One platform, five modules
Endpoint security, EDR, XDR, DLP and SIEM are not five products competing for one budget. Each name says where a defence sits and which question it answers. Reading them as alternatives is the shortest route to paying twice for one capability and leaving another uncovered entirely.
Endpoint security is the pair that lives on the machine itself. EPP decides whether a file is allowed to run: the verdict is reached BEFORE the process starts, so an attack stopped here leaves no damage behind to investigate. EDR assumes something already ran, and keeps the record that can answer what it did — which process started which, what it wrote, where it connected.
The disciplines, and the question each one answers| Discipline | What it watches | The question it answers |
|---|
| EPP — endpoint protection | The file, before it runs | Should this file be allowed to run? |
|---|
| EDR — detection and response | Processes, memory and connections on the machine | What happened on this host, and who started it? |
|---|
| SIEM — event management | Logs from every source in the estate | What did the whole estate see? |
|---|
| XDR — extended detection | Endpoint, identity and network signals together | Is this one attack, or separate incidents? |
|---|
| DLP — data loss prevention | The movement of sensitive data | Where is this data going, and should it be? |
|---|
HEDE stands for Helxis Endpoint Defense Engine. All five modules are parts of one platform: one data model, one incident queue, one console — so a process on the endpoint and an authentication in the estate meet on the same screen. Modules are enabled per deployment: a customer starts with what they need and adds the rest to that same console, with no second system and no second pane of glass.