The detection gap
ADR alone | EDR alone | ADR + EDR correlated |
Confirmed command injection in | Suspicious process: | Confirmed: command injection in |
Sees the injection and possibly the outbound connection. Cannot see file drops, persistence mechanisms, or lateral movement. | Sees the process tree. Cannot tell AppSec which function to patch — the ticket would be “investigate your Python app.” | AppSec gets the exact function. SOC gets the full impact. Response is surgical, not a fishing expedition. |