Security operations delivered as a service from the Aurora Agentic SOC on the Aurora Superintelligence Platform— Arctic Wolf’s MDR first, with endpoint security, vulnerability and attack surface management, awareness training and incident response around it, and how each one is sold. This hub covers seven Arctic Wolf products.
Buy through TechBag
Same software. Better outcome — at a lower cost.
The company, at a glance
Quick answer
Arctic Wolf’s line, product by product — every linked card is a full intel page, from Aurora MDR and the managed endpoint service to the ex-Cylance agent, vulnerability and attack surface management, awareness training and IR retainers.
A 24×7 SOC over the tools you already run.
Agentic SOC detection over endpoint, network, identity and cloud with a Concierge team; included response is containment and guidance.
Aurora Protect prevention, Endpoint Defense EDR.
The former CylancePROTECT and CylanceOPTICS for Windows, macOS and Linux; Endpoint Defense adds EDR with 30 days of data retention.
The Agentic SOC on Arctic Wolf’s own agent.
Round-the-clock triage, investigation and response on Aurora Endpoint Security only, with guided remediation and an On-Demand variant.
Formerly Managed Risk: scan, rank and patch.
Internal and external scanning, threat-based ranking, AI remediation guidance and ITSM links; the Resolve add-on patches in one click.
Finds the assets your security tools miss.
Aggregates, correlates and de-duplicates asset data from the tools you already run, then ranks the security coverage gaps it finds.
Three-minute lessons every two weeks, no login.
Fully managed microlearning by email, phishing simulation and a Report Phishing button; Training+ adds custom content and LMS download.
JumpStart or Incident360, agreed before a breach.
JumpStart carries a 4-hour SLA at $325 an hour; Incident360 covers one incident with forensics and up to 30 hours of restoration.
A complimentary suite of tools for planning a security roadmap, offered free rather than licensed. Because nothing is bought, TechBag does not give it a page or a price
A warranty that rides inside the bundles rather than being sold alone: $100k on a three-year Core term, up to $1.5M with Total, and up to $3M in the Cyber Resilience offering launched in August 2026
The MDR tier sold exclusively to MSPs, announced in September 2026, which deploys within hours with no network sensor. It is not a cheaper direct tier, so it is covered on the Aurora MDR page
Listed in Arctic Wolf’s product menu, but whether it can be bought on its own is not published. TechBag lists it here and will page it only once a separate licence is documented
A programme run with insurance partners rather than a security product Arctic Wolf licenses, so it has no TechBag page. Ask the insurer for its terms directly
Arctic Wolf sells 5 of the products TechBag carries in Security. The Security guide shows how the category splits and which part is yours. →
Most organisations cannot staff analysts around the clock. Arctic Wolf sells that SOC as a service: Aurora MDR reads the EDR, network, identity and cloud feeds you already run, and its Agentic SOC works the alerts with humans in the loop and a Concierge team on posture reviews. The catch for India: included response stops at containment and guidance, and there is no India data region or SOC.
The name since March 2026 for the layer that takes in telemetry from 250+ integrations, which Arctic Wolf puts at 10+ trillion events a week.
AI agents work alerts with humans in the loop; Arctic Wolf counts 200,000+ investigations a week and says most customers see about one alert a day.
A Concierge team works with each MDR customer and runs Security Posture in-Depth Reviews (SPiDRs), so findings arrive with context rather than as raw tickets.
Arctic Wolf network sensors and agents, its own endpoint agent, and documented feeds from CrowdStrike, Defender, SentinelOne, Sophos Central and Okta.
Start with the SOC — then decide which agent, scanner, training or retainer belongs around it.
Every claim on this hub traces to one of these public signals.
the Worldwide Managed Detection and Response Service for Midmarket edition, published July 2026
one of 19 vendors assessed worldwide, as Arctic Wolf announced on 29 April 2024
one of 22 providers assessed, according to Arctic Wolf’s release of 26 April 2024
a customer-review award dated 7 April 2026, not an analyst ranking or a Magic Quadrant
a representative vendor in 2024 and 2025; Gartner writes a Market Guide for MDR, not a Magic Quadrant
bought from BlackBerry on 3 February 2025 and relaunched as Aurora Endpoint Security
the base of Aurora ASM; Sevco’s 2025 Gartner Visionary placement was Sevco’s own, earned before the deal
the latest Cylance agent flaw, CVE-2024-35214 (CVSS 7.1), was published in August 2024 under BlackBerry
A May 2026 brand film setting out how Arctic Wolf sees its role; a pitch, not a product demo.
An August 2026 spot for the Aurora Agentic SOC, pairing human analysts with AI agents.
An August 2026 interview with CEO Nick Schneider, filmed at Black Hat 2026.
Two company-level views you won’t find on any vendor site — tap any dot for the rationale. The category-level grid lives on the product page.
Each dot is a Arctic Wolf solution area: competitive position vs category momentum.
The core business: an IDC MarketScape Leader in 2024 and again in the 2026 midmarket edition, and a Frost Radar Leader in 2024.
How far each MDR service runs on tools you already own vs how much incident response the base contract includes.
Watches your existing EDR, network and identity feeds, but full forensics and restoration sit in the paid Incident360 retainer, and there is no India region.
Positions are TechBag’s illustrative synthesis of public review-platform standings and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Zero-jargon starting points, in reading order. Each links into the deep education on the product page.
