XDR · SIEM · SOAR · cases

Detection and response, rebuilt around the analyst.

One platform for logs, endpoints, alerts and cases. AI does the first pass and explains itself. A person decides. Runs on your servers, or ours.

One agentLightweight, outbound-only endpoint agent for Windows and Linux.
One pipelineEvery source normalised into one store. Raw events preserved.
Any modelAdvisory AI on any OpenAI-compatible endpoint, including your own hardware.
One serverSelf-hosted on a single Linux server, with automatic TLS.

Facts, not benchmarks. Throughput and storage depend on your telemetry mix; see the sizing table in the docs.

Telemetry in

  • Elastic Beats (winlogbeat, filebeat)
  • Syslog (RFC 3164/5424)
  • CEF
  • LEEF
  • HTTP JSON
  • Splunk HEC
  • Sysmon
  • Microsoft Defender Antivirus events
  • Windows Event Log
  • Linux journald
  • Linux auditd
  • FortiGate (syslog)
  • Okta System Log
  • Microsoft Entra ID / Microsoft 365
  • Fluence Account audit log
  • AWS CloudTrailcoming soon
  • CrowdStrike Falconcoming soon
  • Microsoft Defender for Endpointcoming soon
  • Google Workspacecoming soon

One platform, three jobs

Stop stitching tools together.

A SIEM that does not know your endpoints. An EDR that does not know your logs. A ticket system that knows nothing at all. XenXDR replaces the duct tape with one platform where every part shares the same data.

SIEM

Every log from every source, searchable in one place. Saved views your analysts keep, and a one-click jump from any alert to the exact evidence behind it.

XDR

A lightweight endpoint agent. See what is happening on any host, cut it off from the network, stop malicious processes and collect evidence remotely.

SOAR and cases

When an alert becomes an incident, the case opens itself: notes, evidence and indicators carried over, nothing retyped. Track every investigation from first alert to final report.

The console

Built for the people on shift.

Monospaced, keyboard-first, quiet. The console shows the number and the timestamp and gets out of the way.

A capture of the XenXDR console running on demo data.
  1. 01Dictionary autocomplete

    Every field has one canonical name and a description. The query bar suggests both.

  2. 02Histogram, then rows

    Volume over time first, the documents second. Expand any row for the fields, or jump to the raw event.

  3. 03AI Hunt

    Ask a question in plain language. The hunt runs bounded, read-only queries and shows you what it ran.

AI inside

Humans decide. AI does the grunt work.

Most alerts are not incidents. They are noise that burns out good analysts. XenXDR works through that queue the way your best analyst would: gather context, check the pattern, write up what happened. Your team keeps the interesting work and the final say.

Triages every alert

Each new alert runs through the workflow you attached to its detection, around the clock. Nothing sits unread over a weekend.

Gathers the context

Related activity across hosts, users and network is pulled together and laid out as a timeline before a person opens the alert.

Explains and suggests

A plain-language summary, a suggested verdict with confidence, and a grade for how much of the evidence is actually about this alert.

Cuts the noise

Recurring benign patterns close automatically, but only under a policy you set, with the full trail kept and reversible.

  1. 01

    Alert fires

    A detection matches, from the shipped content pack or the rules your team brings. Duplicates fold into one alert.

  2. 02

    AI investigates

    The attached workflow enriches, correlates and reconstructs what led to what, using bounded read-only queries.

  3. 03

    Verdict, advisory

    Benign, malicious or needs a person, with confidence, a recommendation and the evidence grade behind it.

  4. 04

    Your policy applies

    • Clearly benign: closed automatically, trail kept.
    • Clearly malicious: a case opens with evidence attached.
    • Anything uncertain waits for a person. Always.
  • The AI acts only within playbooks you approved. It advises; your policy decides.
  • Every AI conclusion is logged next to the human ones: reviewable, auditable, attributable.
  • Run AI on your own hardware, or run on built-in deterministic logic. The choice is yours.
  • Your data is used only to protect your organization.

Architecture

One spine. Every source, one picture.

Everything you send, from endpoints, firewalls, cloud identity or scripts, flows through one pipeline into one store. Alerts, cases and response all see the same picture.

  • Original events are always preserved, so evidence stays intact for investigations and audits.
  • Every event is accounted for: anything that fails to parse is kept and flagged.
  • Pivot on IPs, file hashes, users and domains across every source at once.
  • Built on open standards: ECS-compatible fields, Sigma rules, syslog, Beats and HEC.

Capabilities

Everything a shift needs, nothing it does not.

Log search

Search your whole environment in seconds. Saved views, keyboard control, and a straight jump from any alert to the evidence.

Detections

Start with the shipped rules, then make them yours. Import Sigma directly; write query, sequence and correlation rules natively.

Alert triage

A queue your team can manage: list or kanban, SLA timers, assignment, tags, and related alerts grouped into one story.

