CrowdStrike today introduced a new managed extended detection and response (MXDR) service based on its existing MDR capabilities. The vendor also allows customers to consume this service through its partners.
The vendor claims the product provides 24/7 management, threat hunting, monitoring and end-to-end remediation via its MDR services. CrowdStrike extended this model to all supported Falcon modules and third-party vendors including CrowdXDR Alliance partners through the new CrowdStrike Falcon Complete XDR.
The MXDR service combines human expertise with artificial intelligence (AI)-powered automation and threat intelligence to operationalize XDR.
XDR commonly combines elements of security information and event management (SIEM), security orchestration, automation and response (SOAR), endpoint detection and response (EDR) and network traffic analysis (NTA) in a software-as-a-service (SaaS) platform to centralize security data and incident response.
CrowdStrike’s Falcon XDR service is built on its EDR platform and cloud log management and observability technology from its Humio acquisition, and it offers the rest either natively or through partnerships.
CTO Michael Sentonas told SDxCentral in an earlier interview that the company saw managed security services gain traction and more large companies asking for help due to the economic downturn and talent shortage. “Larger organizations are talking to us about managed security services. They simply don’t have as many people to run the technology so they’re asking us to do that on their behalf," Sentonas said.
IDC Research VP of Security Services Craig Robinson echoed that sentiment, noting organizations are looking for security services that meet their detection and response needs, but they don’t have the resources to appropriately implement, operate and maintain those services. “Organizations that are looking for a follow-the-sun coverage model and full hands-on remote triage, investigation and end-to-end remediation actions should strongly consider a managed XDR service,” Robinson explained in a statement.
“With Managed XDR services, organizations can entrust the implementation, management, response and end-to-end remediation of advanced threats across multiple vendors and attack surfaces — all without the burden, overhead or costs of deploying and managing a 24/7 threat detection and response function on their own,” Tom Etheridge, chief global services officer at CrowdStrike, added.
CrowdStrike powers partner-delivered MXDRCrowdStrike provides customers a choice of getting MXDR through the vendor itself or managed capabilities offered by some of its partners, including BT, eSentire, Eviden, Red Canary, ReliaQuest and Telefonica Tech. These global system integrators and managed security service providers (MSSPs) have built MXDR services on the CrowdStrike Falcon platform.
“This unique collaboration, which has proven successful in the MDR market, has become the hallmark of CrowdStrike’s better-together strategy for bringing the value of XDR to organizations of all sizes,” the vendor claims.
“Partners have the same challenges as customers, which is finding the cybersecurity staff to deliver their services," Daniel Bernard, chief business officer at CrowdStrike, added. "That’s where the value proposition of CrowdStrike Falcon Complete XDR becomes extremely compelling with partners … who are turning to us to augment their own SOCs with CrowdStrike-powered offerings."
Comments