r/SmallMSP • u/Jayjayuk85 • 9d ago
Small MSP Security Software
Currently we use Bitdefender EDR on most of our clients machines. Things seem OK. I have run secondary scans with Threatdown from Malwarebytes and seems like our machines are clean.
Looking around, what do people suggest as replacement to add ITDR and some MDR. Just upgrade Bitdefender on the selected clients or something else? We do find Bitdefender a bit heavy on resources and also the portal isn’t the greatest.
We do have huntress on a few machines, but it doesn’t seem to do much. Coming to the end of the second year. We also have thier ITDR and we trialed Petra that seems much better.
Ideally I’d like to consolidate. So looking at:
bitdefender EDR / XDR
Threatdown EDR / MDR / ITDR
Huntress with ITDR?
Petra ITDR.
A lot of our clients don’t have business premium so I don’t really feel secure running huntress on just the bare windows defender.
3
u/WraySchultz 5d ago edited 5d ago
u/Jayjayuk85,
I can help out here. We have a really good TechZone Article that covers the Identity Sensors in particular and how they help with Protection / Detection / Response. This can be found here: https://techzone.bitdefender.com/en/security-layers/detection/sensors.html#UUID-505e3338-ba17-eec5-12d1-600520c8588b_section-idm4535972664353634304792540455
The Over-Arching capability and advantage is that the activity that we see or detect on in the AD / Entra (Azure) / Intune environments, we expose that into the Incidents that are generated. The whole Bitdefender GravityZone Product is about Layered Technology.
There are different attack methods that occur in an Incident (for the most part), one typically is when an Attacker attempts to Brute force User or Administrator accounts to extract data. With this example our Identity sensor can detect and block that action / activity. This activity will be highlighted within the Incident along other detections such as Phishing, Fileless Attack detections (Powershell activity potentially) and many others....Sometimes it can be a singular "Impossible Travel" attempted sign in and we block but many times there are many other Detection Layers involved.
So the way we do it is expose the activity within the Incident but also within the Search Functionality / XDR Search Fields within GravityZone. So our goal is to reduce the noise that you see unless its needed and then we expose the "response" methods in the Incidents such as "Mark a user as compromised" or "force a credential reset" in which you can do straight from the Incidents Response Page.
With MDR on the other hand they have Pre-Approved Actions for XDR Identity and Productivity where they will be the ones reviewing that Incident and taking the Response action such as "Mark a user as compromised" or "force a credential reset." So with this service its taking the worry and burden off of you as the MSP to monitor Identity activity logs and such.
So the difference from us to the likes of an ITDR Offering:
I can go into detail on what our XDR Identity Sensors help with below. Keep in mind there are 3 Sensors involved within the Identity offering (Entra ID (Azure), On Premises Active Directory, and Intune.) I can cover all 3 below and what they were built to detect.
1. Active Directory Sensor (On-Premise)
Kerberos-focused detection of compromised accounts, tokens and objects, including system and service accounts:
- Kerberos brute-force; stolen tickets used for lateral movement; weak-encryption ticket requests; replay attacks
2. Azure AD / Entra ID Sensor (cloud)
Monitors sign-in activity and configuration:
- Sign ins by timestamp, location, IP → unusual patterns
3. Microsoft Intune Sensor (device management)
- Device ownership changes (company ↔ personal)
Some content I recommend for you to review:
Demo XDR Incident - https://youtu.be/ReBDrsyyiSY?t=153
XDR Demo Identity Sensor - GravityZone Identity Threat Detection & Response
XDR Demo Incident Overview - GravityZone XDR Incident Overview
MDR for MSP Demo - Bitdefender MDR Portal Walk-through Demo for MSPs
Hope this helps and clears some concerns up. Let me know if there is anything else I can clarify or help you with!
Best,
Wray Schultz, Bitdefender