Top Tools / August 3, 2026
StartupStash

StartupStash is an editorial team. Each Top Tools shortlist is researched by a writer who works in that category, then checked against first-party product pages, public pricing, and recent product changes. A second editor reviews the piece before it goes live. We also run a directory of startup tools. A paid listing does not buy a place on a shortlist.

Best Managed Detection And Response Services: 6 Solutions Reviewed for 2026

MDR is a vendor team that watches your hosts overnight and, if you paid for it, contains the threat. What gets bundled into the sales pitch is often three different things: the endpoint sensor, the managed response service, and a warranty headline. Those are not the same purchase.

EDR is the agent. MDR is the vendor team that reads the alerts and, if you paid for it, takes action. Mix those up and you can spend Complete money on a guided plan that emails you a ticket while you still own nights and weekends. NIST SP 800-61 Rev. 3 treats detection, response, and recovery as work a team has to do, not a logo on a quote. CISA’s Cybersecurity Performance Goals 2.0 put Detect and Respond in the same baseline. The method we used is on How we review tools.

We compared six vendors on that split: who is allowed to contain, which console you already need, and what telemetry is in the seat. CrowdStrike, Unit 42, and Wayfinder sit with the console you already run and can contain under written rules. Sophos Complete is the mixed-stack authorized buy with a public rate. Arctic Wolf and Microsoft start as guided: a concierge that works with you, or experts who act only if you grant the operator role.

What usually goes wrong when buying MDR

Most MDR quotes fail for the same few reasons. The fix is operational, not a new acronym.

Problem Solution
Alerts fire overnight and no one is on the keyboard Buy a vendor authorized to contain under written rules, not a guided plan that only opens a ticket
The quote mixes EDR seats with a managed team Separate the sensor price from the MDR tier. Make sure the contract names the platform and the tier
A $1 million warranty is on the slide Read the per-host cap, the wait, the bundle rules, and the claim limits before you treat it as insurance
The stack is already Falcon, Cortex, Singularity, Defender, or mixed Match the vendor to the console you already run. A second agent in the same estate is wasted spend

How we evaluated MDR services

The filter was four first-party checks: who is allowed to contain, which console you already need, whether any price is public, and what the warranty or retainer actually reimburses. Marketing labels like “AI SOC” did not move a ranking. Neighbor products sit under What we left out. Some SentinelOne pages still say Vigilance. The live product page is Wayfinder, so that product is on this list.

TL;DR: The Six Compared

Solution Best For Pricing Model Highlights
CrowdStrike Falcon Complete Falcon already on the fleet Contact sales. Falcon EDR list rates are $7.99 to $19.99 per device / month and are not MDR Authorized containment. Warranty is $2,000 per host, $1M / $2M caps, posture rules
Unit 42 MDR / Managed XSIAM Cortex already the console Quote only. Budget the Cortex license separately Authorized once the Cortex tenant is in scope. 250 IR hours on Managed XSIAM Pro/Premium is a retainer, not a warranty check
Sophos MDR Complete Mixed stack, need a budget number this week Public per-asset rate: $239.64 per endpoint / year, $390.72 per server / year Complete contains. Essentials only guides. 60-day wait, $5,000 minimum claim, one claim across all orders
Arctic Wolf Aurora MDR Mixed stack, want a concierge on tools you already run Quote only. Meter is users, servers, and internet egress points Guided containment. CST works with you to start host and network isolation. Warranty up to $3M is bundle-and-term
SentinelOne Wayfinder MDR Singularity already the agent Quote only. Tiers are Threat Hunting, MDR Essentials, and MDR Elite Contains at machine speed under your response policy. Up to $1M if an undetected breach occurs
Microsoft Defender Experts MDR Defender already the portal Contact sales. Sold separately from Defender products Guidance by default. Operator role can act in Defender. Plan 2 guides third-party, does not act there. No published MDR warranty

CrowdStrike Falcon Complete

CrowdStrike

Falcon Complete is CrowdStrike’s analysts running Falcon for you: hunt, contain, wipe persistence, and restore the host. In 2026 they started calling that model Agentic MDR, which still means humans own the outcome and agents take the slow steps.

