WhatDR or What Detection Domain Needs Its Own Tools? | by Anton Chuvakin | Anton on Security | Medium
This is the blog where I really (briefly) miss my analyst life and my “awesome+” peers like Augusto and Anna. It relies on ideas and comments from my past collaborators … and my current ones. And, yes, this blog was inspired by a hallways conversation at a conference that took place more than a year ago :-( So, the question: Bear with me for a moment as we ponder this mystery. Everybody knows EDR, some know NDR, a few ramble about XDR. We also have ITDR emerging (IMHO, ITDR is a bastard half-brother of UEBA). We talk of CDR for cloud. Some vendors tried to create DDR (for data). I almost forgot MDR (Gemini helpfully reminded me), but this is different (because service aka “rent a human”). There was once a clown who tried making VMDR (OMG, this is the dumbest, as it makes no sense whatsoever). ADR for Application Detection and Response is probably coming, because ASPM is here already (this eBPF observability stuff may yet lead to more odd-duck *DRs or RASP 2.0… but I digress). And, gods
This is the blog where I really (briefly) miss my analyst life and my “awesome+” peers like Augusto and Anna. It relies on ideas and comments from my past collaborators … and my current ones. And, yes, this blog was inspired by a hallways conversation at a conference that took place more than a year ago :-( So, the question: Bear with me for a moment as we ponder this mystery. Everybody knows EDR, some know NDR, a few ramble about XDR. We also have ITDR emerging (IMHO, ITDR is a bastard half-brother of UEBA). We talk of CDR for cloud. Some vendors tried to create DDR (for data). I almost forgo
Explore this link on the map →