Service type

XDR Providers

Providers listing XDR. Compare monitoring scope, response ownership, and what your team still owns.

CrowdStrike Falcon Complete

24/7 threat detection, investigation, and full remote remediation — they find threats and eliminate them without you lifting a finger

Enterprise / Mid-Market · Endpoints

Service MDR
Response Contain threats
Price Around $15-25/endpoint/month plus Falcon licensing

Expel

24/7 threat detection and automated response across your existing security tools — with full transparency into every action taken

Enterprise / Mid-Market · Endpoints

Service MDR
Response Contain threats
Price Custom per-asset pricing based on integrations and environment size. Not publicly listed — request a quote.

Microsoft Defender Experts

24/7 threat hunting and managed response natively built into the Microsoft security stack — no additional tools or agents needed

Enterprise / Mid-Market · Endpoints

Service XDR
Response Contain threats
Price Per-user/month pricing. Requires 1,500-seat minimum. Defender Experts Suite bundles MXDR + IR + advisory.

Red Canary

24/7 threat detection and response layered on top of your existing EDR — expert analysts and automation operationalize your security tools

Mid-Market / Enterprise · Endpoints

Service MDR
Response Contain threats
Price ~$100-120/endpoint/year

SentinelOne Vigilance

AI-powered autonomous endpoint protection with 24/7 human analyst oversight — threats are contained in minutes, not hours

Enterprise / Mid-Market · Endpoints

Service MDR
Response Contain threats
Price ~$17-50/endpoint/year (on top of platform license)

Sophos MDR

24/7 threat monitoring and full incident response across your existing security tools — they work with what you already have

Enterprise / Mid-Market · Endpoints

Service MDR
Response Contain threats
Price ~$5-12/endpoint/month

Adlumin

A managed security operations platform that bundles SIEM-style log collection, behavioral analytics, response automation, and 24/7 MDR support.

Mid-Market / MSP/MSSP · Endpoints

Service MDR
Response Contain threats
Price Quote-based, directional range $2K-$15K/month

Alert Logic

24/7 threat detection with built-in web application firewall and vulnerability scanning — comprehensive cloud-first security monitoring

Mid-Market / Enterprise · Endpoints

Service MDR
Response Investigate alerts
Price Three tiers: Essentials, Professional, Enterprise. Per-host pricing with custom quotes.

AT&T Cybersecurity

24/7 security monitoring and detection through a unified platform — with built-in threat intelligence from one of the largest open threat sharing communities

Enterprise / Mid-Market · Endpoints

Service MSSP
Response Investigate alerts
Price $1,695/year (USM Anywhere)

Barracuda Managed XDR

24/7 managed threat detection and response across email, endpoint, cloud, and network — with accessible pricing and fast deployment built for SMBs and MSPs

SMB / Mid-Market · Endpoints

Service MDR
Response Contain threats
Price ~$3-7/user/month

Binary Defense

24/7 threat detection and response from offensive security experts — using your existing SIEM and tools without vendor lock-in

Mid-Market / Enterprise · Endpoints

Service SOCaaS
Response Full SOC
Price Custom pricing based on environment size. Mid-market focused — contact for quote.

Bitdefender MDR

24/7 threat monitoring, detection, and response across endpoints, cloud, identity, email, and network — with $1M breach warranty on the PLUS tier

SMB / Mid-Market · Endpoints

Service MDR
Response Contain threats
Price Around $7-15/endpoint/month

Blumira

Automated threat detection with guided response playbooks — a cloud SIEM you can actually use without a dedicated security team

SMB / Mid-Market · Endpoints

Service XDR
Response Investigate alerts
Price Free tier; paid plans around $12-$21/user/month

Critical Start

24/7 threat detection and response that resolves every single alert — no alert fatigue, no ignored warnings, every signal gets triaged

Enterprise / Mid-Market · Endpoints

Service MDR
Response Contain threats
Price Custom tiered pricing based on environment complexity. Not publicly listed — contact for quote.

