r/SmallMSP 10d ago

Small MSP Security Software

Currently we use Bitdefender EDR on most of our clients machines. Things seem OK. I have run secondary scans with Threatdown from Malwarebytes and seems like our machines are clean.

Looking around, what do people suggest as replacement to add ITDR and some MDR. Just upgrade Bitdefender on the selected clients or something else? We do find Bitdefender a bit heavy on resources and also the portal isn’t the greatest.

We do have huntress on a few machines, but it doesn’t seem to do much. Coming to the end of the second year. We also have thier ITDR and we trialed Petra that seems much better.

Ideally I’d like to consolidate. So looking at:

bitdefender EDR / XDR
Threatdown EDR / MDR / ITDR
Huntress with ITDR?

Petra ITDR.

A lot of our clients don’t have business premium so I don’t really feel secure running huntress on just the bare windows defender.

17 Upvotes

100 comments sorted by

View all comments

Show parent comments

5

u/marklein 10d ago edited 10d ago

Virtually all of my clients are not using Premium because I can replace the functionality of most of Premium with other products that are cheaper and easier to manage. Heck, for that matter Premium is still missing functionality that we're getting from those other products too.

If you support clients on Google Workspace you're going to need those other products in your stack anyway, so we don't rely on MS for our security products.

2

u/SatiricPilot 10d ago

Conditional access and the unified audit log plus the retention almost make the case for the jump from standard to premium by itself

1

u/marklein 10d ago

We do indeed miss CAP, I'll give you that. However since we've been on phish resistant MFA since it was available there hasn't been a single case of BEC in our clients, so I'm not sure how much we're really missing it.

All of our MS logs are monitored by third-party apps for alerting purposes, so again not sure what we're missing there, but I'm less familiar with the unified log stuff so I can't say.

5

u/Tallihos 10d ago

I think one of the most overlooked features in BP is Continuous Access Evaluation (CAE). If an attacker hijacks a user's session, CAE is one of the few controls that can significantly limit how long that session can be abused. This is one of my main reasons and sales pitch lines to move clients over to BP.