You only want this if Falcon is already the path. Adding Complete is an operating model. It is not a way to keep a second EDR, and identity, cloud, and Next-Gen SIEM still show up as extra quote lines.

Best for: Teams that already run Falcon and want analysts to take direct action on endpoints and identities.

What you get:

  • 24/7 monitoring with hands-on containment, persistence removal, and host restore.
  • Agentic MDR: analysts orchestrate agents on Falcon telemetry across endpoint, identity, cloud, and Next-Gen SIEM connectors.
  • Falcon Complete Hub for investigation timelines and the actions the SOC already took.
  • Public proof: IDC MarketScape Leader (Aug 2026, doc US54792426); Gartner Voice of the Customer Customers’ Choice (Apr 2026, 98% of 137 responses). Product page still quotes a 1-minute median time-to-contain.

Why we like it: If Falcon is already the default agent, Complete is the operating-model add. You are not ripping out a console you just finished rolling out.

Limits:

  • Bound to Falcon. A second EDR in the same estate is wasted spend.
  • Identity and cloud coverage are separate quote lines, so the POC can look cheaper than the contract.
  • Public reviews still mention alert noise and console assignment that is harder than the pitch.

Price: Complete is contact-sales. The self-serve numbers on CrowdStrike’s first-party pricing page are Falcon EDR, not MDR:

  • Falcon Go / Pro / Enterprise: $7.99 / $14.99 / $19.99 per device per month, or $59.99 / $99.99 / $184.99 billed annually.
  • Go is capped at 100 devices.

Warranty: Included with an active Complete subscription. Terms dated 8 Jan 2026. The Falcon Complete warranty reimburses ransomware response at $2,000 per impacted endpoint, capped at $1 million on EDR-only and $2 million when Identity Threat Protection is also licensed. It is not sold on its own.

A host counts only if it is on a supported OS, at the recommended Measured Security Posture or higher, on a current-or-two-prior sensor, with MFA on internet-facing logins. A host that is not in posture is not a covered endpoint.

Palo Alto Networks Unit 42 MDR

Palo Alto Networks

Palo Alto sells two managed offerings under the Unit 42 badge, and that is the first thing to pin on a quote. “Unit 42” is the team. It is not a product you can order by itself. Make sure the contract names the platform and the tier.

Unit 42 MDR still runs on Cortex XDR. Managed XSIAM 2.0, launched February 2026, is a 24/7 managed SOC on Cortex XSIAM. Pro is detection, hunt, and full-cycle response, including third-party EDR ingested into XSIAM. Premium adds a designated hunter and dedicated SOC engineering.

Best for: Organizations already on Cortex XDR, or ready to buy an XSIAM tenant, who want Unit 42 on the keyboard instead of a tools-only Cortex rollout.

The two products:

Product Runs on What you get
Unit 42 MDR Cortex XDR 24/7 monitor, hunt, investigate, respond inside the customer tenant
Managed XSIAM 2.0 Cortex XSIAM Managed SOC. Pro includes the 250-hour IR retainer. Premium adds a designated hunter and SOC engineering

Why we like it: If Cortex is already the console, you are buying operations. Managed XSIAM 2.0 is the honest path for estates that cannot rip out a third-party EDR on day one.

Limits:

  • XDR MDR needs a Cortex XDR license. Managed XSIAM needs an XSIAM tenant (NG-SIEM, Enterprise, or Premium). Neither is a bolt-on for an EPP-only fleet.
  • Public review volume is thinner than CrowdStrike or Sophos.
  • Product names moved fast in 2026. Make sure the contract names the platform and the tier.

