XDR — Extended Detection and Response

Incident detection and response correlating signals from several layers at once.

1 min read · Last updated: 08.2026

The term

XDR is the practice of correlating signals from different sources — endpoint, network, identity, files — instead of looking at each in isolation. A single event is rarely an incident; the combination usually is.

An example: copying a large file says nothing. Copying a large file, after hours, to removable media, days after a resignation, says quite a lot — and correlation is what sees that.

XDR, EDR and SIEM

  • EDR looks at the endpoint in depth, and only the endpoint.
  • SIEM gathers logs from everything, but depends on someone writing the rule that spots the pattern.
  • XDR is born from correlation across layers, with the response in the same tool that detected it.

At Vigilioo

The platform cross-references device activity, network traffic, file access and the analysis of screen captures. When the combination breaks the pattern, the alert reaches the security team with the context that raised it — not just the bare event.

And the response

From the same dashboard, with no need for physical access:

  • Cut the device's USB and Bluetooth ports.
  • Block sites, IPs and programs by policy.
  • Apply a precautionary lock, taking the machine out of use.
  • Shut the device down remotely.

Up next

IdP and SSO — identity and access

How your company identity talks to the platform, and who sees what.

Keep reading

Need a hand?

If the steps did not solve it, talk to our team.

Open a support channel

Klar til at overvåge dit team med præcision?

Kom gratis i gang i dag. Intet kort nødvendigt. Klar på under 5 minutter.

7 dages gratis prøveperiode
Intet kort
Opsig når som helst
Skærmovervågning i realtidLåsning af USB-porte og BluetoothVagtstyring med automatisk tidsregistreringSider og programmer tilladt af politikPlacering og geografiske grænserForebyggende låsning af enhedenProduktivitetsrapporter for teametAES-256-kryptering hele vejenSkærmovervågning i realtidLåsning af USB-porte og BluetoothVagtstyring med automatisk tidsregistreringSider og programmer tilladt af politikPlacering og geografiske grænserForebyggende låsning af enhedenProduktivitetsrapporter for teametAES-256-kryptering hele vejen