CrowdStrike and Qualys officially rolled out their extended detection and response (XDR) modules this week during what was supposed to be the first in-person RSA security conference in two years.

Both companies say their technology solves enterprises’ threat detection and response pain points. And neither are alone in this claim as customers seek out unified visibility across the security stack and a simplified platform approach while vendors fight for customers in a consolidating market.

XDR combines elements of security information and event management (SIEM); security orchestration, automation, and response (SOAR); endpoint detection and response (EDR); and network traffic analysis (NTA) in a software-as-a-service platform to centralize security data and incident response.

Qualys’ XDR module, announced today, puts a premium on providing context — in fact, it’s named Context XDR.

Qualys Context XDR

“Two overly used cliches in our industry: finding the needle in the haystack and increasing the signal to noise ratio,” said Qualys’ Hiep Dang, VP of product management for EDR. But while overly used, they are key to a successful security strategy.

“Every vendor will say we do that better than everyone else,” Dang said. “But the end of the day, whether it be EDR or SIEM or even network clients, they’re regurgitating data to their users and leaving it up to the users to sift through all that noise to be able to detect and take action on it.”

Qualys’ XDR, on the other hand, offers users clarity by providing context into their risk posture via the vendor’s well-known vulnerability management and threat intelligence capabilities, according to Dang. It also uses Qualys Cloud Platform for active asset discovery and policy-based criticality assignments, plus the vendor’s cloud-based agent and on-premises sensors for real-time log and telemetry data across third-party products.

“With our asset management, you get a full view of your corporate environment, but we allow our customers to be able to prioritize those assets,” Dang explained. “Not all assets are created equal. And from a vulnerability perspective: not all vulnerabilities are created equal.”

Qualys’ XDR provides security teams with this contextual priority, he added. For example, a vulnerability that is being actively exploited by malware on a chief executive’s computer or a highly sensitive server introduces a higher level of risk to the business than proof-of-concept academic exploit on a system in a test environment.

“That bubbles everything up to the top and really showcases to our customers where they should be focusing their attention on that which has the biggest business impact,” Dang said.

Larger Cloud Security Platform Play

Context XDR is also part of Qualys’ larger platform play. The vendor's cloud platform processes more than nine trillion data points across its native sensors and third-party logs. The vendor, widely known for its vulnerability and asset management, over the last few years has added cloud, container, and mobile security capabilities along with endpoint detection and response and now XDR.

The XDR module leverages this telemetry and the platform’s cloud agent response capabilities including patching, fixing misconfigurations, killing processes and network connections, and quarantining hosts.

“We are building up our portfolio, but the approach we are taking is uniquely different,” Dang said. Instead of adding new security capabilities by buying startups and then trying to piece the different technologies together, Qualys prefers to build new modules natively on top of its platform. And if it does acquire technology, it takes the product off the market for up to a year to ensure the integration works, Dang explained.

CrowdStrike Falcon XDR

Meanwhile, after talking about its XDR for the past year, and paying $400 million to buy Humio to advance the platform, CrowdStrike this week also announced the general availability of its Falcon XDR module.

It builds on CrowdStrike’s market-leading endpoint security product, and also uses telemetry from third-party data from vendors including CrowdXDR Alliance partners. In an earlier interview with SDxCentral, CrowdStrike CTO Mike Sentonas said the ability to ingest third-party data and correlate it with data from its Security Cloud makes its XDR unique and allows it to do real-time threat detection and response.

The new XDR module also uses Falcon Fusion, the vendor’s homegrown SOAR framework, to orchestrate and automate response across security workflows.

While both vendors’ approach XDR from their perspective strengths, CrowdStrike and Qualys both say they their XDR module provides multi-domain visibility and solves security analysts’ alert fatigue.

In a blog about its new module, CrowdStrike’s Nick Hayes cites his company’s 2021 Global Security Attitude Survey of 2,200 IT decision makers.

“When it comes to detection and response, the top limitation cited by nearly half (47%) of security pros is the siloed, disconnected nature of their security tools and data,” Hayes wrote. “Falcon XDR tackles this issue head-on, turning formerly cryptic signals from siloed systems into high-efficacy detections and deep investigation context. And with the console’s interactive graph explorer, security pros intuitively visualize and follow an entire multi-domain attack populated with full context for each step in the attack chain.”

CISOs Want Security Consolidation

Both CrowdStrike and Qualys plunge into XDR as CISOs look to consolidate security tools and converge network, endpoint, data, and workload security and telemetry.

“CISOs are coming to grips with the fact that they don’t have enough security people,” IDC Security and Trust Program VP Frank Dickson said in an earlier interview. “They’ve got hundreds of applications to protect, thousands of devices to protect, and too many security tools are making it hard to implement security. So we’re looking for more and more integrated solutions.”

And this makes XDR, long considered the holy grail of security, an especially appealing investment.

“Siloed security platforms — SIEMs, and EDR, and [network detection and response], and things like that — only give you a very small snippet of what’s going on in the environment,” ZK Research founder Zeus Kerravala said in an earlier interview. “Where you should be seeing the investment is the platform-based approach, products that ingest data from a whole bunch of different sources and use AI to look across the entire kill chain.”

Most vendors can’t provide full XDR across an entire enterprise IT environment, but that’s where partnerships and API integrations come into play. Kerravala suggests CISOs that do adopt XDR start with their biggest pain point, and he adds that EDR it a big part of XDR.

“To me the core components of XDR are network, cloud, and endpoint, and then you can build the rest around that,” he said. “If you don’t have good knowledge about what’s going on in the cloud, knowledge of what’s going to the network, and good knowledge going down to the endpoint, that’ll just leave them a bunch of blind spots.”