Price: Quote-only. Contact Palo Alto or a NextWave partner. Budget the Cortex platform license and data-lake volume as separate lines from the Unit 42 service.

Retainer, not a warranty: The Managed XSIAM datasheet puts a 250-hour Breach Response Guarantee on Pro and Premium. That is hours of Unit 42 incident response, not a per-host warranty check.

Sophos MDR

Sophos

Sophos MDR is a 24/7 managed SOC that will run on Sophos telemetry or on the stack you already have. That is why it is on this shortlist: it is the only vendor here with a public per-asset rate you can put in a budget before the first sales call.

Two tiers remain, and they are not the same product. Essentials is monitor, hunt, and guided response. Complete is authorized response under pre-agreed rules, a dedicated incident-response lead on confirmed incidents, and the warranty. Taegis MDR, from the February 2025 Secureworks acquisition, is still a separate enterprise line. Get the roadmap in writing on a multi-year deal.

Best for: Mixed-vendor estates and teams that want a published per-asset rate, two named tiers, and marketplace procurement.

What you get:

  • Essentials vs Complete. Complete is the tier that executes containment and includes the warranty.
  • Vendor-agnostic ingestion, including an XDR Sensor that is detection-only on third-party EDR.
  • Critical incident response on Complete with no hourly cap. Sophos states a 60-minute response-time SLA for 90 percent of high-severity cases on Complete.
  • Sophos Central for the console. Raw hunt queries are thinner than a SIEM you already own.
  • Public proof: Gartner Voice of the Customer for MDR, March 2026, 4.8 / 5.0 on 290 reviews, the largest sample in that report.

Why we like it: The two-tier split is honest. Guided and authorized are different products, and only Complete publishes a rate you can budget this week.

Limits:

  • Essentials does not include full incident response or the warranty. Price Complete if that is what you meant.
  • Linux server protection can require a separate Workload Protection line. Ask.
  • Sophos MDR and Taegis still run as two products. Do not assume a merge.

Price: First-party AWS Marketplace dimensions for 12 months include:

  • MDR Complete including XDR: $239.64 per endpoint / year, $390.72 per server / year.
  • EDR and XDR seats are cheaper ($69.96 and $136.60 endpoint; $153.56 and $222.66 server) and are not MDR.

Warranty: The MDR Complete warranty covers up to $1 million in response expenses, $1,000 per breached machine, and $100,000 toward a ransom. The catch is a $5,000 minimum claim, a 60-day wait on new subscriptions, and one claim across all orders. Essentials does not include it. Read the legal page before you treat it as insurance.

Arctic Wolf Aurora MDR

Arctic Wolf

Aurora Managed Detection and Response is Arctic Wolf’s concierge SOC on an open XDR platform. It plugs into 200-plus integrations, so you are buying operations on the stack you already run, not a rip-and-replace agent.

Containment is guided, not lights-out. The FAQ says your Concierge Security Team works with you to start the Managed Containment workflow at host and network. Remediation is guided. Humans stay in the loop. That is a different product from a Complete plan that already has written permission to isolate a laptop at 3am.

Best for: Mixed estates that want a named concierge on existing tools and will accept a human on their side for containment.

What you get:

  • 24/7 monitoring across networks, endpoints, and cloud, with a Concierge Security Team paired to the account.
  • Open XDR. The product page cites 200-plus integrations. Agents, unlimited log retention and search, and external scanning sit in the core offering.
  • Managed Containment at host and network once the CST starts that workflow with you.
  • Aurora Agentic SOC language on the 2026 page: AI investigates in parallel, humans validate decisions.

Why we like it: If the stack is mixed and you do not want a second EDR, this is the concierge path. Arctic Wolf bases pricing on users, servers, and internet egress points.

Limits:

  • Containment is co-managed. If no one on your side answers, the workflow does not start itself.
  • Pricing is custom. Do not treat a reseller list as Arctic Wolf’s price.
  • The “up to 90%” attack-reduction line is a company and Forrester claim on the marketing page. It is not a warranty term.

