by IruTechBag Intel Page

Iru EDR

Your Macs already run one agent for management. Security shouldn’t need a second one — Iru EDR switches detection on inside the Iru agent your Macs and PCs already run — behavioural Protect mode on macOS, file scanning in Detect mode on Windows.

EDR inside the Iru agentProtect mode on Mac, Detect on WindowsQuote-only; US or EU tenants

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
Iru publishes no EDR price; contracts are annual and billed once a year
Quote
Windows
File-based scanning that reports malware and PUPs; quarantine and behaviour rules are Mac-only
Detect only
Analysts
Iru announces no Gartner Magic Quadrant placement for any of its products
None announced
India
Tenants are pinned to AWS in the United States or Germany; no Indian region is offered
US or EU

Quick answer

Iru EDR (formerly Kandji EDR) is an add-on licence that turns the Iru management agent into endpoint detection and response for Mac and Windows. On a Mac it pairs file-based and behavioural detection through Apple’s Endpoint Security framework, and Protect mode kills the process and quarantines the file; on Windows it is file-based scanning in Detect mode only. It is quoted on annual contracts, and tenants live in the US or the EU, not India. Read more ↓ Show less ↑
Part 01 · Orient

The Iru platform family

This page covers Iru EDR — the detection and response add-on for Mac and Windows. The rest:

Quick facts

30-second orientation
Product
Endpoint detection and response for Mac and Windows, delivered to the Iru agent as a Library Item
Maker
Iru, Inc., renamed on 22 October 2025; US-based (Miami and San Diego), CEO Adam Pettit
Licence
A separate add-on on top of Iru Endpoint Management, counted per device by platform
Price
Quote-only; annual commitment billed annually, after a free 14-day trial
On macOS
File-based plus behavioural detection; Protect mode terminates processes and quarantines files
On Windows
File-based detection in Detect mode: malware and PUPs are reported, not quarantined
Left out
No Linux agent, no phones or tablets, no rollback and no managed detection service
SIEM feed
Detection data exported to an Amazon S3 bucket that your SIEM reads from
India
No Indian region: tenants run on AWS in the US or Germany; support is 24/5
In India via
TechBag — Mac-versus-Windows scoping, quote in INR with GST, trial set-up
Part 02 · Learn

Understand MDM-native EDR before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is MDM-native EDR?

Detection and response that runs inside the device-management agent you already have, licensed as an add-on instead of a second product.

A management agent plus separate antivirus vs Iru EDR — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionA management agent plus separate antivirusIru EDR
Agents on a MacOne to manage it, one more for securityOne Iru agent doing both jobs
A malicious Mac processNoticed after the damage is doneEnded and its file quarantined in Protect mode
A suspect laptopSomeone asks the user to unplug itIsolated from the network from the console
USB sticks on the Mac fleetA written policy nobody enforcesAccessory & Storage Access rules
Detection logs for the SOCScreenshots pasted into a ticketAn Amazon S3 export your SIEM ingests
What it is NOT—Windows behaviour rules, Linux, rollback or MDR

The cheapest test is the free trial: put ten Macs in Protect mode, allow-list your in-house tools, and see what the engine flags in two weeks.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
What runs on each Mac or PC

Agent

The Iru agent already on the device

The agent that applies settings and updates for Iru Endpoint Management also carries the detection engine, so switching EDR on needs no second installer on the machine.

02
How detection policy is assigned

Library Item

The EDR Library Item

Detection settings travel as a Library Item scoped through Blueprints; Iru’s documentation says the EDR add-on licence is required before that item can be used at all.

03
Where Mac threats are judged

macOS engine

Endpoint Security framework sensor

On macOS the engine reads events from Apple’s Endpoint Security framework and judges both files and process behaviour; Protect mode then ends the process and quarantines the file.

04
What a Windows PC receives

Windows engine

File-based scanner in Detect mode

Windows 11 machines under Iru get file-based scanning that flags malware and potentially unwanted programs, with no behavioural layer and no automatic quarantine of what it finds.

One agent for management and detection — an EDR Library Item decides whether a Mac protects or a PC just reports.

Part 03 · Evaluate

Six capabilities. Detect, respond, control.

