Managed Detection & Response

Start With The Endpoint. Grow Into Everything.

MDR · Managed Detection & Response

ArmorPoint's 24/7 U.S.-based SOC runs on your EDR, detecting, investigating, and responding where most attacks land. When you're ready to cover more, the same operation extends across your whole environment with MXDR.

The gap

An EDR raises alarms. It doesn't answer them.

A good EDR catches what's happening on your endpoints. But it still just sends alerts, and an alert no one investigates is a breach with a head start. You might recognize the signs:

Your EDR alerts 24/7, but no one watches it 24/7

It fires around the clock. Your team doesn't work around the clock.

Alerts pile up faster than anyone can investigate

Without a team to triage them, the ones that matter get buried in the noise.

Catching a threat and stopping it are different jobs

Detection is the easy part now. Response is where breaches are won or lost.

Staffing a 24/7 endpoint watch isn't realistic

The analysts to run it around the clock are expensive, scarce, and already taken.

ArmorPoint runs the SOC on top of your EDR.

How MDR works

From endpoint alert to closed case.

Your EDR catches it. Our SOC investigates, responds, and proves it, around the clock.

YOUR ENDPOINTS Every endpoint, fully managed. Windows · macOS · Linux AI triage engine .98 Classification Benign? Suspicious Malicious Human confirms the call OUTPUTS Triaged & prioritized Contained on your rules Audit-ready evidence
Detection · what the EDR does
Response & proof · what ArmorPoint adds
Discover
Inventory endpoints
Your EDR does this
Detect
EDR + AI triage
Your EDR does this
MOST
EDR
TOOLS
STOP
Investigate
A human takes the call
  • Validated, never auto-closed
  • Agree/disagree trains the engine
The human decides. Always.
Respond
Contain by process
  • Isolate, kill, quarantine
  • On the rules you approve
Active or guided, your call
Prove
Evidence in real time
  • One-click incident report
  • Mapped to MITRE ATT&CK
No black box
Endpoint covered. Ready for more? MXDR extends the same SOC across identity, cloud, SaaS, and network. Additive, never a re-implementation.
Detection is only the beginning

What happens the moment something looks wrong.

Most security pages go quiet about the actual moment of truth. Here is exactly how a single endpoint alert becomes a resolved, documented incident, and where you stay in control.

01
The EDR flags it

An alert fires on an endpoint, a suspicious process, an unexpected script.

02
The platform connects it

It correlates the alert with the account that launched it and an outbound connection, one story, not three alerts.

03
An analyst investigates

A SOC analyst reviews the device, user, and timeline, and decides: benign, suspicious, or malicious.

04
It becomes an incident

Confirmed malicious, it's escalated and you're notified through your defined escalation path, with severity and context.

05
We containyour approval

With your authorization we isolate the host, kill the process, and quarantine the file, where technically available.

06
We guide eradication & recoveryyour approval

We recommend the steps to remove the root cause and restore the endpoint; you approve and we assist.

07
It's documented and tuned

Every action becomes a record in your reporting, and detections are tuned so it's caught faster next time.

The result isn't another alert to decode. It's a managed incident with clear ownership and a defined path forward.

What's included

A managed SOC on your endpoints.

EDR, managed
  • Anti-virus, anti-malware, ransomware & exploit protection
  • Managed EDR: CrowdStrike, SentinelOne, Cybereason
  • Or bring your own EDR
  • OS & process telemetry
24/7 SOC operations
  • Continuous monitoring
  • Alert investigation & validation
  • Escalation to incident
  • SANS-based incident response
  • Ongoing tuning
Response & recovery
  • Endpoint containment on your approval
  • Isolate, kill, quarantine
  • Guided eradication & recovery
  • 5 hrs/month post-eradication
  • Post-incident documentation
Customer experience
  • Platform access & dashboards
  • Configured notification & escalation
  • 24/7 ticketing portal
  • Service reviews
  • Security activity reporting
OSWindows, macOS, Linux
Retention365 days for alerts & incidents; 30 days online + 365 archived for logs
DataUS-owned data centers

MDR is endpoint-focused. Network, identity, cloud, and SaaS coverage is MXDR. Implementation, hardware, OS reinstalls, and data recovery are out of scope, see your service agreement for the full list.

Know who owns what

Security operations without ambiguous handoffs.

ResponsibilityYour teamArmorPoint
24/7 monitoringVisibilityPrimary
Investigate & validate alertsContextPrimary
Classify & escalate incidentsInformedPrimary
Approve containment & eradicationRequiredRecommends
Execute approved containmentInformedPrimary
Eradication & recoveryApproves & actsGuides
Remediate business apps & rebuild systemsPrimaryAdvises
Incident record & reportingVisibilityPrimary

ArmorPoint isn't a black box. You keep full platform visibility while we run the security operations work. Containment and eradication always happen on your approval, the specific steps are your call.

The platform you don't operate

Your security operation shouldn't be another tool to babysit.

The ArmorPoint platform is not another console for your team to manage. It is the technology our SOC uses to deliver the service. You keep access to incidents, dashboards, raw logs, and reports, while ArmorPoint runs detection, investigations, and response on your endpoints.

You see the operation. ArmorPoint runs it.

Runs on your EDR
AI triage, human in the loop
Every detection maps to MITRE ATT&CK
Tokens to the model, never your data
US data, US-owned data centers
You keep full platform visibility
In their words

Detection gets noticed. Response gets remembered.

24/7
U.S.-based SOC, every hour of every day
30 min
response target on Critical and High alerts
SANS
based incident response, every phase
Response

“We get notified when it's important, and we can take quick action.”

Lt. Brandon Krieger, Pike Township Fire
Visibility

“The ability to log in and see the incidents we have on the go is incredibly reassuring.”

CPL
Partnership

“A level of partnership and transparency other major players do not provide.”

Daniel Holm, InterWorks · ArmorPoint partner
Predictable pricing

Priced by endpoints, not data volume.

MDR pricing is based on the number of endpoints you protect, not on data volume or events per second. Every subscription includes platform access, onboarding, and the operations in your scope. Exact scope and pricing are confirmed in a short review.

Is MDR just antivirus?

No. EDR is the technology on the endpoint; MDR adds the 24/7 SOC that investigates, escalates, and responds to what it finds.

Does ArmorPoint take response actions?

Yes, endpoint containment and eradication, on your approval and per your runbook. Specific steps are always your call.

Can you contain an endpoint?

Where technically available, yes, isolate the host, kill a process, or quarantine a file, with your authorization.

Who handles remediation?

We guide eradication and recovery; you approve and own changes to your business systems. 5 hours per month of post-eradication support are included.

How fast are incidents escalated?

A 30-minute response target on Critical and High, 2 hours Medium, 4 hours Low, 24/7/365. Targets, not guarantees.

See it in action

Your EDR catches it. We close it.

Get a live walkthrough of the platform and the 24/7 SOC that runs on your EDR. See how ArmorPoint turns endpoint alerts into closed, documented incidents, and what that gives your team back.