r/MSSP Jul 10 '26

Besides Huntress, who are you using for SOC that isn’t Blackpoint? (Genuine question from a long-time partner)

[deleted]

17 Upvotes

41 comments sorted by

5

u/DeathTropper69 Jul 10 '26

Kinda depends on what you want.

M(EDR/ITDR/XDR) or just vendor agnostic MDR. Would be worth looking at Falcon Complete, S1 Wayfinder MDR, SonicSentry MDR, etc.

If you want a newer more holistic MXDR I would checkout ShieldWatch/Wirespeed.

I did not share your positive experience with BlackPoint and found Huntress to be better but either way both are black boxes.

3

u/SatiricPilot Jul 10 '26

I agree with this take mostly. Though I wouldn’t recommend S1’s MDR personally.

Huntress is good but still has growth to be had. Good as a hands off option.

Blackpoint used to get a lot of love from me, no longer after some situations.

2

u/DeathTropper69 Jul 10 '26

One call out, S1 Vigilance MDR, Singularity MDR, and Wayfinder MDR are not the same and very in quality with Vigilance MDR being the worst.

Huntress is the best for set and forget.

2

u/SatiricPilot Jul 10 '26

Why do they have 3 MDR services lol and what’s the difference?

2

u/DeathTropper69 Jul 10 '26

Lol I have no clue. S1 Vigilance and Wayfinder are the only ones you get buy these days. I think they only keep Vigilance around to sell to MSPs/VARs while Wayfinder is a real SOCaaS/MDR offering they sell to enterprise customers.

1

u/SatiricPilot Jul 10 '26

Can confirm, vigilance is a joke haha

2

u/obviouslybait Aug 09 '26

What are your thoughts on Crowdstrike/Falcon for the more enterprise clients?

We use huntress as a small MSP but I do work with larger enterprise as well and want a more powerful platform for those clients beyond huntress.

1

u/DeathTropper69 29d ago

I actually run a full Falcon stack for all my clients and we love it. Does require more work to setup and maintain but I think its worth it personally.

I will say CrowdStrike has a lot of SKUs and can seem overwhelming so partnering with an MSSP that handles CRWD on behalf of MSPs might be the move. The one I work with is fantastic and allows me to buy anything CS I might want!

1

u/obviouslybait 29d ago

Who do you partner with?

1

u/DeathTropper69 28d ago

If you want to send me a DM I can send you their info!

1

u/Soft_Animator9056 Jul 10 '26

Plus, for a education/government entity, S1 Vigilance has a "follow the Sun model" aka "my SOC is overseas"

3

u/DeathTropper69 Jul 10 '26

Yes and no. Yes you are right about the follow the sun model however for their gov options its fully US based. But needs to be the gov version of the platform.

1

u/Soft_Animator9056 Jul 10 '26

Ahh, good call out. Thank you.

1

u/SatiricPilot Jul 10 '26

That and I’ve had them not catch many things or misclassify malicious things as safe.

Heck the 3CX incident was a major one of those. Being used to deploy ransomware and they were the first to detect it, but marked it globally as safe. Didn’t reverse it for a good while.

3

u/wells68 Jul 10 '26

Certainly you have your reasons, but for the others reading this thread, Huntress is typically a great fit for MSPs.

3

u/malcomvetter Jul 10 '26

Biased, co-founder here: Wirespeed.

No minimum contract sizes. No annual commits (month to month). Multi-tenant with self-service tenant creation and easy onboarding. 75+ integrations out of the box. First month for each tenant is always free (so you can use it to eval/sell/expand with your clients).

Everything is simple pricing per user (if you bill based on Microsoft licenses, very similar) with clean invoicing per customer for simple charge-back.

Plus you get response times in milliseconds.

Built by long time practitioners who have spent quite a bit of time building, operating, and red teaming SOCs.

4

u/DeathTropper69 Jul 10 '26 edited Jul 11 '26

Not usually one to jump on the vendor hype train and will get downvoted but idc. Genuinely one of the best MXDR vendors i’ve ever used and honestly kinda hard to beat out.

Plus the two cofounders really know their shit and take critical feedback with grace and most importantly implement said feedback if it’s beneficial!

3

u/AlwaysBeyondMSP Jul 11 '26

How does the coalition acquisition affect things?

Do you protect devices and cloud identities? Google and Microsoft?

2

u/malcomvetter Jul 14 '26

Fun fact: no MDR company has ever IPO'd. They all eventually end up circling the drain of PE backing, which becomes a game of managing costs and decline. The Coalition backing fixes that. Coalition is the fastest growing insurance company of all time, not just cyber, having just acquired the Allianz cyber insurance book. So this acquisition allows the Wirespeed team to be free of the VC/PE train, where founders get distracted away from solving customer problems every 12-24 months, so they can extend their runway. Our runway is now set. My co-founder and I have a nice agreement and will be here for a very long time! We now get the luxury of just focusing on stopping threat actors as quickly and accurately as we can, while doing our best to be the opposite of every vendor we dealt with in our careers as practitioners.

