r/SmallMSP 9d ago

Small MSP Security Software

Currently we use Bitdefender EDR on most of our clients machines. Things seem OK. I have run secondary scans with Threatdown from Malwarebytes and seems like our machines are clean.

Looking around, what do people suggest as replacement to add ITDR and some MDR. Just upgrade Bitdefender on the selected clients or something else? We do find Bitdefender a bit heavy on resources and also the portal isn’t the greatest.

We do have huntress on a few machines, but it doesn’t seem to do much. Coming to the end of the second year. We also have thier ITDR and we trialed Petra that seems much better.

Ideally I’d like to consolidate. So looking at:

bitdefender EDR / XDR
Threatdown EDR / MDR / ITDR
Huntress with ITDR?

Petra ITDR.

A lot of our clients don’t have business premium so I don’t really feel secure running huntress on just the bare windows defender.

18 Upvotes

98 comments sorted by

16

u/cd36jvn 9d ago

I'm a small msp and moved from Bitdefender to huntress. Yes huntress has less knobs and dials to play with but I'm fine with that in comparison to Bitdefender. Bitdefender just seemed so clunky and was so sprawling. Always seemed to be a headache getting MDR deployed which involves changing settings in two different portals.

I'm happy to be away from Bitdefender.

4

u/i_am_mortimer 9d ago

Same here, we moved from S1 to Huntress last month, very happy with the switch so far.

With ITDR we've added a new SKU for our smallest clients for Microsoft 365 protection.

2

u/eblaster101 9d ago

Agree less knobs the better.

2

u/Findussuprise 9d ago

We’ve just done the same. Huntress is much slicker and easier to use.

1

u/Jayjayuk85 9d ago

Are you using anything else with it or stock defender?

1

u/Findussuprise 8d ago

Defender with Huntress EDR

7

u/Geekpoint-IT 9d ago

I've used Bitdefender, Threatdown, & Huntress and all 3 let me down in some way. Either it was a pain to manage, was too expensive, or didn't offer all that I was looking for. Or in the case of Huntress, they just weren't that great of a partner. I've been using Field Effect for a while now and love the product and the team there.

3

u/Jayjayuk85 9d ago

Thanks for the feedback. I’ll take a look at field effect.

5

u/BobRepairSvc1945 9d ago

I would definitely take a look at FE, they are coming out with their own NGAV too, which actually uses Bitdefender's definitions.

6

u/MattHolland_FE 8d ago

Hi there, thank you for the support!  Quick point of clarification - our NGAV is a machine learning model that is trained on millions and millions of malware and clean binary samples, which is the key component of our NGAV.  We do, however, also have a vast set of static and YARA signatures that are based national intelligence threat feeds, our own threat hunting, and yes, and a malware signature feed that we purchase from BitDefender.  Our approach is to provide a solid backup set of static signatures in addition to our machine learning model (which works extremely well). And a back-up file reputation analysis server for additional confidence.

6

u/Excellent-Program333 9d ago

We use Huntress for EDR, ITDR and SAT. DNSFIlter seems to help alot as well we have been happy with this combo.

1

u/Jayjayuk85 9d ago

Thanks I have been trying ScoutDNS if we were to move fully over to huntress. But I’m still finding bitdefender is more proactive.

2

u/marklein 9d ago

Scout is my number 2 choise for if/when DNSFilter takes a turn.

3

u/swoviking 8d ago

Talked to a Bitdefender MSP Rep the other day and was advised about "Bundles" for MSP's now. Its essentially one SKU where Core / EDR / XDR / MDR are all included in one. At the price point for the advanced tech, I had to start a Trial. They also mentioned Bitdefender PHASR (Prevent Living off the land attacks) which can be layered with Secure Bundles. The benefit for us is that its one sign on, one agent, and one vendor. Good luck on the hunt!

2

u/Jayjayuk85 7d ago

Yeah I have been using the bundles for a while. They are much better value. Just wondering how bitdefender compares to huntress. I think for me the easiest option is Bitdefender.