Cybereason

24/7 threat detection, investigation, and response powered by MalOp technology that maps complete attack operations — not just isolated alerts

Enterprise / Mid-Market · Endpoints

Service MDR
Response Contain threats
Price Per-endpoint pricing with tiered service levels. Mid-market organizations typically pay $10K-$25K/month.

eSentire

24/7 multi-signal threat detection and full incident response across endpoint, network, cloud, identity, and insider threats

Mid-Market / Enterprise · Endpoints

Service MDR
Response Contain threats
Price ~$15-25/endpoint/month

Forescout

24/7 threat detection and response across IT, OT, IoT, and unmanaged devices — with agentless visibility into infrastructure that other MDR providers cannot see

Enterprise / Mid-Market · Endpoints

Service MDR
Response Contain threats
Price Per-asset pricing with custom quotes. Premium positioning — mid-market organizations typically pay $15K-$40K/month.

Fortinet FortiGuard MDR

24/7 managed detection and response across endpoints, network, and OT environments — fully integrated with your existing Fortinet infrastructure

Enterprise / Mid-Market · Endpoints

Service MDR
Response Contain threats
Price ~$3-8/endpoint/month

IBM Security

24/7 global security operations from one of the world's largest security teams — monitoring, detection, response, and strategic consulting

Enterprise / Government · Endpoints

Service MSSP
Response Co‑managed SOC
Price Enterprise custom pricing. QRadar on Cloud starts ~$800/month. Full managed services priced per organization.

Mandiant / Google Security Operations

24/7 managed detection and response from the world's most experienced incident response team — detection rules written by the same experts investigating nation-state breaches

Enterprise / Mid-Market · Endpoints

Service MDR
Response Contain threats
Price Custom enterprise pricing — contact for quote. Premium tier reflecting Mandiant's IR expertise and Google-scale analytics. Expect $ pricing.

Netsurion

Co-managed security monitoring where your team and theirs share the same dashboard — 24/7 coverage without losing control

Mid-Market / SMB · Endpoints

Service Co‑managed SOC
Response Co‑managed SOC
Price ~$3,000-$5,000/month

NTT Security

24/7 global security operations from one of the world's largest IT services companies — monitoring, detection, and incident response at massive scale

Enterprise / Government · Endpoints

Service MSSP
Response Contain threats
Price Custom enterprise pricing based on organization size and services. Contact for quote.

Palo Alto Networks Unit 42

24/7 threat detection, hunting, and full incident response powered by one of the world's largest threat research teams

Enterprise / Mid-Market · Endpoints

Service MDR
Response Contain threats
Price ~$80/endpoint/year (Cortex XDR Pro)

Proficio

24/7 global threat detection and rapid automated response — follow-the-sun SOCs mean analysts are always working during business hours

Enterprise / Mid-Market · Endpoints

Service MDR
Response Contain threats
Price Custom per-asset pricing based on environment size and selected services. Contact for quote.

Rapid7 MDR

24/7 threat detection and response bundled with unlimited vulnerability management — detect threats and fix the weaknesses they exploit

Enterprise / Mid-Market · Endpoints

Service MDR
Response Contain threats
Price ~$17/asset/month

ReliaQuest

A force-multiplier for your existing security team — AI and analysts that make your current tools work better together and respond faster

Enterprise / Mid-Market · Endpoints

Service Co‑managed SOC
Response Co‑managed SOC
Price Enterprise custom pricing. Average engagements around $170K/year. Large enterprises can exceed $1M/year.

Secureworks

24/7 threat detection, investigation, and response powered by Taegis XDR — backed by one of the industry's oldest threat research teams

Enterprise / Mid-Market · Endpoints

Service XDR
Response Contain threats
Price Custom enterprise pricing based on organization size and selected services. Contact for quote.

Todyl

One platform that replaces your firewall, SIEM, EDR, and SOC — true convergence instead of bolting tools together

MSP/MSSP / SMB · Endpoints

Service MDR
Response Contain threats
Price Channel-only tiered pricing: Essentials, Advanced, and Complete. Custom quotes through MSP partners.