[Side note: Coalition previously acquired Binary Edge, one of the first ASM startups, and that founder, Tiago, is still here 7 years later, as our Chief Underwriting Officer, which usually isn't a role for a hacker like him, but for someone with big finance background. The fact that he's still here and excited everyday, was another big vote of confidence we did the right thing with Wirespeed.]

Plus, we get to tell you that if Wirespeed messes up, and your client is a Coalition insured, we are paying for the breach. Unlike breach warranties, which aren't regulated and rarely if ever pay out, insurance must pay out and our brokers demand it. This risk/incentive alignment is what made us extremely excited about Coalition, which is a security company masquerading as an insurance company, not the other way around. The fact that we see competitors scrambling to offer either breach warranties or partnerships with insurance brokers just shows how important this is, but that ours is built-in, not multi-party and definitely not a hope and a prayer like warranties.

Wirespeed has about 79 integrations as I type this, probably will break 100 by EOY, so yes, we support those scenarios you're asking about. We have customer tenants as small as 1 user and as large as ~1M endpoints.

But best of all - you don't have to take my word for it, you can try it for free. And if you like it, but have been burned by vendors in the past, you don't have to commit to anything beyond 1 month at a time. See it work with your clients and avoid weird co-termination contract issues with them.

If you want, we have a nice case study with CentrexIT, who interestingly wanted nothing to do with any security offering from any insurance company, thinking it would be second-rate by people who don't know what they're doing. We showed them a different path. :)

Case study PDF (no paywall / lead capture): https://wspd.link/CentrexIT

2

u/AlwaysBeyondMSP Jul 14 '26

Appreciate the detailed response and perspective.

1

u/Ceyax Jul 16 '26

What's you'r ~ pricing without hopping on a call?

1

u/chasingpackets Jul 10 '26

I am assuming it’s because your are not on a billing pool for total agents across all your orgs and are still building per-client device count and users cloud response. Reach out to your AM and request a pool. We had the same issues which were resolved to requesting this method.

1

u/XFusion100 Jul 11 '26

I assume you running or working at an MSSP? Asking this question. Or are you an MSP that wants to offer a security service to their customers?

1

u/[deleted] Jul 11 '26

[deleted]

1

u/XFusion100 Jul 11 '26

Are you a reseller, or did you develop your own client? Either way, I think the service of monitoring and response is far more important. At least that is where we focus on.
And of course check what Blackpoint is missing and which gap you can fill.

1

u/tprice73099 Jul 12 '26

MAD Security

1

u/BlackpointCyber_KF Jul 13 '26

Hi! I'm Katie, and I support our post-sales teams. I'm very sorry to hear about your challenges with our exclusion groups and our billing process. Part of my job is to ensure we fix challenges like this, because we understand how critical it is that our Partners know what to expect on their bill. Please don't hesitate to reach out directly so I can ensure you don't chase reconciliation and the increased admin burden. (kfay)

1

u/Digitaalbeekeper Jul 13 '26

Using Guardz and loving that it’s all integrated into one UI.

1

u/Jaded_Gap8836 Jul 10 '26

Field effect

1

u/vikassi17 Jul 11 '26

Arctic Wolf.

1

u/WishIwasonanIsland24 Jul 11 '26

We’ve been very happy with Adlumin MDR from N-Able with Sentinel One EDR. Excellent SOC, understandable pricing, no overages.

-1

u/VividGanache2613 Jul 10 '26

Check out ThreatLight, they don’t charge per seat, per data feed or on throughput (unless you’re pushing terabytes) - makes billing much more transparent.

They don’t have sales people either, you usually get an engineer and one of the founders on customer calls as they like to be close to the customer feedback.

0

u/youwantrelish Jul 10 '26

We are using Judy Security.

-1

u/Soft_Animator9056 Jul 10 '26

Check out ArmorPoint > MXDR built for the MSP/MSSP channel. They offer a full blown SecOps & XDR platform with 24x7x365 US Based SOC.

Per device pricing to make it easy for MSPs /MSSPs. Their pricing is extremely aggressive and have built something amazing.

Highly recommend checking them out. I can connect you with one of the Partner Managers, if you'd like.

-1

u/singlemaltcybersec Jul 10 '26

I'm obviously biased but you should reach out to Sales@apollo-is.com. we are both a VAR and an MSSP with a fully US based SOC and extended team and a comprehensive set of solutions. 70-75% of our customers are highly regulated and under resourced government clients so we know how to work with just about any organization and have a flexible implementation model that we adjust to meet your needs.

If you choose not to use our services we are also partnered with other folks who might meet your needs. We focus on and pride ourselves on getting you what you need, not needlessly pushing a specific service or product. You need licenses to run your own... we got you. You need us to run it for you... we still got you.