XDRShield features

All XDRShield features for endpoint security operations.

Explore the complete XDRShield feature set for endpoint visibility, detection, investigation, governed response, policy control, and service-provider-ready tenant operations.

Endpoint detection and responseXDR operationsMSP / SOC ready

Capability map

Endpoint visibility, detection, investigation, and response in one operating view.

XDRShield organizes security work around the way teams operate each day: understand endpoint coverage, identify risky signals, investigate with evidence, act with control, and keep tenant-specific accountability visible.

XDRShield security operations dashboard full console view spanning endpoint coverage, alerts, cases, and response modules

Endpoint healthAlert pressureCase operationsActive agents

Console-led operations

Security teams can move from estate awareness to investigation without losing operational context.

The dashboard view brings endpoint coverage, alert volume, case pressure, telemetry trends, and agent activity into one starting point. From there, analysts can move into alerts, events, hunts, cases, response actions, policies, and activity records with tenant scope intact.

  • Review endpoint coverage and telemetry freshness before triage.
  • Use alerts, events, and hunts to validate what needs investigation.
  • Move confirmed issues into cases with ownership and timelines.
  • Govern containment actions with requester, approver, and result context.

Detection engineering

Create alert, file integrity, registry, process, metrics, antivirus, URL filtering, and IOC rules that match the monitored endpoint scope.

  • Default rule templates
  • Rule-to-policy mapping
  • Signal quality review

Policy management

Turn rules into reusable security baselines that can be assigned to compatible endpoints and reviewed by tenant or operating scope.

  • Reusable policy sets
  • Agent assignment
  • Synchronization review

Event and alert management

Prioritize endpoint signals with severity, status, asset context, acknowledgement, and event evidence available for triage.

  • Alert queues
  • Event telemetry
  • Status and severity filters

Threat hunting and cases

Search retained evidence, save useful hunts, correlate alerts into cases, assign ownership, and preserve the investigation timeline.

  • Saved hunts
  • Case lifecycle
  • Timeline and notes

Governed endpoint response

Request and track supported actions such as host isolation, process termination, user disablement, IOC blocking, and release workflows.

  • Containment controls
  • Approval context
  • Execution history

Visibility and inventory

Understand agent health, system metrics, installed packages, vulnerabilities, software deployment status, and monitored network devices.

  • Asset context
  • Package visibility
  • Network monitoring
Why XDRShield is different

Built for controlled security operations, not just another alert queue.

Security teams need confidence that their tools can collect useful evidence, preserve tenant boundaries, guide investigation, and support response without creating uncontrolled disruption.

Detection that adapts to your environment

XDRShield gives teams the building blocks for environment-aware detection: file integrity monitoring, registry monitoring, process rules, metrics rules, alert rules, URL filtering, antivirus monitoring, and IOC blocking. The goal is practical detection logic that maps to policy scope and can be reviewed.

Response with governance

Containment actions can protect operations, but they can also disrupt them. XDRShield response workflows keep requester, approval, execution, error, retry, and activity context visible so analysts can move quickly without losing accountability.

Investigation that keeps the record intact

Alerts, events, hunts, cases, timelines, notes, and supporting evidence remain connected. That helps SOC teams explain what happened, what was done, who owns the next step, and what still needs review.

Architecture for MSP and multi-tenant SOC operations

Provider, customer, tenant, and workspace boundaries help service teams standardize security operations while keeping each customer’s evidence, policies, users, and reporting scope separated.

Endpoint evidence and policy control

Connect monitored endpoint data with the rules and policies that define action.

XDRShield helps teams keep endpoint security operations grounded in current evidence. Agent status, telemetry, package inventory, vulnerabilities, monitoring rules, and assigned policies stay connected so teams can validate coverage before they rely on a detection or response workflow.

Agent coverage

Review enrolled endpoints, health state, sync freshness, and version status.

Protection controls

Apply FIM, registry, process, metrics, AV, URL filtering, and IOC rules through policies.

Risk context

Use inventory, packages, metrics, and vulnerability visibility to prioritize triage.

XDRShield product view for endpoint coverage and operational security status

Workflow

From endpoint signal to verified resolution.

XDRShield keeps the operational path clear: collect trusted telemetry, prioritize what matters, investigate with evidence, respond with control, and preserve the record for review.

01

Detect

Collect file, registry, process, metric, URL, AV, IOC, inventory, vulnerability, and agent health evidence from managed endpoints.

02

Prioritize

Use rule scope, severity, status, deduplication, asset context, and vulnerability visibility to focus analyst attention.

03

Investigate

Move from events and alerts into hunts, cases, timelines, ownership, notes, and supporting evidence.

04

Respond

Request supported containment actions such as host isolation, process termination, user disablement, and IOC blocking.

05

Govern

Review activity records, tenant scope, roles, notification settings, policy history, and execution outcomes.

