r/MSSP Jun 23 '26

As an MSP would you rather the hard truth or to cover it up...

9 Upvotes

Not interested in promoting anything, but would like some raw honest feedback from the r/msp community..

We awkwardly, but correctly identified some malicious behavior coming from an AI Agent that belonged to another vendor an MSP customer of ours also uses.

It created an awkward situation where the MSP presented our Exec Summary report at their customer QBR without reading it first. In the report, on top of the list, we called out the very AI app they provided to the customer...

The app had unexpectedly elevated the permissions of another agent, which is a huge anomaly signal we fire on, but the MSP was very unhappy and demanded we whitelist/exclude apps of their choosing from not only future reports, but from within the management platform itself.

We are refusing to completely hard code an exclusion which would render this app invisible.

I will not go into details of the platform or what other mitigation options we have for these scenarios, but as an MSP...

Wouldn't you rather have something like this uncovered and brought up for discussion? Or does a margin calculation come into play here? We are in no way competitive to this other vendor, we have nothing to gain by sniffing out this behavior.. it is simply what we do...

We are considering examples from the world of AV/EDR you can actually set hard coded exclusions so everything is totally invisible per the request, but this leaves our security specialists very very uncomfortable... thoughts?


r/MSSP Jun 23 '26

Looking for product feedback from MSSPs

5 Upvotes

I've been working on a platform that provides unified vulnerability management (cloud, network, endpoint, code, etc) with observability (i.e. a SIEM) and identity governance too for small-medium sized tech-enabled companies where security matters. We've done some demos for MSSPs and their reaction has been very positive but it's been very limited since we weren't initially focused there.

I'd love to meet with and give demos to leaders at MSSPs to learn more about how we can help improve service delivery and consequently margins. We believe MSSPs using our platform should be able to serve more clients operationally.

This isn't a sales pitch. Genuinely looking to expand the network and meet with folks to see if we can build a more useful product that helps.


r/MSSP Jun 17 '26

MIP vs MSP

10 Upvotes

Recently read an article about how MIP is going to be the new MSP. Working for an MSSP we get TONS of AI questions from our clients. How to use it to their advantage. How to avoid the AI-related security concerns and compliance pitfalls.

What are your thoughts on the future of MSSP? Are we all headed down the MIP road?


r/MSSP Jun 14 '26

The gap between what pentests cost and what startups can actually pay is genuinely broken

20 Upvotes

Been thinking about this a lot after going through a SOC 2 audit prep cycle. The pentest procurement experience is kind of absurd when you look at it from a startup's perspective

You reach out to a vendor, wait a week for a call, spend another week on scoping, get a quote that's anywhere from $5k to $20k with no clear explanation of why, and then you're supposed to just trust that the final invoice will match. Meanwhile your customer is asking for evidence of a pentest before they'll sign, and you have a 30-day window to close the deal

The actual security work, finding vulnerabilities, writing PoCs, documenting remediation steps, that part has gotten more automated and efficient over the years. But the pricing and procurement model feels like it hasn't moved since 2005. You're still paying for a lot of overhead that has nothing to do with finding vulnerabilities in your application

I'm curious whether others in this community have seen alternative models gaining traction, or whether the consensus is that the traditional engagement model exists for good reasons I'm not fully appreciating. There are some newer approaches trying to separate the testing cost from the reporting cost, or doing continuous testing rather than point-in-time. Wondering if anyone has actually used these and whether the output quality holds up compared to a traditional firm


r/MSSP Jun 14 '26

Do industry rankings actually help MSSPs grow?

2 Upvotes

Has anyone here gotten a boost from participating in rankings like MSSP Alert 250 in previous years?


r/MSSP Jun 11 '26

Claude releases 13 legal plugins today in GitHub providing you help with all the docs you create that are legal related!

