A file that never runs can’t encrypt anything. Stop it on the device, and keep a record when something slips through — Arctic Wolf Aurora Endpoint Security is the former Cylance line: Aurora Protect blocks threats on Windows, macOS and Linux, and Aurora Endpoint Defense adds the Aurora Focus EDR agent with 30 days of data to hunt through.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Arctic Wolf Aurora Endpoint Security — Aurora Protect and Aurora Endpoint Defense, with Aurora Mobile Threat Defense folded in. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
An agent on every device blocks threats before they run, and an EDR layer records what happens so analysts can investigate.
What consolidation actually replaces, dimension by dimension.
| Dimension | Signature AV plus a separate EDR | Arctic Wolf Aurora Endpoint Security |
|---|---|---|
| How malware is stopped | A signature match after an update | An AI verdict before the file runs |
| Fileless and script attacks | Often missed by file scanning | Memory and script controls in Protect |
| Seeing what happened | Event logs pulled by hand | Aurora Focus keeps 30 days to search |
| Who watches at night | Nobody, or an unrelated MDR firm | Optional Arctic Wolf managed tier |
| Phones and tablets | Another vendor’s mobile product | Aurora Mobile Threat Defense |
| What it is NOT | — | India-hosted, or sold at a published price |
The cheapest test is a 50-machine pilot across your operating systems, with the storage region agreed in writing before a single agent goes out.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
The prevention agent, formerly CylancePROTECT, runs Aurora AI for Endpoint as next-generation antivirus and adds memory, script, PE, device and application controls.
In Aurora Endpoint Defense a second agent, Aurora Focus (once CylanceOPTICS), feeds a behavioural detection engine, maps detections to MITRE ATT&CK and keeps 30 days of data.
Policies, alerts and endpoint data sit in Arctic Wolf’s hosted service, stored in one of six regions: the US, Frankfurt, ANZ, Canada, South America or Japan. India is not one.
Launched on 12 May 2026, the mobile product protects corporate and BYOD iOS and Android devices, so phones are covered by the same vendor as laptops and servers.
Two agents, one hosted service — Protect prevents on the device, Focus records 30 days for hunting, stored outside India.
Aurora Endpoint Security prevents on the device first, then records what happens for analysts to hunt.
Aurora AI for Endpoint judges a file before execution, the prevention-first model Cylance was built on, rather than waiting for a signature.
Memory, script and PE controls stop in-memory exploits and malicious scripts that never drop a file for a scanner to inspect.
Device control limits which peripherals may connect, and application control holds fixed-purpose machines to an approved set of programs.
Endpoint Defense watches process activity for attacker techniques that a verdict on a single file would never reveal.
Each detection is tagged with its MITRE ATT&CK technique, so an analyst sees which stage of an intrusion is under way.
Analysts hunt across the 30 days of endpoint data Endpoint Defense keeps, using the advanced queries Arctic Wolf documents.
Playbook automation runs preset response steps when a detection fires, so routine threats are handled consistently.
Aurora Managed Endpoint Defense puts Arctic Wolf’s Agentic SOC on this agent for 24×7 triage, investigation and guided fixes.
Aurora Mobile Threat Defense brings iOS and Android, both corporate and personally owned, into the endpoint line since May 2026.
Aurora Protect against modern threats, the behavioural engine behind the EDR, stopping fileless attacks, and the new mobile product.
The prevention tier, once CylancePROTECT, set against the attack types it is built to stop.
The behavioural engine that turns Aurora Endpoint Defense into an EDR.
Memory and script controls in action against attacks that never write a file.
The iOS and Android product launched in May 2026 for corporate and BYOD phones.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Aurora Protect, once CylancePROTECT, is AI-driven antivirus with memory, script, device and application controls, built to stop a file before it runs. A Tolly Group test Arctic Wolf commissioned (August 2025) scored it 100% on threat protection; read that as a vendor-paid result.
Aurora Endpoint Defense adds the Aurora Focus agent, formerly CylanceOPTICS: behavioural detection, threat hunting, MITRE ATT&CK mapping and playbooks over 30 days of endpoint data. Start a fleet on Protect and move machines up a tier once someone is ready to hunt.
On top sits Aurora Managed Endpoint Defense, in which Arctic Wolf’s Agentic SOC triages and acts on this agent’s alerts around the clock. That service runs only on Aurora Endpoint Security, so agent and analysts come under one contract; the full Aurora MDR also takes rival EDRs.
Neither tier has a public price. Data is stored in the US, Frankfurt, ANZ, Canada, South America or Japan, never India, and EDR history stops at 30 days. The line changed owner in February 2025, Cylance’s on-prem console status is unconfirmed, and TechBag found no documented file rollback.
List Windows, Mac, Linux and mobile devices, then decide which need Protect alone and which need Endpoint Defense’s EDR.
Pick one of the six storage regions, note that none is in India, and have legal approve that transfer before any rollout.
Deploy to about 50 machines across operating systems, start with permissive policies, and tune memory, script and app controls.
Remove the previous antivirus group by group, roll the agent out, and check performance on older machines as you go.
Set playbooks for common detections, then choose in-house hunting, the managed tier or Aurora MDR for after-hours cover.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“We ran CylancePROTECT before the sale. Under Arctic Wolf the agent got a new name, and for months the docs used both.”
