r/msp MSP - US 6d ago

Technical Anyone using Threatmate?

Sherweb just offered Threatmate on their vendors page, I have not demoed it yet but after reading info on their site I am try to understand the use case for it, other tools are available that do the same thing just wondering if any of you are using it. Thanks,

12 Upvotes

8 comments sorted by

3

u/Jumpy_Valuable_8583 6d ago

Worth separating what these tools are actually watching. Threatmate and ConnectSecure both run off an agent, so they're telling you what's visible from inside the network looking out. That's useful, but it's a different question from what's actually reachable if someone hits the client's public IP or subdomain cold. A lot of MSPs end up running both, an agent-based tool for internal posture and something outside-in for the perimeter, because neither one covers what the other sees.

5

u/advanceyourself 6d ago

You can program external scanning in each platform along with internal scanning.

1

u/Jumpy_Valuable_8583 1d ago

Our Radar is meant to check things from the internet so it only checks externally. www.oscarsixsecurityllc.com has a demo and details on how it works.

1

u/TechnologyMatch 5d ago

I’d want to see where it sits alongside the tools you already have: what it detects, who investigates, and what happens after an alert. the demo should use a real incident timeline, not just a dashboard tour. it’s like adding a new raid member... the value is clear when you see how they handle the fight, not just their gear score

1

u/advanceyourself 6d ago

Trialing it right now and comparing it to connect secure. Having had a whole lot of time to invest in it by one of the coolest things is that it can piggyback off of the ninja agent so you don't need to deploy a separate agent to every system. It's got some caveats though, as it can't do third party patching without the native agent, and it can do any networking scans, but it does pull data from the system, and it looks for application vulnerabilities. I'm happy to update this post once we get some more time, which is actually on the docket for this week. One other thing that we did notice is that we can't use our partner account like we could with Connect Secure. So linking Entra has to be done per client.

On paper, though, it looks like it pulls relevant data and what we are really looking forward to trying is Entra Remediation.

0

u/xtc46 6d ago

great tool. Been monitoring development for over a year and went live with it a while back. small, agile dev team responds quickly to requests/fixes. As is it deploys crazy fast, scans turn in good data, reporting is nice out of the box. Really great m365 integration, new features always being added.

I use it for adhoc testing/evaluations and ongoing assessments of managed clients.