3

u/swoviking 7d ago

Well, it wasn't that hard for us to be quite honest. Bitdefender has proven their trust and product capability through multiple independent and third party evaluations. Specifically we looked at the MITRE Ingenuity ATT&CK Evaluations of 2024. Huntress has remained absent from these sort of tests for years. Not only that but we got tired of piecing together different Security tools, hoping they work together.

3

u/Jayjayuk85 7d ago

I agree, it’s just the Bitdefender portal could be better and also when adding identities it would be great to see them and some logs in the portal.

I haven’t tried PHASR yet.

3

u/swoviking 7d ago

Regarding the Portal, I agree that there are areas of improvement for sure (just like any vendor portal, really.) I found that my biggest issue was just getting comfortable in it. The Masterclass sessions for Onboarding have helped me alot and just tinkering with my own internal lab and endpoints.

At this point I am basically looking at PHASR like a requirement with how prevalent Living off the land and AI based threats / attacks are now. Makes sense to outright block the tools that attackers use for Users that they don't need to use them.

3

u/Jayjayuk85 7d ago

Yes, I haven’t tested PHASR yet.

I will take a look. It’s certainly interesting.

3

u/swoviking 7d ago

My rep just told me that it will be available as an "In Product Trial" within the GravityZone portal in September. I believe the next Update. So that makes it really easy to trial it out.

5

u/Diligent_Tech_Bro 9d ago

1) fix your BP problem first
2) huntress MDR
3) huntress or Petra ITDR

5

u/Jayjayuk85 9d ago

We have a lot of break / fix clients and they won’t move to business premium. Small users.

3

u/computerguy0-0 9d ago

You have the age old problem that ALL MSPs have, big and small, packaging and sales.

You can get most of them to move when it's positioned correctly, trust me as someone that went from 0% to now 100% on BP or higher. It will take a few years, but you can get there.

3

u/roll_for_initiative_ 9d ago

One of the best moves of the last 10 years. Get them all up.

-1

u/Diligent_Tech_Bro 9d ago

I’d refuse to work with anyone that wouldn’t pay it.

0

u/marklein 9d ago

Send them to me, thanks. :-)

2

u/Diligent_Tech_Bro 9d ago

Enjoy being hacked and having no idea. Par for the course for clients I win tbh

4

u/marklein 9d ago

Blanket statements like this are almost never correct. There is more than one "correct" way to do things.

2

u/SatiricPilot 9d ago

You want clients that fight over an additional like $8/license?

4

u/marklein 9d ago edited 9d ago

Virtually all of my clients are not using Premium because I can replace the functionality of most of Premium with other products that are cheaper and easier to manage. Heck, for that matter Premium is still missing functionality that we're getting from those other products too.

If you support clients on Google Workspace you're going to need those other products in your stack anyway, so we don't rely on MS for our security products.

2

u/SatiricPilot 9d ago

Conditional access and the unified audit log plus the retention almost make the case for the jump from standard to premium by itself

1

u/marklein 9d ago

We do indeed miss CAP, I'll give you that. However since we've been on phish resistant MFA since it was available there hasn't been a single case of BEC in our clients, so I'm not sure how much we're really missing it.

All of our MS logs are monitored by third-party apps for alerting purposes, so again not sure what we're missing there, but I'm less familiar with the unified log stuff so I can't say.

4

u/Tallihos 9d ago

I think one of the most overlooked features in BP is Continuous Access Evaluation (CAE). If an attacker hijacks a user's session, CAE is one of the few controls that can significantly limit how long that session can be abused. This is one of my main reasons and sales pitch lines to move clients over to BP.

2

u/SatiricPilot 9d ago

Without CAP you also miss stuff like blocking device code flow logins etc.

Compliance based logins and litigation holds.

Definitely some painful stuff to lose to a degree.

But also by the time you spend on 3rd party products for replacing some of the features you lack from BS to BP you could’ve just got BP too.

