XDR Correlation Demo
A useful XDR POC should show more than generated traffic. It should connect what DSP generated, what NDR/XDR detected, and what the analyst can investigate. Third-party alerts are optional context. DSP itself does not ingest or manufacture those alerts.Recommended demo pattern
DSP’s role
DSP is responsible for observable activity and execution evidence. It can generate network, DNS, web, identity-service, protocol, and controlled host-side behavior, then record what it generated under a run ID. The XDR/NDR platform is responsible for detection, alerting, correlation, severity, and case creation.Practical demo workflow
- Run DSP inside the authorized scope.
- Confirm the intended activity in
traffic_summary.jsonandreport.md. - Find the matching NDR/XDR detection using the same time window and hosts.
- If the POC includes an external/third-party alert, confirm that it is present in XDR.
- Verify whether the platform correlates the related signals into a case.
- Capture the detection IDs, case ID, timestamps, hosts, screenshots, and analyst conclusion.
Evidence checklist
For each signal used in the demo, capture:- DSP run ID and scenario ID
- scenario start/end time
- source and destination hosts
- XDR/NDR alert or detection ID
- optional third-party alert ID and source
- XDR case ID, when created
- screenshot or exported evidence
- analyst note explaining the relationship
Build the evidence chain
Use DSP run artifacts and product-side IDs/screenshots to create an auditable POC record.