Extended Detection and Response
Also known as:XDR
Extended DetectionDetectionThe capability to identify suspicious activity, attacks, or policy violations in time. and Response: Correlated detection and response across endpointsEndpointA user or server device that communicates with a network and runs workloads or applications., identities, email, networks, and the cloud. The term relates to operational security. People, processes, and technology must work together to ensure alerts are evaluated, measures coordinated, and insights implemented sustainably.
How it works and where it fits
Extended Detection and Response connects data sources to detection or assessment logic. Raw records become security-relevant only when timing, identity, system context, and expected behavior are considered. Rules, correlations, statistical models, and analyst decisions may work together; no single method reliably covers every attack pattern.
Practical security relevance
Operational quality is reflected in coverage, data completeness, detection time, and false-alert workload. Data sources need owners, time synchronization, retention, and quality controls. Detections should be tested, versioned, and improved using real incidents. Every meaningful alert also requires triage guidance, escalation, and possible response actions.
Related concepts
- Endpoint Detection and ResponseEndpoint Detection and ResponseContinuously monitors endpoints and supports detection, investigation, and containment.: Continuously monitors endpoints and supports detection, investigation, and containment.
- Intrusion Detection SystemIntrusion Detection SystemDetects suspicious or anomalous activities on hosts or within networks.: Detects suspicious or anomalous activities on hosts or within networks.
- Incident ResponseIncident ResponseA structured process for the preparation, detection, containment, eradication, and post-incident review regarding security incidents.: A structured process for the preparation, detection, containment, eradication, and post-incident review regarding security incidents.
- Network Detection and ResponseNetwork Detection and ResponseAnalyzes network traffic to detect and investigate suspicious activity.: Analyzes network traffic to detect and investigate suspicious activity.