公開済みEvidenceをIdentity / Capability / Credibility / Use Case / Constraints・Current Statusの軸で機械的に集約したものです(新規の主張・推測は含みません)。
Identity
CrowdStrike公式サイトによれば、MDRは「EDR "as a service." Provides the same capabilities as EDR, plus 24/7 managed services to monitor, mitigate, eliminate and remediate threats(EDRと同等の機能を提供しつつ、24時間365日の管理サービスで脅威の監視・低減・排除・復旧を行う"サービスとしてのEDR")」と説明されている。検証待ちEDR vs MDR vs XDR: Everything You Need To Know | CrowdStrike
Capability
Sophos公式サイトによれば、Sophos MDRは「Detection of human-led and AI-driven attacks designed to bypass security controls. Full-scale incident response included(セキュリティ制御を回避する人間主導・AI駆動の攻撃の検知。大規模なインシデント対応を含む)」「Proactive threat hunting, powered by autonomous agents and the latest threat intelligence(自律エージェントと最新の脅威インテリジェンスによる能動的な脅威ハンティング)」を提供するとされ、MDRの実装例の一つである。検証待ちSophos MDR | 24/7 Managed Detection & Response | Agentic SOC
CrowdStrike公式サイトの比較表によれば、EDRは「Monitors endpoints for threats that have circumvented antivirus solutions and other preventative techniques(アンチウイルス等の防御技術を回避した脅威についてエンドポイントを監視する)」製品カテゴリ、XDRは「Full-spectrum, threat-centric security solution that integrates data from various existing security tools(既存の複数セキュリティツールのデータを統合する全方位型ソリューション)」であり、MDRとは異なるカテゴリとして整理されている。検証待ちEDR vs MDR vs XDR: Everything You Need To Know | CrowdStrike
NIST公式Glossary(CSRC)を「managed detection and response」で確認したところ、本Draft作成時点(2026年7月)で該当する独立した用語定義エントリは確認できず、一般的なGlossary検索ページへフォールバックする状態であった。これは政府・標準文書によるMDRの統一定義が(少なくともNIST CSRC上には)存在しないことを示す。検証待ちGlossary | CSRC (search fallback confirmation)