Iru EDR adds detection and response to the agent that already manages your Macs and Windows PCs.

Detect
Behavioural

Process behaviour on the Mac

Mac detection looks at what a running process does as well as at the file on disk, using events from Apple’s Endpoint Security framework.

Detect
File scanning

Malware and PUPs on both systems

File-based detection runs on macOS and Windows alike and raises known malware and potentially unwanted programs it finds on a device.

Respond
Protect mode

Terminate and quarantine on macOS

Put Macs in Protect mode and a detected process is stopped and its file moved to quarantine; Windows devices stay in Detect mode and only report.

Respond
Isolation

Take a Mac off the network

Device isolation is listed among the Mac response actions, so a suspect laptop can be cut off from the network while someone investigates it.

Control
Allow and block

Exceptions you write yourself

Allow and block list entries let admins stop an in-house tool from being flagged and make sure a banned binary is always treated as a threat.

Control
Device control

Rules for USB and storage

Accessory & Storage Access controls set what removable media a Mac will accept, managed from the same console as the rest of the policy.

See it, don’t just read it

Watch Iru EDR in action

Iru’s 2025 overview of the EDR add-on, a 2026 customer session on reaching ISO 27001 with endpoint security, and a 2025 episode on Mac malware with Patrick Wardle. All from Iru’s official channel.

Iru (official)·Product overview, 2025

Iru Endpoint Detection & Response

Iru’s own walkthrough of the EDR add-on, recorded for the October 2025 launch of the Iru name.

Iru (official)·Virtual event, 2026

How Bindplane Achieved ISO 27001 with Endpoint Security | Iru Virtual Event

A customer session on using endpoint security controls as evidence on the way to an ISO 27001 certificate.

Iru (official)·Episode, 2025

Mac Malware: The Cat & Mouse Game with Patrick Wardle | Patch Me If You Can™

A conversation with Mac security researcher Patrick Wardle on how macOS malware and its defenders keep adapting.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Iru EDR

Most security tools arrive as a second install on every Mac. Iru EDR runs inside the management agent.

Here’s what genuinely sets it apart — and exactly where it stops.

01

Detection without a second agent

Iru EDR is not another installer to push. The agent that already enforces settings and OS updates on your Macs and Windows PCs takes on the detection engine once the add-on is licensed and the EDR Library Item is assigned, so an existing Iru Endpoint Management customer turns it on from the console the team already uses.

02

Mac depth comes first

On macOS Iru combines file and behavioural detection on Apple’s Endpoint Security framework, and Protect mode ends the offending process and quarantines its file. Allow and block lists, device isolation and removable-media rules sit alongside. Planning Center, per Iru’s customer story, moved to it after running SentinelOne.

03

Claims to test before you trust

Iru’s product page says the engine stops 2.3x more zero-day exploits and uses 22% fewer resources, yet it names no AV-TEST run, MITRE evaluation or other test behind either number. Treat both as marketing, and let a pilot on your own Macs show the detection results and CPU load you will actually live with.

04

Where it stops

On Windows the engine only scans files in Detect mode, reporting malware and PUPs without ever quarantining them, and no behaviour rules apply. There is no Linux agent, no mobile coverage, no file rollback and no MDR service. Each tenant is hosted in America or Germany, and help desks answer 24/5 rather than around the clock.

The idea
EDR inside the agent you already run
The residency
US or EU tenants; no Indian region
The price
Quote-only, annual; 14-day trial
Proof, not promises

The numbers behind the platform

2 systems
covered by the EDR add-on, macOS and Windows; Linux, iOS and Android are not
— Vendor
14 days
of free trial before the annual EDR contract begins
— Vendor
99.9%
platform availability Iru commits to, crediting 2.5% of the monthly fee per hour down
— Vendor
5 days
a week of 24-hour support, from Sunday 22:30 to Saturday 01:00 UTC
— Vendor
6000+ teams
using Iru across its product line, by Iru’s About page in 2026
— Vendor
2 regions
where a tenant can live, the US or the EU (AWS Germany); India is not one
— Vendor

What your Iru EDR rollout looks like

Week 1Model

Count Macs and PCs separately

List how many Macs and Windows 11 machines need cover, because Windows gets Detect mode only and is licensed apart.

