Listing Thumbnail

    Secureworks Taegis XDR

     Info
    Sold by: Secureworks 
    Deployed on AWS
    Vendor Insights
    Secureworks® Taegis™ XDR is an open cloud-native platform that combines the power of human intellect with insights from security analytics to unify detection and response across endpoint, network and cloud environments for better security outcomes and simpler security operations. Taegis™ IDR, an add-on designed to improve your security posture, continuously monitors your environment for identity misconfigurations and risks, while also providing dark web intelligence on compromised credentials. Learn more at https://www.secureworks.com/partners/aws
    4.2

    Overview

    Taegis XDR helps reduce the noise so you can identify more threats faster. We apply knowledge from 20+ years of attack and threat data plus 1400+ incident response engagements performed in the past year to recognize adversary behavior. This expertise is applied to your environment through behavioral analytics to detect the stealthiest of threat actor tactics with Tactic Graphs™. You'll see the full story of your endpoint, network and cloud activity in a single dashboard that makes event correlation easy. XDR operationalizes threat intelligence by automatically correlating our knowledge of the threat landscape with your security telemetry and built-in threat intelligence that's continuously updated.

    Taegis XDR allows your security operations teams to respond to security incidents with greater confidence. With capabilities such as extended log retention, search query, user-defined reporting and custom use case support, security analysts gain more ability to actively investigate and proactively hunt for threats in your environment. With Ask an Expert live chat, your security team has 24x7 access to our expert analysts. As a result, XDR can easily replace your current SIEM giving you advanced threat detection as well as additional SIEM capabilities to gain actionable insights into malicious activity. Our goal is to give you enough business and security context to make sense of an investigation and take the right action.

    Secureworks detects and responds to identity threats that bypass traditional identity security controls, protecting against 100% of MITRE ATT&CK Credential Access techniques. Taegis™ IDR, an add-on designed to improve your security posture, continuously monitors your environment for identity misconfigurations and risks, while also providing dark web intelligence on compromised credentials. Uncover identity risks in under 90 seconds compared to days with legacy solutions and benchmark the reduction of your attack surface over time.

    Learn more at https://www.secureworks.com/products/xdr  and https://www.secureworks.com/products/idr 

    Highlights

    • Advanced Analytics
    • Accelerated Investigation & Response
    • Quickly Detect and Respond to Identity Attacks

    Details

    Categories

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Vendor Insights

     Info
    Skip the manual risk assessment. Get verified and regularly updated security info on this product with Vendor Insights.
    Security credentials achieved
    (1)

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Secureworks Taegis XDR

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (5)

     Info
    Dimension
    Description
    Cost/12 months
    TDR - 1000 Endpoints
    Price per monitored endpoint, 1000 endpoints
    $43,000.00
    Custom Pricing
    Custom pricing w/terms via Private Offer
    $100,000.00
    IDR Add-on Custom Pricing
    Custom pricing w/terms via Private Offer
    $16,500.00
    Taegis MDR Combo
    10,001 to 25,000 Endpoints
    $550,055.00
    Penetration Test: External: Small
    Penetration Test: External: Small
    $9,280.00

    Vendor refund policy

    N/A

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    Taegis™ XDR is supported through a web portal, live chat and live agent (telephone) support.

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    25
    In Data Security and Governance

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Behavioral Analytics Engine
    Applies behavioral analytics to detect threat actor tactics through Tactic Graphs, leveraging 20+ years of attack and threat data plus 1400+ incident response engagements
    Multi-Environment Threat Detection
    Unifies detection and response across endpoint, network, and cloud environments with correlated event visibility in a single dashboard
    Identity Risk Monitoring
    Continuously monitors environment for identity misconfigurations and risks, detects 100% of MITRE ATT&CK Credential Access techniques, and provides dark web intelligence on compromised credentials
    Extended Investigation Capabilities
    Supports extended log retention, search query functionality, user-defined reporting, and custom use case support for threat hunting and incident investigation
    Automated Threat Intelligence Correlation
    Automatically correlates threat landscape knowledge with security telemetry and continuously updated built-in threat intelligence
    Threat Detection Engine
    Library of 900+ out-of-the-box detections with user and attacker behavior analytics backed by community threat intelligence
    Data Ingestion and Integration
    Ingests CloudTrail, GuardDuty, EC2 network traffic, raw logs via SQS from multiple AWS accounts, on-premises networks, remote endpoints, and SaaS solutions
    Investigation and Response Capabilities
    Visual investigation timeline with detailed log timelines, automated response workflows, and instant actions such as asset quarantining
    Deception Technology
    Honeypots, honey credentials, and honey files for layered defense mechanisms
    Compliance and Monitoring
    File Integrity Monitoring (FIM) with support for PCI, HIPAA, and GDPR compliance requirements, plus detection of new AWS regions, services, and EC2 instance types
    Multi-Source Threat Data Integration
    Correlates security events from Trellix Security Platform and over 500 third-party tools including 13 AWS integrations to create unified threat visibility across the security stack.
    AI-Driven Alert Triage and Prioritization
    Applies artificial intelligence-driven analytics to perform 100% alert triage, prioritize threats, and provide GenAI-powered insights for threat investigation and remediation guidance.
    No-Code Automation for Investigation and Response
    Provides UI-driven, point-and-click automation capabilities to offload repetitive security operations tasks and accelerate investigation and response workflows.
    Pre-Built Analytics and Correlation Rules
    Ingests data from multiple sources and correlates events using pre-built analytics and rules to reconstruct complete attack narratives and reduce manual investigation pivots.
    Multi-Deployment Architecture Support
    Supports cloud, hybrid, and air-gapped deployment models with an open integration ecosystem for flexible security infrastructure configurations.

