Managed EDR Operations (MDR)
Managed EDR and MDR are two names for one deliverable, and this is it. You hold the licence and the tenant; our analysts work inside your console, triage what the agent raises, contain what is confirmed under the authority you granted, and hand back the write-up. Because the licence is never ours, the service is not tied to a vendor: the agent you already sold is the agent we operate.
$3.90USDper endpoint / month
List $5.20 — what your customer pays. You keep the difference. · 25% off list
- Priced by
- per endpoint / month
- Delivered as
- Your brand, your template
- Client access
- Scoped, granted by your customer
Scoped before you quote, not after you have sold it
You bring the tenant and the licence, we bring the operators. Nothing in this service depends on you buying a product from us.
The team works in the CrowdStrike, SentinelOne, Microsoft Defender and Sangfor consoles day to day. That is a list of consoles we are fluent in, not a list of licences we sell you.
Each EDR vendor's own managed service watches only its own agent. An estate running two or three agents ends up with two or three operators and no single queue — this is the one operator that covers all of them.
Monitoring is the same 24/7 shift in Bangkok that runs Managed SOC Operations, so a detection that fires at 3am is worked when it fires rather than read the next morning.
What we may contain on our own authority — isolate a host, kill a process, quarantine a file — is written down per partner before go-live, and anything outside that list waits for your approval.
Policy tuning and exclusion management are part of the monthly unit. A noisy policy is fixed in your tenant instead of arriving on your engineer's desk as a ticket.
You quote it, we operate it, you deliver it
Your price is the published list price minus 25%, on every line in the catalogue. You decide what your customer pays and keep the difference, so your margin is settled before the quotation leaves your office.
Our engineers work it from Bangkok on UTC+7, against a methodology that is written down rather than improvised per customer. A senior engineer reads every finding before it leaves the building, because you are the one who has to defend it.
Findings, reports and escalations reach you in your template with your logo on them. Your customer talks to you, and our name is not on the ticket.
What a partner checks before putting this on their price list
Why is the service not named after an EDR vendor?
Because the name would promise something we cannot always deliver. Our reseller rights for the products we know best are Thailand-only, so a service named after one of them would read as an offer to sell you that licence wherever you are. This is the operator layer only. You buy the licence from whoever you buy it from, in your own market, and we run it.
Which EDR products can you operate?
CrowdStrike, SentinelOne, Microsoft Defender and Sangfor are the consoles the team is in every day. If you run something else, ask before you sign and we will tell you honestly whether we can operate it well or whether you would be paying us to learn it.
We already pay the vendor for their managed service. Why this?
Their managed service covers their agent, which is the right answer while you only ever sell one agent. The moment an estate has two, you have two escalation paths, two report formats and nobody who owns the whole picture. Mixed estates are the normal case after a few acquisitions, and this is the operator that sits across them.
Whose tenant do the analysts work in?
The analysts work inside your tenant, under accounts you issue. The licence, the data, the audit trail and the contract with the EDR vendor all stay with you, and you can revoke our access without asking anyone. Our name does not appear in the console, the tickets or the reports.
Can we buy this and Managed SOC Operations together?
Yes, and it is the common pattern: endpoint telemetry is worked in the EDR console while everything else is worked in zcrSIEM. The escalation path and the write-up are the same either way, so your customer sees one service rather than two suppliers.
What counts as an endpoint?
Every device with the agent installed, server and workstation alike, counted once a month. Billing is per endpoint per month with a monthly minimum per end customer, both published on the price list, so you can quote a site before you have the exact device count.
Pick one customer. We will run it for 60 days.
Choose a customer you already serve. We deliver Managed Exposure on their domain for two months, in your template, at no cost — so you can see exactly what your customer would receive before you sign anything.
Apply as a partner