Red Canary Managed Detection and Response logo

    Red Canary Managed Detection and Response

    Sold by
    Red Canary detects and stops threats 24x7 across your endpoints, network, cloud, identities and SaaS applications.

    Ratings and reviews

    4.7
    135 ratings
    2 star
    1 star
    83%
    16%
    1%
    0%
    0%
    1 AWS reviews
    |
    134 external reviews
    External reviews are from G2  and PeerSpot .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (135)
    reviewer2856117

    Security team has gained reliable secondary threat detection and rapid incident response

    Reviewed on Jun 14, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My main use case for Red Canary is that a Red Canary analyst monitors our logs, and if they see any abnormality, they create a ticket that we use to analyze the situation. We assign that ticket and analyze it to ensure we have all the details needed. We use other tools to investigate, but we mainly rely on the evidence from Red Canary, and we can also use the isolate feature from Red Canary. There are threat reports and agents, and in our environment, we have endpoints and identity as well.

    A recent situation where I used Red Canary to analyze a ticket involved an employee from the US who logged in from the UK, a country he had never visited before. Red Canary's analyst assumed that account was compromised, but after analyzing using our other tools, it seemed the login was legitimate. The user confirmed he had traveled to the UK and used one of our company phones to log into the account to check emails, so the alert triggered was a true positive but a legitimate anomaly.

    What is most valuable?

    The best features Red Canary offers are that they monitor our logs and have their own use cases, providing us with these tickets. If we miss anything, we treat Red Canary as a secondary triggering tool, so we use it as a secondary detection tool.

    The most valuable feature in my day-to-day work is that those logs are monitored by actual experienced analysts from Red Canary. Although we have tools from our end with use cases, those can miss some events and incidents, but since Red Canary uses active, live agents to monitor and detect these anomalies, we rely on that feature for our security operation center.

    Red Canary has impacted my organization positively because we treat any ticket triggered by them as high priority due to the fact that 99 percent of the time it is a true positive. They can isolate machines, which is a feature I really appreciate because if something happens on a weekend when we are not available, they can isolate it and contain the situation.

    What needs improvement?

    I wish Red Canary could have a graph that shows the endpoint, user, and how it spreads, providing a visual representation to easily identify what happened.

    For how long have I used the solution?

    I have been using Red Canary for one year.

    What do I think about the stability of the solution?

    I have not experienced any stability or reliability issues with Red Canary so far.

    What do I think about the scalability of the solution?

    Red Canary's scalability is good in my experience, and we have not had any problems with scalability.

    How are customer service and support?

    The customer support has been really good from what I have seen. If I need more details about any incident, there is a contact us option to reach an agent, or another agent can substitute if the previous one is not available, allowing us to get additional details and opinions.

    Which solution did I use previously and why did I switch?

    I cannot speak to using a different solution before Red Canary because I started working here, and it has always been Red Canary.

    How was the initial setup?

    I cannot speak to the process to purchase Red Canary with certainty because I am an end user. Perhaps our managers or directors have a better answer regarding the purchasing process, but I do not know those details.

    What about the implementation team?

    I lack insight into pricing, setup cost, and licensing because I am an end user.

    What was our ROI?

    I believe we have seen a return on investment because we utilize Red Canary effectively. Any missed detection will definitely be triggered by Red Canary. I think it is a good investment since it provides accurate details.

    Which other solutions did I evaluate?

    I have no idea if my organization evaluated other options before choosing Red Canary, as that was perhaps another person's or another team's decision. Our role is to utilize this application without involvement in purchasing or decision-making.

    What other advice do I have?

    We use Red Canary as a secondary monitoring service so if our main tools miss any detection, Red Canary will detect it. We critically treat any alert from Red Canary as a high-priority ticket because it is most probably a true positive, but it can also be a legitimate anomaly, so we will treat it as a priority one case.

    Red Canary serves as a secondary triggering tool, and we do not really use any kind of SLA or anything. They monitor and create threat tickets they believe are threats, and we use it as a secondary monitoring tool.

    My advice to others looking into using Red Canary is to consider it as a good secondary detection tool, and they have good customer support. I would rate this product an 8 out of 10.

    Luciana S.

    Brilliant Threat Detection and SOC Monitoring with Strong Remediation Guidance

    Reviewed on May 15, 2026
    Review provided by G2
    What do you like best about the product?
    Red Canary is a helpful solution that offers brilliant threat detection and this makes it easy to identify security challenges
    The software handles and manages SOC processes, and this includes active monitoring and proper security alerts
    Red Canary reduces chances for false positives and this makes the entire security process successful
    The app provides robust remediation procedures and guidance, which makes the users more solid and efficient
    The app connects with Microsoft Defender and this helps in improving security visibility
    Red Canary has remarkable threat intelligence capabilities and this helps in identifying and learning threat patterns
    What do you dislike about the product?
    Red Canary has premium pricing, something that makes small businesses ignore it and prefer to others
    The customization of a dashboard is inflexible and this affects companies performance
    What problems is the product solving and how is that benefiting you?
    The software is outstanding in detecting all threats and vulnerabilities, creating a reliable work environment
    The program issues 24/7 systems and incidents monitoring, and this amplifies the response speed
    When attacks appear, Red Canary is fast to offer reliable remediation and recovery
    The visibility of ant endpoint status and cloud protection is also well addressed by this software
    The program saves on time that can be used for triaging security alerts and this makes companies mature their SOC operations
    Red Canary offers expert analysis and this largely supports companies with less security teams
    Rinalon E.

