Overview
Taegis XDR helps reduce the noise so you can identify more threats faster. We apply knowledge from 20+ years of attack and threat data plus 1400+ incident response engagements performed in the past year to recognize adversary behavior. This expertise is applied to your environment through behavioral analytics to detect the stealthiest of threat actor tactics with Tactic Graphs™. You'll see the full story of your endpoint, network and cloud activity in a single dashboard that makes event correlation easy. XDR operationalizes threat intelligence by automatically correlating our knowledge of the threat landscape with your security telemetry and built-in threat intelligence that's continuously updated.
Taegis XDR allows your security operations teams to respond to security incidents with greater confidence. With capabilities such as extended log retention, search query, user-defined reporting and custom use case support, security analysts gain more ability to actively investigate and proactively hunt for threats in your environment. With Ask an Expert live chat, your security team has 24x7 access to our expert analysts. As a result, XDR can easily replace your current SIEM giving you advanced threat detection as well as additional SIEM capabilities to gain actionable insights into malicious activity. Our goal is to give you enough business and security context to make sense of an investigation and take the right action.
Secureworks detects and responds to identity threats that bypass traditional identity security controls, protecting against 100% of MITRE ATT&CK Credential Access techniques. Taegis™ IDR, an add-on designed to improve your security posture, continuously monitors your environment for identity misconfigurations and risks, while also providing dark web intelligence on compromised credentials. Uncover identity risks in under 90 seconds compared to days with legacy solutions and benchmark the reduction of your attack surface over time.
Learn more at https://www.secureworks.com/products/xdr and https://www.secureworks.com/products/idr
Highlights
- Advanced Analytics
- Accelerated Investigation & Response
- Quickly Detect and Respond to Identity Attacks
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Security credentials achieved
(1)

Buyer guide

Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/12 months |
|---|---|---|
TDR - 1000 Endpoints | Price per monitored endpoint, 1000 endpoints | $43,000.00 |
Custom Pricing | Custom pricing w/terms via Private Offer | $100,000.00 |
IDR Add-on Custom Pricing | Custom pricing w/terms via Private Offer | $16,500.00 |
Taegis MDR Combo | 10,001 to 25,000 Endpoints | $550,055.00 |
Penetration Test: External: Small | Penetration Test: External: Small | $9,280.00 |
Vendor refund policy
N/A
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Vendor resources
Support
Vendor support
Taegis™ XDR is supported through a web portal, live chat and live agent (telephone) support.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
FedRAMP
GDPR
HIPAA
ISO/IEC 27001
PCI DSS
SOC 2 Type 2
Standard contract
Customer reviews
Centralized monitoring has strengthened threat hunting and improved ransomware protection
What is our primary use case?
Clients are primarily using Secureworks Taegis XDR for securing endpoints, networks, and extending to cloud, identity management, and email protection. It functions as an antivirus in enterprise terms, known for being an EDR, MDR, and XDR. For organizations looking for ransomware protection, threat detection, and incident response, it works as cloud security monitoring as well, monitoring cloud environments for any suspicious activity and detecting threats.
What is most valuable?
Threat hunting and SOC augmentation represent the most special features about Secureworks Taegis XDR, where some of the best people in cybersecurity proactively search, provide reports, and deliver indicators of compromise for any activity in your network. This monitoring and reporting can be conducted weekly or monthly.
Centralized security monitoring and reporting is one of the most valuable aspects, as security fundamentally revolves around compliance. Having a centralized security monitoring platform that detects endpoints, networks, and cloud environments, including servers and switches, is essential. Secureworks Taegis XDR's architecture involves a collector device that collects all your data, even from small laptops, and allows you to monitor everything in one platform. This centralized system provides compliance and security visibility, ensuring evidence and visibility for your security and any compliance requirements you have.
Analytics with Secureworks Taegis XDR give you a full preview of everything on your device. It takes all the inputs and outputs of your infrastructure; for example, if it is a firewall, it scans all of the traffic. While it is not a SIEM, it is an open XDR, which excels at conducting analytics. This represents one of its best features because Secureworks has implemented a machine learning model that can detect and analyze everything independently, providing AI-driven features.
Integration with third-party tools is quite seamless. Secureworks Taegis XDR can integrate with virtually anything. One of the best features of this product is its integration capabilities with multiple sources of EDRs and any operating system, whether protecting Linux or Windows servers. It boasts very good integration, and if a specific integration is not available, you can raise a ticket to Secureworks, and they will work on your integration, whatever it is, even if it is custom-built software.
Secureworks Taegis XDR absolutely aids in efficiency. SOC augmentation extends an organization's existing SOC, which helps reduce alert fatigue significantly. It provides additional threat intelligence and expert investigation, making it very useful for organizations that have a security team but lack twenty-four seven coverage.
