Your EDR raises alerts at 2 a.m. Someone should be awake to read them — Kaseya MDR, the rebuilt RocketCyber, puts a 24/7 SOC over your endpoints, firewalls and Microsoft 365, working beside the EDR you already run and keeping logs for 400 days.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Kaseya MDR — formerly RocketCyber, including Managed SOC Services. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
A vendor’s analysts watch your security alerts around the clock and act on real threats, so you need no SOC of your own.
What consolidation actually replaces, dimension by dimension.
| Dimension | EDR alerts nobody reads at night | Kaseya MDR |
|---|---|---|
| Who reads alerts at 2 a.m. | Nobody, until someone checks email | Analysts in Florida or Ireland, around the clock |
| Containing a hacked laptop | A technician on the phone or on site | The SOC isolates it remotely |
| Firewall logs | Kept on the box and rarely read | Collected by syslog and triaged with endpoint data |
| Evidence for an auditor | Whatever the EDR console still holds | 400 days of searchable logs |
| Where the work lands | Alert emails in a shared inbox | PSA tickets with the next steps written in |
| What it is NOT | — | A SIEM, SaaS user monitoring, or a published price |
The cheapest test is one client: deploy the agent, connect its EDR and firewall, and run a tabletop from alert to closed PSA ticket.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Runs on Windows 8.1 and Server 2012 R2 onward, macOS 10.15 to 26 and major Linux distributions; it talks only outbound on port 443 and offers no remote control.
Datto EDR, Defender, SentinelOne and six other EDRs connect by integration; a Windows agent doubles as a syslog collector for 14 firewall brands, and Microsoft 365 links in.
Kaseya Intelligence triages and correlates alerts at machine speed; analysts in Florida and Ireland validate what is left and take containment actions without waiting for you.
An alert-centric console with one Analysis timeline across devices, users and IP addresses; incidents land as tickets in Autotask, BMS, ConnectWise Manage or Syncro.
One agent beside your EDR — AI triage first, then analysts in Florida and Ireland who contain and ticket.
Kaseya MDR puts analysts on your alerts around the clock, without replacing your EDR.
By default the agent forwards key Windows events, such as cleared audit logs, new scheduled tasks and lockouts, plus sudo and SSH use.
On Windows and Mac the agent watches for ATT&CK techniques and flags connections to known malicious IPs, command-and-control servers and Tor.
A Windows agent collects syslog from Fortinet, SonicWall, Palo Alto, Sophos, Meraki and others, then adds geo and IP-reputation alerts.
Analysts isolate a device, lock an account or revoke sessions themselves; you can also isolate or restore many devices at once from the console.
Kaseya’s own agent logic detects ransomware, kills the process and isolates the endpoint, working alongside the anti-malware you already run.
Microsoft 365 detection and response rules can be customised; confirm the scope, as SaaS user monitoring is sold as SaaS Alerts.
Telemetry is normalised and correlated into one searchable timeline of devices, users and IPs, replacing RocketCyber’s per-app pages.
Analysts write ready-to-action tickets into Autotask, Kaseya BMS, ConnectWise Manage or Syncro, with the remediation steps attached.
Global defaults apply to every organisation you manage, overrides per client stay visible, and security reports show clients what was done.
Isolating a hacked device, a customer moving from no SOC to 24/7 cover, and the managed SOC under its former name RocketCyber (2023 and 2020).
Forty seconds on spotting a compromised device and isolating it before the attack spreads.
Ark ICT on gaining a 24/7 SOC and EDR through Kaseya 365 instead of building its own.
A 2023 tour of the managed SOC under its former name RocketCyber, made for MSPs and their clients.
A 30-second teaser from 2020 for the SOC service under its former name RocketCyber.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
The rebuild is designed around third-party EDR: Datto EDR, Microsoft Defender, SentinelOne, Sophos, Bitdefender, Webroot and others connect. You change who reads the alerts, not the agent on every laptop, so leaving later does not strand your endpoint protection.
Incidents arrive as tickets in Autotask, Kaseya BMS, ConnectWise Manage or Syncro, and the agent deploys through VSA, Datto RMM, NinjaOne or ConnectWise Automate. Global defaults with per-client overrides keep tenants consistent, and reports show clients what the SOC did.
Kaseya keeps 400 days of logs, longer than CERT-In’s 180-day log period, though where they sit is another question. The SOC itself isolates devices, locks accounts and revokes sessions, and you can phone its analysts, so a 3 a.m. incident does not wait for your on-call.
No public price, and the rebuild is five months old. Kaseya’s help centre puts SaaS user monitoring in SaaS Alerts, a separate SKU, so get the Microsoft 365 scope in writing. Firewall syslog needs a Windows agent, ARM is unsupported, data is US-hosted, and no analyst ranks it.
List every client’s endpoints, EDR, firewall and Microsoft 365 tenant, and note any ARM devices the agent cannot cover.
Get MDR quoted alone and inside Kaseya 365 Endpoint Pro, with endpoint counts, terms and GST written into both versions.
Push the agent through your RMM, connect the EDR and Microsoft 365, and point the firewall’s syslog at a Windows agent.
Set what the SOC may isolate, lock or revoke, wire tickets into your PSA, and run a tabletop from alert to closed ticket.
Extend to every client with global defaults and overrides, tune noisy rules, and send each client its first security report.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“We kept SentinelOne on every client laptop and only changed who watches it overnight. Nobody had to reinstall anything.”