Trellix

24/7 XDR-powered threat detection and response across endpoints, email, network, cloud, and data — backed by FireEye-heritage detection technology and 68 billion daily threat queries

Enterprise / Mid-Market · Endpoints

Service XDR
Response Contain threats
Price Custom enterprise pricing — contact for quote. Expect $ tier pricing typical of large-enterprise XDR platforms.

Trend Micro MDR

24/7 managed detection and response across endpoint, email, cloud, network, and OT — powered by the broadest native XDR platform and Zero Day Initiative threat intelligence

Enterprise / Mid-Market · Endpoints

Service XDR
Response Contain threats
Price Credit-based licensing via Vision One platform. MDR add-on pricing varies by coverage scope. Mid-market deployments typically run $15K-$40K/month; enterprise ranges from $40K-$150K+.

Vectra AI MXDR

24/7 managed detection, investigation, and response across network, identity, and cloud — powered by 170+ AI models that catch the threats your EDR misses

Enterprise / Mid-Market · Endpoints

Service MDR
Response Contain threats
Price Custom pricing based on IP address count and environment scope. A mid-market deployment typically runs $15K-$40K/month; enterprise engagements range from $40K-$150K+.

How to use this list

Use it when

Use this list when you know the service label, but still need to compare the operational scope behind it.

Do not assume

The label is not enough. Two providers can both sell MDR while handling alert triage, containment, tooling, and reporting very differently.

Ask before shortlisting

  1. Compare the actual work performed, not only the service label.
  2. Check whether the provider uses your existing tools or requires its own platform.
  3. Confirm how pricing changes with endpoints, users, log volume, and response scope.
Category background

Extended Detection and Response (XDR) has emerged as one of the most significant shifts in security operations architecture. By unifying telemetry from endpoints, networks, cloud environments, email systems, and identity providers into a single correlation and response platform, XDR breaks down the data silos that have long plagued security teams. XDR providers deliver the cross-domain visibility needed to detect and respond to modern, multi-stage attacks.

Why XDR Matters

Traditional security operations rely on analysts manually pivoting between dozens of disconnected tools — an EDR console, a firewall dashboard, cloud security logs, email gateway alerts, and more. XDR eliminates this fragmentation by ingesting and correlating signals across domains automatically. This means faster detection of attack chains that span multiple surfaces, reduced analyst fatigue, and more effective response through unified playbooks.

Managed XDR vs. Platform XDR

XDR providers generally fall into two camps: platform XDR (you get the technology and your team operates it) and managed XDR (the provider supplies both the platform and the analyst team). For organizations evaluating SOC providers, managed XDR is often the more relevant option — it combines the cross-domain detection advantages of XDR with the operational expertise of a managed service.

Evaluating XDR Providers

When comparing XDR providers, focus on the breadth of native integrations, the quality of cross-domain correlation logic, response automation capabilities, and whether the platform can incorporate third-party telemetry or only its own proprietary tools. Open XDR providers that support heterogeneous environments tend to offer more flexibility, while native XDR providers that bundle their own endpoint, network, and cloud tools may offer tighter integration out of the box.

Questions

What is XDR?
Extended Detection and Response (XDR) is a security approach that unifies telemetry from endpoints, networks, cloud workloads, email, and identity systems into a single detection and response platform. XDR providers correlate signals across these domains to identify sophisticated attacks that point-solution tools might miss in isolation.
What is the difference between XDR and EDR?
EDR (Endpoint Detection and Response) focuses exclusively on endpoint telemetry — laptops, servers, and workstations. XDR extends this concept across multiple security layers including network, cloud, email, and identity. XDR correlates data from all of these sources to detect multi-stage attacks and provide unified investigation and response capabilities.
Do I need XDR if I already have a SIEM?
XDR and SIEM serve overlapping but distinct purposes. SIEMs are log-centric platforms that require significant tuning and rule-writing. XDR platforms are more turnkey, with pre-built detection logic and tighter integration across their supported data sources. Many organizations use XDR alongside a SIEM, or migrate from SIEM to XDR for faster time-to-value.