    Security credentials

     Info
    Validated by AWS Marketplace
    FedRAMP
    GDPR
    HIPAA
    ISO/IEC 27001
    PCI DSS
    SOC 2 Type 2
    -
    -
    -
    -
    -
    No security profile
    No security profile

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.2
    16 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    50%
    37%
    13%
    0%
    0%
    2 AWS reviews
    |
    14 external reviews
    External reviews are from G2  and PeerSpot .
    Mohammad Jundiah

    Centralized monitoring has strengthened threat hunting and improved ransomware protection

    Reviewed on Jul 24, 2026
    Review from a verified AWS customer

    What is our primary use case?

    Clients are primarily using Secureworks Taegis XDR for securing endpoints, networks, and extending to cloud, identity management, and email protection. It functions as an antivirus in enterprise terms, known for being an EDR, MDR, and XDR. For organizations looking for ransomware protection, threat detection, and incident response, it works as cloud security monitoring as well, monitoring cloud environments for any suspicious activity and detecting threats.

    What is most valuable?

    Threat hunting and SOC augmentation represent the most special features about Secureworks Taegis XDR, where some of the best people in cybersecurity proactively search, provide reports, and deliver indicators of compromise for any activity in your network. This monitoring and reporting can be conducted weekly or monthly.

    Centralized security monitoring and reporting is one of the most valuable aspects, as security fundamentally revolves around compliance. Having a centralized security monitoring platform that detects endpoints, networks, and cloud environments, including servers and switches, is essential. Secureworks Taegis XDR's architecture involves a collector device that collects all your data, even from small laptops, and allows you to monitor everything in one platform. This centralized system provides compliance and security visibility, ensuring evidence and visibility for your security and any compliance requirements you have.

    Analytics with Secureworks Taegis XDR give you a full preview of everything on your device. It takes all the inputs and outputs of your infrastructure; for example, if it is a firewall, it scans all of the traffic. While it is not a SIEM, it is an open XDR, which excels at conducting analytics. This represents one of its best features because Secureworks has implemented a machine learning model that can detect and analyze everything independently, providing AI-driven features.

    Integration with third-party tools is quite seamless. Secureworks Taegis XDR can integrate with virtually anything. One of the best features of this product is its integration capabilities with multiple sources of EDRs and any operating system, whether protecting Linux or Windows servers. It boasts very good integration, and if a specific integration is not available, you can raise a ticket to Secureworks, and they will work on your integration, whatever it is, even if it is custom-built software.

    Secureworks Taegis XDR absolutely aids in efficiency. SOC augmentation extends an organization's existing SOC, which helps reduce alert fatigue significantly. It provides additional threat intelligence and expert investigation, making it very useful for organizations that have a security team but lack twenty-four seven coverage.

    What needs improvement?

    If there were a next release of the product, I would like to see an increase in playbooks, specifically for augmentation and automation. Increasing the automation playbooks would be beneficial, as there are templates for implementing automation.

    What do I think about the stability of the solution?

    I have not heard anyone report stability issues, and I believe Secureworks Taegis XDR is approximately ninety-nine point nine percent stable without any reliability issues or latency problems.

    What do I think about the scalability of the solution?

    Secureworks Taegis XDR is very highly scalable.

    How are customer service and support?

    The customer service from Secureworks is quite helpful. The best aspect of this is the support window; you can click on the support link, and you will connect with a real person, not an AI, who will assist you. Given the high cost of the product, you would expect high-quality support, and security being a critical aspect elevates this expectation. I would rate the support a ten out of ten.

