Talk to us
by Arctic WolfTechBag Intel Page

Arctic Wolf Aurora Endpoint Security

A file that never runs can’t encrypt anything. Stop it on the device, and keep a record when something slips through — Arctic Wolf Aurora Endpoint Security is the former Cylance line: Aurora Protect blocks threats on Windows, macOS and Linux, and Aurora Endpoint Defense adds the Aurora Focus EDR agent with 30 days of data to hunt through.

Ex-Cylance prevention and EDR30 days of EDR dataQuote-only; no India region

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
Arctic Wolf prints no price for Aurora Protect or Aurora Endpoint Defense; both tiers are quoted
Quote
EDR data
Kept by Aurora Endpoint Defense for hunting; Aurora Protect is the prevention tier, without EDR
30 days
Lab test
An Arctic Wolf-commissioned Tolly Group evaluation from August 2025, not an independent ranking
100% (Tolly)
India
Endpoint data is stored in the US, Frankfurt, ANZ, Canada, South America or Japan
No region

Quick answer

Aurora Endpoint Security is the former Cylance line, which Arctic Wolf bought from BlackBerry in February 2025. Aurora Protect is the prevention tier: AI-led NGAV with memory, script, device and application control. Aurora Endpoint Defense adds the Aurora Focus EDR agent and keeps 30 days of endpoint data. It covers Windows, macOS and Linux, and phones through Mobile Threat Defense. Both tiers are quoted, and no storage region is in India. Read more ↓ Show less ↑
Part 01 · Orient

The Arctic Wolf platform family

This page covers Arctic Wolf Aurora Endpoint Security — Aurora Protect and Aurora Endpoint Defense, with Aurora Mobile Threat Defense folded in. The rest:

Quick facts

30-second orientation
Product
Ex-Cylance endpoint protection in two tiers: Aurora Protect (EPP) and Aurora Endpoint Defense (EPP + EDR)
Maker
Arctic Wolf Networks, Eden Prairie, Minnesota; private, founded 2012, CEO Nick Schneider since 2021
Origin
CylancePROTECT and CylanceOPTICS, bought from BlackBerry; the sale closed on 3 February 2025
Price
Not published for either tier; both are quoted, and the managed tier is a separate SKU
EDR
Aurora Focus agent: behavioural engine, threat hunting, MITRE ATT&CK mapping and playbooks
Retention
30 days of endpoint data in Aurora Endpoint Defense
Platforms
Windows, macOS and Linux; iOS and Android through Aurora Mobile Threat Defense (May 2026)
Data regions
US, Frankfurt, ANZ, Canada, South America and Japan; none in India
Managed option
Aurora Managed Endpoint Defense puts Arctic Wolf’s SOC on this agent around the clock
In India via
TechBag — tier mapping, move off an old agent, quote in INR with GST
Part 02 · Learn

Understand endpoint protection before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is endpoint protection with EDR?

An agent on every device blocks threats before they run, and an EDR layer records what happens so analysts can investigate.

Signature antivirus and a separate EDR vendor vs one prevention-first line — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionSignature AV plus a separate EDRArctic Wolf Aurora Endpoint Security
How malware is stoppedA signature match after an updateAn AI verdict before the file runs
Fileless and script attacksOften missed by file scanningMemory and script controls in Protect
Seeing what happenedEvent logs pulled by handAurora Focus keeps 30 days to search
Who watches at nightNobody, or an unrelated MDR firmOptional Arctic Wolf managed tier
Phones and tabletsAnother vendor’s mobile productAurora Mobile Threat Defense
What it is NOT—India-hosted, or sold at a published price

The cheapest test is a 50-machine pilot across your operating systems, with the storage region agreed in writing before a single agent goes out.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Prevention on the device

Protect

Aurora Protect agent

The prevention agent, formerly CylancePROTECT, runs Aurora AI for Endpoint as next-generation antivirus and adds memory, script, PE, device and application controls.

02
Recording what happens

Focus

Aurora Focus EDR agent

In Aurora Endpoint Defense a second agent, Aurora Focus (once CylanceOPTICS), feeds a behavioural detection engine, maps detections to MITRE ATT&CK and keeps 30 days of data.

03
Where policy and data live

Cloud

Hosted console and storage

Policies, alerts and endpoint data sit in Arctic Wolf’s hosted service, stored in one of six regions: the US, Frankfurt, ANZ, Canada, South America or Japan. India is not one.

04
Phones and tablets

Mobile

Aurora Mobile Threat Defense

Launched on 12 May 2026, the mobile product protects corporate and BYOD iOS and Android devices, so phones are covered by the same vendor as laptops and servers.

