Managed Security (EDR/MDR)Informational

MDR demystified: what a real incident looks like end-to-end

A walkthrough of a live MDR investigation, from first alert to contained threat.

11 March 2026 7 min read
MDR demystified: what a real incident looks like end-to-end — Managed Security (EDR/MDR) illustration

MDR can sound abstract until you've seen one work. Here's a real (anonymised) end-to-end incident from a 60-person UK professional services firm earlier this year.

00:00 — The alert

EDR fires a medium-severity alert: a finance laptop has spawned an unusual PowerShell command shortly after a Teams message was opened. Out of business hours.

00:03 — Triage

An analyst picks up the alert. They pivot through telemetry: the PowerShell command is attempting to download a second-stage payload from an unfamiliar domain. The user account has just authenticated from the UK and from a VPS in another country, two minutes apart.

00:08 — Containment

The analyst isolates the endpoint via EDR. The user account is force-signed-out of all sessions and an interim password reset is triggered. Conditional Access is tightened to block the suspicious IP range.

00:20 — Scoping

Identity logs are reviewed: the attacker also accessed the user's mailbox and created a hidden inbox rule to auto-forward and delete messages containing 'invoice'. The rule is removed; mailbox rules across the tenant are audited; no other accounts affected.

00:45 — Communication

The client's named contact is called. A plain-English summary is sent: what happened, what we did, what they need to do (revoke a small number of sessions, brief the affected user).

Morning — Hardening

Root cause: a convincing phishing message that bypassed click-time protection on a brand-new domain. Recommendations issued: move admins to phishing-resistant MFA, tighten mailbox rule policies, add the lookalike domain to gateway blocks. All actions implemented within 48 hours.

What MDR did that EDR alone wouldn't

  • Triaged an out-of-hours alert in minutes, not the next morning.
  • Connected endpoint, identity and email signals into one story.
  • Took response actions without waiting for the client to wake up.
  • Delivered a plain-English brief and a hardening plan, not a wall of logs.

Next step

If you'd like to see what 24/7 monitoring would look like for your business — and what it would have caught in the last 12 months — book a free 30-minute review.

Related services

Free cyber security review

Get a plain-English view of where your business stands.

30 minutes with a UK specialist. No obligation, no sales pitch.

Book my free cyber security review