How XDRShield supports security operations

Built for security teams that need evidence, control, and tenant-safe execution.

XDRShield brings together the operational layers that matter when endpoint security work must be repeatable: endpoint telemetry, alert and event review, investigation queues, governed response, policy assignment, asset context, and service-provider administration.

XDRShield product view for alert, case, and response operations

Endpoint detection and response

Collect endpoint evidence, review alerts, validate event context, and connect findings to response workflows.

Threat hunting and case work

Search across retained evidence, preserve useful hunts, assign case ownership, and keep a timeline for handoff.

Governed response

Use controlled actions with requester, approval, target, execution, retry, and result visibility.

MSP-ready operations

Separate customer scope, tenant policies, users, notifications, branding, and reporting context for service delivery.

Endpoint detection and responseXDR operationsThreat huntingCase managementGoverned containmentPolicy managementTenant administrationAsset visibilityNetwork-device monitoringVulnerability context
XDRShield feature directory

Explore the full XDRShield capability set.

Review the endpoint monitoring, investigation, response, network visibility, policy, asset, and service-provider features that help teams operate XDRShield across customer and enterprise environments.

Multi-layer endpoint detection and monitoring

File Integrity Monitoring

Track changes to important files and directories so teams can identify unexpected modification, deletion, or creation activity with review-ready evidence.

What this helps teams do

  • Observe supported file and directory changes on enrolled endpoints
  • Use review workflows to separate expected change from suspicious activity
  • Connect file-change evidence with alerts, cases, and investigation timelines

Learn more about File Integrity Monitoring →

XDRShield product view for File Integrity Monitoring
Multi-layer endpoint detection and monitoring

Registry Key Monitoring

Monitor configured Windows registry locations to surface configuration changes, persistence attempts, and other endpoint activity that deserves investigation.

What this helps teams do

  • Track supported registry locations through reusable rules
  • Review registry evidence alongside process and endpoint context
  • Use policy assignment to standardize monitoring across compatible agents

Learn more about Registry Key Monitoring →

XDRShield product view for Registry Key Monitoring
Multi-layer endpoint detection and monitoring

Process and System Metrics Monitoring

Combine process-level visibility with system metrics so analysts can detect suspicious execution patterns, resource abuse, and operational health anomalies.

What this helps teams do

  • Review reported process activity and system metric observations
  • Investigate suspicious execution with endpoint and inventory context
  • Use health and metric evidence to distinguish active issues from stale data

Learn more about Process and System Metrics Monitoring →

XDRShield product view for Process and System Metrics Monitoring
Multi-layer endpoint detection and monitoring

URL Filtering and Violation Monitoring

Define trusted and blocked domains, review attempted access, and keep URL policy context available when web activity becomes part of an investigation.

What this helps teams do

  • Manage URL rules, policy behavior, categories, and enforcement settings
  • Review violation evidence with affected endpoint and policy context
  • Support investigation of suspicious or blocked web access attempts

Learn more about URL Filtering and Violation Monitoring →

XDRShield product view for URL Filtering and Violation Monitoring
Multi-layer endpoint detection and monitoring

Antivirus Integration and Findings

Bring supported antivirus policy, finding, status, and enforcement visibility into the same operating workflow as endpoint evidence and investigations.

What this helps teams do

  • Review supported AV findings and protection status where configured
  • Connect antivirus evidence with alerts, cases, and endpoint context
  • Validate provider, OS, agent-version, and configuration dependencies before deployment

Learn more about Antivirus Integration and Findings →

XDRShield product view for Antivirus Integration and Findings
Multi-layer endpoint detection and monitoring

IOC Monitoring and Supported Blocking

Use indicators of compromise to monitor or block supported activity, distribute compatible rules through policy, and review findings with enforcement context.

What this helps teams do

  • Define supported indicators for monitoring or blocking workflows
  • Review IOC findings, enforcement state, and affected endpoint context
  • Route high-impact actions through governed response where supported

Learn more about IOC Monitoring and Supported Blocking →

XDRShield product view for IOC Monitoring and Supported Blocking
Network-device visibility

Network Device Monitoring

Monitor supported network devices with read-only reachability and SNMP v2c evidence, either directly or through an endpoint collector inside the customer network.

What this helps teams do

  • Inventory licensed network devices within tenant scope
  • Review availability, interface, port, VLAN, and diagnostic evidence where supported
  • Use endpoint-assisted collectors for private customer networks

Learn more about Network Device Monitoring →

XDRShield product view for Network Device Monitoring
Policy, asset, and platform operations

Endpoint Inventory and Vulnerability Visibility

Use endpoint hardware, software, operating-system, network, process, service, and vulnerability context to support investigations and operational decisions.

