Detection software finds things. It does not decide whether they matter, and it does not isolate a laptop at three in the morning. Managed security operations is the part with people in it — a 24/7 security operations centre that investigates, escalates and acts while your business is asleep.
Three different jobs, sold as if they were the same product. Here is the honest version.
A list of things already identified as malicious. Necessary, cheap, and blind to anything new or anything that uses your own legitimate tools against you. Included with Windows.
Endpoint detection and response looks at what a process is doing rather than what it is called, and keeps a forensic trail. It generates findings. Somebody still has to read them.
Managed detection and response puts a staffed security operations centre behind the EDR. Analysts triage every finding, discard the noise, investigate the rest, and act — at any hour.
The endpoint agent flags behaviour that does not fit — a credential dump, an unexpected persistence mechanism, a remote access tool nobody installed.
A human analyst reviews it against the wider picture. Most findings are explained within minutes and never reach you. That filtering is the product.
Where it is real, the analyst traces how it started, what it touched, and whether it spread. You get the timeline, not a raw alert.
The device is isolated from the network and the account disabled — before the call, not after it. Isolation is reversible; a ransomware detonation is not.
We call you. Not an email at 3am you will read at 8. A phone call, with what happened, what we did, and what you need to decide.
A written incident record, and the configuration change that stops the same route being used twice.
A genuine security operations centre needs analysts on shift around the clock, every day of the year. No provider our size can staff that honestly, and the ones who claim to are usually describing an on-call phone.
So we do not claim it. We run Huntress Managed EDR and Managed MDR across our client base — a purpose-built SOC with the scale to see attack patterns across tens of thousands of environments, which is exactly the visibility a single MSP cannot manufacture.
What we bring is the part that has to be local: knowing your business, holding the isolation authority, making the call, and being on site the next morning. That is the honest division of labour, and it is included in every tier of our management stack.
Deploying detection on an existing estate almost always finds something. We would rather you learn about it from us.
No obligation. We will tell you if you do not need us.