XDR — Extended Detection and Response

Incident detection and response correlating signals from several layers at once.

1 min read · Last updated: 2026年8月

The term

XDR is the practice of correlating signals from different sources — endpoint, network, identity, files — instead of looking at each in isolation. A single event is rarely an incident; the combination usually is.

An example: copying a large file says nothing. Copying a large file, after hours, to removable media, days after a resignation, says quite a lot — and correlation is what sees that.

XDR, EDR and SIEM

  • EDR looks at the endpoint in depth, and only the endpoint.
  • SIEM gathers logs from everything, but depends on someone writing the rule that spots the pattern.
  • XDR is born from correlation across layers, with the response in the same tool that detected it.

At Vigilioo

The platform cross-references device activity, network traffic, file access and the analysis of screen captures. When the combination breaks the pattern, the alert reaches the security team with the context that raised it — not just the bare event.

And the response

From the same dashboard, with no need for physical access:

  • Cut the device's USB and Bluetooth ports.
  • Block sites, IPs and programs by policy.
  • Apply a precautionary lock, taking the machine out of use.
  • Shut the device down remotely.

Up next

IdP and SSO — identity and access

How your company identity talks to the platform, and who sees what.

Keep reading

Need a hand?

If the steps did not solve it, talk to our team.

Open a support channel

准备好更 精准?

今天就免费开始。无需银行卡,5 分钟内即可配置完成。

7 天免费试用
无需银行卡
随时可取消
实时画面监控USB 端口与蓝牙锁定带自动打卡的排班管理按策略放行的网站与程序位置与地理范围设备预防性锁定团队生产力报表端到端 AES-256 加密实时画面监控USB 端口与蓝牙锁定带自动打卡的排班管理按策略放行的网站与程序位置与地理范围设备预防性锁定团队生产力报表端到端 AES-256 加密