What EDR / XDR / AIDR is built to catch
Adversarial activity coming in
- Prompt injection, jailbreaks, malicious content, compromised packages
- A verdict per event: allow, block, redact, quarantine
- Rule engines and entity matching, tuned to fire on known patterns
- An outcome measured in alerts closed and dwell time reduced
