Managed XDR is a unified platform that covers endpoint, email, cloud, network, and server security, backed by a 24/7/365 SOC.
SOC watches your email security environment 24/7.
Examples include:
- Phishing
- Business Email Compromise
- Suspicious attachments
- Malicious URLs
- Email-based data exfiltration
- Email security policy events
Barracuda XDR Email Security monitors existing email-security infrastructure and provides additional analysis and detection.
SOC monitors your cloud environment for suspicious identity and administrative activity.
Monitoring across services, including:
- Microsoft 365
- Azure
- AWS
- Google Workspace
- Okta
- Duo
and detecting events such as:
- Account takeover
- Suspicious login
- MFA attacks
- Privilege changes
- Unauthorized access
- Impossible logins
- Cloud mailbox compromise
Protect and continuously monitor employee computers and endpoints
Uses SentinelOne technology within its XDR Managed Endpoint Security offering and provides SOC monitoring, threat hunting, remediation guidance, and automated response capabilities.
It addresses threats such as:
- Malware
- Ransomware
- Fileless attacks
- Privilege escalation
- Malicious scripts
- Application abuse
- Crypto mining
Monitor servers and Active Directory for signs of compromise or unauthorized activity.
XDR Server Security monitors security logs and Active Directory-related activity, looking for patterns such as password spraying, abnormal logins, privilege escalation and suspicious account activity.
Watch network traffic for attacks and suspicious activity
It can detect:
- Intrusions
- Malicious network traffic
- Command-and-control activity
- Data exfiltration
- Reconnaissance
- Denial-of-service activity
- Brute-force attacks
Automated response capabilities that can block malicious traffic through supported firewall integrations.
Find security weaknesses before attackers exploit them.
Managed Vulnerability Security provides regular vulnerability scanning, reporting, and prioritized remediation guidance, with Barracuda’s SOC managing the service.
It helps identify:
- Vulnerable systems
- Missing patches
- Security weaknesses
- Risk exposure
- Remediation priorities
The service can operate independently or integrate with Managed XDR.
Keep XDR security logs available for longer so Barracuda can support monitoring, investigation and service delivery
It extends retention of logs for service purposes to a rolling 12-month period. These retained logs are used to deliver the service and aren’t generally available to customers for direct dashboard download; limited samples may be provided upon written request for audit purposes.
The collector gathers security information from the customer’s environment so Barracuda’s SOC can monitor it.
The Managed XDR Collector is infrastructure used to collect security telemetry/logs from a customer’s environment and send the relevant information into the XDR platform.
It is therefore an XDR deployment component, rather than a standalone security service.
Barracuda documentation describes the collector infrastructure as part of the XDR log-ingestion architecture.
