SecurityBrief Asia - Technology news for CISOs & cybersecurity decision-makers
Asia
Hexnode XDR adds macOS support & new response tools

Hexnode XDR adds macOS support & new response tools

Thu, 1st Oct 2026 (Today)
Raphael Veloso
RAPHAEL VELOSO News Editor

Hexnode has expanded its XDR product with new threat detection, alert prioritisation and remediation features, while adding macOS support alongside Windows.

The update broadens its endpoint detection and response offering by combining threat investigation tools with endpoint management functions from its UEM platform. The additions are intended to help IT and security teams move from identifying suspicious activity to taking action with fewer manual steps.

The latest version adds integrations with Mandiant and Recorded Future, allowing endpoint activity to be checked against external threat intelligence feeds. It also introduces sandbox analysis for suspicious files and anomaly detection to flag unusual behaviour that may not match known threat signatures.

Alert handling is another focus. Hexnode has added severity-based alert ranking and dynamic risk scoring for devices, which should help security teams decide which incidents and endpoints need attention first.

The product now includes automated remediation based on configured rules and policies. This sits alongside one-click endpoint isolation, allowing affected devices to be cut off from the network while retaining management access through Hexnode.

Vulnerability management is also part of the wider package. The system can identify vulnerabilities and missing patches, with remediation carried out through Hexnode UEM, linking incident investigation to patching on affected devices.

Hexnode has also added custom dashboards so teams can tailor monitoring views by role and priority. Integrations with Splunk and QRadar are designed to connect the product with existing security information and event management systems for broader investigation and reporting.

The update extends support beyond Windows to macOS, expanding the number of desktop operating environments that can be monitored and managed from the same platform. That broadens the scope of a product Hexnode has positioned as closely tied to unified endpoint management.

Security spending is rising across South East Asia, according to figures cited by Hexnode, with 52% of ASEAN organisations planning to increase cybersecurity budgets. Detection, response and cloud security are among the priorities receiving greater attention, reflecting pressure on businesses to turn large volumes of alerts into decisions and actions.

Hexnode, part of Mitsogo, has been building its XDR offering around the link between security monitoring and endpoint management. It argues that bringing threat detection, device intelligence and management tools together can reduce the operational burden on security teams that would otherwise have to switch between multiple systems.

Artificial intelligence features are also included. Hexnode Genie AI provides plain-language alert summaries, while a feature called Analyse with Genie uses live incident data to explain what happened, identify what is affected and recommend a fix.

Hexnode presents alert prioritisation, asset scoring and automated remediation as building blocks for broader AI-assisted security operations workflows. It says these functions create the context and response framework needed to move from identifying incidents to deciding where action should be taken.

Apu Pavithran, Chief Executive Officer and Founder of Hexnode, set out the thinking behind the update in remarks cited by the company. “We built Hexnode XDR around one complaint we heard constantly: security tools are good at telling you something is wrong, and bad at helping you do anything about it. More alerts was never the request. Fewer steps between the alert and the fix - that was the request,” Pavithran said.

The product also allows administrators to configure exclusion policies for trusted files, applications and processes. This is intended to reduce false positives and keep investigations focused on activity that requires review.

By combining external threat intelligence, incident context, endpoint isolation, patch management and automated fixes, Hexnode is seeking to cover more of the security workflow within one product set.