Engine 01 — XDR

Detection That Sees
The Whole Attack.

nPro XDR watches behaviour across endpoints, servers and cloud workloads, maps every finding to MITRE ATT&CK, and assembles them into one chain instead of a queue of alerts.

One intrusion, several signals, one chain

Endpoint tooling would report the steps below as unrelated events on different machines. Each node is a detection nPro produces on its own; the line between them is what XDR adds.

An illustrative sequence, not a customer incident.

T1110 Credential brute force against an exposed service

Initial access. Repeated authentication failures followed by a success, correlated across sources rather than counted on one host.

T1059 Scripted execution from an unexpected parent process

Execution. Behaviour, not signature: a command interpreter launched by an application that has no reason to launch one.

T1543 Persistence written to a system location

Persistence. Caught by File Integrity Monitoring, which is watching those paths continuously rather than scanning on a schedule.

T1021 Lateral movement to a second host

The step that separates XDR from EDR. Two machines, one campaign, recognised as such because both report to the same correlation engine.

RESPONSE Containment without waiting for an analyst

A SOAR playbook isolates the host and revokes the session. The chain is already assembled, so the responder reads context rather than reconstructing it.

What has to be true for that chain to exist

Continuous file integrity monitoring

Persistence is invisible to anything that scans on a schedule. FIM watches sensitive paths in real time, which is why step three appears at all.

Technique-level ATT&CK mapping

Mapping to tactics is too coarse to link events. Technique-level references are what let the engine recognise that two detections belong to one sequence.

One backend, not an integration

XDR and SIEM write to the same ClickHouse store. Correlation is a query, not a data pipeline between two vendors with two retention policies.

Posture as well as behaviour

Security Configuration Assessment and continuous vulnerability detection close the gaps that make step one possible in the first place.

Wherever the workload runs

Public cloud — AWS, Azure, GCP Private cloud On-premise Air-gapped Hybrid Containers Windows, Linux, macOS agents

Start Detecting Today

Free tier available. No credit card. Full platform access in 5 minutes.

nPro AI

Online

Hi! I'm the nPro assistant. How can I help you learn about our SIEM & monitoring tools today?

Powered by nPro AI