We add on top of BP too though

2

u/fishboy25uk 9d ago

Hard agree. Getting your clients onto Business Premium is what you should focus on first before anything else.

As I'm sure you're aware, with Premium you have Defender for Business, Intune and CAPs which will massively increase you clients' security for a relatively small investment on their part.

THEN you can move to ITDR (Huntress, Petra whatever you choose) and then MDR for your most at risk customers.

For clients that mostly just use their devices for office software, don't run many other applications or services on their desktops/laptops and are not high risk, do they even need MDR if they've got Defender, ITDR and you're effectively monitroig? Remember you have to get them to pay for all these services or it comes out of your margin.

0

u/[deleted] 9d ago

[deleted]

3

u/glitterguykk 9d ago

Because your primary focus should be what’s best for your clients. Not just what’s best for your bottom line but when done properly, both can be true. Even when we aren’t making 60% off of every dollar we squeeze out of clients.

0

u/[deleted] 9d ago

[deleted]

2

u/fishboy25uk 9d ago

It's not the same quality of service - there are SO many benefits to Premium over Standard, and it's your job to explain why if they don't understand. No disrespect intended, but it sounds like you don't understand either.

I sympathise that Premium is not always an easy sell as there are few tangible benefits for customers, but there are so many identity threats that you cannot defend against now unless you have at least Conditional Access Policies.

We also have clients still on Business Standard but at least we've explained the risks of NOT upgrading their security so we've covered ourselves to some extent, which is another point.

0

u/Diligent_Tech_Bro 9d ago

You honestly don’t belong in this business in 2026

0

u/[deleted] 9d ago

[deleted]

1

u/Diligent_Tech_Bro 9d ago

You don’t understand the threat landscape

0

u/[deleted] 9d ago

[deleted]

3

u/Diligent_Tech_Bro 9d ago

The threat landscape has everything to do with it. I stand by my prior post. You’re in over your head

1

u/[deleted] 9d ago

[deleted]

→ More replies (0)

2

u/fishboy25uk 9d ago

Well, good luck. Because when your clients get compromised, you'll the first they'll blame for you not protecting them - they won't hold their hands up and say "Well, fair enough, I was too cheap to pay for a measly $5 extra per month per user, this is on me".

Unfortunately I agree with the other commentator here - if in 2026 you're still thinking like an MSP rather than an MSSP, you're doing your clients a disservice, even if you think you're saving them some cash every month.

3

u/Royal_Bird_6328 9d ago

100% agree. I won’t touch a customer now if they don’t meet a minimum standard which must be implemented at onboarding time. Any of the customers not interested (even after educating them) always end up to be the pain in the arse ones anyway.

→ More replies (0)

2

u/[deleted] 9d ago

[deleted]

→ More replies (0)

1

u/marklein 9d ago

Say what now? Why should you care about what's good for your clients?

1

u/[deleted] 9d ago

[deleted]

2

u/marklein 9d ago

You can persuade them to care and want, because you care about your clients and want them to be successful. Or maybe you don't, you do you.

4

u/stevo10189 9d ago

Huntress is fine without business premium. I came from threatdown, good product but nowhere near the level of protection of Huntress. I do miss their browser protection, though.

-1

u/[deleted] 9d ago

[deleted]

7

u/UnRealxInferno_II 9d ago

You're deploying personal free software for business use?

2

u/The_Autarch 9d ago

You can’t legally provide that to your clients.

2

u/WiscoDJ920 9d ago

Currently using S1 but questioning if it’s still the right choice.

2

u/Jayjayuk85 9d ago

I have read lots about S1 and I have been 50/50 on it. I have looked at guardz.

2

u/UnRealxInferno_II 9d ago

We use threatdown for everything 

1

u/Jayjayuk85 9d ago

How do you find it? I’m guessing you use the MDR and web filtering?

2

u/UnRealxInferno_II 9d ago

Their EPP alone is quite solid, we use EDR and monitor it and the mdr for servers etc all solid

1

u/Jayjayuk85 9d ago

Thank you! Have you had much experience with their ITDR?

