Skip to main content
StandardCurrent

XDR

Also known as: Extended Detection and Response

Following adds this technology to your private workspace so related learning is easier to organise and revisit.

Technology explained

What is XDR?

Extended detection and response correlates security telemetry and response across endpoints, identities, email, cloud and other control planes. This profile connects the concept to KBY's practical engineering guidance.

XDR products combine signals that would otherwise sit in separate tools to build higher-confidence incidents and coordinated actions. Integration breadth does not guarantee coverage; sensor health, data quality, permissions and response playbooks remain essential.

Primary purpose

Detect and respond to multi-stage threats across several security domains.

Typical environments
Security Operations Centers (SOC)
Typical use cases
  • Cross-domain threat hunting
  • Automated incident response
  • Correlating endpoint and network telemetry
Connected knowledge

1 resource for XDR

Browse by purpose, from definitions and learning through operations, diagnostics and controlled recovery.

Technology journey

Learn and operate with XDR

Ordered as a reader progression -- from core definitions through to operational reference -- using only the content already connected in the technology registry.

Lexicon Definitions(1)

Start here: understand the core vocabulary.