{"id":100813,"date":"2019-08-12T06:00:12","date_gmt":"2019-08-12T13:00:12","guid":{"rendered":"https:\/\/www.paloaltonetworks.com\/blog\/?p=100813"},"modified":"2019-08-13T21:46:07","modified_gmt":"2019-08-14T04:46:07","slug":"xdr-gains-traction-customers-analysts-vendors-embrace-new-category","status":"publish","type":"post","link":"https:\/\/www2.paloaltonetworks.com\/blog\/2019\/08\/xdr-gains-traction-customers-analysts-vendors-embrace-new-category\/","title":{"rendered":"XDR Gains Traction as Customers, Analysts, Vendors Embrace New Category"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">Palo Alto Networks founder Nir Zuk last year called for <\/span><a href=\"https:\/\/youtu.be\/c71uPTimW_A?t=2677\" rel=\"nofollow,noopener\" ><span style=\"font-weight: 400;\">radically transforming the security market<\/span><\/a><span style=\"font-weight: 400;\"> by creating a new product category for endpoint protection: XDR. We launched the category in February with the release of Cortex XDR and other players have announced their intent to enter the XDR market soon.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">XDR is the next leap forward for endpoint detection and response (EDR). We replaced the \u201cE\u201d in EDR with an <\/span><b>\u201cX\u201d<\/b><span style=\"font-weight: 400;\"> to show that we have expanded<\/span> <span style=\"font-weight: 400;\">detection and response beyond the endpoint - adding integration with the network, the cloud and all of the data subsets that flow through those sources.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The need for XDR was validated early on by analyst firms including <\/span><a href=\"https:\/\/ovum.informa.com\/resources\/product-content\/2019-trends-to-watch-cybersecurity-int003-000295\" rel=\"nofollow,noopener\" ><span style=\"font-weight: 400;\">Ovum<\/span><\/a><span style=\"font-weight: 400;\"> and <\/span><a href=\"https:\/\/zkresearch.com\/blog\/2018\/09\/edr-is-dead-long-live-xdr\/\" rel=\"nofollow,noopener\" ><span style=\"font-weight: 400;\">ZK Research<\/span><\/a><span style=\"font-weight: 400;\">. They recognized that modern attackers don\u2019t just target endpoints, but instead aim their sights on an organization\u2019s entire infrastructure. Point products that each only see a tiny slice of the technology stack don\u2019t provide sufficient context or insight to understand how an attack progresses. What\u2019s worse, they generate a huge number of false positive alerts that increase workloads and obscure visibility into the real threats.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For an XDR product to effectively solve these challenges, it must be:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Offered as a single cloud-based product for unrestricted accessibility and scale<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Able to collect, correlate and analyze data from network, endpoint and cloud within a single repository offering at least 30 days of historical retention<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Designed with embedded machine learning and automation that reduces manual efforts for security users<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Able to reduce future risk and continually strengthen prevention by applying knowledge gained through detection, investigation and response<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">After we <\/span><a href=\"https:\/\/start.paloaltonetworks.com\/new-era-of-detection-and-response-begins.html\"><span style=\"font-weight: 400;\">released Cortex XDR<\/span><\/a><span style=\"font-weight: 400;\"> in February as the industry\u2019s first XDR product, it quickly gained traction helping security operations teams make sense of the hundreds or thousands of isolated, low-fidelity alerts that they receive daily. By integrating multiple tools and data sources into one, Cortex XDR provides greater visibility and efficiency, while delivering machine learning-aided capabilities that allow analysts of all skill levels to quickly and easily respond to attacks.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Cortex XDR has gained strong momentum with enterprise customers since its release. The feedback has been overwhelmingly positive. Cortex XDR has also proven its mettle in third-party testing \u2013 recently<\/span><a href=\"https:\/\/www.paloaltonetworks.com\/detection-response\/xdr\/mitre\"> <span style=\"font-weight: 400;\">delivering the most (and best) detections of all products <\/span><\/a><span style=\"font-weight: 400;\">examined in the MITRE ATT&amp;CK APT-3 evaluation.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Other security providers have noticed our success. Several startups and legacy technology vendors have announced plans to build <\/span><a href=\"https:\/\/www.paloaltonetworks.com\/resources\/whitepapers\/redefine-security-operations-with-xdr\"><span style=\"font-weight: 400;\">XDR<\/span><\/a><span style=\"font-weight: 400;\"> solutions over the past few months, including one announcement last week. This category growth reflects market recognition of the reality that security operations teams have a critical need that siloed endpoint protection tools cannot meet.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">We will continue to push the limits of innovation in this category as we build new capabilities to help security teams win against sophisticated attackers. Cortex XDR already supports the widest set of operating systems and delivers the broadest visibility and enforcement, and we\u2019re getting better every day. We are pleased to see others working to enter the XDR category; we truly believe it will deliver a brighter and more secure future for organizations everywhere.<\/span><\/p>\n<p><strong><em>To learn how Cortex\u00a0<span class=\"il\">XDR<\/span>\u00a0stacks up against traditional EDR products in testing using the independent MITRE ATT&amp;CK framework, click\u00a0<a href=\"https:\/\/www.paloaltonetworks.com\/detection-response\/xdr\/mitre.html\">here<\/a>.<\/em><\/strong><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Palo Alto Networks founder Nir Zuk last year called for radically transforming the security market by creating a new product category for endpoint protection: XDR. We launched the category in February with the release of Cortex XDR and other players have announced their intent to soon enter the XDR market. <\/p>\n","protected":false},"author":632,"featured_media":100814,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[6770],"tags":[6737,6735],"coauthors":[6734],"class_list":["post-100813","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-secure-the-future","tag-cortex-xdr","tag-xdr"],"jetpack_featured_media_url":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2019\/08\/XDR-image-1.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/100813","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/users\/632"}],"replies":[{"embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/comments?post=100813"}],"version-history":[{"count":7,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/100813\/revisions"}],"predecessor-version":[{"id":101546,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/100813\/revisions\/101546"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/media\/100814"}],"wp:attachment":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/media?parent=100813"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/categories?post=100813"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/tags?post=100813"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/coauthors?post=100813"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}