Managed Detection and Response

Also known as:MDR

Managed DetectionDetectionThe capability to identify suspicious activity, attacks, or policy violations in time. and Response: Outsourced service for continuous monitoringMonitoringThe continuous observation of systems, identities, networks, and controls for relevant changes., analysis, and response to threats. The term relates to operational security. People, processes, and technology must work together to evaluate alerts, coordinate measures, and implement insights effectively.

How it works and where it fits

Managed Detection and Response connects data sources to detection or assessment logic. Raw records become security-relevant only when timing, identity, system context, and expected behavior are considered. Rules, correlations, statistical models, and analyst decisions may work together; no single method reliably covers every attack pattern.

Practical security relevance

Operational quality is reflected in coverage, data completeness, detection time, and false-alert workload. Data sources need owners, time synchronization, retention, and quality controls. Detections should be tested, versioned, and improved using real incidents. Every meaningful alert also requires triage guidance, escalation, and possible response actions.

  • Endpoint Detection and ResponseEndpoint Detection and ResponseContinuously monitors endpoints and supports detection, investigation, and containment.: Continuously monitors endpoints and supports detection, investigation, and containment.
  • Extended Detection and ResponseExtended Detection and ResponseCorrelated detection and response across endpoints, identities, email, networks, and the cloud.: Correlated detection and response across endpoints, identities, email, networks, and the cloud.
  • Security Operations CenterSecurity Operations CenterA central function for the continuous monitoring, analysis, and response to security events.: A central function for the continuous monitoring, analysis, and response to security events.
  • Threat HuntingThreat HuntingSearches for previously undetected attacker activity based on hypotheses.: Searches for previously undetected attacker activity based on hypotheses.