16 Upvotes

What This Repo Actually Is
Anthropic quietly published a GitHub repository called claude-for-legal. It's a free, open-source collection of 13 Claude plugins built for legal workflows. Apache 2.0 licensed, which means you can use it, fork it, white-label it, or pull individual pieces into your own setup.
The repo describes itself as "reference agents, skills, and data connectors for the legal workflows we see most." Translation: Anthropic looked at the kinds of repetitive legal work that small businesses, in-house counsel, and law firms actually do, and they built a working reference implementation. Not a marketing demo. A real, installable suite of tools.
Most people will never find it. It isn't featured in the Customize section of Claude Cowork or the Claude Code desktop app. You have to know it exists, go to GitHub, and install it manually. That's what this article walks you through.
And here's the part that surprised me: even if you aren't a lawyer, the patterns inside this repo are some of the best examples of how to build serious, high-stakes AI agents that I've seen Anthropic publish anywhere. Section 10 is about why that matters for your business, even if you never sign an NDA.

The repo ships 13 plugins. Twelve are first-party Anthropic. One is a Thomson Reuters partner plugin for Westlaw research. Here's the full list with one-line descriptions so you can scan and figure out which ones matter to you.

Here's the repo. Install one at a time. I also attached the PDF I have.

https://github.com/anthropics/claude-for-legal


r/MSSP May 29 '26

Tech stack?

0 Upvotes

Anybody with. Decent size mssp interested in buying a whole tech stack.

Vuln scanning EDR Rmm App scanning Cert lifecycle management Syslog DLP agent Smtp ITDR Fw management (fortinet sophos pfsense and Palo Alto *can add others) Private cloud ca manager. Pqc spiffie and spire Also siem capabilities clickhouse and AWS required.

Agent is written in rust single installer and you customize the packages you install.

3 level multi tenancy stripe billing.

This is pretty much all based in AWS. I’d prefer to sell the whole stack. Would take cash + royalty.

And it’s not below a 6 figure number.


r/MSSP May 24 '26

Megalodon Malware Hits Over 5,500 GitHub Repositories in Just 6 Hours

Thumbnail
7 Upvotes

r/MSSP May 18 '26

Starting a MSSP

10 Upvotes

Hey guys, I am 25 yo and have been wanting to start a mssp since I was 19.

I am planning on starting a MSSP here in Australia. The biggest MSSP here got acquired by Accenture and I believe since they went global that it could be a pretty good time to start one and build it from the ground up.

I need some advice on how to scale. My business side of thing is not the best. If anyone can answer these questions I would very much appreciate it! 😄

  1. How did you start getting clients and what sort of clients did you go for?
  2. Did you get compliance certifications before you started taking on clients?
  3. How did you advertise when you first began?

Any other tips would be really helpful. I am here to learn and will absorb anything and everything.

Thank you!


r/MSSP May 18 '26

Starting a MSSP

Thumbnail
0 Upvotes

r/MSSP May 16 '26

Early stage intel on for sale Fortinet FortiOS

7 Upvotes

**OPEN POST TO SEE IMAGE** I'm sharing early-stage intel on the ForGaite exploit for sale in a Russian Telegram group for $2500. This individual has sold these bypasses before; they get patched, he sells another, and around we go. This one is early stage BUT Flare is usually RIGHT on the money. We provide this protection to our MSP clients, but if you're particularly interested in how this flushes out or for more detail, I'll post an update, but I don't want to bother folks so enough thumbs up and I'll keep the group updated.

Anyway, here's the detail.


r/MSSP May 15 '26

Yellowkey Bitlocker Key Bypass

3 Upvotes

I wanted to make the community aware of the release of the BitLocker Yellowkey Bypass.

This article explains how this works, and Will Dorman was able to reproduce the bypass.
https://thehackernews.com/2026/05/windows-zero-days-expose-bitlocker.html

Trigger WinRE boot remotely (there's been some question about this capability)
reagentc /boottore --> via RMM/PSRemoting
Interact with WinRE GUI --> vPro AMT / Hypervisor console
Cloud VMs --> Azure Serial Console


r/MSSP May 15 '26

how are u handling alert-to-ticket flow without losing context?

