EDR vendor MDR overlay (platform-led)
The endpoint protection platform vendor offers managed detection on top of their own product. Strong telemetry integration; deep platform expertise. Weakness: limited cross-vendor visibility; tied to one EDR stack.
- Examples
- CrowdStrike Falcon Complete, SentinelOne Vigilance, Microsoft Defender for Endpoint with managed service overlay, Palo Alto Cortex XDR Managed Threat Hunting.
- Best for
- Organizations standardized on a single EDR vendor who want to extract maximum value from the existing platform.
- Pricing
- $30-$80/endpoint/month on top of the EDR license. Annual minimums typical.