Detection is the easy half. Response is the product.
Most organizations that get breached were not short of alerts. They were short of someone qualified reading them at the hour they fired, with the authority to do something. That is what a managed detection and response service is for, and it is the part worth comparing providers on.
Managed detection and response is an outsourced service that monitors an organization's environment continuously, investigates what looks like an intrusion, and responds to it. All three parts are the service. Monitoring without investigation produces alerts nobody triages; investigation without a response mandate produces a well-written description of a breach in progress.
Vijilan delivers MDR two ways. ThreatRespond™ wraps a 24/7 SOC around the endpoint tooling an organization already owns. ThreatDefend™ deploys and operates CrowdStrike Falcon® end to end. Both include ThreatLog™, an index-free SIEM, so findings arrive with the evidence still queryable.
From the Advanced tier up the SOC acts directly under a pre-approved runbook: isolating hosts, disabling accounts, terminating processes and blocking addresses. At the Essential tier the SOC investigates and advises, and the customer's team executes.
Three situations, one service.
A mid-market IT team with no night shift. You have tooling, often more than you have configured. What you do not have is a rotation, and the failure mode is not a missing product. It is that the alert fires at 2am on a Sunday into an empty room.
An enterprise security team that is outnumbered. You have analysts and they are spending their expertise on triage. MDR takes the queue so they can do the work that needs to know your business, which is the work nobody outside it can do.
An MSP or MSSP selling security. Your clients want 24/7 coverage and you cannot staff it per client. The SOC runs under your brand and we do not approach the clients you bring. See MDR for MSPs for how that is structured.
Capabilities.
Detection across more than the endpoint
Endpoint, identity, cloud, email and network signals land in one investigation queue rather than five consoles. Most intrusions that matter cross at least two of those, and a tool watching one of them in isolation sees a normal day.
Investigation by a person
A human analyst decides whether a signal is an intrusion. That is the part a rules engine cannot finish, because the modern intrusion is a legitimate credential doing legitimate things in an order nobody authorized.
Response, not notification
From the Advanced tier up, the SOC acts: isolating hosts, disabling accounts, killing processes, blocking addresses and suspending email domains, under a runbook you approved in advance. At the Essential tier the SOC advises and your team executes.
A SIEM underneath, not beside
ThreatLog™, index-free, is included in every tier. MDR findings arrive with the evidence still queryable, which is what lets a timeline be rebuilt three weeks later and what keeps an auditor satisfied.
Staffed at the hours that matter
The SOC runs continuously, which is a staffing commitment rather than a dashboard that is technically reachable at 3am. Intrusions are not distributed evenly across business hours, and neither is the cost of missing one.
Hunting for what did not alert
Detection finds what the rules anticipated. Threat hunting looks for what they did not, which is where the intrusions that survive a year tend to live.
Detect, investigate, contain, remediate.
Written out because the stage most services quietly omit is the second one, and it is the stage that decides whether the other three were needed.
- 01
Detect
Telemetry from every connected source is correlated continuously. Automation does the first pass, discarding the volume that is obviously noise and enriching what is left with threat intelligence and asset context before a person sees it.
- 02
Investigate
An analyst establishes what happened, on which hosts, using which account, and whether it is still happening. This is the stage that decides whether the next two are necessary, and it is the stage most heavily automated services skip.
- 03
Contain
Cut the intrusion off from the rest of the estate while the investigation continues. Isolation keeps a host reachable by the responder and unreachable by everything else, so containment does not have to wait for certainty.
- 04
Remediate
Remove the persistence, reset what needs resetting, close the path they used, and hand back a written timeline. An incident that is contained but not understood tends to recur through the same door.
Where the machine stops and a person starts.
Automation does the first pass. It has to: the volume is beyond what any staffing model absorbs, and most of it is genuinely nothing. Correlation, enrichment, deduplication and the discarding of obvious noise all happen before a human sees a queue.
What automation does not do here is decide that an intrusion is real and take an irreversible action on your estate on that basis. A working credential performing authorized actions in an unauthorized order is the majority case now, and recognizing it is a judgment about context rather than a pattern match. That judgment belongs to an analyst, and the analyst is accountable for it.
We are deliberate about saying that, because the industry vocabulary is drifting toward implying otherwise. Anyone claiming a fully autonomous SOC is describing a roadmap. How the platform is put together covers the tooling side of this in more detail.
Keep your stack, or take ours.
The SOC is the same in both. What changes is who owns the tooling, which is usually a question about contracts you have already signed rather than about security.
ThreatRespond™
Your tools. Our SOC.
Vendor-agnostic managed XDR over the EDR you already run, including SentinelOne, Microsoft Defender, Carbon Black and CrowdStrike Falcon®. Nothing to rip out.
ThreatRespond in detailThreatDefend™
Our stack. Our SOC.
CrowdStrike Falcon® licensed, deployed and operated end to end. For teams who would rather buy the outcome than assemble it.
ThreatDefend in detailBoth include the SIEM
ThreatLog™, index-free
Retention and search ship with every tier rather than arriving as a second purchase with a per-gigabyte bill that grows every time you improve coverage.
