> For the complete documentation index, see [llms.txt](https://docs.sec1.io/user-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.sec1.io/user-docs/10-siem-edr-xdr.md).

# SIEM + EDR/XDR

Sec1 SIEM + EDR/XDR is unified detection and response. A lightweight agent collects logs and endpoint telemetry from your fleet; the platform detects threats, correlates them into incidents and lets your SOC respond — from one console.

## Overview

Understand what the platform does and how the pieces fit together:

* [Overview](/user-docs/10-siem-edr-xdr/overview.md)

## Architecture

A simple end-to-end picture — agents, ingest, pipeline, detection, correlation, AI and response:

* [Architecture](/user-docs/10-siem-edr-xdr/architecture.md)

## Data collection

Two ways to get data in — the Sec1 agent or an existing log collector — and how one agent serves SIEM, EDR and XDR:

* [Data Collection](/user-docs/10-siem-edr-xdr/data-collection.md)

## Setup & access

Reach the live console, sign in with your platform credentials and understand the gateway:

* [Setup & Access](/user-docs/10-siem-edr-xdr/setup-and-access.md)

## Install the agent

Prerequisites, the network allowlist and single vs bulk install on Windows, Linux or macOS:

* [Install the Agent](/user-docs/10-siem-edr-xdr/install-the-agent.md)

## Endpoints & telemetry

Read the per-host detail view — the telemetry collected from each endpoint:

* [Endpoints & Telemetry](/user-docs/10-siem-edr-xdr/endpoints-and-telemetry.md)

## Vulnerability management

Find and triage vulnerable software across the fleet and per host:

* [Vulnerability Management](/user-docs/10-siem-edr-xdr/vulnerability-management.md)

## Device control

Inventory connected peripherals and approve or block them:

* [Device Control](/user-docs/10-siem-edr-xdr/device-control.md)

## Application control

Allow or deny software execution and installation by rule:

* [Application Control](/user-docs/10-siem-edr-xdr/application-control.md)

## Detections, alerts & incidents

Follow the detection-to-incident flow and investigate cases:

* [Detections, Alerts & Incidents](/user-docs/10-siem-edr-xdr/detections-alerts-incidents.md)

## Response actions

The live-response toolkit for acting on a host:

* [Response Actions](/user-docs/10-siem-edr-xdr/response-actions.md)
