# What is Extended Detection and Response (XDR)?

> Extended detection and response (XDR) is a security technology approach that collects and correlates telemetry from multiple control points — commonly endpoints, identities, email, cloud workloads, and networks — to support detection, investigation, and response from a more unified view.

- Canonical URL: https://yellowcube.eu/glossary/extended-detection-and-response/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

It aims to connect related signals that might appear harmless when examined separately.

XDR implementations differ substantially. Some are tightly integrated suites from one supplier; others accept a wider range of third-party data and controls. The name therefore says less than the actual integrations, telemetry quality, detection logic, response actions, and operating effort. No standards body defines XDR either, which is why two products carrying the label can differ so widely.

### Key points

- **Primary purpose:** Join evidence across security domains and reduce fragmented investigations.
- **Typical capabilities:** Cross-source correlation, incident grouping, investigation timelines, analytics, and response actions.
- **What to assess:** Native and third-party coverage, data ownership, retention, APIs, response controls, and analyst workflow.
- **Important limitation:** XDR does not create visibility where sensors or logs are absent, and correlation does not make every conclusion correct.

### Related terms

[Endpoint detection and response (EDR)](<https://yellowcube.eu/glossary/endpoint-detection-and-response/>) · [Network detection and response (NDR)](<https://yellowcube.eu/glossary/network-detection-and-response/>) · [Security information and event management (SIEM)](<https://yellowcube.eu/glossary/security-information-and-event-management/>) · [Managed detection and response (MDR)](<https://yellowcube.eu/glossary/managed-detection-and-response/>) · [Security operations center (SOC)](<https://yellowcube.eu/glossary/security-operations-center/>) · [Managed extended detection and response (MXDR)](<https://yellowcube.eu/glossary/managed-extended-detection-and-response/>)

### Sources

[NIST SP 800-61r3: Incident Response Recommendations](https://csrc.nist.gov/pubs/sp/800/61/r3/final) · [NIST SP 800-92: Guide to Computer Security Log Management](https://csrc.nist.gov/pubs/sp/800/92/final)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