Managed SIEM servicesSix questions worth asking any MDR provider.
Including us. These are the questions where two services that use identical vocabulary turn out to be different purchases.
Does the provider act, or only notify?
This is the single biggest difference between two services that both call themselves MDR, and it is usually buried. Ask what the provider is contractually permitted to do on your estate at 3am without waking anyone, and get the answer in writing.
Is a SIEM included, and what does the data cost?
Many MDR services watch the endpoint and leave log management to you, which means a second purchase and a per-gigabyte bill that rises every time you improve your coverage. Ask whether retention is included and how ingestion is priced.
Can you keep the tooling you already bought?
Some providers require their stack. If you are two years into an EDR contract, that is a rip-and-replace disguised as a service change. Ask whether they operate over your existing tools, and which ones.
Who is on the other end, and at what tier?
Ask who actually reads the alert at 2am on a Sunday: a senior analyst, a tier-one queue, or an automation that pages someone if it is unsure. All three are legitimate models and they are not the same purchase.
What happens to the evidence afterwards?
Insurers, regulators and counsel all want the timeline. A service that closes the ticket and moves on leaves you reconstructing an incident from memory, which is how findings quietly become opinions.
If you are an MSP, whose brand is on it?
And, separately, whether the provider will approach your clients directly. Those are two different questions and only one of them is usually answered in the datasheet.
Onboarding and integrations
Sensor or connector rollout, data source identification, detection tuning against your environment, then a runbook agreed before anything is allowed to act. Priority alerts route into the service desk you already use: ConnectWise, Autotask, Datto, Kaseya and Jira.
Multi-tenant by design for partners, with per-client separation and co-branded reporting.
Compliance
Vijilan is SOC 2 Type II certified and ISO/IEC 27001 certified. Vijilan is a CrowdStrike Powered Service Provider, which is a partner program designation and not an audit. Evidence packs for HIPAA, PCI and CMMC Level 2 are available on request.
Those are three different categories of assurance. Keeping them apart is worth doing when you compare providers, because not everyone does.
The auditor, the scope and the documents"Vijilan takes our problems on as their own. They care about our clients the same way we do, and that level of attention and trust makes all the difference."
MDR, answered plainly.
What is managed detection and response?
MDR is an outsourced service that watches your environment continuously, investigates what looks like an intrusion, and does something about it. The three parts matter in that order. Monitoring without investigation produces alerts nobody triages, and investigation without the authority to respond produces a well-written description of a breach in progress.
How is MDR different from EDR?
EDR is software; MDR is a service, usually delivered on top of EDR or something like it. Buying EDR gives you the telemetry and the ability to respond. Buying MDR gives you the people who watch it at 3am and the mandate to act. Organizations that own excellent EDR and still get breached are usually not short of data.
How is MDR different from an MSSP?
The traditional MSSP model manages security devices and forwards alerts to you, so the investigation and the response stay in your team. MDR takes both. There is real overlap in the market and the labels are used loosely, so the useful question is not which word a provider uses but what they are contractually able to do on your estate without asking first.
How is MDR different from a SIEM?
A SIEM is where the data goes and where you query it. MDR is the people and the process operating on that data. The two are complements rather than alternatives, which is why every Vijilan MDR tier includes ThreatLog™ rather than treating log management as a separate purchase.
Do we have to replace our current EDR?
No. ThreatRespond™ is vendor-agnostic and wraps the SOC around whatever endpoint tooling you already run, including SentinelOne, Microsoft Defender, Carbon Black and CrowdStrike Falcon®. If you would rather we brought the stack, ThreatDefend™ deploys and operates CrowdStrike Falcon end to end. The SOC behind both is the same one.
Does the SOC actually take action, or does it send us a ticket?
It depends on the tier, and we would rather be exact about it than sell past the question. At the Essential tier the SOC investigates and advises, and your team executes. From the Advanced tier up the SOC acts directly under a runbook you approve in advance: isolating hosts, disabling accounts, terminating processes, blocking addresses and suspending email domains.
We are an MSP. Can we resell this under our own brand?
Yes. Every tier is white-label: your brand on the reports, the portal and the incident communications. And we never compete with our partners for their clients, which is a promise about our conduct rather than a restriction on who can buy from us.
What does MDR cost?
Rates are not published, because they are channel rates and they depend on endpoint count, log volume, retention and how much response mandate you want. What we can do without a sales call is explain the drivers, which is what the pricing guides are for.
What certifications does the provider hold?
Vijilan is SOC 2 Type II certified and ISO/IEC 27001 certified, and is a CrowdStrike Powered Service Provider, which is a partner program designation rather than an audit. Evidence packs for HIPAA, PCI and CMMC Level 2 are available on request. Those are four different kinds of thing and it is worth keeping them apart when you compare providers.
Find out what is actually
running in your environment.
Before a service change, a picture of the estate. Choose up to three assessments, run on CrowdStrike Falcon at no license cost for a sixty day window, and keep the findings either way.