XDR — Extended Detection and Response

Incident detection and response correlating signals from several layers at once.

1 min read · Last updated: 2026. 8.

The term

XDR is the practice of correlating signals from different sources — endpoint, network, identity, files — instead of looking at each in isolation. A single event is rarely an incident; the combination usually is.

An example: copying a large file says nothing. Copying a large file, after hours, to removable media, days after a resignation, says quite a lot — and correlation is what sees that.

XDR, EDR and SIEM

  • EDR looks at the endpoint in depth, and only the endpoint.
  • SIEM gathers logs from everything, but depends on someone writing the rule that spots the pattern.
  • XDR is born from correlation across layers, with the response in the same tool that detected it.

At Vigilioo

The platform cross-references device activity, network traffic, file access and the analysis of screen captures. When the combination breaks the pattern, the alert reaches the security team with the context that raised it — not just the bare event.

And the response

From the same dashboard, with no need for physical access:

  • Cut the device's USB and Bluetooth ports.
  • Block sites, IPs and programs by policy.
  • Apply a precautionary lock, taking the machine out of use.
  • Shut the device down remotely.

Up next

IdP and SSO — identity and access

How your company identity talks to the platform, and who sees what.

Keep reading

Need a hand?

If the steps did not solve it, talk to our team.

Open a support channel

팀을 더 정확하게?

오늘 무료로 시작하세요. 카드 등록은 필요 없고, 설정은 5분이 걸리지 않습니다.

7일 무료 체험
카드 등록 불필요
언제든 해지 가능
실시간 화면 모니터링USB 포트와 블루투스 잠금자동 출퇴근 기록이 있는 근무 관리정책으로 허용한 사이트와 프로그램위치와 지리적 범위기기 예방적 잠금팀 생산성 리포트종단 간 AES-256 암호화실시간 화면 모니터링USB 포트와 블루투스 잠금자동 출퇴근 기록이 있는 근무 관리정책으로 허용한 사이트와 프로그램위치와 지리적 범위기기 예방적 잠금팀 생산성 리포트종단 간 AES-256 암호화