How Does Managed Detection and Response Work?
Managed Detection and Response continuously monitors security data from endpoints, identities, email, cloud environments, networks, and other supported systems for activity that may indicate a cyber threat. When suspicious activity is detected, the MDR process goes beyond simply creating an alert.
Security analysts investigate the activity, examine available evidence, and determine whether it represents normal behavior, a false positive, or a legitimate security incident. When a threat is confirmed, the MDR team can escalate the incident and help contain, remediate, and respond to the threat based on the capabilities and responsibilities defined in the MDR service.
Continuous Monitoring and Threat Detection
Cyberattacks can occur at any time, including nights, weekends, and holidays. MDR provides continuous monitoring designed to identify suspicious activity without depending on someone inside the business to manually watch security alerts.
Detection technologies analyze security telemetry for indicators such as malicious processes, unusual account activity, suspicious authentication attempts, ransomware behavior, command-and-control communications, and other potentially harmful activity.
Investigation and Threat Validation
An alert does not necessarily mean a cyberattack is occurring. One of the important functions of MDR is determining which alerts require action.
Security analysts investigate suspicious activity and correlate available information to establish context, determine the scope of the activity, and assess its potential impact. This helps reduce the burden of sorting through large numbers of security alerts while allowing legitimate threats to receive greater attention.
What Happens When MDR Detects a Threat?
When MDR identifies and validates a threat, the response depends on the nature of the incident and the capabilities included in the MDR service. The objective is to limit the attacker’s ability to continue operating while protecting affected systems, accounts, and business data.
Containment, Response, and Remediation
Response actions may include isolating a compromised endpoint, disabling or protecting an affected account, blocking malicious activity, collecting additional evidence, escalating the incident, and providing remediation guidance.
MDR should also establish a defined escalation process so the appropriate people within the organization know when a significant security event has occurred, what actions have already been taken, and what additional steps may be required.
Organizations should also maintain a documented incident response plan that defines roles, responsibilities, communications, and actions before an incident occurs.