“The SOC isolated a finance PC at 1 a.m., and the Autotask ticket told my technician exactly what to check that morning.”
“Pointing our FortiGate syslog at a Windows agent was quick. We wish the Linux agent could collect firewall logs too.”
“Moving from RocketCyber needed no new agent, though both consoles raised duplicate tickets for about a week.”
“Four hundred days of logs answered the auditor’s look-back question. Where those logs are stored was the harder talk.”
“Solid service, but we asked twice before the quote showed what the Pro tier adds over Express for our 60 endpoints.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the MDR market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Rebuilt in April 2026; quoted per endpoint; no analyst placement.
The grid nobody publishes — how freely the service runs on the EDR, firewalls and cloud you already own vs how far its analysts go once a threat is confirmed.
Nine EDRs and 14 firewall brands; isolate, lock and revoke.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Sophos MDR, Barracuda Managed XDR, N-able Adlumin MDR, Rapid7 Managed Threat Complete and Bitdefender MDR — on telemetry, response, SOC, price, retention, MSP tooling and India.
| Dimension | Kaseya MDR | Sophos MDR | Barracuda Managed XDR | N-able Adlumin MDR | Rapid7 Managed Threat Complete | Bitdefender MDR |
|---|---|---|---|---|---|---|
| What it is | RocketCyber, rebuilt | Agentic SOC + analysts | XDR platform + SOC | Adlumin’s SOC and XDR | MDR on Rapid7’s SIEM | Service + GravityZone |
| Whose telemetry | Its agent + your EDR | Bring your own stack | Vendor-agnostic feeds | Adlumin agent first | Rapid7 Agent required | Bitdefender’s agent |
| Surfaces watched | Endpoint, firewall, M365 | Six layers | Endpoint to cloud | Grows with the tier | Estate via its SIEM | Endpoint, plus sensors |
| Response authority | Isolate, lock, revoke | Full removal, no caps | Automated containment | Contain, then hand over | 2 actions, unlimited IR | Pre-approved actions |
| SOC and contact | Florida and Ireland | Global team, no cities | Follow-the-sun SOC | Phone in an incident | 15-min start, contract | Three SOCs, 30-min call |
| Pricing model | Per endpoint, quoted | Per user or device | Build & Price, quoted | Three tiers, quoted | Per asset, no log cap | Platform in the fee |
| Published entry price | Not published | Not published | Not published | Not published | ~$15–22/asset/month | Not published |
| Included vs add-on | SIEM, SaaS Alerts apart | Integrations included | Vuln service separate | Warranty needs a suite | VM and IR bundled | Platform included |
| Log retention | 400 days | Not published | Not published | 30 or 90 days | 13 months | Not stated |
| MSP tooling | PSA tickets, RMM deploy | Partner dashboard | MSP option | Shared SOC console | Direct-buyer focus | Per-customer controls |
| India storage region | US-hosted | Mumbai DC; check MDR | Mumbai listed | Not documented | No India region | Singapore SOC only |
| Lock-in and exit | Your EDR stays | Tools stay put | Terms not public | Logs are yours | Agent to replace | Platform bundled |
| Analyst standing | No placement | IDC Leader, 2026 | None cited | None cited | Frost Radar Leader | IDC Major Player |
| Best fit | Kaseya MSPs, mixed EDR | Mixed estates, full IR | Logs must stay in India | N-able MSPs | SOC plus scanning | GravityZone estates |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Kaseya MDR is one of 19 managed detection & response products TechBag carries. The Managed Detection & Response guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (endpoints monitored; analyst-hour cost). Estimates model in-house time spent reading and triaging EDR, firewall and Microsoft 365 alerts, at an assumed 1.5 hours per endpoint a year, with 70% of it taken over by a managed SOC. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Not published. Kaseya prints no price for Kaseya MDR and asks buyers to request a demo. It is quoted per endpoint, either standalone or inside Kaseya 365 Endpoint Pro, the bundle tier that adds MDR to the RMM, Datto EDR and AV, third-party patching and endpoint backup; the Express tier leaves MDR out, and new bundle customers start at 50 endpoints. Existing RocketCyber customers move across with no price increase, per Kaseya. TechBag lays the two quotes next to each other and adds GST.
Best for MSPs keeping their own EDR and RMM
Best for a broader rollout
Best for buying the SOC with RMM, EDR and backup
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Which surfaces must the SOC watch — endpoints, firewalls, Microsoft 365 — and is SaaS user activity in or out?
Is every client’s EDR on Kaseya’s integration list: Datto, Defender, SentinelOne, Sophos, Bitdefender or others?
Any ARM machines, Raspberry Pis or Linux boxes expected to collect syslog? The agent will not cover them.
What may the SOC do without asking — isolate, lock accounts, revoke sessions — and who approves anything else?
Kaseya lists only US hosting; does any client contract, regulator or insurer require logs to be kept in India?
Is 400 days enough for your auditors and insurers, and can logs be exported before the contract ends?
Coming from RocketCyber? Plan for both consoles running in parallel and duplicate PSA tickets for a while.
Standalone or Kaseya 365 Endpoint Pro? New bundle customers start at 50 endpoints; ask for both quotes with GST.
Check every client’s EDR and firewall against Kaseya’s integration list first, or let a TechBag advisor get MDR quoted standalone and inside Kaseya 365 Endpoint Pro.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.