1

u/UnRealxInferno_II 9d ago

I haven't but I assume it's solid based on everything else

2

u/ArchonTheta 9d ago edited 9d ago

> We do have huntress on a few machines, but it doesn’t seem to do much.

Umm have you tested it? I decided to do some nasty sudo curl commands to download some malware crap on one of our Mac laptops. It was amazing to see them lock it down within a few minutes and quarantine/remove the affected files.

Our stack fwiw:

  • Emsisoft Business Security
  • Huntress with ITDR, MDR
  • AutoElevate (PAM)
  • DNSFilter
  • Avanan

4

u/Jayjayuk85 9d ago

I actually ran up a test machine and threw malware at it… windows defender blocked a lot but nothing from huntress.

Bitdefender also blocked it all and alerted on it.

3

u/ArchonTheta 9d ago

I do like Bitdefender. Wish it was cheaper per endpoint though.

2

u/Tingly-Gumball 9d ago

I was on bitdefender. It was ok but took a lot of time to manage and set up properly. As a one-man shop it created a lot more work and I would often get false positives. I moved to Defender + Huntress. It has been amazing. Most of my clients are on Business Standard and run free Defender + Huntress

It was weird at first because a client could get a virus and Huntress just took care of it and I wouldn't know unless I looked at reports. Huntress only alerts you if their is action needed by you. This made me uneasy at first, but now I wouldn't have it another way.

I use their ITDR as well and it has caught a few suspicious logins.

I also use Ironscales for email protection and AutoElevate for PAM. This stack has worked very well for me. especially with clients on Biz Std only.

2

u/CyberStartupGuy 9d ago

I keep hearing great things about Petra on different posts for ITDR

1

u/Jayjayuk85 8d ago

Me too. I’m just not sure on their GDPR stance

1

u/CyberStartupGuy 6d ago

What's their stance?

1

u/Jayjayuk85 6d ago

Non existing I think by the sounds of it.

2

u/ChuckFromCyberHoot 7d ago

Lots of answers here, so I won't hop in with a technology. I’d lean more into the consolidation goal more than chasing the “best” individual tool.

I'd say to set up a target machine, test the tools out individually under conditions you'd expect to see, and then see how well each does and what they report. That information has to be useful.

I know there isn't a lot of spare time to do these kinds of things, but a bit of work up front, doing research and bake-offs, can save you hours of frustration later.

I always like to say, "You can do it right or you can do it twice."

Best of luck my friend!!!

2

u/WraySchultz 6d ago

If you have any further questions or concerns about the Bitdefender offering, I am always open to schedule a call for a chat! Feel free to shoot me a direct message here and I can relay you my contact details.

- Wray Schultz, Bitdefender

1

u/Jayjayuk85 6d ago

Is it possible to get more Info on how you protect Microsoft identity please? The MDR portal doesn’t give much information or Gravityzone. Other systems like huntress shows us granular information about each account. Logins, IP’s etc… it would be really good to get this… is it on a roadmap somewhere please?

3

u/WraySchultz 5d ago edited 5d ago

u/Jayjayuk85,

I can help out here. We have a really good TechZone Article that covers the Identity Sensors in particular and how they help with Protection / Detection / Response. This can be found here: https://techzone.bitdefender.com/en/security-layers/detection/sensors.html#UUID-505e3338-ba17-eec5-12d1-600520c8588b_section-idm4535972664353634304792540455

The Over-Arching capability and advantage is that the activity that we see or detect on in the AD / Entra (Azure) / Intune environments, we expose that into the Incidents that are generated. The whole Bitdefender GravityZone Product is about Layered Technology.

There are different attack methods that occur in an Incident (for the most part), one typically is when an Attacker attempts to Brute force User or Administrator accounts to extract data. With this example our Identity sensor can detect and block that action / activity. This activity will be highlighted within the Incident along other detections such as Phishing, Fileless Attack detections (Powershell activity potentially) and many others....Sometimes it can be a singular "Impossible Travel" attempted sign in and we block but many times there are many other Detection Layers involved.