Answer three questions; we’ll point you at the right starting product. No email required — this isn’t that kind of quiz.
1. What problem is forcing the decision?
2. What do you already run?
3. Who will own it?
Aurora MDR is the centre; endpoint, vulnerability, attack surface, training and IR are sold on their own or folded into bundles.
Read →Aurora MDR watches your whole estate on the tools you run; Managed Endpoint Defense watches only Arctic Wolf’s own endpoint agent.
Read →Cylance products became Aurora Protect and Aurora Focus, Managed Risk became Aurora Vulnerability Management, IR JumpStart is a retainer.
Read →Core is MDR with Concierge; Plus adds log retention, vulnerability management, training and a JumpStart Retainer; Total adds the warranty.
Read →MDR contains a threat and guides you; forensics and restoration need the Incident360 retainer, which covers one incident.
Read →The Security category compares MDR, endpoint protection and vulnerability management, the three markets five of these products compete in.
Read →The procurement playbook TechBag runs with IT buyers — steps, licensing cheat-sheet, and the pitfalls that cost quarters.
Most buyers start with Aurora MDR and add products later. Decide whether you need the SOC now or only an agent, a scanner or training.
MDR is counted in monitored users and Managed Endpoint Defense in devices, so list both before comparing a bundle with single products.
Core, Plus and Total add log retention, vulnerability management, training, a JumpStart Retainer and warranty levels; none publishes a price.
MDR’s included response stops at containment and guidance. If you need forensics and restoration, add an Incident360 retainer up front.
There is no India region; endpoint data sits in regions such as the US or Frankfurt. Check that against your DPDP and CERT-In obligations.
Arctic Wolf publishes no INR price, only US marketplace offers. TechBag scopes the users, devices and retainers and quotes the total in INR with GST.
| Product | Licensing model | How you enter | Best for |
|---|---|---|---|
| Aurora MDR | Per monitored user · alone or in the Core, Plus and Total bundles · MDR Connect for MSPs | $44,000/yr for 100 users (AWS offer) | 24×7 SOC on your tools |
| Aurora Endpoint Security | Per endpoint · Aurora Protect (EPP) or Aurora Endpoint Defense (adds EDR) · mobile add-on | Quote | Agent replacement |
| Managed Endpoint Defense | Per device per year · runs on Aurora Endpoint Security · On-Demand variant | $18,240/yr for 100 devices (AWS offer) | Managed endpoint only |
| Vulnerability Management | Quote · Resolve patching is an add-on · included in Security Operations Plus | Quote | Scanning and patching |
| Attack Surface Management | Quote · reads asset data from the tools you already run | Quote | Coverage gaps |
| Security Awareness and Training | Quote · base tier or Training+ · Compliance Pack of 16 courses | Quote | Phishing-prone staff |
| Incident Response | JumpStart, Incident360 or Incident360 Plus retainer · Rapid Response add-on | $325/hour IR rate | Breach readiness |
arcticwolf.com publishes no list prices. The only public figures are US AWS Marketplace offers (MDR Basic $44,000 a year for 100 users; Managed Endpoint Defense $18,240 a year for 100 devices) and IR rates of $325 an hour, or $295 with Rapid Response. TechBag gets the quote itemised in INR with GST.
MDR contains threats and guides the fix. Forensics, threat-actor communication and restoration belong to the Incident360 retainer.
Bengaluru is an engineering and research site. Arctic Wolf documents no India data region and no SOC in India, so plan for offshore data.
Aurora Endpoint Defense is the EDR product tier; Aurora Managed Endpoint Defense is the SOC service on top. Check which one a quote lists.
Aurora MDR Connect is sold only through MSPs and skips the network sensor. A direct buyer cannot order it as a lower-cost MDR plan.
The $44,000 and $18,240 figures are US AWS Marketplace offers for 100 users or devices. Larger or Indian deals are quoted separately.
Each intel page carries an 8-question vendor checklist and a value calculator:
Bring your requirements and current tool bills — a TechBag advisor models the whole decision for you.
Book a discovery call →Four trends with momentum scores (TechBag’s read of analyst and market signals) — and what each means for your next decision.
*TechBag’s illustrative estimate, not a quoted analyst figure. The takeaway: buyers who cannot staff a SOC are renting one, and MDR providers are adding endpoint, exposure management and retainers around it — which is why Arctic Wolf now sells all of them.
Arctic Wolf renamed its platform Aurora Superintelligence in March 2026 and now sells the Aurora Agentic SOC, with humans in the loop.
What it means for you
Ask any MDR provider which decisions an AI agent makes alone.
Arctic Wolf closed its purchase of Cylance from BlackBerry in February 2025 and now sells its own agent alongside MDR on third-party EDR.
What it means for you
Check whether the provider still treats your EDR as a first-class feed.
Aurora Attack Surface Management, built on Sevco, launched with the renamed vulnerability service in May 2026.
What it means for you
Judge exposure tools on the asset sources they read.
The Cyber Resilience offering of August 2026 bundles up to $3M of Security Operations Warranty with MDR, ASM and IR.
What it means for you
Read the warranty’s exclusions before you count it as cover.
Open any of the seven intel pages for the deep dive, or let a TechBag advisor build the case with you — the users and devices to count, MDR alone or a bundle, and the retainer you need, quotes, trials, GST invoicing and lifecycle support included.
Stats, positions and figures are illustrative syntheses of public materials; verify before purchase.