# 2. EDR, XDR, MDR: Endpoint and Extended Detection

Share
# 2. EDR, XDR, MDR: Endpoint and Extended Detection

This space is mature, crowded, and genuinely confusing because vendors have blurred the lines between EDR, XDR, and MDR to the point where the acronyms are nearly meaningless in marketing materials. Let's fix that.


Context: EDR (Endpoint Detection & Response) protects endpoints. XDR (Extended Detection & Response) promises to correlate signals across endpoint, network, identity, cloud, and email, but most "XDR" is just EDR with a few extra log sources. MDR (Managed Detection & Response) is a service layered on top of EDR/XDR, where humans (theirs) watch the tools so your team doesn't have to. The vendor market loves to conflate these. Your job: figure out what you're actually buying, who's actually responding, and whether it'll work in your environment, not the demo.


13 Questions to Ask EDR/XDR/MDR Vendors

1. "Are you selling me a product (EDR/XDR), a service (MDR), or both, and where exactly does your responsibility end and mine begin?"
Why: This is the single most misunderstood line in the entire category. Many breaches happen in the gap between "the vendor detected it" and "someone actually did something about it."
Good answer: A written, role-by-role RACI matrix. Red flag: "We work as an extension of your team" with no specifics.

2. "For your XDR claim, list every data source you natively ingest, parse, and correlate, versus those you just accept logs from."
Why: "Ingesting" a log is not the same as understanding it. Real XDR correlates across sources; fake XDR is a SIEM-lite with a fancy name.
Good answer: A clear list with depth-of-integration tiers. Red flag: "We integrate with everything via API."

3. "What's your mean time to detect (MTTD) and mean time to respond (MTTR) for MDR customers, measured how, and reported how often?"
Why: If they can't quantify this, they're not running a mature service. If the numbers seem too good (e.g., "5 minutes MTTR"), ask for the methodology.
Good answer: Honest metrics, defined per severity tier, with quarterly reporting. Red flag: Aspirational SLAs with no measurement methodology.

4. "When your MDR analyst detects something at 3am on a Sunday, what exactly do they do, autonomously, with my approval, or just notify me?"
Why: Response authority is everything. "We'll call you" at 3am is not response, that's a notification service. Real MDR has pre-authorized containment actions.
Good answer: Tiered response playbook with pre-approved actions (isolate host, kill process, disable account). Red flag: "We'll always coordinate with your team first."

5. "Show me the actual SOC. How many analysts, what shifts, what locations, what certifications, and what's their average tenure?"
Why: MDR economics force many providers to lean on junior analysts and overseas tier-1 teams. You're paying for human expertise, verify it exists.
Good answer: Named SOC locations, 24/7/365 with follow-the-sun, defined L1/L2/L3 escalation, low attrition. Red flag: "We have a global team" with no specifics, or refusal to disclose.

6. "What's your detection engineering process? How often are new detections shipped, and can I see your detection coverage mapped to MITRE ATT&CK?"
Why: MITRE coverage isn't a silver bullet, but it's the closest thing to a common language. A vendor who can't show you their coverage map is hiding something.
Good answer: Live or quarterly-updated MITRE heatmap, named detection engineering team, weekly+ release cadence. Red flag: "We cover all of MITRE" (no one does).

7. "How do you handle EDR evasion, unhooking, BYOVD (bring your own vulnerable driver), in-memory attacks, and tampering with your agent?"
Why: Modern attackers specifically target EDR agents. If a vendor hasn't deeply considered self-protection, they're shipping a paper tiger.
Good answer: Specific anti-tampering, kernel-level protections, tamper alerts, behavioral detection of evasion attempts. Red flag: "Our agent can't be disabled" (everything can; the question is whether you'll know).

8. "What's your agent's performance impact, CPU, memory, disk I/O, under normal load and during a scan? Show me real telemetry, not a datasheet."
Why: Endpoint teams hate security agents that slow user machines. Adoption fails when developers and execs uninstall the agent or whitelist their own laptops.
Good answer: Published benchmarks, customer testimonials, trial-period data from your own environment. Red flag: "<2% CPU" with no methodology.

9. "What happens to detection if my endpoints are offline, on a plane, or behind a captive portal? Does the agent still detect and respond locally?"
Why: Cloud-native EDR is fine until your salesperson is in a hotel and gets phished. Local detection logic matters.
Good answer: Local detection engine, offline buffering, autonomous response capabilities. Red flag: "We're cloud-native" without any local detection story.

10. "When I terminate the contract, what happens to my data, my detections, my custom rules, and my historical investigations? Can I export everything?"
Why: Vendor lock-in in this space is real and painful. Migration projects can take 6–12 months. Get exit terms in writing before you sign.
Good answer: Documented export formats (JSON, CEF, etc.), retention guarantees, transition support. Red flag: "We don't typically have customers leave" (deflection).

11. "Walk me through a real customer breach you contained end-to-end. What was detected, when, by whom, what was done, and what was missed?"
Why: Forces a story with edges and lessons learned. Vendors who only tell heroic stories are hiding something, every real incident has misses.
Good answer: A candid retrospective including what didn't go perfectly. Red flag: Sanitized hero-narrative with no flaws.

12. "How do you integrate with my existing SIEM, SOAR, ticketing system, and identity provider? And critically, do those integrations cost extra?"
Why: Integration tax is the hidden line item. Vendors love quoting the base license, then add $50K for the SIEM connector you actually need.
Good answer: Documented integrations included in license, API access standard, no per-integration fees. Red flag: "Premium integrations are tiered."

13. "What's your stance on threat intelligence, do you produce your own, license it, or both? Can I see a sample of your proprietary intel from the last 30 days?"
Why: Many vendors resell intel and call it proprietary. Asking for a sample exposes whether they have a real intel team or just license feeds.
Good answer: Named threat research team, public reporting cadence, original research. Red flag: "Our intel comes from many sources."

14. (Bonus, especially for MDR) "If I have an incident that escalates to a full IR engagement, is that included, or do you bill separately at $500+/hr, and who actually does the IR work?"
Why: The dirty secret of MDR: the moment things get serious, many providers hand you off to a partner IR firm at full rate. Know this before you need it.
Good answer: Clear inclusion limits (e.g., "X hours of IR per year included"), named IR team or partner, transparent billing. Red flag: "We'll handle anything that comes up" with no contractual specifics.


🎯 The Meta-Test

If a vendor sells "XDR" but can't crisply answer Q2 and Q6, they're selling EDR with marketing makeup.
If a vendor sells "MDR" but can't answer Q4 and Q5, they're selling alert forwarding, not detection and response.
Ask Q1, Q4, and Q14 in writing. The answers belong in your contract, not their slide deck.


Read more