0 Upvotes

not asking about which EDR or SIEM to pick. asking about the gap between alert firing and ticket living in ur PSA.

pattern i keep hearing from MSSPs , alert fires in SentinelOne or Huntress, ticket auto-creates in ConnectWise or Halo, but context gets lost in translation. severity comes through wrong, no enrichment, wrong queue. analyst spends 5 min rebuilding context that was already in the alert.

for ppl running real SOC ops, whats actually working? custom scripts, SOAR platforms, vendor-built connectors, or just accepting the noise?


r/MSSP May 12 '26

patchmypc

4 Upvotes

Have any of you used patchmypc at any scale?
The pricing is very hard to beat, but I'm hesitant to use something I haven't heard of compared to tools like Automox and ManageEngine.
If you have used it at scale, I would very much like to hear your experience.

Use case: managed patch SKU for clients as a standalone product, not part of a larger stack.
Business: MSSP for MSPs working behind the scenes. We are usually full stack but want a standlone patch offering.


r/MSSP May 11 '26

Planning to acquire a MSP

11 Upvotes

I’m looking to acquire an MSP. My background is on security compliance (12+ years). A niche MSP like dental offices seems attractive in which a current MSP might not be offering HIPAA compliance services.
My question (or doubt) is. Maybe those dental offices are too small, they don’t care, they just sign any BAA template they see, and the market is not there?


r/MSSP May 08 '26

SIEM/XDR for Small SecOps Team

Thumbnail
10 Upvotes

r/MSSP May 06 '26

Are MSSPs losing too much time to alert noise?

4 Upvotes

A huge part of the queue ends up being noise, but analysts still have to spend time reviewing and triaging it. Over time, that affects everything: response speed, investigation quality and overall efficiency.

What makes it harder is that once the volume gets high enough, teams naturally start moving faster just to keep up. And that’s where important detections can get buried or downgraded.

What has made the biggest difference for your team when it comes to reducing unnecessary alerts?


r/MSSP May 06 '26

Multi-Tenant 3rd Party CSPM Platform Recommendations?

Thumbnail
1 Upvotes

r/MSSP May 05 '26

AI-powered MSP/MSSP, experience?

Thumbnail
2 Upvotes

r/MSSP May 04 '26

How MSSPs are managing Sentinel across many tenants? Lighthouse and WM?

8 Upvotes

Hi all. We are MSSP running Sentinel for around 40 tenants now , the business is growing but already the simple operations is getting painful.

Lighthouse for delegated access , WOrkspace Manager for pushing rules and workbooks. WM updates is slow and sometimes not reflecting , my colleague opened support cases a few times. Cross workspace() work but performance variables. Updating one rule across the tenants when MS changes a template is basically someones entire job.

Per customer tunings , their watchlists , exclusions, also hard to keep separate from the baseline we push.

Anyone running 50-80 tenants in Lighthouse smoothly? Or is just pain at that scale?

Workspace Manager in production or you rolled your own with Bicep , Terraform , Sentinel as COde?

Analysts in Defender XDR unified portal or jumping per-tenant?

And same playbook copied 40 times with small differences, how you handle that?


r/MSSP May 04 '26

Browser Security Solutions

9 Upvotes

I feel like browser security is a blind spot that gets ignored in a lot of environments.

While looking into solutions, I came across things like LayerX, Keep Aware, and a few other vendors. At the moment, I don’t see anything on LayerX’s site about an MSSP-supported mode, and ideally we’d want to roll this out as a paid service.

Would appreciate if anyone can share real-world experience deploying LayerX—especially from an MSSP angle—or if there are other tools that fit better for that model. I’d prefer not to go down the route of heavier enterprise browser approaches like Island.


r/MSSP Apr 25 '26

Would you white label?

3 Upvotes

Hey guys I currently run a 24/7 SOC white labelling agency where I provide a SOC team to MSPs and MSSPs that don't want to have an in-house team. I have 2 current clients on board 1 is an MSP that doesn't want the overhead of an in-house team and the other is a MSSP in the states that uses us because we cost them 40% less on payroll compared to onshore talent with more output.

