G DATA XDR: The most important questions from practice
(This text was translated from English into German with the help of AI.)
Which companies benefit from XDR?
In short: most of them. The need for protection has increased in recent years across all industries β and with it, the requirements for effective defense. G DATA XDR extends classic endpoint protection with additional sensors and links the information from all endpoints within a company. Instead of looking at each device in isolation, this creates an overall picture of all activity on the network, resulting in a significantly higher level of protection.
This topic is especially relevant for companies that must meet regulatory requirements, for example those affected by NIS2 β as an important or particularly important entity, or in the field of critical infrastructure. The directive requires protection in line with the "state of the art" and explicitly names solutions such as XDR as one way to fulfill monitoring requirements.
But even independent of regulatory obligations, one thing holds true: a security incident quickly becomes expensive. Anyone who invests in a higher level of protection today may save significant costs tomorrow on incident response and infrastructure recovery.
What is the difference between XDR and EDR?
To understand the difference, it helps to look at the full range of protection technologies:
- Antivirus solutions detect threats based on signatures and certain behavioral patterns. The focus here is on the individual endpoint.
- Endpoint Detection and Response (EDR) continues to keep an eye on the endpoint but adds detection and response capabilities. This also brings into focus activities that are not clearly malicious but suspicious β such as admin tools like PsExec, which attackers also abuse to move around the network and escalate their privileges. These so-called living-off-the-land attacks only become visible with EDR solutions.
- Extended Detection and Response (XDR) takes a decisive step further and shifts the focus from the individual device to the entire corporate network. With a modern web console, XDR can be managed centrally without a dedicated management server. More sensors, more data points, and more correlation mean: if the same behavior is suddenly detected on multiple devices, it can be assessed in context. Is it a known, regularly used, and legitimate program, or a new, potentially dangerous tool?
With EDR and XDR, users get more context and more accurate assessments, resulting in fewer false alarms alongside a higher detection rate.
Who is the TAM service (Technical Account Management) designed for β customers or partners?
Both β though with a slightly different scope. MSP partners already receive support through the integrated MSP service from the outset, from the portal introduction to onboarding their own customers. Anyone who additionally wants ongoing, personal support can also book the MSP TAM service β for example, for questions about scripts or for remote assistance in the event of a fault.
End customers can optionally add the TAM service and likewise receive continuous support from our Technical Account Management team.
The common denominator: companies decide for themselves how much personal support they need β from standard operations all the way to close 24/7 support.
How do you migrate from endpoint protection to XDR?
The scope of the migration depends, among other things, on whether a company is migrating as a partner or as an end customer, and how large the IT environment is. Among other things, it matters whether it involves just a few individual devices or a double- or triple-digit number of clients that are already connected to a software distribution system.
To ensure a smooth transition, the TAM service uses suitable scripts to uninstall the existing solution and install G DATA XDR. In addition, a migration assistant is also available: systems can be migrated directly via the tree structure in the administrator console.
Our tip: for larger-scale migrations, it is worth working with our TAM team. Our colleagues have experience with many different environments and will find the right approach for every company.
Which operating systems are supported?
G DATA XDR covers the relevant range of operating systems:
- Windows, including Windows on ARM β new compared to classic Endpoint Protection
- Linux, with full protection including sensors and scanning
- macOS
- mobile devices, if companies add Mobile Device Management as an add-on
Important: the currently supported versions of each operating system are covered. Systems that have reached end of life, such as outdated Linux distributions, will eventually fall outside the scope of protection. This is not a coincidence but follows a simple principle: a level of protection is only ever as strong as the security of the underlying system.
What is the difference between G DATA XDR and G DATA Managed XDR (MXDR)?
Both products are based on the same platform. The difference lies in who handles the security alerts:
- With G DATA XDR, companies operate the product themselves. They configure settings, assess alerts, and decide on measures. This requires appropriate specialist staff in-house.
- With G DATA Managed XDR, experienced security analysts in our Security Operations Center (SOC) in Bochum take on this task β around the clock, seven days a week. The analysis team filters out the truly relevant alerts and issues concrete recommendations for action, or, by prior agreement, initiates measures directly.
Switching between the two, by the way, is straightforward: since XDR and MXDR run on the same platform, you can upgrade to the managed variant with SOC support at any time as your needs grow.
Which activities and information are monitored on the endpoints?
G DATA XDR's sensor technology is deliberately broad-based β with variations depending on the operating system. The interplay is especially clear using Windows as an example:
- classic signature-based antivirus scanning of files,
- process activity and a look into the memory of running processes, in order to reliably detect unpacked malware as well,
- registry and network events, which are assessed in context,
- suspicious login activity β a sensor capability that is new with XDR
From this information, a behavioral graph is created locally on the endpoint, revealing suspicious patterns. In addition, aggregated data is transmitted to our backend, where it is correlated and assessed across devices. This makes it possible to detect attacks that appear less suspicious when looked at on a single endpoint alone, such as living-off-the-land attacks. Only through correlation and assessment across other endpoints does a different picture emerge, turning it into a detection. For companies, this means: threats are not only detected faster, but also assessed in the right context.
For more information on G DATA XDR, visit our website.
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content β general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached β you'll always get the same 5 for this article.