Price: Quote-only. First-party FAQ prices coverage by users, servers, and internet egress points. Endpoint agents, unlimited log retention and search, and external network scanning are included in that core offering. There is no self-serve MDR list rate on arcticwolf.com.

Warranty: The Security Operations Warranty goes up to $3 million. That ceiling needs the Total Security Operations Bundle, Aurora Managed Endpoint Defense, and a three-year term. Total on a three-year bundle without that endpoint combo is $1.5 million. Coverage also scales down by bundle and term. There is no per-host figure on the warranty page.

SentinelOne Wayfinder MDR

SentinelOne Wayfinder MDR

Wayfinder MDR is SentinelOne’s current first-party name for the managed layer on Singularity. Some secondary pages still say Vigilance. The live product page is Wayfinder. Make sure the contract uses that name.

Analysts monitor, investigate, and contain around the clock. The page says confirmed threats are contained at machine speed according to your configured response policy. That is authorized action inside Singularity, not a ticket-only concierge. Google Threat Intelligence and Purple AI are the named accelerators on that page.

Best for: Teams that already run Singularity and want that vendor’s hunters, with containment written into the response policy.

What you get:

  • 24/7 monitoring, investigation, and mitigation on the Singularity console.
  • Three named tiers on the product page: Threat Hunting, MDR Essentials, and MDR Elite. Elite adds identity, supported third-party integrations, a dedicated threat advisor, and DFIR access.
  • Containment under your policy: kill, isolate, rollback, and related actions the page lists as mitigation.
  • Public proof on the same page: SentinelOne states 100% detection and the best signal-to-noise in the MITRE ATT&CK Managed Services Evaluation, and a 3.3-minute average time to detect. Those are company figures.

Why we like it: If Singularity is already the agent, Wayfinder is the operating-model add. You are not buying a second console to babysit.

Limits:

  • Bound to Singularity the same way Complete is bound to Falcon. A second EDR in the same estate is wasted spend.
  • Quote-only. The page names tiers. It does not print a seat rate.
  • Machine-speed containment only happens for actions you already allowed. A tight policy turns this back into a guided service.

Price: Quote-only. Contact SentinelOne. Make sure the quote names the tier (Threat Hunting, MDR Essentials, or MDR Elite). The public EDR price on other SentinelOne pages is not this product.

Warranty: The same product page includes an up to $1 million breach-response warranty for incident response and recovery if an undetected breach occurs. Coverage language names Windows, Linux, macOS, and cloud workloads. There is no per-host cap on that page. Confirm which tier carries it before you treat the headline as insurance.

Microsoft Defender Experts MDR

Microsoft Defender Experts

Microsoft Defender Experts MDR is the managed queue on Microsoft Defender. Microsoft’s docs (updated 29 July 2026) say analysts triage and investigate around the clock, then either take action or guide your team. It is sold separately from Defender products. Plan 1 is the product that used to be called Defender Experts for XDR.

Two plans, and they are not the same buy. Plan 1 covers Microsoft Defender workloads. Plan 2 adds supported third-party sources you ingest through Microsoft Sentinel, and it needs a Sentinel workspace plus a 1,500-seat floor. On third-party products, experts give guidance. They do not act inside those products.

Best for: Teams already deep in Defender who will accept guidance as the default, and who will write the operator role into the contract if they want Microsoft to click.

What you get:

  • Plan 1: managed detection and response on Defender for Endpoint, Office 365, Identity, Cloud Apps, and Entra ID, plus built-in hunting and Ask Defender Experts in the portal.
  • Plan 2: everything in Plan 1, plus supported third-party telemetry in Sentinel (the docs name Okta, Proofpoint TAP, AWS CloudTrail and GuardDuty, and a short firewall list). Experts author Sentinel content. You still own the workspace.
  • Role-dependent action: Security Reader means investigate and guidance. Security Operator means agreed remediation in Defender. That split is in Microsoft’s FAQ, not a slide.
  • Neither plan is a managed SIEM, and neither plan is an incident-response engagement for an active compromise.

