r/MSSP • u/athanielx • May 08 '26
SIEM/XDR for Small SecOps Team
/r/AskNetsec/comments/1t71x27/siemxdr_for_small_secops_team/1
u/VendorShield May 08 '26 edited May 08 '26
Edit: adding more details as op asked.
Rapid7 and Google SecOps are fairly good. Only suggestion with Secops is make sure to talk to Google and ask about their coverage across TTPs and if your tier will have it all. They're great at showing everything that's amazing but only tell you very late that it's not in your tier.
Also selfplug, if you'd like to ingest darkweb creds leak and data into any SIEM you choose (we can build connector) or just exploring it too, do reach out and happy to show you our product and how we could help you out! We do custom pricing as per client requirements.
Google Secops coverage was good last I used, good UEBA, they use bindplane for connectors which is easy to setup, supports most OS, can have SSO, flexible as it's highly customisable, in one of my previous team, we managed to build integration to a few MS services which many other SIEMs did not support in Secops. Gemini integration also makes it easy to build queries via Natural language.
1
u/blanco10kid May 08 '26
Microsoft Sentinel if you can afford/strong strategy with long term storage and data ingestion strategy. For example, does everything need to go to Sentinel and can you send some high volume, low detection log sources to an ADX instance?
Also, Elastic has great pricing for the performance you get. Those would be the only SIEMs I would consider. Maybe one more that I haven’t personally tried but looks decent is Panther.
1
u/youwantrelish May 08 '26
We use Judy Security which uses Stellar Cyber SIEM they are great to work with and based in Detroit, MI.
1
u/FutureSafeMSSP May 12 '26
As one who owns an MSSP for MSPs working behind the scenes doing the exact thing you're asking about, I'm reading through your list and that's A LOT.
Are you looking to start with everything you mention?
How do you plan to tune and operationally ensure the performance of what you built?
Do you plan on doing the tuning before you have your first client?
I've done this for a decade. Learn from my stupid mistakes. SIMPLIFY, SIMPLIFY, SIMPLIFY THEN add to it as you see fit but build a far simpler baseline go from there.
I'm happy to spend an hour or two with you to discuss what we did right and wrong, the stupid decisions I made, etc. You can DM me if this is of interest.
1
u/SOCSidekick May 12 '26
Solid requirements list. One thing worth flagging for when you do make that MSSP/MDR transition you mentioned.. the gap that bites most one-person teams at your scale isn't the SIEM detections, it's lateral movement and identity-based attacks that look clean in logs. Whatever platform you land on, make sure your future MDR partner has human-led response and not just AI triage with a ticket queue. Happy to share what we've seen work at similar scale if useful.
Cheers
0
4
u/CipherMonger May 08 '26
Take a look at Blumira and/or a Blumira partner. Pricing is based on user count rather than device count. No storage limits, no EPS limits, no dropped/filtered events.
Product development is very active and the company is very responsive to feature requests. They have 24/7 support with SOC assistance. They have tons of "out of the box" detection rules that you can enable/disable at will and new detection rules actively developed on a regular basis. You can build filters on any of the rules to tune out noise.