Extended detection and response (XDR) platforms are tools used to automate the discovery and remediation of security issues across hybrid systems. These tools are capable of performing detection and response related to networks, endpoints, cloud services, and applications. Companies are adopting these technologies because most traditional detection and response solutions are limited to a single medium such as endpoint security or network security while XDR is capable of securing complex hybrid environments.
XDR solutions provide a single system for managing security issues as they arise regardless of the source within the organization. They can also be used to consolidate redundant, similar detection and response technologies and simplify detection and remediation for security teams.
Endpoint detection & response (EDR) software and network detection and response (NDR) software operate similarly, but most are limited to their specific medium. For example, many NDR solutions can analyze and resolve issues on a local business network, but cannot support detection and response for cloud workloads or remote endpoints. While numerous families of detection and response solutions have emerged in recent years, XDR is capable of extending security across networks, endpoints, cloud services, and virtual environments.
To qualify for inclusion in the Extended Detection and Response (XDR) category, a product must:
Analyze network, cloud, and endpoint activity continuously
Utilize artificial intelligence (AI) or machine learning (ML) to develop baselines for system behaviors
Automate threat and anomaly detection across the hybrid environments
Deploy forensics upon detection for investigation and remediation