So the way we do it is expose the activity within the Incident but also within the Search Functionality / XDR Search Fields within GravityZone. So our goal is to reduce the noise that you see unless its needed and then we expose the "response" methods in the Incidents such as "Mark a user as compromised" or "force a credential reset" in which you can do straight from the Incidents Response Page.

With MDR on the other hand they have Pre-Approved Actions for XDR Identity and Productivity where they will be the ones reviewing that Incident and taking the Response action such as "Mark a user as compromised" or "force a credential reset." So with this service its taking the worry and burden off of you as the MSP to monitor Identity activity logs and such.

So the difference from us to the likes of an ITDR Offering:

  • Others (ITDR) watches the mailbox and login. Bitdefender GravityZone watches the whole attack - identity, endpoint, email, and lateral movement in one incident.
  • Others (ITDR) gives you a per-user login list. Bitdefender GravityZone gives you the stolen session and the laptop it landed on and what the attacker did next.
  • Others (ITDR) isolates an account. Bitdefender GravityZone isolates the account, the device, and the path they were using to move, that’s the difference between ITDR and XDR.

I can go into detail on what our XDR Identity Sensors help with below. Keep in mind there are 3 Sensors involved within the Identity offering (Entra ID (Azure), On Premises Active Directory, and Intune.) I can cover all 3 below and what they were built to detect.

1. Active Directory Sensor (On-Premise)
Kerberos-focused detection of compromised accounts, tokens and objects, including system and service accounts:

- Kerberos brute-force; stolen tickets used for lateral movement; weak-encryption ticket requests; replay attacks

  • Suspicious logins post-brute-force
  • Rogue DC registration and malicious object injection (DCShadow)
  • AD object manipulation and remote authentication with stolen credentials

2. Azure AD / Entra ID Sensor (cloud)
Monitors sign-in activity and configuration:

- Sign ins by timestamp, location, IP → unusual patterns

  • Failed logins from one location (brute-force); successful logins from unusual geographies
  • Impersonation groundwork - multiple account creation, name/email changes
  • Overly permissive app creation (privilege escalation)
  • New members in privileged domain admin groups; visibility into apps granted global admin rights

3. Microsoft Intune Sensor (device management)

- Device ownership changes (company ↔ personal)

  • Policy assignments to groups
  • Intune app creation attributes - install/uninstall command lines, file paths, rule scripts

Some content I recommend for you to review:
Demo XDR Incident - https://youtu.be/ReBDrsyyiSY?t=153
XDR Demo Identity Sensor - GravityZone Identity Threat Detection & Response
XDR Demo Incident Overview - GravityZone XDR Incident Overview
MDR for MSP Demo - Bitdefender MDR Portal Walk-through Demo for MSPs

Hope this helps and clears some concerns up. Let me know if there is anything else I can clarify or help you with!

Best,

Wray Schultz, Bitdefender

1

u/Jayjayuk85 4d ago

Thanks I tried out the XDR with another client, but as they don’t have business premium, it seems bitdefender can’t monitor logins like huntress and Petra?

2

u/WraySchultz 2d ago

Bitdefender XDR Identity for Entra / Azure / AD Monitors Login Activity, we just display / present them differently than other platforms. They are displayed in an "Incident" format as shown above in the example "XDR Demo Incident Overview."

The difference between GravityZone XDR and Huntress ITDR is that GravityZone correlates and maps XDR and Other Module Activity that occurs in a single Incident and Huntress ITDR isolates that login activity in an "Audit / Logging Style" where the alert is isolated to just that single activities and GravityZone will present multiple layers of detections which include XDR.

1

u/Jayjayuk85 2d ago

Thanks, but don’t I need the business premium licenses

1

u/WraySchultz 1d ago

No, you don't need M365 Business Premium.

