Glossary
XDR
Extended Detection and Response — A security platform that unifies detection and response data across multiple layers, such as endpoint, network, email, and cloud, into a single correlated view, extending the endpoint-only scope of EDR. The goal is to reduce the number of disconnected alerts an analyst must manually piece together during an investigation.
Recent coverage mentioning XDR
State of AI-Enabled Malware: Real-World Impact and Defenses
Unit 42 reports AI-enabled malware is primarily proof-of-concept, with minimal operational activity. Existing defenses effectively detect current threats.
Augmenting SOCs with Wazuh AI Analyst and LLM Integrations
Wazuh integrates AI, including its AI Analyst and LLM options, to augment SOC workflows, reduce analyst fatigue, and accelerate threat detection and response.
UAT-10147 Leverages Agentic AI for EDR-Evasive Cybercrime
Talos details UAT-10147, an AI-driven cybercrime group orchestrating sophisticated post-compromise operations and evading EDR with custom rootkits.
AI-Driven Cyberattack Targets APAC Government Agencies
A China-linked actor reportedly deployed a near-autonomous AI framework to compromise government agencies in the APAC region, signaling a new threat landscape.
AI Agentic Threats: Countering Automated Attacks with AI-Driven Defense
The rise of AI agents introduces new attack vectors. Enterprises must adopt AI-driven agentic defenses to counter automated reconnaissance, exploitation, and evasion…
Advertisement