XDR — Extended Detection and Response

Incident detection and response correlating signals from several layers at once.

1 min read · Last updated: 2026/08

The term

XDR is the practice of correlating signals from different sources — endpoint, network, identity, files — instead of looking at each in isolation. A single event is rarely an incident; the combination usually is.

An example: copying a large file says nothing. Copying a large file, after hours, to removable media, days after a resignation, says quite a lot — and correlation is what sees that.

XDR, EDR and SIEM

  • EDR looks at the endpoint in depth, and only the endpoint.
  • SIEM gathers logs from everything, but depends on someone writing the rule that spots the pattern.
  • XDR is born from correlation across layers, with the response in the same tool that detected it.

At Vigilioo

The platform cross-references device activity, network traffic, file access and the analysis of screen captures. When the combination breaks the pattern, the alert reaches the security team with the context that raised it — not just the bare event.

And the response

From the same dashboard, with no need for physical access:

  • Cut the device's USB and Bluetooth ports.
  • Block sites, IPs and programs by policy.
  • Apply a precautionary lock, taking the machine out of use.
  • Shut the device down remotely.

Up next

IdP and SSO — identity and access

How your company identity talks to the platform, and who sees what.

Keep reading

Need a hand?

If the steps did not solve it, talk to our team.

Open a support channel

チームの運用を、 より正確に?

今日から無料で始められます。カード登録は不要、設定は 5 分未満です。

7 日間の無料トライアル
カード登録不要
いつでも解約可能
リアルタイムの画面モニタリングUSB ポートと Bluetooth のロック自動打刻によるシフト管理ポリシーで許可されたサイトとプログラム位置情報と地理的な範囲端末の予防的ロックチームの生産性レポートエンドツーエンドの AES-256 暗号化リアルタイムの画面モニタリングUSB ポートと Bluetooth のロック自動打刻によるシフト管理ポリシーで許可されたサイトとプログラム位置情報と地理的な範囲端末の予防的ロックチームの生産性レポートエンドツーエンドの AES-256 暗号化