    What about the implementation team?

    The deployment usually depends on the implementation team itself.

    What was our ROI?

    I see a return on investment despite the price being relatively high. It is costly, but it delivers whatever you ask for. Some people perceive advantages and disadvantages here; it can be complex if you want to integrate and tune multiple data sources based on your requirements. While some users find it complicated due to the numerous integrations in their environment, others find it very simple, as it allows for a plug-and-play setup where everything can be read seamlessly, and reports are generated easily.

    What's my experience with pricing, setup cost, and licensing?

    One negative aspect I always hear from customers is about the cost. This product is not aimed at SMB regular customers, and it is definitely not for small businesses. Cost is a factor when considering this solution, particularly for large environments. Even with notable clients like the Pentagon and Qatar Energy, the high enterprise solution necessitates a total cost of ownership analysis before quoting.

    Which other solutions did I evaluate?

    I would not say there is anything that provides a one-to-one comparison with Secureworks Taegis XDR, but I think vendors like CrowdStrike, Fortinet, Palo Alto, and Trend Micro have their own open XDR solutions.

    What other advice do I have?

    One of the best features of this product is its integration capabilities with multiple sources of EDRs and any operating system, whether protecting Linux or Windows servers. Secureworks Taegis XDR boasts very good integration, and if you do not have that integration, you can raise a ticket to Secureworks, and they will work on your integration, whatever it is, even if it is custom-built software.

    The model clients usually use is a hybrid approach, as it can stretch to the cloud. I believe they utilize various cloud providers, including AWS, GCP, and Azure.

    I rate this product a nine out of ten overall.

    Vishal Khedekar

    Threat hunting has improved visibility and now protects us from ransomware and lateral movement

    Reviewed on Jul 14, 2026
    Review provided by PeerSpot

    What is our primary use case?

    Secureworks Taegis XDR is designed for customers looking for next-generation antivirus or those who want to protect their systems from ransomware attacks or next-generation attacks. Customers seeking this type of solution primarily look for comprehensive threat protection capabilities.

    What is most valuable?

    We use the Threat Hunting feature of Secureworks Taegis XDR. Once we deploy this solution, we get visibility on a dashboard and we come to know what the challenges are in the customer's network. If there is any lateral movement about to happen, we can figure it out and catch it as well. The threat hunting part helps significantly with this capability.

    Using Secureworks Taegis XDR has positively impacted our organization overall. It is quite competitive from a price perspective. Price is one of the advantages, and the second advantage is that it has a user-friendly GUI. The rules are very easy to set up and the dashboard is also very good.

    What needs improvement?

    To improve Secureworks Taegis XDR, we need to enhance the support part. Although the GUI is very user-friendly, the support needs to be increased for critical P1 tickets.

    For how long have I used the solution?

    I have worked with Secureworks for 10 years.

    Which solution did I use previously and why did I switch?

    Before working with Secureworks Taegis XDR, we considered other vendors like SentinelOne and CrowdStrike, which are competitors for Secureworks Taegis XDR and are also providing the same solution in the market.

    How was the initial setup?

    The deployment of Secureworks Taegis XDR is quite simple. We have proper training for that and we have trained our engineers.

    In a couple of hours, we are able to deploy Secureworks Taegis XDR. Only the agent deployment takes some time because it is dependent on the customer's number of users and the users' availability.

    What about the implementation team?

    One person can deploy Secureworks Taegis XDR.

    What other advice do I have?

    We purchased Secureworks Taegis XDR through a distributor. We place the order on the distributor and the distributor places the order to Secureworks Taegis XDR.

    The integration part with third-party tools is easy and is not a challenge.

    As of now, we have not worked with customizable workflows in Secureworks Taegis XDR.

    I would rate this review as a 9.

    Ligor Medina

    Bundled endpoint protection has simplified deployments but hardware compatibility still needs work

    Reviewed on Jul 10, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I have known Secureworks Taegis XDR for about three or four years when I forgot about this solution that Broadcom has acquired. They have their security and then I think that was the time that Sophos also introduced their solutions. Most of the products are also in line with each other. If Trend Micro introduced this, of course, CrowdStrike introduced it, and Sophos as well will also introduce a solution like that.

    Secureworks Taegis XDR is easy to deploy, although there may be some challenges. Most of the customers have their own IT team and will just ask for the license and they can do it by themselves.

    I stand more as a reseller, but not as an integrator. It is more of a delivery and supply of this solution.

