Hexnode has expanded its XDR product with new threat detection, alert prioritisation and remediation features, and added macOS support alongside Windows.
The changes are aimed at IT and security teams that need to investigate incidents and act on affected devices with less manual work. Hexnode XDR is tied to the group's unified endpoint management platform, allowing security teams to move from identifying a threat to isolating or remediating a device within the same environment.
At the centre of the update is a broader set of detection and triage tools. The product now pulls in external threat intelligence from Mandiant and Recorded Future, giving analysts added context when reviewing suspicious activity on endpoints.
Hexnode has also added sandbox analysis for suspicious files, allowing them to be examined in an isolated environment before the results are fed back into the detection process.
Anomaly detection is another part of the release, intended to flag unusual behaviour that may not match established threat signatures. The system also ranks alerts by severity and urgency, while assigning devices dynamic risk scores based on defined parameters.
These features are designed to help security teams decide which incidents need attention first. Administrators can also set exclusion policies for trusted files, applications and processes to reduce false positives and unnecessary investigation.
Response tools
On the response side, the product adds one-click endpoint isolation, allowing affected devices to be cut off from the network while retaining management access through Hexnode. This can help organisations contain threats during an investigation without losing the ability to manage a compromised machine.
Vulnerability management has also been linked to the wider Hexnode platform. Vulnerabilities and missing patches identified during an incident can be addressed through Hexnode's endpoint management tools, connecting investigation with patching and follow-up remediation.
Automated remediation is another new element. Predefined fixes can be triggered through configured rules and policies, reducing the amount of repetitive manual corrective work required from analysts and administrators.
Custom dashboards have been added so different teams can tailor views to their role and monitoring priorities. The product also includes integrations with Splunk and QRadar, linking Hexnode XDR to existing security information and event management systems used for investigation and reporting.
Platform expansion
The addition of macOS broadens the product beyond Windows endpoints. That matters for organisations running mixed device estates, where security teams often need consistent investigation and response workflows across more than one desktop operating system.
The update reflects a wider pattern in the endpoint security market, where suppliers are trying to combine detection, prioritisation and action in a single workflow. Security teams have long faced large volumes of alerts, and vendors have increasingly focused on helping analysts identify which incidents matter most and how to address them quickly.
Hexnode also framed the new alert ranking, asset scoring and remediation workflow as the basis for broader AI-assisted security operations. Its Genie AI tool provides plain-language summaries of alerts, uses live incident data to explain what happened, identifies what is affected and recommends a fix.
Apu Pavithran outlined the company's thinking in a keynote address.
"We built Hexnode XDR around one complaint we heard constantly: security tools are good at telling you something is wrong, and bad at helping you do anything about it. More alerts was never the request. Fewer steps between the alert and the fix - that was the request," said Apu Pavithran, Chief Executive Officer and Founder, Hexnode.
Hexnode is the software division of Mitsogo. The latest changes place it more directly in the market for tools that tie endpoint monitoring to device management, with features intended to help security teams move from alert review to containment and remediation in fewer steps.