Talk to us
by KaseyaTechBag Intel Page

Kaseya MDR

Your EDR raises alerts at 2 a.m. Someone should be awake to read them — Kaseya MDR, the rebuilt RocketCyber, puts a 24/7 SOC over your endpoints, firewalls and Microsoft 365, working beside the EDR you already run and keeping logs for 400 days.

24/7 SOC over the EDR you already run400 days of logs, US-hostedQuoted per endpoint or in Kaseya 365 Pro

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
Per endpoint; Kaseya prints no figure for standalone MDR or for Kaseya 365 Endpoint Pro
Quote
Retention
Kaseya’s stated log retention for the rebuilt platform, longer than a year of look-back
400 days
Analysts
No Gartner, Forrester or IDC placement was found for Kaseya MDR or for RocketCyber
None
India
Kaseya’s sub-processor list names only US locations for RocketCyber data
US-hosted

Quick answer

Kaseya MDR, formerly RocketCyber, is a 24/7 managed detection and response service relaunched on 28 April 2026 as a rebuild. Analysts in Florida and Ireland watch endpoints, 14 firewall brands and Microsoft 365, and can isolate devices, lock accounts and revoke sessions. It works beside Datto EDR, Defender or SentinelOne, keeps logs for 400 days and is quoted per endpoint. Kaseya lists only US hosting for it. Read more ↓ Show less ↑
Part 01 · Orient

The Kaseya platform family

This page covers Kaseya MDR — formerly RocketCyber, including Managed SOC Services. The rest:

Quick facts

30-second orientation
Product
24/7 MDR over endpoints, firewalls and Microsoft 365; the April 2026 rebuild of RocketCyber
Maker
Kaseya, Miami; majority-owned by Insight Partners, led by CEO Rania Succar since June 2025
Lineage
RocketCyber, bought by Kaseya in February 2021; Managed SOC Services is the same offer
SOC
AI triage first, then human analysts in Florida and Ireland, with direct phone access to them
Response
The SOC isolates devices, locks accounts and revokes sessions; ransomware processes are killed
Telemetry
Kaseya’s agent on Windows, macOS and Linux, plus Datto EDR, Defender, SentinelOne and six more EDRs
Retention
400 days of logs, which Kaseya lists among the rebuild’s new capabilities
Price
Quote only, per endpoint; standalone or in Kaseya 365 Endpoint Pro (50-endpoint minimum for new customers)
India
Kaseya’s sub-processor list gives only US locations for RocketCyber; no Indian hosting region
In India via
TechBag — scoping, EDR fit, a quote with GST and the first incident drill
Part 02 · Learn

Understand MDR before you buy one

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is managed detection and response?

A vendor’s analysts watch your security alerts around the clock and act on real threats, so you need no SOC of your own.

EDR alerts nobody reads at night vs Kaseya MDR — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionEDR alerts nobody reads at nightKaseya MDR
Who reads alerts at 2 a.m.Nobody, until someone checks emailAnalysts in Florida or Ireland, around the clock
Containing a hacked laptopA technician on the phone or on siteThe SOC isolates it remotely
Firewall logsKept on the box and rarely readCollected by syslog and triaged with endpoint data
Evidence for an auditorWhatever the EDR console still holds400 days of searchable logs
Where the work landsAlert emails in a shared inboxPSA tickets with the next steps written in
What it is NOT—A SIEM, SaaS user monitoring, or a published price

The cheapest test is one client: deploy the agent, connect its EDR and firewall, and run a tabletop from alert to closed PSA ticket.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
What collects on the endpoint

Agent

Kaseya MDR agent on each device

Runs on Windows 8.1 and Server 2012 R2 onward, macOS 10.15 to 26 and major Linux distributions; it talks only outbound on port 443 and offers no remote control.

02
What else the SOC can see

Feeds

EDR, firewall and Microsoft 365 feeds

Datto EDR, Defender, SentinelOne and six other EDRs connect by integration; a Windows agent doubles as a syslog collector for 14 firewall brands, and Microsoft 365 links in.

03
Who decides and acts

SOC

AI triage, then human analysts

Kaseya Intelligence triages and correlates alerts at machine speed; analysts in Florida and Ireland validate what is left and take containment actions without waiting for you.

04
Where your team sees the work

Console

Alerts, Analysis and PSA tickets

An alert-centric console with one Analysis timeline across devices, users and IP addresses; incidents land as tickets in Autotask, BMS, ConnectWise Manage or Syncro.

One agent beside your EDR — AI triage first, then analysts in Florida and Ireland who contain and ticket.

Part 03 · Evaluate

Nine capabilities. Detect, respond, operate.

Kaseya MDR puts analysts on your alerts around the clock, without replacing your EDR.

Detect
Event logs

The log events that matter

By default the agent forwards key Windows events, such as cleared audit logs, new scheduled tasks and lockouts, plus sudo and SSH use.

Detect
Breach detection

MITRE-mapped behaviour checks

On Windows and Mac the agent watches for ATT&CK techniques and flags connections to known malicious IPs, command-and-control servers and Tor.

Detect
Firewalls

Syslog from 14 firewall brands

A Windows agent collects syslog from Fortinet, SonicWall, Palo Alto, Sophos, Meraki and others, then adds geo and IP-reputation alerts.

