EDR, MDR & XDR Explained

Поділитися
Вставка
  • Опубліковано 22 тра 2024
  • Traditional antivirus is no longer sufficient to protect you. Everyone running a business should upgrade to EDR, MDR, or XDR immediately; but what is the difference between them, and how do SIEM and SOAR fit into the picture? Time to unravel the acronyms!
    📄 Acronym cheat sheet:
    EDR: Endpoint Detection and Response
    MDR: Managed Detection and Response
    XDR: eXtended Detection and Response
    MXDR: Managed eXtended Detection and Response
    SIEM: Security Information and Event Management
    SOAR: Security Orchestration, Automation, and Response
    SOC: Security Operations Centre
    MSP: Managed Services Provider
    MSSP: Managed Security Services Provider
    💬 Follow Me
    / andrewmrquinn
    Video timestamps:
    0:00 - EDR
    3:11 - MDR
    4:41 - XDR
    5:33 - Comparison with SIEM + SOAR
    9:20 - Summary
    #EDR #MDR #XDR #SIEM #SOAR #CyberSecurity #SOC #MSSP
  • Наука та технологія

КОМЕНТАРІ • 42

  • @rockychau2451
    @rockychau2451 3 місяці тому +10

    one of the best explanation so far on UA-cam

    • @ProTechShow
      @ProTechShow  3 місяці тому +1

      Thanks 🙂

    • @Wahinies
      @Wahinies Місяць тому

      Yes and I am catching it at the perfect time. Many thanks @ProTechShow

  • @wizardofwifi
    @wizardofwifi 5 днів тому

    This is a great summary of these topics, Cybersecurity 101 foundation, simply explained!

  • @neomatrix2091
    @neomatrix2091 4 місяці тому +4

    Very nice breakdown, i appreciate your effort on presenting these concepts on a simplified manner for us to understand!

  • @andrewmurray5255
    @andrewmurray5255 10 місяців тому +2

    Amazing breakdown. Thank you!

    • @ProTechShow
      @ProTechShow  10 місяців тому

      Thanks. Glad it's useful!

  • @marcioguedescavalcante3094
    @marcioguedescavalcante3094 8 місяців тому +2

    Oh man, thank you so much to make this!

    • @ProTechShow
      @ProTechShow  8 місяців тому

      You're welcome. Glad it's of use!

  • @user-ur5br3ne9h
    @user-ur5br3ne9h 5 місяців тому +2

    excellent high level explanation of these technologies.

  • @richlab2927
    @richlab2927 2 місяці тому +1

    Love your explanation. You made it simple

  • @hammamiahlem9792
    @hammamiahlem9792 7 днів тому

    amazing explanation ! thank you

  • @eek0212
    @eek0212 8 днів тому

    I was sick of all those security acronym terms, thanks for the video mate

    • @ProTechShow
      @ProTechShow  7 днів тому

      You're welcome. Glad it was useful.

  • @nitram419
    @nitram419 9 місяців тому

    Many thanks indeed for a great tutorial! I just have a question about the restoring the system image created using the built-in Windows backup tool **to a brand new SSD**. Here's my scenario:
    ~ I have one NVMe SSD slot, with my OS C: drive on it.
    ~ In Windows I make an system image of the above, using the Windows backup tool;
    ~ I also make a Windows DVD bootable DVD (ie. with the recovery tools).
    ~ I turn off & unplug the PC and remove the old NVMe drive.
    ~ I insert a brand new and bigger NVMe drive in the slot where the old one used to be.
    ~ I boot the machine using the DVD-ROM Windows bootable recovery tools disk.
    Question: How do I get the image onto the brand new unformatted NVMe drive, and assign it as the "C" drive?
    Most grateful for your advice!

  • @Israelxox
    @Israelxox 5 місяців тому

    Underrated video! Thanks 🙏

  • @notevenfalse
    @notevenfalse Місяць тому

    A+ content mate. All I can say is thank you.

  • @user-kn3yr3sg7x
    @user-kn3yr3sg7x 10 місяців тому +1

    Thank you for video 😊

  • @MENTOKz
    @MENTOKz 6 місяців тому

    thanks man just starting to learn are XDR tool trend micro one

  • @elijahcrawford3049
    @elijahcrawford3049 20 днів тому

    ....and now my 8 page research paper due today makes sense.....thank you!

  • @asdkjh4370
    @asdkjh4370 10 місяців тому +2

    Thanks for video. Many thanks for valuable advice. Something on OpenHAB maybe? I'm looking for something to switch from HA which is going strange way. Any new updates?

    • @ProTechShow
      @ProTechShow  10 місяців тому

      OpenHAB 4 is expected to land in a couple of weeks. 2 and 3 were quite significant updates, so it'll be interesting to see what 4 brings to the table.

  • @EducateWithMe573
    @EducateWithMe573 22 дні тому

    Edr End Point Response, Adr data breach, for future & Rdr are all separate packages of…?

  • @EducateWithMe573
    @EducateWithMe573 22 дні тому

    mDR eDR & xDr , what is the diff?

  • @kaentertainment2215
    @kaentertainment2215 2 місяці тому

    How does EDR defend against Zero Day Exploits given its primary focus on detecting suspicious patterns from historical occurrences?

    • @ProTechShow
      @ProTechShow  2 місяці тому

      Let's say you have an internet-facing web app with a zero-day vulnerability. It gets exploited to drop a web shell onto the server. The vulnerability was previously unknown, and the web shell doesn't match any known malware patterns.
      EDR/antivirus may not initially detect the exploit or the web shell as malicious, but EDR will see the file creation/modification by the web server process, followed by it attempting to spawn child processes or execute commands that are not typical behaviour of a web server. It doesn't require knowledge of the vulnerability itself to detect suspicious behaviour resulting from its exploitation and take action - raising an alert, removing the file, isolating the system, etc.

  • @riccardo1434
    @riccardo1434 8 днів тому

    Hello, I've got some questions: is EDR a software agent that needs to be installed on each endpoint?
    while XDR is centralized or does it need to be installed on every endpoint like EDR? In order to monitor endpoint, firewall, cloud, network, etc. etc. activities to perform analysis, threat intelligence and response?
    Also, does XDR need EDR to collect activity information or does it completely replace EDR?

    • @ProTechShow
      @ProTechShow  7 днів тому

      Usually, EDR is a software agent that gets installed on endpoints and checks in to a central location, similar to most business antivirus solutions. XDR does this as well, but additionally consumes data from other devices - usually via API calls or syslog.

  • @ChapalPuteh_
    @ChapalPuteh_ 3 місяці тому

    We use only XDR and EDR to operate our incident in the network ..

  • @paulj9657
    @paulj9657 3 місяці тому

    Not acronyms. They are initialisms. :-) Great info. Thanks.

    • @ProTechShow
      @ProTechShow  3 місяці тому

      You are... correct. They are initialisms.

    • @paulj9657
      @paulj9657 3 місяці тому

      Sorry, my dad was an English teacher. :-). I'm not that pedantic in real life.

  • @iamagastya0
    @iamagastya0 Місяць тому

    i think toyota have better CooL cars