TrustRadius: an HG Insights company

Arctic Wolf Managed Detection and Response

Score9.1 out of 10

34 Reviews and Ratings

What is Arctic Wolf Managed Detection and Response?

Arctic Wolf Networks in Sunnyvale provides scalable managed cybersecurity protection for IT-constrained companies, to keep their critical data, networks, web-based applications, and devices safe. Working as an extension of an internal team, Arctic Wolf security experts deliver 24x7 cloud-based monitoring, risk management, threat detection, and response services that protect companies from ever-evolving methods of cyber attack.

Videos

Who Buys & Uses Arctic Wolf Managed Detection and Response

Better than most security solutions

Use Cases and Deployment Scope

They are our main security partner and have integrated most endpoints, and logging into Arctic Wolf. We also use them for our end-user security training. We count on them to filter through all of our alerts or suspicious incident, and raise alerts to us that we should review and determine whether action needs to be taken.

Pros

  • Integration of man disparate systems.
  • End user training
  • Cutting down on the amount of data we have to review.

Cons

  • Cylance integration is not great.
  • I'd like to see lower false positives, but that can be a tradeoff
  • Less required meetings with them

Return on Investment

  • We continue to have low downtime due to security issues
  • Our users have become much more savvy due to the training
  • It has freed up time from our security officer

Usability

Alternatives Considered

CrowdStrike Falcon Complete Next-Gen MDR

Arctic Wolf - Another Layer of Protection

Use Cases and Deployment Scope

Agents installed on all end points and servers. Monitoring location, logins and potential malicious file and scripts running. Email alerts sent to specified contacts and phone call if issue severity is high. Location based alerts for 365 accounts will trigger when a user account is accessed outside of whitelisted countries.

Pros

  • Monitoring 365 logins
  • Monitoring Windows processes
  • Active Directory monitoring

Cons

  • Some erroneous 365 alerts about failed logins
  • Need an easier method to suppress alerts (outside of email)
  • Too many places to look for info in console

Return on Investment

  • Stopped unauthorized 365 access on user account
  • Pointed out malicious file activity on end point
  • Alert sent when a domain admin account was enabled

Alternatives Considered

Check Point Harmony Endpoint, Check Point Harmony Email & Office and NinjaOne

Arctic Wolf has the teeth in our network to keep us protected.

Pros

  • Dashboard
  • Notification
  • Dedicated team of engineers at my disposal

Cons

  • Too many independent dashboards to look at (they are working on consolidating)

Most Important Features

  • Reporting tools

Return on Investment

  • I have been informed about Zero days prior to vendors releasing information to the public which has allowed me to patch in advanced of the general release of the information

Other Software Used

Zoom, iManage Work