GlossarySOC and monitoring

XDR

Short answer

XDR (Extended Detection and Response) is a security approach that combines data from endpoints, email, identities, networks and cloud services in one platform to detect attacks that span several systems and respond to them from a single console.

How XDR works

XDR collects telemetry from several security layers, typically endpoints, email, identity, network and cloud workloads, and correlates it in one platform. An alert on a laptop can then be linked to the phishing email that started it and the account that was used afterwards, giving the security team the full chain of an attack instead of isolated alerts.

XDR vs EDR

EDR focuses on endpoints. XDR extends the same detection and response approach to other sources. Many XDR products are built on top of a vendor's EDR.

XDR vs SIEM

XDR usually works best with the vendor's own products and comes with detection rules already tuned. A SIEM is designed to take logs from any source and needs more configuration, but gives broader visibility, including business applications. Many organisations use both.

Who operates it

Like EDR and SIEM, XDR needs people who review alerts and respond. That role is often covered by a SOC or an MDR service.

Related terms

Keep reading on this topic

Continuous monitoring and response: EDR, SIEM, 24/7 SOC operations, detection engineering and incident handling.

Go to the topic hub