security//XDR
Extended Detection and Response (XDR) correlates security signals across several domains, commonly endpoints, identity, email, network and cloud workloads, then supports coordinated investigation and response.
Extended Detection and Response (XDR) correlates security signals across several domains, commonly endpoints, identity, email, network and cloud workloads, then supports coordinated investigation and response.
Its value appears when no single event is decisive. A normal login, a harmless-looking process and an allowed outbound connection may become suspicious when they belong to one trajectory. XDR is a product and architecture category, not a magic algorithm or a technology owned by one vendor.
Correlation turns scattered footprints into a route.