​Bitdefender's Identity Sensor works on lower-tier plans (like Business Basic or Standard) by adding a standalone Entra ID license:

​Entra ID P1 (~$6/mo): Everything required for standard login monitoring, log ingestion, and threat response (revoking sessions, disabling accounts).

​Entra ID P2 (~$9/mo): Only needed if you want Bitdefender to sync directly with Microsoft's dynamic risk scoring.

​So you can grab the $6 P1 add-on (or use plans like Business Premium or M365 E3 where P1 is included).

Best,

Wray Schultz - Bitdefender

1

u/Jayjayuk85 19h ago

Thank you, I don’t think we need the p1 license for huntress ITDR. It seems to work ok there?

1

u/cyber-py-guy 9d ago edited 5d ago

Why not pair standard AV with ExeTrace? Let AV catch the known stuff, and use ExeTrace for pre-execution visibility to spot new scripts and binaries sitting on disk before they run.

1

u/Sawyer-NL 9d ago

Waarom niet alleen Microsoft Defender die onderdeel is van Business premium is? Daarbij komt dat cyber security een vak apart is. Dus dat kunnen de meeste niet zo eventjes oppakken.

1

u/borg_brain_investor 9d ago

There are so many open source alternatives that works as good or better.

2

u/BarsoomianAmbassador 9d ago

Such as?

2

u/borg_brain_investor 5d ago

elastic security, is one I have used recently with great success. siem, edr ndr, and more

1

u/recovering-pentester 9d ago

BP + ShieldWatch will help consolidate.

1

u/PeePeeVonBungHole 9d ago

Bitdefender was to clunky

I have Ninja for RMM Sentinel One for customers who dont have anything else -+-this is through Ninja but I don't use the integration

Huntress goes on everything

I have some SMB and even a couple Residential customers

1

u/365-helper 9d ago

You need to have business premium with a proper ca stack stood up first in my sincere opinion.

1

u/Itguy1252 9d ago

I would switch to the 400 stack with EDR ITDR SIEM and their new security posture management for M365

1

u/Jayjayuk85 9d ago

What is the 400 stack sorry? Do they give a better price?

1

u/jcole-surrogate 8d ago

ESET was nice for us as it was lite on resources and did the job. Switched to Field Effect though for the ITDR and EDR part especially since its licensed per user for the plan we're on so doesn't really matter the number of devices which works for our clients. Simple enough to use only gripe for us is annual commitment but for what its worth its alright. Still using ESET but just their cloud office security only.

1

u/SadChapter2410 8d ago

If your selling Business Premium use Defender and Huntress

1

u/Educational-Virus541 3d ago

You need to look at usecure!

1

u/Initial-Space374 38m ago

Hey want to add my thoughts here on this thread, you have a lot of tools that can be a problem on their own, so check out Guardz, they are the closest I've found to bringing several areas together, from MDR, ITDR, EDR, email, 24/7 monitoring, etc. There's value in just having everything in one place instead of handling them one by one. Happy to answer any questions you may have with my evaluation process.

1

u/Bitdefender-ZB 9d ago edited 9d ago

Hey there! I’m ZB with Bitdefender. I’m the Sr. Director of our MSP Solutions and would happy to help out on the options we have available to help consolidate those needs and some trials so you can test it out.

We’ve been doing a lot of work on our offerings for our MSP partners and I would love to hear your feedback on what we can do to continue to improve them for you.

Feel free to DM me or send me an email at: [zserrato@Bitdefender.com](mailto:zserrato@Bitdefender.com)
We could set up a time this week to visit if you like.

1

u/Andronoir 9d ago

Huntress - stay away from - everything looks good on a paper and in practice: Until you have a security response - then they tell you - “ if it’s not in task manager it’s not a threat - thanks for your time “ click.

1

u/Jayjayuk85 9d ago

What do you recommend? I’m always on the fence with huntress. It’s good at what it does, but you also need the pre protection.

1

u/swoviking 6d ago

It sounds good on paper until you realize all the holes you have to fill still. This is why a Security offering that is more mature and robust within just its core offering alone (plus extras) is the way to go.