Three Different Categories, Not Three Tiers
EDR
Endpoint Detection & Response. A software agent on laptops, servers, and workstations that captures telemetry, detects suspicious behavior, and enables response actions on that device. The baseline building block for endpoint security.
XDR
Extended Detection & Response. Aggregates and correlates telemetry across endpoints, network, cloud, identity, and email into one platform, unifying detection and response workflows across the whole stack instead of one layer at a time.
MDR
Managed Detection & Response. A vendor-operated service that uses EDR, XDR, or similar telemetry as its raw material, then adds 24/7 human monitoring, triage, threat hunting, and active response. You are buying an outcome, not a console license.
In short: EDR and XDR generate telemetry and alerts. MDR investigates those alerts, validates real threats, and responds — with people, not just software. A meaningful MDR program is almost always built on top of EDR or XDR tooling, not a replacement for it.
Where the Confusion Comes From
Vendors sell both the tool and, increasingly, the managed layer on top of it — so a single company might sell you “XDR” as a self-managed platform and “MDR” as the fully staffed version of the same telemetry pipeline. That’s legitimate, but it means the acronym alone doesn’t tell you whether a human is watching it at 2 a.m. Ask directly: is this a console I have to staff, or a service someone else staffs for me? That question resolves the confusion faster than the acronym does. See MDR vs. MSSP for the related distinction between response-included and alerting-only services.
Frequently Asked Questions
Not Sure Which Layer You’re Missing?
Tell us what’s already deployed in your environment. We’ll tell you plainly whether you have a tooling gap, a staffing gap, or both.