.
It automates detection of complex attacks that traverse multiple infrastructure layers.
It reduces alert fatigue through centralized analysis instead of separate consoles.
It covers everything EDR covers, plus network and cloud visibility.
What people often say
- XDR is not a replacement for EDR — it encompasses and extends it with network and cloud layers.
- It is not the same as SIEM: XDR automates response, SIEM is an analytical tool.
Covers / does not cover
Covers
- Correlation of events from endpoints, network, email, and cloud
- Detection of multi-stage attacks spanning multiple infrastructure layers
- Automated incident response coordinating actions across multiple systems
- Centralized visibility over the entire security environment
Does not cover
- Systems and data sources not integrated into the XDR platform
- Threats that do not generate sufficient telemetry in any covered layer
- Identity and access management (XDR detects, it does not manage)
Mentioned in the news
Threats
reduces 15Threats it reduces. Select one to open its page.
Techniques
neutralizes 18Techniques it neutralizes. Select one to open its page.
- Exploitation→
- Data Exfiltration→
- Malware Delivery→
- Lateral Movement→
- Command & Control→
- Configuration Abuse→
- Reconnaissance→
- Impair Defenses→
- Persistence→
- Automation & Scripting→
- Living off the Land→
- Process Injection→
- Payload Obfuscation→
- In-Memory Execution→
- DLL Sideloading→
- Network Sniffing→
- Domain Account Discovery→
- Rootkit Installation→