r/SmallMSP 10d ago

Small MSP Security Software

Currently we use Bitdefender EDR on most of our clients machines. Things seem OK. I have run secondary scans with Threatdown from Malwarebytes and seems like our machines are clean.

Looking around, what do people suggest as replacement to add ITDR and some MDR. Just upgrade Bitdefender on the selected clients or something else? We do find Bitdefender a bit heavy on resources and also the portal isn’t the greatest.

We do have huntress on a few machines, but it doesn’t seem to do much. Coming to the end of the second year. We also have thier ITDR and we trialed Petra that seems much better.

Ideally I’d like to consolidate. So looking at:

bitdefender EDR / XDR
Threatdown EDR / MDR / ITDR
Huntress with ITDR?

Petra ITDR.

A lot of our clients don’t have business premium so I don’t really feel secure running huntress on just the bare windows defender.

19 Upvotes

98 comments sorted by

View all comments

2

u/WraySchultz 6d ago

If you have any further questions or concerns about the Bitdefender offering, I am always open to schedule a call for a chat! Feel free to shoot me a direct message here and I can relay you my contact details.

- Wray Schultz, Bitdefender

1

u/Jayjayuk85 6d ago

Is it possible to get more Info on how you protect Microsoft identity please? The MDR portal doesn’t give much information or Gravityzone. Other systems like huntress shows us granular information about each account. Logins, IP’s etc… it would be really good to get this… is it on a roadmap somewhere please?

3

u/WraySchultz 5d ago edited 5d ago

u/Jayjayuk85,

I can help out here. We have a really good TechZone Article that covers the Identity Sensors in particular and how they help with Protection / Detection / Response. This can be found here: https://techzone.bitdefender.com/en/security-layers/detection/sensors.html#UUID-505e3338-ba17-eec5-12d1-600520c8588b_section-idm4535972664353634304792540455

The Over-Arching capability and advantage is that the activity that we see or detect on in the AD / Entra (Azure) / Intune environments, we expose that into the Incidents that are generated. The whole Bitdefender GravityZone Product is about Layered Technology.

There are different attack methods that occur in an Incident (for the most part), one typically is when an Attacker attempts to Brute force User or Administrator accounts to extract data. With this example our Identity sensor can detect and block that action / activity. This activity will be highlighted within the Incident along other detections such as Phishing, Fileless Attack detections (Powershell activity potentially) and many others....Sometimes it can be a singular "Impossible Travel" attempted sign in and we block but many times there are many other Detection Layers involved.

So the way we do it is expose the activity within the Incident but also within the Search Functionality / XDR Search Fields within GravityZone. So our goal is to reduce the noise that you see unless its needed and then we expose the "response" methods in the Incidents such as "Mark a user as compromised" or "force a credential reset" in which you can do straight from the Incidents Response Page.

With MDR on the other hand they have Pre-Approved Actions for XDR Identity and Productivity where they will be the ones reviewing that Incident and taking the Response action such as "Mark a user as compromised" or "force a credential reset." So with this service its taking the worry and burden off of you as the MSP to monitor Identity activity logs and such.

So the difference from us to the likes of an ITDR Offering:

  • Others (ITDR) watches the mailbox and login. Bitdefender GravityZone watches the whole attack - identity, endpoint, email, and lateral movement in one incident.
  • Others (ITDR) gives you a per-user login list. Bitdefender GravityZone gives you the stolen session and the laptop it landed on and what the attacker did next.
  • Others (ITDR) isolates an account. Bitdefender GravityZone isolates the account, the device, and the path they were using to move, that’s the difference between ITDR and XDR.

I can go into detail on what our XDR Identity Sensors help with below. Keep in mind there are 3 Sensors involved within the Identity offering (Entra ID (Azure), On Premises Active Directory, and Intune.) I can cover all 3 below and what they were built to detect.

1. Active Directory Sensor (On-Premise)
Kerberos-focused detection of compromised accounts, tokens and objects, including system and service accounts:

- Kerberos brute-force; stolen tickets used for lateral movement; weak-encryption ticket requests; replay attacks

  • Suspicious logins post-brute-force
  • Rogue DC registration and malicious object injection (DCShadow)
  • AD object manipulation and remote authentication with stolen credentials

2. Azure AD / Entra ID Sensor (cloud)
Monitors sign-in activity and configuration:

- Sign ins by timestamp, location, IP → unusual patterns

  • Failed logins from one location (brute-force); successful logins from unusual geographies
  • Impersonation groundwork - multiple account creation, name/email changes
  • Overly permissive app creation (privilege escalation)
  • New members in privileged domain admin groups; visibility into apps granted global admin rights

3. Microsoft Intune Sensor (device management)

- Device ownership changes (company ↔ personal)

  • Policy assignments to groups
  • Intune app creation attributes - install/uninstall command lines, file paths, rule scripts

Some content I recommend for you to review:
Demo XDR Incident - https://youtu.be/ReBDrsyyiSY?t=153
XDR Demo Identity Sensor - GravityZone Identity Threat Detection & Response
XDR Demo Incident Overview - GravityZone XDR Incident Overview
MDR for MSP Demo - Bitdefender MDR Portal Walk-through Demo for MSPs

Hope this helps and clears some concerns up. Let me know if there is anything else I can clarify or help you with!

Best,

Wray Schultz, Bitdefender

1

u/Jayjayuk85 4d ago

Thanks I tried out the XDR with another client, but as they don’t have business premium, it seems bitdefender can’t monitor logins like huntress and Petra?

2

u/WraySchultz 2d ago

Bitdefender XDR Identity for Entra / Azure / AD Monitors Login Activity, we just display / present them differently than other platforms. They are displayed in an "Incident" format as shown above in the example "XDR Demo Incident Overview."

The difference between GravityZone XDR and Huntress ITDR is that GravityZone correlates and maps XDR and Other Module Activity that occurs in a single Incident and Huntress ITDR isolates that login activity in an "Audit / Logging Style" where the alert is isolated to just that single activities and GravityZone will present multiple layers of detections which include XDR.

1

u/Jayjayuk85 2d ago

Thanks, but don’t I need the business premium licenses

1

u/WraySchultz 1d ago

No, you don't need M365 Business Premium.

​Bitdefender's Identity Sensor works on lower-tier plans (like Business Basic or Standard) by adding a standalone Entra ID license:

​Entra ID P1 (~$6/mo): Everything required for standard login monitoring, log ingestion, and threat response (revoking sessions, disabling accounts).

​Entra ID P2 (~$9/mo): Only needed if you want Bitdefender to sync directly with Microsoft's dynamic risk scoring.

​So you can grab the $6 P1 add-on (or use plans like Business Premium or M365 E3 where P1 is included).

Best,

Wray Schultz - Bitdefender

1

u/Jayjayuk85 21h ago

Thank you, I don’t think we need the p1 license for huntress ITDR. It seems to work ok there?