Glossary

Extended detection and response (XDR)

A platform that correlates telemetry across endpoints, network, identity, and cloud into a single detection and investigation view.

Also called: XDR

Extended detection and response (XDR) correlates telemetry from multiple security layers, endpoints, network, identity, email, and cloud workloads, into a single detection and investigation platform, rather than analyzing each source separately. It aims to reduce the manual work of pivoting between an endpoint detection and response console, a SIEM, and separate network tools to piece together one incident.

XDR differs from a SIEM mainly in depth versus breadth: a SIEM ingests logs from almost any source an organization chooses to send, while XDR typically ships with deep, native integrations across a narrower set of layers from a single vendor, trading flexibility for out-of-the-box correlation. Vendors disagree on exactly which data sources qualify as native XDR versus data simply forwarded in, so the term is defined inconsistently across the market.

XDR matters because a multi-stage attack often leaves traces across several layers that look unremarkable in isolation but form a clear pattern once correlated, the kind of technique chain described in the MITRE ATT&CK framework. The main pitfall is assuming XDR replaces a SIEM outright; most organizations still need broader log retention and compliance-driven ingestion that XDR alone does not cover.

Last reviewed September 22, 2026

In the index now

Related terms