What this helps teams do

  • Review asset and software details alongside security evidence
  • Use supported vulnerability visibility to understand exposure context
  • Distinguish current, stale, and missing endpoint observations before action

Learn more about Endpoint Inventory and Vulnerability Visibility →

XDRShield product view for Endpoint Inventory and Vulnerability Visibility
Threat hunting and case investigation

Threat Hunting, Cases, and Timelines

Search retained endpoint and security evidence, save repeatable hunts, organize findings into cases, and review investigation activity chronologically.

What this helps teams do

  • Run and save threat hunts across available evidence
  • Group alerts and findings into owned cases with priority and status
  • Use timelines to understand what happened and when

Learn more about Threat Hunting, Cases, and Timelines →

XDRShield product view for Threat Hunting, Cases, and Timelines
Governed endpoint response

Governed Response and Action History

Request, approve, execute, and review supported endpoint response actions with retained reason, actor, result, retry, and error history.

What this helps teams do

  • Support controlled host isolation, release, process termination, user disablement, and IOC actions where available
  • Preserve approval, rejection, execution, and result context
  • Keep response decisions connected to the investigation record

Learn more about Governed Response and Action History →

XDRShield product view for Governed Response and Action History
Policy, asset, and platform operations

Detection Rules, Policies, and Synchronization

Create reusable rules, attach them to policies, assign compatible agents, and review synchronization state so detection coverage stays consistent across environments.

What this helps teams do

  • Manage alert, file, registry, process, metric, URL, antivirus, and IOC rules
  • Assign policies to compatible agents within authorized tenant scope
  • Track synchronization and configuration state before relying on coverage

Learn more about Detection Rules, Policies, and Synchronization →

XDRShield product view for Detection Rules, Policies, and Synchronization
Threat hunting and case investigation

Event Search, Ingestion, and Evidence Freshness

Search and filter incoming security evidence while keeping collection time, heartbeat state, and freshness signals visible for reliable investigation decisions.

What this helps teams do

  • Filter and inspect raw event evidence without losing source context
  • Use ingestion and freshness context to understand coverage gaps
  • Pivot from events into alerts, hunts, cases, and timelines

Learn more about Event Search, Ingestion, and Evidence Freshness →

XDRShield product view for Event Search, Ingestion, and Evidence Freshness
Policy, asset, and platform operations

Asset, Vulnerability, and Software Operations

Coordinate asset context, vulnerability visibility, approved software packages, deployments, and compatible agent upgrades from the same operating platform.

What this helps teams do

  • Use asset and software data to support investigation and remediation planning
  • Publish approved packages and track assignment or deployment status
  • Coordinate compatible agent upgrades with operational visibility

Learn more about Asset, Vulnerability, and Software Operations →

XDRShield product view for Asset, Vulnerability, and Software Operations
Service-provider-native multi-tenancy

Tenant-aware Access and Service-provider Governance

Separate customer, tenant, and workspace data while retaining the provider-level control needed for MSP and multi-customer security operations.

What this helps teams do

  • Manage customers, tenants, delegated users, roles, and branding
  • Retain activity evidence, notifications, and operational records
  • Align licensing and governance with Desktop OS, Server OS, and Network Device units

Learn more about Tenant-aware Access and Service-provider Governance →

XDRShield product view for Tenant-aware Access and Service-provider Governance

FAQ

Answers for security leaders, MSPs, and IT teams evaluating XDRShield.

What is XDRShield?

XDRShield is an endpoint security operations platform that combines endpoint detection and response, security event review, alert triage, threat hunting, case management, policy control, response actions, activity records, vulnerability context, and MSP-ready tenant operations.

How is XDRShield different from a basic EDR tool?

A basic EDR tool may focus primarily on endpoint alerts. XDRShield connects endpoint evidence with policy scope, hunts, cases, response governance, activity history, tenant administration, asset visibility, and service-provider workflows so teams can operate from signal to accountable outcome.

Does XDRShield support managed security service providers?

Yes. XDRShield is designed for service-provider-native operations with customer and tenant separation, delegated roles, customer lifecycle controls, per-tenant policies, notifications, branding settings, and review-ready operating records.

What response actions can teams govern through XDRShield?

Supported workflows can include host isolation, host release, process termination, user disablement, IOC blocking, and related enforcement actions depending on product edition, endpoint OS, agent version, role, policy, and release support.

What should teams verify before relying on a feature?

Teams should verify tenant scope, endpoint identity, evidence timestamp, heartbeat, synchronization state, endpoint operating system, agent version, configured integrations, policy assignment, user role, license allocation, and release maturity.

Which operating systems are covered?

XDRShield currently focuses on Windows endpoint coverage, with Linux and macOS support planned. Teams should validate current platform availability, agent version, and feature coverage with the XDRShield team before production rollout.

Let us make sure you are ready

Map XDRShield features to your endpoint, tenant, and response model.

See how XDRShield can help your team strengthen detection coverage, investigate with context, respond with governance, and keep security operations accountable.