GLOSSARY · TOOLING
XDR
Extended Detection and Response: correlates telemetry across one vendor's own sensors, typically endpoint, identity, email and network, and ships its detection content already written.
XDR extends the endpoint detection model outward. Where EDR records and analyses what happens on a machine, XDR correlates across several telemetry types that the same vendor’s sensors produce, most often endpoint, identity, email and network. The point is connection rather than collection: a password-spray attempt, a successful authentication from an unfamiliar location two hours later, and an unusually large file-share download are three unremarkable alerts separately, and one obvious campaign when presented together with a timeline.
The trade against a SIEM is deliberate and worth understanding before comparing prices. A SIEM ingests anything that emits a log and expects you to write and tune the detection logic. XDR narrows the input to what its own sensors see, and in exchange ships detection content already written and maintained. That removes a large amount of tuning work, which is the honest reason the category sells, and it introduces a dependency: the content improves without your effort and also changes without your approval. Anything outside the vendor’s sensor coverage is not merely undetected, it is invisible to the correlation, which produces a picture that is confident and incomplete rather than obviously partial.
Evaluate the category on the breadth of what it genuinely instruments in your estate rather than on the number of letters in the acronym, because the label is applied loosely and some products marketed as XDR are an EDR agent with additional log sources attached. The questions that separate them are which sensors are first-party, what happens to correlation quality when a critical system sits outside them, and whether the detection content maps to a published adversary framework such as MITRE ATT&CK in a way you can verify rather than take on trust.