Anton and The Great XDR Debate, Part 1 | by Anton Chuvakin | Anton on Security | Medium
Here, if you want TL;DR, my position on XDR today is “wait and see” (boring, huh?). Unlike some of my esteemed former colleagues, I don’t really have a horse in the race. First, a very brief bit of history. The origin of the term XDR (Extended Detection and Response) is disputed. Wikipedia (entry, reviewed 8/6/2021) has us believe that Palo Alto invented the term “in 2018.” Josh Zelonis points out that he in fact invented the term. My Googling for its earliest use didn’t yield any revelations. Today, I see several visions of XDR that are somewhat conflicting. So, let me outline them the way I understand them. So, some points of agreement: As a minor aside, somehow I never got to get myself to care deeply about “open” vs “native” XDR. If we don’t agree on what XDR is, this is not the time to debate variations and subspecies of it… And here is my favorite (Really?! No, not really…) list of XDR vs SIEM comparisons, just for fun: There you have it! Not bad for a Friday afternoon? :-) Relat
Here, if you want TL;DR, my position on XDR today is “wait and see” (boring, huh?). Unlike some of my esteemed former colleagues, I don’t really have a horse in the race. First, a very brief bit of history. The origin of the term XDR (Extended Detection and Response) is disputed. Wikipedia (entry, reviewed 8/6/2021) has us believe that Palo Alto invented the term “in 2018.” Josh Zelonis points out that he in fact invented the term. My Googling for its earliest use didn’t yield any revelations. Today, I see several visions of XDR that are somewhat conflicting. So, let me outline them the way I
Explore this link on the map →