Week 2Pilot

Start the 14-day trial

Assign the EDR Library Item to a pilot Blueprint of IT and developer Macs, plus a few PCs, while Protect mode stays off.

Week 3Prove

Tune exceptions, then protect

Add allow-list entries for in-house tools the engine flags, then move pilot Macs into Protect mode and watch the queue.

Month 2Decide

Wire up the SOC feed

Send detections to an Amazon S3 bucket, point the SIEM at it, and decide who answers alerts outside 24/5 support.

Month 3Commit

Roll out and lock media

Extend EDR to the whole fleet, apply storage access rules to sensitive teams, and sign the annual contract in INR.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4
38+ reviews*
78% would recommend
Mac detection4.3
Same-agent rollout4.5
Windows coverage3.0
Response options3.6
Value for money3.8
5★
38%
4★
40%
3★
15%
2★
5%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
SaaS
“We already ran Iru on 400 MacBooks, so EDR was one Library Item and a licence change. No new agent, no rollout project.”
IT Manager
SaaS
Media
“Protect mode killed an infostealer a designer pulled in with a cracked font tool, and the file was in quarantine before lunch.”
Security Engineer
Media
Fintech
“Our 30 Windows laptops only get Detect mode. It tells us about malware but someone still has to clean each one up by hand.”
Systems Administrator
Fintech
Consulting
“Blocking USB storage on finance Macs from the same console we use for updates closed an audit finding in an afternoon.”
Head of IT
Consulting
E-commerce
“We pull detections from the S3 export into our SIEM. Plan the bucket and the parser early; it is not a native connector.”
SOC Analyst
E-commerce
EdTech
“Support hours suit us in Bengaluru on weekdays, but nobody answers on a Saturday night, so we keep our own on-call rota.”
IT Lead
EdTech
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the endpoint protection market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Endpoint Protection Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Iru EDRThis page

Add-on to Iru’s MDM; quote-only, annual.

Grid 02 · The architecture

Platform Breadth × Response Depth

The grid nobody publishes — how many operating systems the agent fully covers vs how far it goes from an alert into containment and recovery.

Deep on one platformFull-estate respondersNarrow and lightWide but report-led
Iru EDRThis page

macOS and Windows; Protect mode and isolation on Mac only.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Iru EDR vs the endpoint protection field

Against Jamf Protect, CrowdStrike Falcon Insight XDR, SentinelOne Singularity Endpoint, Microsoft Defender for Endpoint and Hexnode XDR — on platforms, Mac depth, response, price, managed service and India.

DimensionIru EDRJamf ProtectCrowdStrike Falcon Insight XDRSentinelOne Singularity EndpointMicrosoft Defender for EndpointHexnode XDR
What it isAdd-on EDR, Mac-firstMac-native securityEDR grown into XDRAutonomous EPP + EDREPP + EDR in two plansXDR on a UEM agent
Deployment and agentSame agent as MDMAgent beside Jamf ProOne Falcon sensorOne agent, cloud consoleBuilt into WindowsRides the UEM agent
Platforms coveredmacOS and Windows 11Mac, plus mobile MTDWindows, Mac, LinuxWindows, Mac, LinuxFive systemsLinux not documented
macOS detectionFile + behaviouralMITRE-mapped analyticsFull Falcon on MacBehavioural AI on MacPresent, Windows-ledSeverity-scored alerts
Windows and Linux depthWindows: Detect modeNot coveredThe same EDR everywhereFull EDR, all threeWindows is the home turfNot documented
Response and rollbackMac: kill, isolateRemediate through ProRTR, no rollbackOne-click rollbackAIR, OneDrive restoreIsolate, restrict, wipe
Pricing modelPer device, annualPer device, in plansPer device, per yearPer endpoint, per yearPer user, per monthPer device, per month
Published entry priceNot publishedBundled, $12.50 a Mac$184.99/device/yearFrom $179.99/year$3 / $5.20 a month$5.50/device/month
Included vs add-onNeeds the MDM licenceMobile is in the boxXDR at no extra costMobile and MDR extraP1 lacks EDRRequires Hexnode UEM
Managed service and supportNo MDR; 24/5 supportNo MDR on this pageFalcon Complete MDRMDR as an add-onExperts needs E5No managed service
SIEM and integrationsS3 exportUnified log streaming10 GB/day ingestStoryline correlationNative SentinelInside the UEM console
India data regionUS or EU onlyNo Indian hostingAnnounced, not liveMumbai regionIndia datacentresNot verified
Lock-in and exitTied to Iru’s agentBest beside Jamf ProIndependent of MDMIndependent of MDMMicrosoft-shapedTied to Hexnode UEM
Best fitIru-managed Mac fleetsJamf Pro shopsTeams that huntRollback + India dataMicrosoft 365 E5 estatesHexnode UEM estates
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Iru EDR if…