What needs improvement?
If there were a next release of the product, I would like to see an increase in playbooks, specifically for augmentation and automation. Increasing the automation playbooks would be beneficial, as there are templates for implementing automation.
What do I think about the stability of the solution?
I have not heard anyone report stability issues, and I believe Secureworks Taegis XDR is approximately ninety-nine point nine percent stable without any reliability issues or latency problems.
What do I think about the scalability of the solution?
Secureworks Taegis XDR is very highly scalable.
How are customer service and support?
The customer service from Secureworks is quite helpful. The best aspect of this is the support window; you can click on the support link, and you will connect with a real person, not an AI, who will assist you. Given the high cost of the product, you would expect high-quality support, and security being a critical aspect elevates this expectation. I would rate the support a ten out of ten.
What about the implementation team?
The deployment usually depends on the implementation team itself.
What was our ROI?
I see a return on investment despite the price being relatively high. It is costly, but it delivers whatever you ask for. Some people perceive advantages and disadvantages here; it can be complex if you want to integrate and tune multiple data sources based on your requirements. While some users find it complicated due to the numerous integrations in their environment, others find it very simple, as it allows for a plug-and-play setup where everything can be read seamlessly, and reports are generated easily.
What's my experience with pricing, setup cost, and licensing?
One negative aspect I always hear from customers is about the cost. This product is not aimed at SMB regular customers, and it is definitely not for small businesses. Cost is a factor when considering this solution, particularly for large environments. Even with notable clients like the Pentagon and Qatar Energy, the high enterprise solution necessitates a total cost of ownership analysis before quoting.
Which other solutions did I evaluate?
I would not say there is anything that provides a one-to-one comparison with Secureworks Taegis XDR, but I think vendors like CrowdStrike, Fortinet, Palo Alto, and Trend Micro have their own open XDR solutions.
What other advice do I have?
One of the best features of this product is its integration capabilities with multiple sources of EDRs and any operating system, whether protecting Linux or Windows servers. Secureworks Taegis XDR boasts very good integration, and if you do not have that integration, you can raise a ticket to Secureworks, and they will work on your integration, whatever it is, even if it is custom-built software.
The model clients usually use is a hybrid approach, as it can stretch to the cloud. I believe they utilize various cloud providers, including AWS, GCP, and Azure.
I rate this product a nine out of ten overall.
Threat hunting has improved visibility and now protects us from ransomware and lateral movement
What is our primary use case?
Secureworks Taegis XDR is designed for customers looking for next-generation antivirus or those who want to protect their systems from ransomware attacks or next-generation attacks. Customers seeking this type of solution primarily look for comprehensive threat protection capabilities.
What is most valuable?
We use the Threat Hunting feature of Secureworks Taegis XDR. Once we deploy this solution, we get visibility on a dashboard and we come to know what the challenges are in the customer's network. If there is any lateral movement about to happen, we can figure it out and catch it as well. The threat hunting part helps significantly with this capability.
Using Secureworks Taegis XDR has positively impacted our organization overall. It is quite competitive from a price perspective. Price is one of the advantages, and the second advantage is that it has a user-friendly GUI. The rules are very easy to set up and the dashboard is also very good.
What needs improvement?
To improve Secureworks Taegis XDR, we need to enhance the support part. Although the GUI is very user-friendly, the support needs to be increased for critical P1 tickets.
For how long have I used the solution?
I have worked with Secureworks for 10 years.
Which solution did I use previously and why did I switch?
Before working with Secureworks Taegis XDR, we considered other vendors like SentinelOne and CrowdStrike, which are competitors for Secureworks Taegis XDR and are also providing the same solution in the market.
How was the initial setup?
The deployment of Secureworks Taegis XDR is quite simple. We have proper training for that and we have trained our engineers.
In a couple of hours, we are able to deploy Secureworks Taegis XDR. Only the agent deployment takes some time because it is dependent on the customer's number of users and the users' availability.
What about the implementation team?
One person can deploy Secureworks Taegis XDR.
What other advice do I have?
We purchased Secureworks Taegis XDR through a distributor. We place the order on the distributor and the distributor places the order to Secureworks Taegis XDR.
The integration part with third-party tools is easy and is not a challenge.
As of now, we have not worked with customizable workflows in Secureworks Taegis XDR.
I would rate this review as a 9.
Bundled endpoint protection has simplified deployments but hardware compatibility still needs work
What is our primary use case?
