What is the difference between EDR and XDR?
Sort by:
CIO in Manufacturing4 years ago
Based on the discussions I've had with multiple security companies, the X stands for "extended" and just means their own additional services they provide to customers. Rather than just the traditional monitoring, detection, and response, the additional services would include things like SOC 24x7, consulting, corporate incident response, threat hunting, etc..
XDR usually adds a layer of automation to EDR.
We had EDR and when looking to upgrade to XDR one of the main selling features was that it can integrate with our NG firewalls, so you can build a rule when something is being blocked in the EDR it will create a firewall rule as well. It aggregate the data and adds data analytics and threat intelligence