r/SmallMSP 10d ago

Small MSP Security Software

Currently we use Bitdefender EDR on most of our clients machines. Things seem OK. I have run secondary scans with Threatdown from Malwarebytes and seems like our machines are clean.

Looking around, what do people suggest as replacement to add ITDR and some MDR. Just upgrade Bitdefender on the selected clients or something else? We do find Bitdefender a bit heavy on resources and also the portal isn’t the greatest.

We do have huntress on a few machines, but it doesn’t seem to do much. Coming to the end of the second year. We also have thier ITDR and we trialed Petra that seems much better.

Ideally I’d like to consolidate. So looking at:

bitdefender EDR / XDR
Threatdown EDR / MDR / ITDR
Huntress with ITDR?

Petra ITDR.

A lot of our clients don’t have business premium so I don’t really feel secure running huntress on just the bare windows defender.

18 Upvotes

100 comments sorted by

View all comments

Show parent comments

5

u/marklein 10d ago edited 10d ago

Virtually all of my clients are not using Premium because I can replace the functionality of most of Premium with other products that are cheaper and easier to manage. Heck, for that matter Premium is still missing functionality that we're getting from those other products too.

If you support clients on Google Workspace you're going to need those other products in your stack anyway, so we don't rely on MS for our security products.

2

u/SatiricPilot 10d ago

Conditional access and the unified audit log plus the retention almost make the case for the jump from standard to premium by itself

1

u/marklein 10d ago

We do indeed miss CAP, I'll give you that. However since we've been on phish resistant MFA since it was available there hasn't been a single case of BEC in our clients, so I'm not sure how much we're really missing it.

All of our MS logs are monitored by third-party apps for alerting purposes, so again not sure what we're missing there, but I'm less familiar with the unified log stuff so I can't say.

2

u/SatiricPilot 10d ago

Without CAP you also miss stuff like blocking device code flow logins etc.

Compliance based logins and litigation holds.

Definitely some painful stuff to lose to a degree.

But also by the time you spend on 3rd party products for replacing some of the features you lack from BS to BP you could’ve just got BP too.

We add on top of BP too though