I have known Secureworks Taegis XDR for about three or four years when I forgot about this solution that Broadcom has acquired. They have their security and then I think that was the time that Sophos also introduced their solutions. Most of the products are also in line with each other. If Trend Micro introduced this, of course, CrowdStrike introduced it, and Sophos as well will also introduce a solution like that.
Secureworks Taegis XDR is easy to deploy, although there may be some challenges. Most of the customers have their own IT team and will just ask for the license and they can do it by themselves.
I stand more as a reseller, but not as an integrator. It is more of a delivery and supply of this solution.
I am dealing with universities. The units have been distributed to all the faculty members, the teachers, and some of the admin staff. If someone claims a unit or it is not distributed as one distribution, we supply to them and they store it in their own storage area or storeroom. Then a faculty member claims it and they will provide some installation or initiation of the configuration of the laptop. I think it takes less than two hours to install everything, including the other applications. Of course, they provide buffer time. It is pretty much fast.
What is most valuable?
The analysis tools in Secureworks Taegis XDR that are most useful from my perspective are important to note. To be frank, I am not a security person. I am more of an infrastructure person. The reason why this solution is only involved or I was exposed to this is because I always bundle a security solution on every unit that we supply to our customers.
I talk about on-premises solutions. It is always on-premises or installed on endpoints.
What needs improvement?
Hardware compatibility could be an area for improvement. I do not know what the cause is. It is not on the application, but the support that they are asking for. Once we installed everything, it is there and we are good to leave it by themselves. They can administer it and configure it. The only time that they call us is when hardware failures occur.
That is the only room for improvement. Anything else the AVs or the other applications inside it are not that problematic.
For how long have I used the solution?
I have known Secureworks Taegis XDR for about three or four years when I forgot about this solution that Broadcom has acquired.
What do I think about the stability of the solution?
Everyone does not utilize everything that is inside the application. I do not know if everybody utilized everything that is inside the application. But as far as we know, as long as their IT installed it, I think it is just there. We just leave it there. We do not have that much problem when it comes to the endpoint. Only if there are hardware issues and so on. On the application, on the antivirus, or things installed on the PC or the laptop, we encountered no problem at all. Once it is there, it is there. I think it is updating by itself. I do not know how their administrators are dealing with it, but the only problem that we encounter is if there are hardware problems such as battery issues.
How are customer service and support?
Sophos support is good and helpful. We always seek support or help from a distributor and they are very accommodating.
I would rate the support from Sophos at an eight out of ten.
How was the initial setup?
I do not know how much time implementation may require, but I think it is pretty much fast because they are doing it on a per-unit basis. For example, they have their storage, we supply the units, the laptops and the desktops, and once the user claims it, most of the customers that we are dealing with are universities.
What about the implementation team?
I am not involved in the deployment. We are not providing the services for them anymore because they are capable.
Which other solutions did I evaluate?
I am familiar with IBM.
What other advice do I have?
I am familiar with Sophos solutions. Secureworks Taegis XDR is the solution being discussed, which is a Network Detection and Response product.
I do not know if our customers use the threat hunting feature of Secureworks Taegis XDR. I am not sure because whatever is included in the license that we provide, I do not know if they utilize it much.
Customizable workflows in Secureworks Taegis XDR help to consolidate all of the processes. When it comes to Sophos specifically, there is not much complex activities that we have done with our customer. It is more of a direct installation or standalone installation of the solution.
The price for Secureworks Taegis XDR is very competitive. The good thing with Sophos is that it is very competitive with other solutions. In terms of support, they are all the same, but the price is very competitive compared to the other solutions. I would rate this review as a seven out of ten.
Centralized threat hunting and immediate malware blocking have protected thousands of endpoints
What is our primary use case?
I worked with Secureworks Taegis XDR and implemented it for my customers. I deployed Sophos XDR for approximately 2,000 devices.
What is most valuable?
If your organization is experiencing a malware attack while using Secureworks Taegis XDR, you can directly block the malware from the console. The threat hunting feature was also beneficial.
What needs improvement?
I do not see any other problems with Secureworks Taegis XDR besides pricing. There is no room for improvement besides the pricing. All the features are already in place.
For how long have I used the solution?
I have been dealing with Sophos for almost one year.
What do I think about the stability of the solution?
I do not see any other problems with Secureworks Taegis XDR besides pricing.
What do I think about the scalability of the solution?
Sophos is a good XDR, and I recommend it for large companies since they have approximately 2,000 or 3,000 devices and can implement it as it is the best XDR. Smaller companies cannot afford it because of the price.
How are customer service and support?
I rate the technical support by Sophos a 10.
How was the initial setup?
The implementation is straightforward. It is a centralized deployment with Secureworks Taegis XDR, so you can deploy it through the centralized unit and it will automatically deploy on all those devices.
