The term
XDR is the practice of correlating signals from different sources — endpoint, network, identity, files — instead of looking at each in isolation. A single event is rarely an incident; the combination usually is.
An example: copying a large file says nothing. Copying a large file, after hours, to removable media, days after a resignation, says quite a lot — and correlation is what sees that.
XDR, EDR and SIEM
- EDR looks at the endpoint in depth, and only the endpoint.
- SIEM gathers logs from everything, but depends on someone writing the rule that spots the pattern.
- XDR is born from correlation across layers, with the response in the same tool that detected it.
At Vigilioo
The platform cross-references device activity, network traffic, file access and the analysis of screen captures. When the combination breaks the pattern, the alert reaches the security team with the context that raised it — not just the bare event.
And the response
From the same dashboard, with no need for physical access:
- Cut the device's USB and Bluetooth ports.
- Block sites, IPs and programs by policy.
- Apply a precautionary lock, taking the machine out of use.
- Shut the device down remotely.
Up next
IdP and SSO — identity and access
How your company identity talks to the platform, and who sees what.
Keep reading