What is Extended detection and response (XDR)?
A security approach that correlates detection data across endpoints, identity, email, cloud and network in one place, so analysts can see and respond to an attack as a whole.
How it works
Endpoint detection and response (EDR) watches devices. XDR extends that view to other sources, linking related alerts into a single incident. An attacker who phishes a user, signs in from a new location and then runs tools on a laptop shows up as one story rather than three alerts.
XDR is a technology category, often sold by a single vendor. MDR is a service, which may run on top of an XDR platform.
Key points
- Correlates alerts across several security layers
- Reduces duplicate alerts and investigation time
- Often includes built-in response actions
- Is a tool; MDR is the people who use it
Common questions
Is XDR better than SIEM?
They overlap. XDR is optimised for detection and response; a SIEM is broader and stores logs for search, compliance and custom detections.
Do I still need MDR if I have XDR?
XDR still needs people to triage and act on what it finds, especially outside office hours.
Talk to someone who does this every day
Questions about XDR? Our team will give you a straight answer.