    I am dealing with universities. The units have been distributed to all the faculty members, the teachers, and some of the admin staff. If someone claims a unit or it is not distributed as one distribution, we supply to them and they store it in their own storage area or storeroom. Then a faculty member claims it and they will provide some installation or initiation of the configuration of the laptop. I think it takes less than two hours to install everything, including the other applications. Of course, they provide buffer time. It is pretty much fast.

    What is most valuable?

    The analysis tools in Secureworks Taegis XDR that are most useful from my perspective are important to note. To be frank, I am not a security person. I am more of an infrastructure person. The reason why this solution is only involved or I was exposed to this is because I always bundle a security solution on every unit that we supply to our customers.

    I talk about on-premises solutions. It is always on-premises or installed on endpoints.

    What needs improvement?

    Hardware compatibility could be an area for improvement. I do not know what the cause is. It is not on the application, but the support that they are asking for. Once we installed everything, it is there and we are good to leave it by themselves. They can administer it and configure it. The only time that they call us is when hardware failures occur.

    That is the only room for improvement. Anything else the AVs or the other applications inside it are not that problematic.

    For how long have I used the solution?

    I have known Secureworks Taegis XDR for about three or four years when I forgot about this solution that Broadcom has acquired.

    What do I think about the stability of the solution?

    Everyone does not utilize everything that is inside the application. I do not know if everybody utilized everything that is inside the application. But as far as we know, as long as their IT installed it, I think it is just there. We just leave it there. We do not have that much problem when it comes to the endpoint. Only if there are hardware issues and so on. On the application, on the antivirus, or things installed on the PC or the laptop, we encountered no problem at all. Once it is there, it is there. I think it is updating by itself. I do not know how their administrators are dealing with it, but the only problem that we encounter is if there are hardware problems such as battery issues.

    How are customer service and support?

    Sophos support is good and helpful. We always seek support or help from a distributor and they are very accommodating.

    I would rate the support from Sophos at an eight out of ten.

    How was the initial setup?

    I do not know how much time implementation may require, but I think it is pretty much fast because they are doing it on a per-unit basis. For example, they have their storage, we supply the units, the laptops and the desktops, and once the user claims it, most of the customers that we are dealing with are universities.

    What about the implementation team?

    I am not involved in the deployment. We are not providing the services for them anymore because they are capable.

    Which other solutions did I evaluate?

    I am familiar with IBM.

    What other advice do I have?

    I am familiar with Sophos solutions. Secureworks Taegis XDR is the solution being discussed, which is a Network Detection and Response product.

    I do not know if our customers use the threat hunting feature of Secureworks Taegis XDR. I am not sure because whatever is included in the license that we provide, I do not know if they utilize it much.

    Customizable workflows in Secureworks Taegis XDR help to consolidate all of the processes. When it comes to Sophos specifically, there is not much complex activities that we have done with our customer. It is more of a direct installation or standalone installation of the solution.

    The price for Secureworks Taegis XDR is very competitive. The good thing with Sophos is that it is very competitive with other solutions. In terms of support, they are all the same, but the price is very competitive compared to the other solutions. I would rate this review as a seven out of ten.

    Abhishek-Roy

    Centralized threat hunting and immediate malware blocking have protected thousands of endpoints

    Reviewed on Jul 09, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I worked with Secureworks Taegis XDR and implemented it for my customers. I deployed Sophos XDR for approximately 2,000 devices.

    What is most valuable?

    If your organization is experiencing a malware attack while using Secureworks Taegis XDR, you can directly block the malware from the console. The threat hunting feature was also beneficial.

    What needs improvement?

    I do not see any other problems with Secureworks Taegis XDR besides pricing. There is no room for improvement besides the pricing. All the features are already in place.

    For how long have I used the solution?

    I have been dealing with Sophos for almost one year.

    What do I think about the stability of the solution?

    I do not see any other problems with Secureworks Taegis XDR besides pricing.

    What do I think about the scalability of the solution?

    Sophos is a good XDR, and I recommend it for large companies since they have approximately 2,000 or 3,000 devices and can implement it as it is the best XDR. Smaller companies cannot afford it because of the price.

    How are customer service and support?

    I rate the technical support by Sophos a 10.

    How was the initial setup?

    The implementation is straightforward. It is a centralized deployment with Secureworks Taegis XDR, so you can deploy it through the centralized unit and it will automatically deploy on all those devices.

    What about the implementation team?

    For 2,000 users, I estimate we required 10 to 11 engineers.

    What's my experience with pricing, setup cost, and licensing?

    Smaller companies cannot afford it because of the price.

    Which other solutions did I evaluate?