What about the implementation team?
For 2,000 users, I estimate we required 10 to 11 engineers.
What's my experience with pricing, setup cost, and licensing?
Smaller companies cannot afford it because of the price.
Which other solutions did I evaluate?
CrowdStrike is a good product, but I do not think it has any advantages over Secureworks Taegis XDR. Both Secureworks Taegis XDR and CrowdStrike are the same.
What other advice do I have?
I did not integrate it with any third-party tools. Sophos is popular in my region. I rate this review a 10.
Automated threat detection has reduced my incident response workload and supports hybrid environments
What is our primary use case?
I am working with Trend Micro Vision One, mostly MCC Vision One, for smaller customers. I see a lot of customers opting for known brands such as ESET and Kaspersky. On Trend Micro, Vision One is what we see being pushed a lot here.
On Fortinet, we deal a lot with FortiEDR and their other products: FortiSIEM, FortiNAC, and FortiWAF. We are not yet on FortiCNP, as most of our native cloud customers opt to rely on the platform for vulnerability management and identification. Cloud specialists can advise more on that end, though I am more focused on generic security as opposed to cloud security.
With Sophos, we do everything: XDR, MDR, and Sophos EDR. Regarding the threat hunting features, we do not consume the product ourselves; we resell it to customers. From feedback I have received, the threat hunting is very impactful and requires almost no intervention. If you set it up well, you can leave it to run itself with minimal oversight. The identity threat and detection response of the XDR is quite phenomenal.
How has it helped my organization?
The features I find most valuable are the fact that Secureworks Taegis XDR runs itself without any form of intervention. It will detect and deter most indicators of compromise. This makes the job easier for any security officer or information security officer working in an environment. Secureworks Taegis XDR does have its own form of managed services where they can come in with their own SOC services and empower the current analysts you have in place in your work team. This provides almost near-real-time detection and iteration of indicators of compromise.
What is most valuable?
The capability of Intercept X with XDR to integrate with third-party tools has usually helped my customers' security operations. We usually advocate for an agnostic setup where if you are running Secureworks Taegis XDR, to have it on almost every level. However, we do have instances where you find a customer running a FortiGate firewall and perhaps they are on Microsoft 365 or something similar. The integration with third-party tools is quite good. I know they have significant add-ons that can facilitate and ingest information from almost all known third parties. That is a plus as well.
What needs improvement?
To answer how Intercept X with XDR can be improved as an end customer, I would need to sit down with the solution. In my own opinion, I think they are continuing to evolve the solution in the right way. They need to accommodate more hybrid ecosystems as we see a lot of customers with interesting setups running different third parties all over the region. The environments are messy. Furthering the integration capabilities with third parties would be beneficial. Of course, there is no harm in also improving the threat detection and response capabilities as well.
There is an AI wave, so it would be interesting to see what they can do with AI in the future. This would make the solution more independent. While human intervention is needed, they can explore what they can do with machine learning and AI capabilities.
For how long have I used the solution?
I have been working with Secureworks Taegis XDR pretty much since the product has been pushed to the market. I would say it has been a year and a half, close to two.
How are customer service and support?
I would give their technical support a solid nine. I do have customers who also have the MDR package, and the support is quite good.
Which solution did I use previously and why did I switch?
I have been working only with Comodo, and we dropped it. The moment there was a massive price hike on the licenses and our market is quite price-sensitive. It is a good solution and does a lot, but it all boils down to the costings, unfortunately, here in Kenya.
How was the initial setup?
You do not need to be a genius to set it up. The initial setup is quite straightforward.
What was our ROI?
I would not know the exact metrics they use to assess the effectiveness of Intercept X with XDR in reducing incident management time, but I would say it significantly reduces any form of incident response. I do know it has AI capabilities, so it does intervene and assist with significantly reducing the incident response time.
What's my experience with pricing, setup cost, and licensing?
It depends on what you are comparing the pricing to, but there is significant value for money there, given what it does. I would say the pricing is fair for the capabilities presented with the solution.
Which other solutions did I evaluate?
At the moment I do not have alternate solutions, but where I was previously, I was reselling SentinelOne, Comodo, or other products from other vendors as well.
What other advice do I have?
I do have feedback about the customizable workflows. I have a customer who has pretty much loaded the XDR agents on his critical assets, the servers. Once we got it up and running and everything in place, he does not even touch the solution; it does everything for him. When we are talking about workloads and everything, I would say it is pretty much a plug-and-play solution with almost no intervention on what it does. It does pretty much everything for you.
You do need agents on your assets, of course your devices, but all the interfaces are on cloud. There is no need for local storage for your alerts or anything. I would rate this solution an eight overall.