Two agents, one hosted service — Protect prevents on the device, Focus records 30 days for hunting, stored outside India.

Part 03 · Evaluate

Nine capabilities. Prevent, detect, operate.

Aurora Endpoint Security prevents on the device first, then records what happens for analysts to hunt.

Prevent
AI NGAV

A verdict before the file runs

Aurora AI for Endpoint judges a file before execution, the prevention-first model Cylance was built on, rather than waiting for a signature.

Prevent
Memory & script

Fileless attacks blocked

Memory, script and PE controls stop in-memory exploits and malicious scripts that never drop a file for a scanner to inspect.

Prevent
Device & app control

Only approved hardware and code

Device control limits which peripherals may connect, and application control holds fixed-purpose machines to an approved set of programs.

Detect
Behavioural engine

Behaviour, not just files

Endpoint Defense watches process activity for attacker techniques that a verdict on a single file would never reveal.

Detect
MITRE ATT&CK

Detections mapped to tactics

Each detection is tagged with its MITRE ATT&CK technique, so an analyst sees which stage of an intrusion is under way.

Detect
Threat hunting

Thirty days to search

Analysts hunt across the 30 days of endpoint data Endpoint Defense keeps, using the advanced queries Arctic Wolf documents.

Operate
Playbooks

The same response every time

Playbook automation runs preset response steps when a detection fires, so routine threats are handled consistently.

Operate
Managed tier

Hand the night shift over

Aurora Managed Endpoint Defense puts Arctic Wolf’s Agentic SOC on this agent for 24×7 triage, investigation and guided fixes.

Operate
Mobile

Phones join the estate

Aurora Mobile Threat Defense brings iOS and Android, both corporate and personally owned, into the endpoint line since May 2026.

See it, don’t just read it

Watch Aurora Endpoint Security in action

Aurora Protect against modern threats, the behavioural engine behind the EDR, stopping fileless attacks, and the new mobile product.

Arctic Wolf (official)·Explainer, May 2025

How Aurora Protect Defends Against Modern Threats

The prevention tier, once CylancePROTECT, set against the attack types it is built to stop.

Arctic Wolf (official)·Explainer, July 2025

How the Behavioral Detection Engine Delivers Aurora Endpoint Detection and Response Capabilities

The behavioural engine that turns Aurora Endpoint Defense into an EDR.

Arctic Wolf (official)·How-to, December 2025

How to Prevent Fileless and In-Memory Attacks with Aurora Endpoint Defense

Memory and script controls in action against attacks that never write a file.

Arctic Wolf (official)·Explainer, May 2026

How Arctic Wolf Aurora Mobile Threat Defense Protects the Mobile Attack Surface

The iOS and Android product launched in May 2026 for corporate and BYOD phones.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Arctic Wolf Aurora Endpoint Security

Signatures arrive after the attack. Aurora Protect judges the file before it runs.

Here’s what genuinely sets it apart — and exactly where it stops.

01

Prevention first, from the Cylance lineage

Aurora Protect, once CylancePROTECT, is AI-driven antivirus with memory, script, device and application controls, built to stop a file before it runs. A Tolly Group test Arctic Wolf commissioned (August 2025) scored it 100% on threat protection; read that as a vendor-paid result.

02

EDR when you have people to use it

Aurora Endpoint Defense adds the Aurora Focus agent, formerly CylanceOPTICS: behavioural detection, threat hunting, MITRE ATT&CK mapping and playbooks over 30 days of endpoint data. Start a fleet on Protect and move machines up a tier once someone is ready to hunt.

03

The agent and the SOC from one vendor

On top sits Aurora Managed Endpoint Defense, in which Arctic Wolf’s Agentic SOC triages and acts on this agent’s alerts around the clock. That service runs only on Aurora Endpoint Security, so agent and analysts come under one contract; the full Aurora MDR also takes rival EDRs.

04

Where it stops

Neither tier has a public price. Data is stored in the US, Frankfurt, ANZ, Canada, South America or Japan, never India, and EDR history stops at 30 days. The line changed owner in February 2025, Cylance’s on-prem console status is unconfirmed, and TechBag found no documented file rollback.

The idea
Prevent first, add EDR where it pays
The residency
Six regions, none of them in India
The price
Quote-only for both tiers
Proof, not promises

The numbers behind the platform

30 days
of endpoint data that Aurora Endpoint Defense keeps for investigation and hunting
— Vendor
100%
threat protection in a Tolly Group test Arctic Wolf commissioned, August 2025
— Vendor
27%
lower resource consumption claimed in that same commissioned Tolly evaluation
— Vendor
6 regions
where endpoint telemetry can live — Japan, Canada, Frankfurt, ANZ, the US, South America
— Vendor
3 desktop OSes
Windows, macOS and Linux, with iOS and Android in the separate mobile product
— Vendor
2025
the year Arctic Wolf closed its Cylance purchase from BlackBerry, on 3 February
— Vendor

What your Aurora Endpoint Security rollout looks like

Week 1Model

Count devices and pick a tier

List Windows, Mac, Linux and mobile devices, then decide which need Protect alone and which need Endpoint Defense’s EDR.

