Endpoint Detection and Response — EDR vs XDR vs MDR vs SIEM

  • Home
  • Endpoint Detection and Response — EDR vs XDR vs MDR vs SIEM
Endpoint Detection and Response — EDR vs XDR vs MDR vs SIEM
Endpoint Detection and Response — EDR vs XDR vs MDR vs SIEM
Endpoint Detection and Response — EDR vs XDR vs MDR vs SIEM
Endpoint Detection and Response — EDR vs XDR vs MDR vs SIEM

A buyer’s guide · Operating since 2002

Detection and responseEDR, XDR, MDR and SIEM — compared by what each one can actually see

These four get quoted against each other as though they were competing products at different prices. They are not. Two are technologies, one is a platform, one is a service, and the useful way to tell them apart is not by feature list but by which telemetry each one is looking at.

That distinction decides everything, because a detection service can only ever find what its sensors record. Get the telemetry question right and the product choice becomes much simpler.

The question worth asking first. Not “which product do you use?” but “which telemetry sources will you ingest for us?” A service watching only endpoints cannot see an intrusion that runs entirely through your identity provider, however good its endpoint tooling is.
3K+
Projects delivered
1,000+
Enterprises protected
50+
In-house NOC & SOC engineers
24+
Years, since 2002
ISO/IEC 27001:2022
Certified — SOC in scope

Coverage

Five attacks, five telemetry sources

What each source would actually have recorded. Three of these five never meaningfully touch an endpoint.

No single source sees them allFilled = the source that would actually catch it. Half = partial signal.EndpointIdentityNetworkCloud/SaaSEmailRansomware on a laptopStolen credential, valid loginBusiness email compromiseData taken from a cloud storeLateral movement to a serverAsk a provider which of these five they ingest. The gaps are where the expensive incidents live.

The useful question for any provider is not which acronym they sell but which of these five sources they actually ingest. The gaps are where the expensive incidents live.

What each telemetry source would actually have seenManaged detection is a service wrapped around telemetry.EndpointNetworkIdentityCloud / SaaSEmailRansomware running on a laptopsees itpartialblindblindblindLateral movement between serverspartialsees itpartialblindblindStolen cloud token replayedblindblindsees itsees itblindValid credentials used over VPNblindpartialsees itblindblindInvoice fraud from a real mailboxblindblindblindpartialsees itendpoint-only serviceThree of these five never meaningfully touch an endpoint.Coverage stops where the sensors stop — ask which sources are ingested, not which product is used.

Why this matters more than the product choice

A managed service is people and process wrapped around telemetry. If a source is not ingested, no amount of analyst skill recovers the signal — there is nothing to analyse.

An endpoint-only service watching an attacker replay a stolen cloud token is not performing badly. It was never given the data, and the gap is a scoping decision rather than a technology failure.

What has changed

The most damaging intrusions increasingly avoid endpoints entirely. Session tokens replayed from an attacker’s own browser, OAuth consent abuse, mailbox rules that quietly hide the replies, valid credentials used through legitimate remote access.

None of that executes anything unusual on a managed laptop. All of it appears clearly in identity, cloud and email logs — provided somebody is collecting them.

The comparison

Antivirus vs EDR vs XDR vs SIEM vs MDR

Five things at three different levels — software, platform and service. The last column is a telemetry limit rather than a missing feature, which is why it cannot be fixed by buying the next tier up.

Scroll the table sideways →

Layer What it does What it is The honest limitation
Antivirus / NGAV Blocks known-bad files and recognisable malicious behaviour at execution. Software on the endpoint. Prevention. Stops what it recognises and records almost nothing about what it did not. There is no investigation trail after the fact.
EDRendpoint detection and response Records process execution, command lines, registry and file activity, and network connections from the endpoint, then detects patterns in it. Software on the endpoint. Detection and forensics. Sees only what the endpoint does. An attack conducted entirely against a cloud tenant or an identity provider never appears.
XDRextended detection and response Correlates endpoint telemetry with other sources — network, identity, email, cloud — in one place. A platform. Correlation across sources. “Extended” is not a defined boundary. Ask which sources a given product actually ingests; several are endpoint tools with two extra connectors.
SIEM Collects and correlates logs from anything that produces them, with retention and search. A platform. Collection, correlation, evidence. Records that something happened. It has no opinion and takes no action, and without analysts reading it, it is an expensive archive.
MDRmanaged detection and response A service: someone else runs the detection technology, investigates what it produces, and responds within agreed limits. People, wrapped around whichever of the above the provider ingests. The service is only as wide as its telemetry. This is the single most important thing to establish and the least commonly asked.