“Prevention catches most things before they run, and Endpoint Defense gave our two analysts something to dig into when it did not.”
“Thirty days of EDR history covers triage, but our auditors wanted longer, so we export anything we must keep.”
“Linux build servers and the Mac design team sit on the same tiers as Windows, which made it one rollout, not three.”
“We asked for India-hosted storage during procurement and were offered another region, so legal had to approve the transfer.”
“Arctic Wolf’s SOC watching the same agent overnight is why we picked it over a cheaper antivirus.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the endpoint protection market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Quote-only; the former Cylance line, under Arctic Wolf since February 2025.
The grid nobody publishes — how far endpoint data and the console can stay in India vs how deep detection, hunting and retention go.
No India region; on-prem unconfirmed; 30 days of EDR data.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against CrowdStrike Falcon Insight XDR, SentinelOne Singularity Endpoint, Microsoft Defender for Endpoint, Sophos Intercept X with XDR and Bitdefender GravityZone EDR — on price, retention, recovery, MDR and India.
| Dimension | Arctic Wolf Aurora Endpoint Security | CrowdStrike Falcon Insight XDR | SentinelOne Singularity Endpoint | Microsoft Defender for Endpoint | Sophos Intercept X Advanced with XDR | Bitdefender GravityZone EDR / XDR |
|---|---|---|---|---|---|---|
| What it is | Ex-Cylance EPP + EDR | EDR/XDR module | Autonomous EPP + EDR | Plan 1 or Plan 2 | Intercept X + XDR tier | EDR in GravityZone |
| Deployment and console | Hosted; on-prem unclear | Cloud console only | SaaS; self-hosted due | Defender portal | Sophos Central | Cloud or on-prem |
| OS and mobile coverage | Win, Mac, Linux, mobile | Win, Mac, Linux | Win, Mac, Linux, K8s | Five platforms | Win, Mac, Linux | Win, Mac, Linux, VMs |
| Pricing model | Quote, by tier | Per device, annual | Per endpoint, partners | Per user, or bundled | Per user, quoted | Per device, packages |
| Published entry price | Not published | $184.99/device/yr | From $179.99/yr | $3 / $5.20 a month | ~$48/user, reported | ~$95.89, year one |
| Included vs add-on | EDR is the upper tier | SIEM, identity bundled | Hunting by tier | EDR only in Plan 2 | MDR, storage extra | Many paid extras |
| Telemetry retention | 30 days | Default unpublished | 14 or 90 days | 180 days in Plan 2 | 90 days, 365 paid | 3 days raw |
| Detection and hunting | Behavioural, ATT&CK | Forensic timeline | Storyline | Advanced hunting | Data-lake queries | Cross-endpoint search |
| Ransomware recovery | Rollback unconfirmed | No auto rollback | One-click rollback | OneDrive restore | CryptoGuard | Ransomware Mitigation |
| Integrations | Feeds Arctic Wolf SOC | 260+ marketplace apps | API-first marketplace | Sentinel, Intune, Entra | RMM and PSA links | RMM plug-ins |
| India data region | No India region | Announced, undated | Mumbai region | India location | Mumbai, live | No India; on-prem |
| Support and MDR | Managed tier, $182.40 | Falcon Complete | Wayfinder MDR | Defender Experts | Sophos MDR | Bitdefender MDR |
| Lock-in and exit | New owner, renaming | 30-day refund, Flex | Annual, partner terms | Microsoft-first | Data erased at lapse | Auto-renew, 50 minimum |
| Best fit | Cylance and AW estates | Hunting SOCs, one sensor | Lean team, India data | Microsoft 365 tenants | Sophos mid-market | Budget, on-prem rules |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Arctic Wolf Aurora Endpoint Security is one of 47 endpoint protection products TechBag carries. The Endpoint Protection guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (endpoints; IT-hour cost). Estimates model staff time spent on malware clean-ups, reimaging and chasing endpoint alerts at an assumed 1.5 hours per endpoint a year, with 70% of it removed by prevention-first protection and EDR. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Not published: Arctic Wolf prints no price for Aurora Protect or Aurora Endpoint Defense, and both are quoted. The only public endpoint figure is the managed tier, Aurora Managed Endpoint Defense, at $18,240 a year for up to 100 devices as an AWS Marketplace public offer (US). TechBag maps your fleet to a tier first, then quotes in INR with GST.
Best for prevention-first fleets
Best for a broader rollout
Best where someone will hunt
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Which devices need EDR in Aurora Endpoint Defense, and which are covered by prevention alone in Aurora Protect?
Are all the Windows, macOS and Linux versions in your fleet on Arctic Wolf’s supported list for Protect and Focus?
Do phones and tablets need Aurora Mobile Threat Defense, and is it itemised in the same quote?
Which of the six storage regions will hold your data, and has legal approved endpoint data leaving India?
Are 30 days of EDR data enough for your investigations and audits, or will you export it to keep it longer?
Are any CylanceOPTICS installs still on 3.2 or 3.3, the Windows versions named in CVE-2024-35214?
Who will hunt and respond: your own team, Aurora Managed Endpoint Defense, or Arctic Wolf’s full Aurora MDR?
Does the quote name the tier, device count, mobile add-on and term? Ask for it in INR with GST.
Model your endpoint count first, or let a TechBag advisor scope a pilot that tests Protect and Endpoint Defense on a mixed Windows, Mac and Linux group.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.