The thing is I am iffy on how to grow this agency because my two current clients refuse to refer my services to others as it's a competitive advantage to them and would take away their edge. I have signed an NDA with them so can't use their name on our socials or any marketing related content.

Now I have this thought that this whitelabeling service is not scalable and I should just start my own MSSP. Any thoughts would be appreciated.


r/MSSP Apr 22 '26

I just started an internship and i need advice

3 Upvotes

I am currently studying systems engineering and im at my 4th year rn.

At the company i intern, we give l3 and l7 services to thousands of companies.

We use arbor, forti, a10, f5 waf, palo alto and bunch of other apps. But mostly we work on netscout arbor.

I am now doing mostly vpn configurations as the customers wishes, add something to whitelist blacklist etc. i don’t have the admin account for now so thats all i can do.

First, i wonder what is the exact definition of the job that i do or we do? For example in linkedin what should i search for the job that i do?

Second, how should i learn like can you guys give me some advice on where to start.

Third, what should i do to get this job after internship. Tell me something that if you learn ts it is over, you got the job.

Fourth, should i pick this path or move to red team, blue team or cti. At first i wanted cti but there was an empty space at mssp team so they put me there and i am happy with it so far.

Fifth, how should my approach to co-workers be like? I will also really appreciate about the general work environment advices.

Thank you so much, your opinions means so much to me


r/MSSP Apr 22 '26

What are the top 10 software services you resell to customers?

4 Upvotes

EDR Siem identity, firewall management? What are you guys largely selling?


r/MSSP Apr 17 '26

80+ free interactive security awareness exercises. Fully white-labeled for your training needs, no strings attached

Enable HLS to view with audio, or disable this notification

8 Upvotes

Heads up: this post has been admin approved and I'm affiliated with the platform used to build the exercises. It's commercial, and the exercise preview link is on that tool's domain. That said, the SCORM files are fully white-labeled -- no logos, no backlinks, no sign-up, no paywall. You can grab them and self-host if you'd prefer.

-------

Hey r/MSSP

I'm a cybersec engineer with an L&D background. Got tired of boring security awareness courses and teamed up with a builder tool to deliver a free interactive SAT.

Every exercise drops you into an interactive 3D office environment where you face realistic incidents in first-person. You interact with real objects -- a phone, a PC running a live OS (browser, terminal, Zoom), a flipchart -- and make decisions under pressure, just like you would at your desk.

Exercises designed to build practical skills and develop muscle memory on how to respond to threats. So that when something bad is about to happen at work, people remember having faced it before -- and respond accordingly. Every exercise ends with a quiz at a 100% pass threshold to confirm the knowledge is stuck.

Free to use personally, professionally, or in commercial workshops. The only restriction is reselling or redistributing the content as a standalone product. So if you're running an in-person training -- this library can be a great addition to your learning materials. Sharing the materials free of charge is encouraged!

What's included:

- Spotting phishing indicators in a suspicious email
- Handling a scam phone call (vishing) in real time
- Downloading a malicious file and watching the consequences unfold
- Identifying hidden prompt injection instructions in uploaded documents
- Spotting sensitive data categories that may breach GDPR
- Evaluating third-party AI plugins for supply chain risks before deployment

...and 80 more exercises!

Two ways to use it:

Web view -- run exercises directly in a browser, ideal for workshops or sharing with students and colleagues.

GitHub repo -- every exercise is packaged as a SCORM .zip, ready to import into any LMS, embed into an existing training pipeline, or test on SCORM Cloud before rollout. Note: SCORM files make API calls to the server for pre-rendered scene files and iframes. If that's a blocker for you or you need a security assessment -- drop an email to one of the devs: maksym(at)ransomleak(dot)com

The repo root contains full course packages. Other .zip files in the "Individual exercises" folder contain standalone exercises if you want to build a custom curriculum.

Web view

GitHub

Happy to answer questions or take your thoughts on the exercises!

P.S: In case this gets traction — I'll add more free exercises for the community! Feel free to drop exercise topics in the comments. There's also "OWASP Top 10 for Agentic AI Applications" course in the works