The row people misread is the last one. MDR is not a bigger version of EDR — it is people wrapped around whatever the provider ingests. Two MDR services can differ more from each other than EDR differs from XDR, and the per-endpoint price will not tell you which you are buying.

Straight answers

What buyers get wrong about detection and response

Fact

Coverage stops where the sensors stop

A managed detection service is people and process wrapped around telemetry. Whatever the marketing says, it cannot detect an attack that produces no signal in a source it ingests. An endpoint-only service watching an intrusion conducted entirely through a cloud identity provider is not failing at its job — it was never given the data.

Fact

The most damaging attacks increasingly avoid endpoints

Stolen session tokens replayed from an attacker’s browser, OAuth consent abuse, mailbox rule manipulation, valid credentials used through legitimate remote access. None of these execute anything unusual on a managed laptop, and all of them appear clearly in identity, cloud or email logs — if those are being collected.

Ask

“What does the X in XDR extend to?”

There is no standard answer. Some XDR products genuinely correlate endpoint, network, identity, email and cloud. Others are endpoint tools with two additional connectors and a new name. The question is not rude and it is the only way to compare two products carrying the same label.

Fact

Antivirus and EDR answer different questions

Antivirus asks whether this file is known to be bad and blocks it. EDR asks what happened on this machine and keeps enough record to reconstruct it. Prevention without recording means a successful intrusion leaves you with no way to establish what was reached — which is the question that actually matters afterwards.

Ask

“Which of our systems cannot take an agent?”

There are always some: servers under change control, unsupported operating systems, appliances, OT equipment, contractor machines. That list is precisely where a competent attacker prefers to operate, and it rarely appears in a proposal.

Fact

A SIEM has no opinion

It records that events occurred and correlates them if someone wrote a rule. It does not decide anything and it does not act. A SIEM without analysts is an expensive, well-organised archive of an incident nobody noticed.

Before you sign

Ten questions for any detection and response provider

Use these on us and on everyone else. Question one determines what the service can possibly detect; everything after it is detail.

Telemetry

Which sources do you actually ingest for us — endpoint only, or identity, cloud, network and email too?

This determines everything the service can possibly detect. Ask for the list, not the product name. The grid above shows what each column does and does not cover.

Identity

Do you monitor our identity provider and cloud tenant?

A large share of modern intrusions run entirely through identity and never execute anything on an endpoint. If those logs are not ingested, that whole class is invisible regardless of how good the endpoint tool is.

Response

Which actions may you take without asking, and at what hour?

“Response” ranges from a phone call to remote host isolation. Get the permitted-action list in writing, with who may authorise the rest at 3 a.m.

Coverage gaps

Which of our systems cannot run your agent?

Servers with change control, legacy operating systems, appliances, OT equipment. The estate that cannot take an agent is exactly where an attacker prefers to sit.

Tuning

Who tunes detections, and how are false positives handled?

An untuned deployment produces noise for weeks and then gets ignored. Ask what the first ninety days look like and who does that work.

Data

Where is our telemetry stored, for how long, and can we export it?

Retention determines how far back an investigation can reach. Export determines whether the evidence is still yours if you change provider.

Integration

Can detections and raw telemetry reach our own SIEM?

Otherwise your detection data lives only in a console you rent, and leaves when the contract does.

People

Who investigates — your analysts, a subcontractor, or an automated triage tier?

All three exist and are priced very differently. Ask who employs the person who would call you.

Metrics

What are your median times to detect, to investigate and to contain?

Three separate numbers. A provider quoting only the first is describing their tooling rather than their service.

Exit

What do we keep — detections, tuning, historical telemetry?

Detection content built inside a provider platform usually leaves with them. Agree what transfers before you need it.

Working with us

How we run this

We run detection as part of a full operations centre rather than as a product subscription, which is why the telemetry conversation comes before the tooling one.

Telemetry list up front

We tell you which sources we will ingest before quoting, and which parts of your estate would remain unseen. The gaps are named rather than discovered.

Identity and cloud included

Not an upsell. That is where a growing share of real intrusions live, and endpoint-only coverage is the gap we most often find when replacing another provider.

Your platform if you own one

Already licensed something capable? We work on top of it rather than selling you a replacement, and we say plainly what it does not cover.

Response authority in writing

A named list of actions we may take unaided, and who authorises the rest at 3 a.m. Agreed before go-live, not during an incident.

Detections into your SIEM

So the evidence and the tuning remain yours if the engagement ends — see managed SIEM.

3K+
Projects delivered
1,000+
Enterprises protected
50+
In-house NOC & SOC engineers
24+
Years, since 2002
ISO/IEC 27001:2022
Certified — SOC in scope

Questions we get asked

Detection and response, answered

What is endpoint detection and response?

