G DATA XDR
Why XDR?
Traditional antivirus solutions attempt to ward off attacks directly through preventive protection technologies. XDR solutions, by contrast, are designed to detect attacks that could not be blocked by the Protection pillar. Modern solutions such as Endpoint Protection or Next-Gen AV often already include certain Detection functions to identify threats in the network based on behavior. However, the key difference is: XDR uses significantly expanded threat-detection sensing and telemetry capabilities (Detect). You can perform in-depth analysis of suspicious processes and manually intervene as needed (Respond).
Product page
You can find the product page here.
Customer participation obligations
Only with continuously ensured operational functionality can G DATA XDR deliver its protective effect.
G DATA XDR serves as a supporting security tool for monitoring endpoints and detecting potentially suspicious activities.
The G DATA Agent intervenes in the case of known security threats—among other things by stopping processes and moving malware files to quarantine—to prevent damage.
It attempts to detect unknown threats by monitoring the entire system for characteristics of an attack and to prevent damage using the same means that it uses for known threats.
In addition, G DATA XDR helps make security-relevant events visible and provides indications to initiate further measures for containment of possible attacks.
It must be noted that G DATA XDR is used as a tool that always requires the user’s active cooperation. To detect cyber risks efficiently and avoid financial or data-protection-related damage, it is strictly necessary that, after installing G DATA Agent, the user regularly checks whether all components of the system are functioning properly. This includes, in particular, verifying whether endpoints are correctly connected, data is being transmitted, and alerts are being received reliably. Only if functionality is ensured continuously can G DATA XDR provide its protective effect.
Customer responsibilities
The user is responsible for the proper operation of the XDR solution used. This includes, in particular, ensuring that all connected endpoints can communicate regularly with the G DATA Cloud Backend. This requires a stable and continuous Internet connection. In addition, it must be ensured that the installed Agent on the endpoints remains continuously active.
The user is also responsible for keeping the software used up to date at all times. So that the G DATA Agent can reach the G DATA servers for updates,
a permanent Internet connection must be available.
To ensure reliable and timely alerting of events and Incidents, the G DATA Cloud must be reachable and must not be blocked by a firewall. The settings listed below are required for this. It must be ensured that *.gdatasecurity.de and *.gdatasoftware.com can be resolved via DNS and are reachable.
-
Port openings
-
The G DATA agents on the Endpoints must be able to reach the IPs of our backend servers via port TCP/443, IP range 194.156.84.0/22 (194.156.84.0 - 194.156.87.255).
-
-
Protocols
-
The systems must be able to communicate using the HTTPS:// and WSS:// protocols.
-
-
TLS
-
Deployed proxy servers must support at least TLS 1.2.
-
SSL Inspection or Deep Packet Inspection must not be enabled.
-
The user is responsible for the protection of the user’s G DATA Web Portal access. This includes offering users two-factor authentication and ensuring that the user accounts created by the user are informed about the use of secure passwords.
A key part of operating G DATA XDR is the continuous monitoring of the alerts displayed in the G DATA Web Portal.
These must be reviewed regularly, assessed, and addressed promptly. The user independently decides whether
further measures or action are necessary.
Maintaining Exclusions is entirely the responsibility of the user, or of the commissioned Managed Service Provider. In particular, it must be ensured that false positives are identified and handled accordingly. Without appropriate maintenance of the exclusion lists, legitimate applications or processes may be blocked by mistake, thereby impairing normal operation.
Handling isolated artifacts moved to quarantine also requires an independent review by the user to decide whether further measures are necessary or whether restoration can be performed.
Risks of insufficient participation
Insufficient cooperation can result in security incidents not being detected or not being addressed in time. There is also a risk that endpoints will not provide current data or that protection mechanisms will not take effect as intended. In such cases, the effectiveness of the security solution may be significantly limited and attacks may, under certain circumstances, spread. The user is solely liable for any resulting financial or data-protection-related damage.
Distinction between G DATA XDR and G DATA MXDR
In contrast to a
Managed XDR Service
when using this solution, there is no operational support or task takeover by G DATA.
In particular, the monitoring and assessment of security alerts, as well as the initiation of measures, are entirely
the responsibility of the user or their service provider.
In our EDR/XDR guide you can find targeted information on Endpoint Detection and Response.
If you have any questions, please contact our Sales team. They will be happy to advise you.
Business Contact Sales
Monday through Friday 8 a.m. to 5 p.m.
Phone: +49 234 9762-170