Anton and The Great XDR Debate, Part 1 | by Anton Chuvakin | Anton on Security | Medium
Here, if you want TL;DR, my position on XDR today is “wait and see” (boring, huh?). Unlike some of my esteemed former colleagues, I don’t really have a horse in the race. First, a very brief bit of history. The origin of the term XDR (Extended Detection and Response) is disputed. Wikipedia (entry, reviewed 8/6/2021) has us believe that Palo Alto invented the term “in 2018.” Josh Zelonis points out that he in fact invented the term. My Googling for its earliest use didn’t yield any revelations. Today, I see several visions of XDR that are somewhat conflicting. So, let me outline them the way I understand them. So, some points of agreement: As a minor aside, somehow I never got to get myself to care deeply about “open” vs “native” XDR. If we don’t agree on what XDR is, this is not the time to debate variations and subspecies of it… And here is my favorite (Really?! No, not really…) list of XDR vs SIEM comparisons, just for fun: There you have it! Not bad for a Friday afternoon? :-) Relat
3 min read Aug 6, 2021 -- I know you may hate me for this, but I‘ve been finally tempted into the Great XDR Debate. Here, if you want TL;DR, my position on XDR today is “wait and see” (boring, huh?). Unlike some of my esteemed former colleagues, I don’t really have a horse in the race. First, a very brief bit of history. The origin of the term XDR (Extended Detection and Response) is disputed. Wikipedia (entry, reviewed 8/6/2021) has us believe that Palo Alto invented the term “in 2018.” Josh Zelonis points out that he in fact invented the term. My Googling for its earliest use didn’t…
related reading
- WhatDR or What Detection Domain Needs Its Own Tools?medium.com
- Is the SIEM dead? - CPO Magazinecpomagazine.com
- Panther Labs' Jack Naglieri on Cloud-Native SIEM and Self-Growthmadrona.com
- Create custom detection rules in Microsoft Defender XDR - Microsoft Defender XDR | Microsoft Learnlearn.microsoft.com
- Empowering Threat Detection With Custom Detections in EDRtruesec.com
- Report: The Era of Endpoints | A Contrary Research Deep Dive | Contrary Researchresearch.contrary.com
- The Race to $100B: The Palo Alto Networks Storyrakgarg.substack.com
- EDR Internals for macOS and Linuxoutflank.nl
- The Evolution of the Modern Security Data Platformsoftwareanalyst.substack.com
- Perimeterperimeter.bio
- Lessons learned from EDR Bypass threat hunting | by Cristóbal Martínez | Mediummedium.com
- The dotted lines between Threat Hunting and Detection Engineering | by Alex Teixeira | Detect FYIdetect.fyi