What an MDR service includes
An MDR provider deploys or operates detection technology, usually EDR or XDR, reviews the alerts it generates, investigates suspicious activity, hunts for threats that tools did not flag, and takes response actions such as isolating a device or disabling an account. The customer receives reports and is contacted when a decision is needed.
MDR vs EDR
EDR is the technology. MDR is the service of people who watch and act on what that technology detects. Buying an EDR without anyone reviewing its alerts leaves most of its value unused.
MDR vs SOC
An MDR is a type of outsourced SOC focused on detection and response. A broader SOC service may also cover log management with a SIEM, vulnerability monitoring and compliance reporting.
What to check with a provider
Coverage hours, which response actions the provider can take without asking, response times, and how incidents are escalated and reported.




