MDR: managed detection and response to threats
Continuous detection, contextual investigation and containment actions executed from the same platform, with metrics you can show to management.
What is MDR
MDR (Managed Detection and Response) is a security service that combines detection technology with analysts who investigate alerts and execute the response. While an EDR or SIEM produces signals, MDR turns them into managed incidents through to containment.
At CiberEm, MDR relies on Wazuh telemetry, TheHive case management and enrichment from Cortex and GreyNoise, all inside one console with full traceability.
Detection with MITRE ATT&CK
Every alert is automatically mapped to MITRE ATT&CK tactics and techniques. The coverage heatmap shows which techniques are watched by active rules and which are not, and the ranking of most frequent techniques points to where detection should be reinforced.
Threat hunting over telemetry validates hypotheses with saved, shared queries, and the identity timeline tracks human and service accounts across authentication, file integrity and rootcheck events.
Active response
Response runs from the case itself, with role-based permission control. Actions are split into reversible and disruptive so each team decides who may execute which.
- Reversible: restart agent and disable account.
- Disruptive: firewall block, host isolation, kill process and file quarantine.
- Every action is logged with user, organization, entity, IP and metadata.
MTTD, MTTC and MTTR metrics
Mean time to detect (MTTD), to contain (MTTC) and to resolve (MTTR) are computed automatically from each case lifecycle. Severity-based SLAs, from 15 minutes for critical alerts to 24 hours for low priority, warn when a case is about to breach.
MDR FAQ
Is MDR the same as EDR?
No. EDR is the technology that collects telemetry and detects on the endpoint. MDR is the service that investigates those detections and executes the response. CiberEm uses Wazuh as the EDR/SIEM layer and adds management, investigation and response.
Which response actions are executed?
Six actions: restart agent, disable account, firewall block, host isolation, kill process and file quarantine. They are launched from the case and fully audited.
Who authorizes a disruptive action?
It depends on the role. The platform distinguishes four roles (admin, organization owner, analyst and viewer) and disruptive actions are restricted to the roles your organization defines.
How is response time measured?
Each case records when it was detected, contained and resolved. Those timestamps yield MTTD, MTTC and MTTR, compared against the SLA for its severity.
Does it cover servers and endpoints?
Yes. Telemetry comes from Wazuh agents deployed on servers and workstations, and the agent health panel shows their connectivity and sync status.