    Robust MDR with Accurate Alerts, Detailed Reports, and Versatile Integrations

    Reviewed on May 12, 2026
    Review provided by G2
    What do you like best about the product?
    Red Canary is a robust managed detection and response approach that facilitates the security team to identify threats faster
    Red Canary has robust reputation on sharing actionable alerts and there is no false positives, hence, the alerts shared are accurate
    The program issues a detailed investigation information or report, and the appropriate remediation guide
    The integration of Red Canary with items such as CrowdStrike, Microsoft Defender, among others is a versatile thing from the app
    The app provides reliable customer service or feedback and it conducts knowledgeable analysis
    What do you dislike about the product?
    Red Canary has an expensive pricing, no small packages for small companies
    Occasionally, Red Canary experiences some delays, and this gaps affects the continuity of the company
    What problems is the product solving and how is that benefiting you?
    Red Canary is resourceful in reducing or filtering noisy detection, where it prioritizes on actionable and real incidents
    The app creates a 24/7 cybersecurity monitoring, and there is timely response to avoid damages
    The app detects credential theft, ransomware, endpoint threats and cloud activities before they cause damages
    The incidence report time or rate is largely supported by the app, and the remediation shared are timely and consistent
    The process of threat monitoring is also a paramount factor, where it conducts proper surveillance both on cloud and across endpoints
    Red Canary strengthens the security preparedness and posture of a business without extreme financial facilitation
    Ahmad O.

    Red Canary Delivers Actionable Alerts and Faster Response

    Reviewed on Apr 23, 2026
    Review provided by G2
    What do you like best about the product?
    It reduces the burden on internal security teams by handling alert monitoring, investigation, and validation, while providing clear and actionable findings instead of noise. This helps improve response speed and overall security confidence.
    What do you dislike about the product?
    One downside of Red Canary is that it can feel less flexible for advanced customization compared to building an in-house SOC. Some users may also find it limited in deep visibility or control over certain investigations since it’s a managed service.
    What problems is the product solving and how is that benefiting you?
    Red Canary solves problems like alert overload, lack of skilled SOC resources, and slow threat detection and investigation.
    John Hoffoss

    Gained trusted 24/7 threat coverage and now focus security efforts on architecture and design

    Reviewed on Mar 25, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Red Canary is to ensure I can sleep at night by getting 24/7 coverage by a capable team to investigate any alerts for the systems that we have in place to ensure we don't have any security or suspicious activity.

    I can give you a specific example of a situation where Red Canary helped me out and made a difference: we've had more than a few instances where a user clicked on a phishing link, invoking connections to hostile sites. Through alerts in Defender, the Red Canary team identified, confirmed, and investigated the threat before they reset the user's credentials and contacted us to work with the user to resolve the situation.

    I have at least one other instance where Red Canary investigated an alert and continued doing additional investigations of logging and activity from that user and their systems around that proximity to confirm that there was no further suspicious activity.

    What is most valuable?

    In my experience, the best features Red Canary offers are their team, their monitoring team, their expertise at incident investigation, and a focus on suspicious or actual indicators of compromise to ensure that we're not spending time just reviewing logs, but that we're actually looking at things that may indicate we have broader issues.

    The Red Canary team's expertise stands out compared to others I've worked with because their team is organized into smaller pods that support a given number of clients, so they're not just a bevy of operators going around the clock. The teams themselves have coordination and cohesion, and they get to know us. Their integrations into the different platforms and systems that we use all line up with our needs, whereas a number of other platforms offered a different variety of integrations that did not line up with our requirements.

    Red Canary has positively impacted my organization because I don't have to spend and hire resources to look at logs, which has enabled us to do much more in terms of improving security across the organization. With the freed-up resources, we've been able to implement CSPM, SAST, software testing tooling, and engage much more closely with our developers and engineers to focus on secure architecture and design.

    What needs improvement?

    Red Canary can be improved by continuing to add new features and capabilities to what they are looking at, including the types of data they're looking at and the types of systems that they're integrating with.

    For how long have I used the solution?

    I have been using Red Canary for three and a half years.

    What do I think about the stability of the solution?

    Red Canary is stable.

    What do I think about the scalability of the solution?

    Red Canary's scalability has been a non-issue for us; we've been able to connect and throw all of the data that we have access to over to their systems to parse, process, and monitor without issue. There have been no issues or challenges in scaling, so I have not noticed any pain points when trying to scale up.

    How are customer service and support?

    Their customer support is excellent, with monthly calls with our CSA, who takes care of us.

    Which solution did I use previously and why did I switch?

    I previously used a different solution called Blue something, but I cannot recall the exact name. I decided to switch from that solution to Red Canary because they were a managed SOC provider and they were not good; they were very cheap, with very poor service.