    CrowdStrike is a good product, but I do not think it has any advantages over Secureworks Taegis XDR. Both Secureworks Taegis XDR and CrowdStrike are the same.

    What other advice do I have?

    I did not integrate it with any third-party tools. Sophos is popular in my region. I rate this review a 10.

    Daniel Wakori

    Automated threat detection has reduced my incident response workload and supports hybrid environments

    Reviewed on Jun 30, 2026
    Review from a verified AWS customer

    What is our primary use case?

    I am working with Trend Micro Vision One, mostly MCC Vision One, for smaller customers. I see a lot of customers opting for known brands such as ESET and Kaspersky. On Trend Micro, Vision One is what we see being pushed a lot here.

    On Fortinet, we deal a lot with FortiEDR and their other products: FortiSIEM, FortiNAC, and FortiWAF. We are not yet on FortiCNP, as most of our native cloud customers opt to rely on the platform for vulnerability management and identification. Cloud specialists can advise more on that end, though I am more focused on generic security as opposed to cloud security.

    With Sophos, we do everything: XDR, MDR, and Sophos EDR. Regarding the threat hunting features, we do not consume the product ourselves; we resell it to customers. From feedback I have received, the threat hunting is very impactful and requires almost no intervention. If you set it up well, you can leave it to run itself with minimal oversight. The identity threat and detection response of the XDR is quite phenomenal.

    How has it helped my organization?

    The features I find most valuable are the fact that Secureworks Taegis XDR runs itself without any form of intervention. It will detect and deter most indicators of compromise. This makes the job easier for any security officer or information security officer working in an environment. Secureworks Taegis XDR does have its own form of managed services where they can come in with their own SOC services and empower the current analysts you have in place in your work team. This provides almost near-real-time detection and iteration of indicators of compromise.

    What is most valuable?

    The capability of Intercept X with XDR to integrate with third-party tools has usually helped my customers' security operations. We usually advocate for an agnostic setup where if you are running Secureworks Taegis XDR, to have it on almost every level. However, we do have instances where you find a customer running a FortiGate firewall and perhaps they are on Microsoft 365 or something similar. The integration with third-party tools is quite good. I know they have significant add-ons that can facilitate and ingest information from almost all known third parties. That is a plus as well.

    What needs improvement?

    To answer how Intercept X with XDR can be improved as an end customer, I would need to sit down with the solution. In my own opinion, I think they are continuing to evolve the solution in the right way. They need to accommodate more hybrid ecosystems as we see a lot of customers with interesting setups running different third parties all over the region. The environments are messy. Furthering the integration capabilities with third parties would be beneficial. Of course, there is no harm in also improving the threat detection and response capabilities as well.

    There is an AI wave, so it would be interesting to see what they can do with AI in the future. This would make the solution more independent. While human intervention is needed, they can explore what they can do with machine learning and AI capabilities.

    For how long have I used the solution?

    I have been working with Secureworks Taegis XDR pretty much since the product has been pushed to the market. I would say it has been a year and a half, close to two.

    How are customer service and support?

    I would give their technical support a solid nine. I do have customers who also have the MDR package, and the support is quite good.

    Which solution did I use previously and why did I switch?

    I have been working only with Comodo, and we dropped it. The moment there was a massive price hike on the licenses and our market is quite price-sensitive. It is a good solution and does a lot, but it all boils down to the costings, unfortunately, here in Kenya.

    How was the initial setup?

    You do not need to be a genius to set it up. The initial setup is quite straightforward.

    What was our ROI?

    I would not know the exact metrics they use to assess the effectiveness of Intercept X with XDR in reducing incident management time, but I would say it significantly reduces any form of incident response. I do know it has AI capabilities, so it does intervene and assist with significantly reducing the incident response time.

    What's my experience with pricing, setup cost, and licensing?

    It depends on what you are comparing the pricing to, but there is significant value for money there, given what it does. I would say the pricing is fair for the capabilities presented with the solution.

    Which other solutions did I evaluate?

    At the moment I do not have alternate solutions, but where I was previously, I was reselling SentinelOne, Comodo, or other products from other vendors as well.

    What other advice do I have?

    I do have feedback about the customizable workflows. I have a customer who has pretty much loaded the XDR agents on his critical assets, the servers. Once we got it up and running and everything in place, he does not even touch the solution; it does everything for him. When we are talking about workloads and everything, I would say it is pretty much a plug-and-play solution with almost no intervention on what it does. It does pretty much everything for you.

    You do need agents on your assets, of course your devices, but all the interfaces are on cloud. There is no need for local storage for your alerts or anything. I would rate this solution an eight overall.

    View all reviews