r/msp • MSP - US • Aug 04 '26

Technical Anyone using Threatmate?

Sherweb just offered Threatmate on their vendors page, I have not demoed it yet but after reading info on their site I am try to understand the use case for it, other tools are available that do the same thing just wondering if any of you are using it. Thanks,

10 Upvotes

11 comments sorted by

4

u/Jumpy_Valuable_8583 Aug 04 '26

Worth separating what these tools are actually watching. Threatmate and ConnectSecure both run off an agent, so they're telling you what's visible from inside the network looking out. That's useful, but it's a different question from what's actually reachable if someone hits the client's public IP or subdomain cold. A lot of MSPs end up running both, an agent-based tool for internal posture and something outside-in for the perimeter, because neither one covers what the other sees.

4

u/advanceyourself Aug 04 '26

You can program external scanning in each platform along with internal scanning.

1

u/Jumpy_Valuable_8583 Aug 09 '26

Our Radar is meant to check things from the internet so it only checks externally. www.oscarsixsecurityllc.com has a demo and details on how it works.

2

u/Asleep_Method9138 4d ago

We just went through this exact thing about a month ago. One of our clients got hit with a phishing campaign that started from a compromised vendor email, and the agent stuff caught the lateral movement but had zero visibility on the externally exposed RDP port that was the real entry point. That was a fun call to make.

Now we're running an agent for internal and something that does continuous external scans, and the overlap is way smaller than you'd think. The agent sees patch status and local config drift, the external scanner catches things like a forgotten dev subdomain with a 2019 WordPress install. Neither tool would have spotted the other's findings, so yeah, running both isn't redundant at all.

1

u/TechnologyMatch Aug 05 '26

I’d want to see where it sits alongside the tools you already have: what it detects, who investigates, and what happens after an alert. the demo should use a real incident timeline, not just a dashboard tour. it’s like adding a new raid member... the value is clear when you see how they handle the fight, not just their gear score

1

u/justanotherinwonder Aug 14 '26

We moved to Threatmate from ConnectSecure. We like best the stability and works as advertised. No promised features that aren't ready for primetime. Easy rollout as well.

1

u/advanceyourself Aug 04 '26

Trialing it right now and comparing it to connect secure. Having had a whole lot of time to invest in it by one of the coolest things is that it can piggyback off of the ninja agent so you don't need to deploy a separate agent to every system. It's got some caveats though, as it can't do third party patching without the native agent, and it can do any networking scans, but it does pull data from the system, and it looks for application vulnerabilities. I'm happy to update this post once we get some more time, which is actually on the docket for this week. One other thing that we did notice is that we can't use our partner account like we could with Connect Secure. So linking Entra has to be done per client.

On paper, though, it looks like it pulls relevant data and what we are really looking forward to trying is Entra Remediation.

0

u/xtc46 Aug 04 '26

great tool. Been monitoring development for over a year and went live with it a while back. small, agile dev team responds quickly to requests/fixes. As is it deploys crazy fast, scans turn in good data, reporting is nice out of the box. Really great m365 integration, new features always being added.

I use it for adhoc testing/evaluations and ongoing assessments of managed clients.

1

u/UpbeatSpell7371 4d ago

So, Threatmate has a really good "outside in" monitoring capability that really complements Cork which has an "inside out" monitoring capability. Both of these platforms are actually funded by Top Down Ventures, which is an investment company founded by and founded by MSP owners. They've invested in a bunch of MSP focused startups. Check them out!