Case management

Escalation carries notes, evidence and indicators automatically. Timeline, tasks, war room and hand-offs in one workspace.

Response console

Act on any endpoint remotely: browse files and processes, isolate a machine, collect evidence, open a live shell.

Fleet overview

Every enrolled endpoint visible with presence, health, risk score and the security tools it should be running.

Playbooks

Automate the routine: attach workflows to detections, run them staged or automatically, review every run.

Multi-tenant

Serve many organizations from one deployment with strict data separation, per-customer access and audit.

Who it is for

One platform, three ways to run it.

For security teams

Replace a pile of consoles with one, without handing your data to someone else's cloud.

  • Logs, endpoints, alerts and incidents in a single view.
  • Your data stays on your infrastructure, in formats you can inspect.
  • AI keeps triaging overnight, so mornings start with verdicts, not a backlog.

For MSSPs

Run all your customers from one deployment you control, with a portal each of them can log into.

  • Per-customer data separation enforced by the platform, not by discipline.
  • Onboarding a customer means creating an organization, not a new stack.
  • SLA reports and monthly write-ups delivered to the customer portal.

Managed by FluenceSecurity

Our SOC in Gdańsk operates XenXDR for you: monitoring, triage, response and a monthly report.

  • Your tenant or ours, your policy either way.
  • The people who built the platform work your queue.
  • Start with a pilot next to your current stack.

Deployment

Your servers. Your data. Up in an afternoon.

XenXDR is self-hosted by design: a single Linux server, automatic TLS, and open data your ops team can inspect for itself. Your data stays on your infrastructure.

  • Every setting and secret documented in one environment file.
  • Endpoint agents install with a one-shot script and enrol with a per-organization token.
  • Prefer not to run it? We host a tenant for you, or our SOC operates it end to end.

A box with 4 vCPU, 16 GB and NVMe storage covers roughly 200 endpoints. The docs have the full sizing table.

Security posture

A security product should survive its own audit.

We hardened XenXDR before asking anyone to run it. Here is how.

  • All telemetry is encrypted in transit. TLS by default, everywhere.
  • Every endpoint agent gets its own credential at enrolment, so each endpoint's access is its own.
  • Remote response sessions are short-lived and tied to a named operator. Fleet credentials stay on the server.
  • Role-based access with per-organization scoping, enforced on the server for every request.
  • Every action, human or automated, lands in an audit trail kept for a year.
  • Backups are scripted and restore-tested, and every release passes automated tests before it ships.

Data residency, the disclosure policy and procurement answers are on the security page. Security and trust

Early access

Onboarding design partners now.

XenXDR is a feature-complete platform, security-hardened, and we are onboarding design partners: security teams and MSSPs alike. Self-host it with your team, build your managed offering on it, or let our SOC operate it for you. Either way, you will be talking to the people who build it.

FAQ

Questions we actually get.

Is XenXDR open source?

The platform is commercial and built on open standards: ECS-compatible fields, Sigma rules, and syslog, Beats and HEC inputs. Your data stays in formats you can inspect, query and export.

Where does my data live?

On your infrastructure, full stop, when you self-host. Your telemetry stays with you. If you prefer a hosted tenant, it runs on a dedicated deployment under the xdr.fluencesecurity.com domain.

The optional AI verdict step sends evidence only to the model endpoint you choose; with a model on your own hardware, everything stays inside the deployment.

Does the AI take actions on its own?

Only when you allow it. The AI's verdict is advice. Automatic close or escalation happens only when you enable it for a specific workflow and the verdict is clear-cut. Everything else waits for a person, and every action is audited. With no model configured, triage runs on built-in deterministic logic.

Which endpoints are supported?

The agent runs on Windows 10 and 11, Windows Server 2016 and later, and Linux (amd64 and arm64) as a system service. It connects outbound only and installs without a reboot. Other systems, including macOS, send their logs by syslog or Beats.

How does XenXDR work with our EDR?

It complements it. The agent collects telemetry from the sources your endpoints already produce, such as Sysmon, the Windows Event Log and auditd, brings in your endpoint protection's detections, and acts on the host when a detection fires: isolate, kill, block, collect.

Can we bring our existing detection rules?

Yes. XenXDR imports Sigma rules directly, staged for your review before anything fires. Subsets of KQL and EQL are supported, and native rules can express query, sequence and correlation logic.

We are an MSSP. Can we run multiple customers?

Yes, that is a first-class use case. One deployment serves many organizations with strict data separation, per-customer access for your analysts, per-tenant SLA policy and automation ceilings, and a portal each customer can log into.

What does it cost?

We price per environment, not per gigabyte, and early-access pilots are scoped individually. The pricing page explains the three ways to buy and what each includes. Ask us and you will get a straight answer.

See XenXDR on your own telemetry.

A 30-minute walkthrough on fictional data, then a pilot in your environment. No slides, no pressure.