  • ✓Your Macs already run Iru Endpoint Management and you want detection switched on in that same agent
  • ✓macOS is most of the fleet, and Protect mode, isolation and USB rules on Macs cover what you need
  • ✓A 14-day trial on real devices matters more to you than a published list price

Compare alternatives if…

  • ✓Windows or Linux machines need full behavioural EDR — CrowdStrike, SentinelOne and Defender cover them in depth
  • ✓You want ransomware rollback or an Indian data region — SentinelOne offers both, per TechBag’s guide
  • ✓Nobody will watch alerts at night — Falcon Complete, SentinelOne MDR or Defender Experts supply a SOC

Do not expect…

  • ✓Automatic quarantine on Windows, or any Linux, iPhone or Android coverage
  • ✓An Iru-run SOC, file rollback, or support outside the 24/5 window
  • ✓Independent test results behind the 2.3x zero-day and 22% resource figures

Iru EDR is one of 47 endpoint protection products TechBag carries. The Endpoint Protection guide narrows them to a shortlist and shows the reasoning. →

Do the math

What do a second agent and manual clean-up cost you?

Drag the sliders (Macs and PCs covered; IT staff-hour cost). Estimates model the hours spent on each device a year chasing suspicious files, rebuilding infected laptops and babysitting a second security agent, assumed at 1.5 hours, of which 70% is assumed to go once detection lives in the management agent. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual malware clean-up cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Quote only. Iru publishes no EDR price: the add-on is licensed per device by platform on top of Iru Endpoint Management, on an annual contract billed annually, after a free 14-day trial. Per-device figures on review sites predate the current quote-only terms. TechBag counts Macs and Windows PCs separately first, then quotes in INR with GST.

EDR on macOS

Best for Apple-first fleets

  • File and behavioural detection
  • Protect mode: kill and quarantine
  • Isolation, allow/block lists, USB rules

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

EDR on Windows

Best for a few PCs beside the Macs

  • File-based scanning in Detect mode
  • Reports malware and PUPs; no auto-quarantine
  • Windows 11 24H2 or later under Iru

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Fleet mix

What share of devices are Macs? Windows gets file scanning in Detect mode only, and Linux has no agent at all.

2
Windows version

Are your PCs on Windows 11 24H2 or later? Older Windows releases cannot be enrolled in Iru management.

3
Response model

Who cleans up a Windows detection by hand, given that nothing on Windows is quarantined automatically?

4
Night cover

Iru runs no MDR and support is 24/5; which SOC or on-call rota answers an alert at 2 a.m. on a Sunday?

5
SIEM

Can your SIEM read an Amazon S3 export, and who builds and maintains the parser for Iru’s detection data?

6
Data location

Is a US or EU tenant acceptable to your DPDP and customer contracts, since Iru offers no Indian region?

7
Vendor claims

Will the pilot measure detection and CPU load yourself rather than relying on Iru’s 2.3x and 22% figures?

8
Agent hygiene

Is every agent at 4.7.5 or later, the build that fixed CVE-2026-39118, and kept current from then on?

FAQ

Questions buyers ask

Iru EDR is the endpoint detection and response add-on to Iru Endpoint Management. It runs inside the same Iru agent and is switched on with an EDR Library Item. Macs get file and behavioural detection with a Protect mode; Windows PCs get file scanning. The product took the Iru name when Kandji renamed itself on 22 October 2025.

Ready to evaluate Iru EDR?

Count your Macs and Windows PCs first, or let a TechBag advisor run the 14-day trial on a pilot group and get the add-on quoted in INR.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.