Why we like it: If Defender is already the portal, this is the operating-model add. Plan names and the operator-versus-reader split are printed in first-party docs.

Limits:

  • Guidance is the default. If the contract leaves analysts on Security Reader, you still own nights.
  • Plan 2 does not act in third-party products. It is also not a managed Sentinel service. Connector health and ingestion costs stay yours.
  • Neither plan covers Microsoft Defender for Cloud workloads. Third-party network signal enrichment in Plan 1 is deprecated from 1 September 2026.
  • No public MDR list rate. No published MDR warranty on the first-party pages.

Price: Contact sales or the customer interest form. Sold separately from other Microsoft Defender products. Plan 2 requires Microsoft Sentinel and a minimum of 1,500 licensed seats.

Warranty: None published on the Defender Experts MDR pages. Incident response, if you need it, is a separate Defender Experts contract under separate terms.

If the next problem is the ticket queue after containment, start with incident management tools.

Who contains, and which console you already run

This grid plots two questions. Across is who is allowed to contain: guided on the left, authorized on the right. Up is the console you already run: mixed stack at the bottom, one console at the top.

GuidedYour consoleGuidance by default in Defender
AuthorizedYour consoleYou already run Falcon, Cortex, or Singularity
GuidedMixed stackOpen XDR, humans in the loop
AuthorizedMixed stackPublished per-asset rate

Placement is from first-party product language: guided vs authorized response, and whether the page assumes Falcon, Cortex, Singularity, Defender, or a mixed stack. Placement is a product map, not a ranking.

Warranty and retainer, side by side

Vendor Headline Per host The catch
CrowdStrike Complete $1 million EDR-only, $2 million with Identity Threat Protection $2,000 Active subscription. Recommended Measured Security Posture or higher. Not for sale alone. Not insurance in every jurisdiction.
Sophos Complete $1 million total, $100,000 toward a ransom $1,000 60-day wait on new subscriptions. $5,000 minimum claim. One claim across all orders. Essentials does not include it.
Unit 42 Managed XSIAM 250 hours of Unit 42 incident response n/a On Pro and Premium. Hours of IR. Different instrument from the warranties on this table.
Arctic Wolf Up to $3 million n/a $3M needs Total bundle, Aurora Managed Endpoint Defense, and a 3-year term. Total 3-year without that combo is $1.5M.
Wayfinder MDR Up to $1 million IR and recovery if an undetected breach occurs Not published On the Wayfinder product page. Windows, Linux, macOS, and cloud. Confirm the tier before you treat it as insurance.
Defender Experts MDR None published n/a No MDR warranty on the first-party pages. Incident response is a separate contract.

What we left out

They sit next door because the page could not show a named console job on this list, a public price you can budget this week, or a warranty you can read before a sales call.

  • eSentire. Multi-signal MDR with Atlas packages you customize, plus a heavier IR and consulting wrapper. The packages page is a builder, not a public per-asset rate.
  • ReliaQuest. GreyMatter open XDR and a heavier consulting wrapper. Quote-only, and a different hole than the six console jobs here.
  • Huntress Managed SOC. 24/7 coverage for MSPs and smaller estates on the Huntress agent. We left it out because Huntress is a Windows, macOS, and Linux endpoint platform, not a named Falcon, Cortex, Singularity, or Defender console. The jobs here are those consoles, or mixed enterprise.

What Real Users Say About Managed Detection And Response

Here is what buyers already write when they compare managed detection and response.

Marked Hacker News comment comparing EDR and MDR
Marked PeerSpot review of Falcon Complete
Marked r/sysadmin comment on Falcon Complete

Questions before you buy an MDR

If the paper cannot answer these three, you are still buying a sensor with a logo on the invoice.