Week 2Decide

Settle the data region in writing

Pick one of the six storage regions, note that none is in India, and have legal approve that transfer before any rollout.

Week 3Pilot

Pilot on a mixed group

Deploy to about 50 machines across operating systems, start with permissive policies, and tune memory, script and app controls.

Month 2Prove

Retire the old agent in waves

Remove the previous antivirus group by group, roll the agent out, and check performance on older machines as you go.

Month 3Commit

Decide who watches it

Set playbooks for common detections, then choose in-house hunting, the managed tier or Aurora MDR for after-hours cover.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4
48+ reviews*
79% would recommend
Prevention4.3
EDR depth3.8
Agent footprint4.1
Console and docs3.6
Value for money3.7
5★
40%
4★
37%
3★
15%
2★
5%
1★
3%

Quick poll — what’s driving your evaluation?

Talk to an advisor
Manufacturing
“We ran CylancePROTECT before the sale. Under Arctic Wolf the agent got a new name, and for months the docs used both.”
IT Security Lead
Manufacturing
BFSI
“Prevention catches most things before they run, and Endpoint Defense gave our two analysts something to dig into when it did not.”
SOC Analyst
BFSI
Healthcare
“Thirty days of EDR history covers triage, but our auditors wanted longer, so we export anything we must keep.”
Security Engineer
Healthcare
Media
“Linux build servers and the Mac design team sit on the same tiers as Windows, which made it one rollout, not three.”
Infrastructure Manager
Media
Insurance
“We asked for India-hosted storage during procurement and were offered another region, so legal had to approve the transfer.”
Head of IT
Insurance
Logistics
“Arctic Wolf’s SOC watching the same agent overnight is why we picked it over a cheaper antivirus.”
CISO
Logistics
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the endpoint protection market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Endpoint Protection Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Arctic Wolf Aurora Endpoint SecurityThis page

Quote-only; the former Cylance line, under Arctic Wolf since February 2025.

Grid 02 · The architecture

India Residency × Detection Depth

The grid nobody publishes — how far endpoint data and the console can stay in India vs how deep detection, hunting and retention go.

Deep EDR, offshore dataDeep and India-readyPrevention-led, offshoreLocal but lighter
Arctic Wolf Aurora Endpoint SecurityThis page

No India region; on-prem unconfirmed; 30 days of EDR data.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Aurora Endpoint Security vs the endpoint field

Against CrowdStrike Falcon Insight XDR, SentinelOne Singularity Endpoint, Microsoft Defender for Endpoint, Sophos Intercept X with XDR and Bitdefender GravityZone EDR — on price, retention, recovery, MDR and India.

DimensionArctic Wolf Aurora Endpoint SecurityCrowdStrike Falcon Insight XDRSentinelOne Singularity EndpointMicrosoft Defender for EndpointSophos Intercept X Advanced with XDRBitdefender GravityZone EDR / XDR
What it isEx-Cylance EPP + EDREDR/XDR moduleAutonomous EPP + EDRPlan 1 or Plan 2Intercept X + XDR tierEDR in GravityZone
Deployment and consoleHosted; on-prem unclearCloud console onlySaaS; self-hosted dueDefender portalSophos CentralCloud or on-prem
OS and mobile coverageWin, Mac, Linux, mobileWin, Mac, LinuxWin, Mac, Linux, K8sFive platformsWin, Mac, LinuxWin, Mac, Linux, VMs
Pricing modelQuote, by tierPer device, annualPer endpoint, partnersPer user, or bundledPer user, quotedPer device, packages
Published entry priceNot published$184.99/device/yrFrom $179.99/yr$3 / $5.20 a month~$48/user, reported~$95.89, year one
Included vs add-onEDR is the upper tierSIEM, identity bundledHunting by tierEDR only in Plan 2MDR, storage extraMany paid extras
Telemetry retention30 daysDefault unpublished14 or 90 days180 days in Plan 290 days, 365 paid3 days raw
Detection and huntingBehavioural, ATT&CKForensic timelineStorylineAdvanced huntingData-lake queriesCross-endpoint search
Ransomware recoveryRollback unconfirmedNo auto rollbackOne-click rollbackOneDrive restoreCryptoGuardRansomware Mitigation
IntegrationsFeeds Arctic Wolf SOC260+ marketplace appsAPI-first marketplaceSentinel, Intune, EntraRMM and PSA linksRMM plug-ins
India data regionNo India regionAnnounced, undatedMumbai regionIndia locationMumbai, liveNo India; on-prem
Support and MDRManaged tier, $182.40Falcon CompleteWayfinder MDRDefender ExpertsSophos MDRBitdefender MDR
Lock-in and exitNew owner, renaming30-day refund, FlexAnnual, partner termsMicrosoft-firstData erased at lapseAuto-renew, 50 minimum
Best fitCylance and AW estatesHunting SOCs, one sensorLean team, India dataMicrosoft 365 tenantsSophos mid-marketBudget, on-prem rules
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Aurora Endpoint Security if…