    How was the initial setup?

    My experience with pricing, setup cost, and licensing is that everything went very smooth. Pricing was straightforward, and we were done with setup during our POC, not having any additional work or rework that we had to do when we moved to production.

    What was our ROI?

    I think that we have probably spent maybe 15% of the time that we were spending on incident investigation and system monitoring, demonstrating a return on investment.

    Which other solutions did I evaluate?

    Before choosing Red Canary, I evaluated other options, specifically Expel and Cydrus.

    What other advice do I have?

    My advice for others looking into using Red Canary is that as long as your system integrations line up with their support, I think you'll be happy.

    Insurance

    Exceptional Partner, But Detection Gaps During Pen Tests

    Reviewed on Oct 31, 2025
    Review provided by G2
    What do you like best about the product?
    The IR team and detection engineers here are truly outstanding, and it's always a pleasure to collaborate with them. The implementation of Red Canary was very easy and their onboarding team was great to work with.
    What do you dislike about the product?
    Over the past few years, we've undergone several external penetration tests, and during these assessments, Red Canary was not able to identify the malicious activity while the tests were ongoing.
    Also, they do not have any sort of alert ingestion integrations with Splunk or other SIEM platforms, and we needed to rely on custom API scripts to ingest alerts into our SIEM.
    What problems is the product solving and how is that benefiting you?
    Red Canary serves as our 24/7 SOC analyst, monitoring our systems during off hours. In addition, Red Canary acts as an extra layer of oversight, working alongside our internal SOC team to enhance our security monitoring.
    Higher Education

    Red Canary Gives Peace of Mind and Streamlines Incident Response

    Reviewed on Oct 31, 2025
    Review provided by G2
    What do you like best about the product?
    I sleep better at night knowing the Red Canary team has our back. Before Red Canary, I would need to interrupt my day to perform investigations on alerts that came into my mailbox, that included after hours alerts that would take me away from my family and friends for hours at a time. With Red Canary, they now take that off my plate and I trust fully in their investigations, analytics, and alert categorization. The configuration of playbooks and integrations into our platforms, allows automation of activity that I would have had to do manually through several different platforms and innumerous clicks. Red Canary has simplified and made more efficient response times in addressing incidents, even in some cases, retroactively analyzing telemetry that was initially not viewed as a threat, but found later to be something to worry about. The platform is easy to navigate, the implementation team was knowledgeable, I'm in the dashboard every day to see what's new on their feed and to see how they've protected our environment. On the rare occasion I need to reach out to support, they are responsive, professional, and knowledgeable to find me a solution. I am whole heartedly thankful that we invested in Red Canary!
    What do you dislike about the product?
    It's hard for me to find a dislike about Red Canary, I've used the service for about 12 months and any negatives I've encountered in their service is addressed by my account team or customer support.
    What problems is the product solving and how is that benefiting you?
    We are required to have 24/7 monitoring, which is difficult for a small staff that likes to sleep at night and spend time with their family after hours. Red Canary has helped us address threats after hours, have alerted us on potential threats that we should be concerned about, and keeps us up to date on the latest threats that could impact our environment.
    Manufacturing

    Quick, Easy, and Supported by an Excellent Team

    Reviewed on Oct 28, 2025
    Review provided by G2
    What do you like best about the product?
    Red Canary is quick and easy to work with. They have excellent people working for them that greatly assist with triage of alerts.
    What do you dislike about the product?
    Identity threats can throw a lot of alerts that Red Canary folks can't act on.
    What problems is the product solving and how is that benefiting you?
    Red Canary is helping to scrub through all of our alerts to help identify security threats.
    Nyír V.

    Innovative Platform with a Fantastic Team

    Reviewed on Oct 28, 2025
    Review provided by G2
    What do you like best about the product?
    Great team, platform, and innovations; I love how they are developing new features, integrations, and listen to client feedback.
    What do you dislike about the product?
    Nothing comes to mind; entirely possible that the few tiny things that would help me with yearly or quarterly administrative tasks (licensing true-up) are in place and I just need to go look myself.
    What problems is the product solving and how is that benefiting you?
    Very nearly a desired single pane of glass for our security stack, which is hugely beneficial to a small and elastic security team.
    Hospital & Health Care

    Excellent Documentation and Support, but Needs Better Automation for Re-activating Devices

    Reviewed on Oct 17, 2025
    Review provided by G2
    What do you like best about the product?
    The documentation for this tool is excellent. Whenever I have a question, I can almost always find the answer there. On the rare occasions when the documentation doesn't cover my issue, the support team is fantastic. They respond quickly and are always very helpful.
    What do you dislike about the product?
    I wish Red Canary would allow customers to create a playbook for automating the re-activation of decommissioned computers that reappear on the network, rather than having to handle each one individually. The current process is very time-consuming.
    What problems is the product solving and how is that benefiting you?
    Red Canary responds rapidly to potential issues, promptly notifying us whenever there is a concern with an account, system, or a user's login location. This helps ensure that we do not overlook anything important, even when we are monitoring things on our own.