  1. Who takes the keyboard? If the contract says notify-only, you still own nights and weekends. CrowdStrike Complete, Sophos Complete, Unit 42 (once the Cortex tenant is in scope), and Wayfinder (under your response policy) take action. Arctic Wolf starts containment with you. Microsoft acts in Defender only if you grant Security Operator. Essentials, Reader, and other guided plans do not.
  2. What telemetry is in the seat? Falcon Complete identity and cloud are add-ons. Unit 42 still needs an XDR or XSIAM tenant. Wayfinder is Singularity. Arctic Wolf prices on users, servers, and egress. Microsoft Plan 1 is Defender workloads. Plan 2 needs Sentinel and 1,500 seats, and still only guides in third-party products. Sophos XDR Sensor on a third-party EDR is detection, not a Sophos agent.
  3. What does the warranty actually pay? Per-device caps, waiting periods, bundle-and-term rules, and “one claim” language are how a million-dollar headline becomes a four-figure check. Microsoft publishes no MDR warranty. Put the legal PDF next to the quote.

Which MDR vendor should you pick

Falcon estate and you want hands on the host: CrowdStrike. Cortex already in place: Unit 42, and make sure the contract names XDR or XSIAM. Singularity already the agent: Wayfinder, and write the response policy. Mixed stack and a number you can budget this week: Sophos Complete. Mixed stack and a concierge on the tools you already run: Arctic Wolf. Defender already the portal: Microsoft, and write the operator role if you want them to click. Then check who is allowed to contain, and put the warranty PDF next to the quote.

Frequently asked questions

Is Falcon EDR the same purchase as Falcon Complete?

No. Falcon Go, Pro, and Enterprise are self-serve EDR, the sensor on the host. Complete is the MDR layer: CrowdStrike analysts hunt and contain. The public $7.99 to $19.99 numbers are EDR, not MDR. The same split applies elsewhere. Singularity is not Wayfinder. Defender is not Defender Experts.

Can I buy Unit 42 without Cortex, or Wayfinder without Singularity?

Not as a bolt-on. Unit 42 MDR runs on a Cortex XDR license. Managed XSIAM needs an XSIAM tenant. Wayfinder runs on Singularity. Microsoft Plan 1 runs on Defender workloads. Arctic Wolf and Sophos are the mixed-stack paths. “Unit 42” or “Complete” on a quote still needs the contract to name the platform and the tier.

Does the $1 million warranty act like insurance?

Usually not. CrowdStrike pays $2,000 per in-posture host, with $1M / $2M caps. Sophos has a 60-day wait, a $5,000 minimum, and one claim across all orders. Unit 42’s 250 hours are a retainer, not a warranty check. Arctic Wolf’s $3M ceiling needs a bundle, Aurora Managed Endpoint Defense, and a three-year term. Wayfinder’s $1M is IR and recovery if they miss a breach. Microsoft publishes no MDR warranty. Read the PDF next to the quote.

List your product on Startup Stash

A listing is not a paid rank on this page.
Get listed

About the author

How we review tools

Written by

StartupStash

StartupStash

Editorial team

StartupStash is an editorial team. Each Top Tools shortlist is researched by a writer who works in that category, then checked against first-party product pages and public prices before it goes live.

Reviewed by

Manaal

Manaal

Content Manager, Startup Stash

Manaal is Content Manager at Startup Stash. She reviews the shortlist, the priced claims, and the sourcing before a Top Tools piece goes live.

Best Managed Detection And Response...
StartupStash

StartupStash is an editorial team. Each Top Tools shortlist is researched by a writer who works in that category, then checked against first-party product pages, public pricing, and recent product changes. A second editor reviews the piece before it goes live. We also run a directory of startup tools. A paid listing does not buy a place on a shortlist.