  • ✓You run CylancePROTECT or CylanceOPTICS today and want the supported successor rather than a move to another agent
  • ✓You buy, or plan to buy, Arctic Wolf’s SOC and want the endpoint agent from the same vendor and contract
  • ✓You want prevention-first protection on Windows, macOS and Linux, adding EDR only where someone will use it

Compare alternatives if…

  • ✓Endpoint data must stay in India — SentinelOne and Sophos run Mumbai regions, and India is a Defender for Endpoint location
  • ✓You want to see a price before a sales call — CrowdStrike, SentinelOne and Microsoft all list theirs
  • ✓You need longer telemetry or file rollback — Defender Plan 2 keeps 180 days, and SentinelOne and Sophos document rollback

Do not expect…

  • ✓An Indian storage region or SOC — Arctic Wolf’s Bengaluru site does R&D
  • ✓An endpoint analyst ranking — the IDC and Frost Leader titles are for Arctic Wolf’s MDR
  • ✓More than 30 days of searchable EDR data in Aurora Endpoint Defense

Arctic Wolf Aurora Endpoint Security is one of 47 endpoint protection products TechBag carries. The Endpoint Protection guide narrows them to a shortlist and shows the reasoning. →

Do the math

What do endpoint clean-ups cost you?

Drag the sliders (endpoints; IT-hour cost). Estimates model staff time spent on malware clean-ups, reimaging and chasing endpoint alerts at an assumed 1.5 hours per endpoint a year, with 70% of it removed by prevention-first protection and EDR. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual endpoint clean-up cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Not published: Arctic Wolf prints no price for Aurora Protect or Aurora Endpoint Defense, and both are quoted. The only public endpoint figure is the managed tier, Aurora Managed Endpoint Defense, at $18,240 a year for up to 100 devices as an AWS Marketplace public offer (US). TechBag maps your fleet to a tier first, then quotes in INR with GST.

Aurora Protect

Best for prevention-first fleets

  • AI-led NGAV on Windows, macOS and Linux
  • Memory, script, device and app control
  • Quoted; no public price

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

Aurora Endpoint Defense

Best where someone will hunt

  • Everything in Protect, plus Aurora Focus EDR
  • Behavioural engine, ATT&CK mapping, playbooks
  • 30 days of endpoint data; quoted

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Tier choice

Which devices need EDR in Aurora Endpoint Defense, and which are covered by prevention alone in Aurora Protect?

2
Platforms

Are all the Windows, macOS and Linux versions in your fleet on Arctic Wolf’s supported list for Protect and Focus?

3
Mobile

Do phones and tablets need Aurora Mobile Threat Defense, and is it itemised in the same quote?

4
Data region

Which of the six storage regions will hold your data, and has legal approved endpoint data leaving India?

5
Retention

Are 30 days of EDR data enough for your investigations and audits, or will you export it to keep it longer?

6
Cylance legacy

Are any CylanceOPTICS installs still on 3.2 or 3.3, the Windows versions named in CVE-2024-35214?

7
Operations

Who will hunt and respond: your own team, Aurora Managed Endpoint Defense, or Arctic Wolf’s full Aurora MDR?

8
Licence

Does the quote name the tier, device count, mobile add-on and term? Ask for it in INR with GST.

FAQ

Questions buyers ask

It is Arctic Wolf’s endpoint protection line, built from the Cylance business it bought from BlackBerry. It comes in two tiers: Aurora Protect, the prevention agent once called CylancePROTECT, and Aurora Endpoint Defense, which adds the Aurora Focus EDR agent, once CylanceOPTICS, with 30 days of data.

Ready to evaluate Aurora Endpoint Security?

Model your endpoint count first, or let a TechBag advisor scope a pilot that tests Protect and Endpoint Defense on a mixed Windows, Mac and Linux group.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.