SecurityBrief UK - Technology news for CISOs & cybersecurity decision-makers
United Kingdom
Hexnode adds macOS support & new XDR response tools

Hexnode adds macOS support & new XDR response tools

Thu, 1st Oct 2026 (Today)
Raphael Veloso
RAPHAEL VELOSO News Editor

Hexnode has expanded its XDR product with new threat detection and response features, along with support for macOS. The update extends the product beyond Windows and adds new tools for security teams.

New capabilities include threat intelligence integrations, alert prioritisation, asset scoring and automated remediation. Hexnode also added sandbox analysis, anomaly detection, endpoint isolation and vulnerability management tied to its unified endpoint management platform.

Hexnode, the software division of Mitsogo, aims to address a common security operations problem: the gap between identifying a threat and fixing the issue on an affected device. According to the company, the product combines detection, device intelligence and endpoint management in a single workflow.

The expansion comes as businesses increase spending on cyber defence. Hexnode cited research showing that 85% of UK enterprises expect cybersecurity budgets to rise, while half are prioritising AI threat hunting.

Detection tools

The latest version of Hexnode XDR brings external threat intelligence into a central incident view. Integrations with Mandiant and Recorded Future are intended to help security teams compare endpoint activity with known threat indicators.

Suspicious files can also be tested in an isolated sandbox, with the results fed back into the detection workflow. Anomaly detection is designed to flag unusual activity that does not match known attack signatures.

Hexnode has also introduced alert prioritisation based on severity and urgency. Asset scoring assigns endpoints a dynamic risk score based on defined parameters, helping teams decide which devices need closer scrutiny.

To reduce false positives, administrators can set exclusion policies for trusted files, applications and processes. Custom dashboards allow security teams to tailor the information they monitor to their role.

Response steps

On the response side, Hexnode XDR now allows one-click endpoint isolation. The feature is intended to disconnect affected devices from the network while preserving management access through Hexnode.

Vulnerability management has also been linked to Hexnode UEM, allowing teams to identify missing patches and carry out remediation through the endpoint management system. The aim is to connect threat investigation with patching and other corrective action.

Automated remediation is another new element. Configured rules and policies can trigger predefined fixes, reducing repetitive manual work for security staff.

Hexnode XDR also integrates with Splunk and QRadar, connecting it with existing security information and event management systems used for wider investigation and reporting.

AI direction

The update also includes AI-based investigation tools under the Hexnode Genie AI name. The system can produce plain-language alert summaries and use live incident data to explain what happened, identify what is affected and recommend a fix, according to the company.

Hexnode said the combination of alert prioritisation, asset scoring and automated remediation forms the basis for broader AI-assisted security operations workflows. That reflects a wider push across the cybersecurity industry to reduce the workload on analysts dealing with growing numbers of alerts and device risks.

Apu Pavithran, Chief Executive Officer and Founder of Hexnode, described the challenge in remarks cited by the company.

"We built Hexnode XDR around one complaint we heard constantly: security tools are good at telling you something is wrong, and bad at helping you do anything about it. More alerts was never the request. Fewer steps between the alert and the fix - that was the request," said Pavithran.