EDR is software on a device that records what happens on it — processes started, command lines, registry and file changes, network connections — and detects patterns in that record. The recording is as important as the detection: it is what allows someone to reconstruct afterwards what an attacker actually did, which antivirus alone cannot support.

What is the difference between EDR and antivirus?

They answer different questions. Antivirus asks whether a file is known to be malicious and blocks it, which is valuable and cheap. EDR asks what happened on this machine and keeps enough detail to reconstruct it. Prevention without recording means that when something does get through — and eventually something does — you have no way to establish what it reached. Modern endpoint products usually do both; the distinction is about which capability you are actually paying for.

What is the difference between EDR, XDR and MDR?

EDR is a technology that watches endpoints. XDR is a platform that correlates endpoint telemetry with other sources such as network, identity, email and cloud. MDR is a service — people who operate the technology, investigate what it produces and respond. The first two are things you buy; the third is someone doing the work. You can have MDR delivered on top of EDR alone, or on top of a genuinely broad XDR, and those are very different services sold under the same three letters.

How does SIEM fit alongside these?

A SIEM collects logs from anything that produces them, retains them and correlates them. Its strengths are breadth and evidence — it will hold the audit trail an investigation needs, including from systems no agent can reach. Its weakness is that it has no opinion and takes no action. Detection tools decide; a SIEM records. Most mature setups run both, and our managed SIEM page covers that side.

What is the single most important question to ask an MDR provider?

Which telemetry sources they will actually ingest for you. Not which product they use — which sources. A service watching only endpoints cannot detect an intrusion that runs entirely through your identity provider or your cloud tenant, no matter how good its endpoint tooling is. The grid above shows five real attacks and which sources would have seen each one; three of the five never meaningfully touch an endpoint.

Do modern attacks really avoid endpoints?

Increasingly, yes, and it is the main reason endpoint-only coverage has become risky. Stolen session tokens replayed from an attacker’s own browser, OAuth consent abuse, mailbox rules that hide replies, and valid credentials used through legitimate remote access all leave clear traces in identity, cloud and email logs, and almost nothing on a managed laptop. Nothing needs to execute for significant damage to occur.

What does XDR actually extend to?

There is no standard, which is the honest answer. Some products correlate endpoint, network, identity, email and cloud genuinely. Others are endpoint tools with a couple of extra connectors and a newer name. Ask any vendor for the specific list of sources ingested in your environment, and compare that list rather than the category label.

Which systems cannot run an agent?

There are always some: servers under strict change control, unsupported or legacy operating systems, network appliances, OT and industrial equipment, and contractor or unmanaged devices. It matters because that set is precisely where an attacker prefers to operate. The answer is usually network and identity telemetry covering what the agent cannot reach, plus a documented, accepted gap where even that is not possible.

How is MDR priced?

Usually per endpoint or per user per month, sometimes per ingested data volume where a SIEM sits underneath. The variables that move it are how many telemetry sources are ingested, retention length, and how much response authority you grant. Compare quotes on the same source list — two MDR quotes covering different telemetry are not comparable numbers even when the per-endpoint price looks similar.

What response actions should be pre-authorised?

Commonly host isolation, killing a process, disabling an account and blocking a hash or domain. Each should be a named item on a written list with a stated authority level, agreed before go-live. “Response included” is not an answer — it is the phrase that hides the difference between a provider who acts at 3 a.m. and one who telephones you and waits.

Can you work with the EDR we already own?

Yes, and it is a common arrangement. Where you have already licensed a capable platform, the sensible engagement is people and process on top of it rather than a rip and replace. What we would want to establish first is which sources it covers and which it does not, because that determines whether anything else needs adding alongside it.

How does this relate to your managed SOC service?

Managed SOC is the whole security operations function — monitoring, detection, investigation, reporting and the contract around all of it. This page is about the detection layer underneath: which technologies collect what, and therefore what any service built on them can possibly see. Many organisations buy MDR first and a fuller SOC engagement later, which is a reasonable order.

Is threat hunting included?

It is a separate discipline and we treat it as one rather than folding it into a detection product. Detection is automated and reactive; hunting is a person asking a question nobody wrote a rule for. Both are worth having and they are not substitutes — see threat hunting.

What happens in the first ninety days?

Deployment is quick; tuning is not, and tuning is what decides whether the service works. Expect a noisy first few weeks while normal behaviour on your estate is learned, then a steady fall in false positives as detections are adjusted. A provider who does not describe this phase honestly is either not doing it or has not run a deployment recently.

Next step

Tell us what you are already collecting

Which endpoint tool you run, whether your identity provider and cloud tenant logs go anywhere, and how much of the estate cannot take an agent. From that we can say what an attacker could currently do without being seen — which is a more useful starting point than a product demonstration.

sanjay@pjnetworks.com