Respond
Containment

Isolate, lock, revoke

Analysts isolate a device, lock an account or revoke sessions themselves; you can also isolate or restore many devices at once from the console.

Respond
Ransomware

Kill the process, cut the host

Kaseya’s own agent logic detects ransomware, kills the process and isolates the endpoint, working alongside the anti-malware you already run.

Respond
Microsoft 365

Tunable Microsoft 365 rules

Microsoft 365 detection and response rules can be customised; confirm the scope, as SaaS user monitoring is sold as SaaS Alerts.

Operate
Analysis

One investigation timeline

Telemetry is normalised and correlated into one searchable timeline of devices, users and IPs, replacing RocketCyber’s per-app pages.

Operate
PSA tickets

Tickets a technician can act on

Analysts write ready-to-action tickets into Autotask, Kaseya BMS, ConnectWise Manage or Syncro, with the remediation steps attached.

Operate
Multi-tenant

Defaults with client overrides

Global defaults apply to every organisation you manage, overrides per client stay visible, and security reports show clients what was done.

See it, don’t just read it

Watch Kaseya MDR in action

Isolating a hacked device, a customer moving from no SOC to 24/7 cover, and the managed SOC under its former name RocketCyber (2023 and 2020).

Kaseya (official)·Short, 2026

How to Stop a Hacked Device From Taking Down Your Network

Forty seconds on spotting a compromised device and isolating it before the attack spreads.

Kaseya (official)·Customer story, 2025

From No SOC to Full Protection - Ark ICT’s Cybersecurity Transformation with Kaseya

Ark ICT on gaining a 24/7 SOC and EDR through Kaseya 365 instead of building its own.

RocketCyber (official)·Overview, 2023

Explore the benefits of RocketCyber Managed SOC for MSPs and their clients.

A 2023 tour of the managed SOC under its former name RocketCyber, made for MSPs and their clients.

RocketCyber (official)·Teaser, 2020

RocketCyber SOC-as-a-Service

A 30-second teaser from 2020 for the SOC service under its former name RocketCyber.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Kaseya MDR

Most MDRs make you switch EDR. Kaseya MDR works with the one you run.

Here’s what genuinely sets it apart — and exactly where it stops.

01

Keep the EDR you already run

The rebuild is designed around third-party EDR: Datto EDR, Microsoft Defender, SentinelOne, Sophos, Bitdefender, Webroot and others connect. You change who reads the alerts, not the agent on every laptop, so leaving later does not strand your endpoint protection.

02

Built for an MSP’s ticket queue

Incidents arrive as tickets in Autotask, Kaseya BMS, ConnectWise Manage or Syncro, and the agent deploys through VSA, Datto RMM, NinjaOne or ConnectWise Automate. Global defaults with per-client overrides keep tenants consistent, and reports show clients what the SOC did.

03

400 days of logs and a phone line

Kaseya keeps 400 days of logs, longer than CERT-In’s 180-day log period, though where they sit is another question. The SOC itself isolates devices, locks accounts and revokes sessions, and you can phone its analysts, so a 3 a.m. incident does not wait for your on-call.

04

Where it stops

No public price, and the rebuild is five months old. Kaseya’s help centre puts SaaS user monitoring in SaaS Alerts, a separate SKU, so get the Microsoft 365 scope in writing. Firewall syslog needs a Windows agent, ARM is unsupported, data is US-hosted, and no analyst ranks it.

The idea
A 24/7 SOC over the EDR you already run
The retention
400 days of logs, hosted in the US
The price
Quote per endpoint, or in Kaseya 365 Pro
Proof, not promises

The numbers behind the platform

400 days
of log retention, which Kaseya lists among the rebuilt platform’s new capabilities
— Vendor
14 firewall brands
whose syslog the Windows agent can collect, from Fortinet and SonicWall to Palo Alto
— Vendor
9 EDR vendors
with documented integrations, including Datto EDR, Microsoft Defender and SentinelOne
— Vendor
2 SOC locations
named by Kaseya at launch: Florida in the US and Ireland in Europe
— Vendor
port 443
the only one the agent uses, outbound; it accepts no inbound connections at all
— Vendor
50 endpoints
the minimum for new Kaseya 365 Endpoint customers; MDR comes in the Pro tier
— Vendor

What your Kaseya MDR rollout looks like

Week 1Model

Map what each client runs

List every client’s endpoints, EDR, firewall and Microsoft 365 tenant, and note any ARM devices the agent cannot cover.

Week 2Decide

Price standalone against the bundle

Get MDR quoted alone and inside Kaseya 365 Endpoint Pro, with endpoint counts, terms and GST written into both versions.

Week 3Pilot

Deploy the agent to one client

Push the agent through your RMM, connect the EDR and Microsoft 365, and point the firewall’s syslog at a Windows agent.

Month 2Prove

Agree authority, then drill it

Set what the SOC may isolate, lock or revoke, wire tickets into your PSA, and run a tabletop from alert to closed ticket.

Month 3Commit

Roll out and report

Extend to every client with global defaults and overrides, tune noisy rules, and send each client its first security report.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.1
38+ reviews*
80% would recommend
Alert quality4.2
Response speed4.3
EDR flexibility4.4
PSA integration4.1
Value for money3.8
5★
42%
4★
38%
3★
13%
2★
5%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
Managed Services
“We kept SentinelOne on every client laptop and only changed who watches it overnight. Nobody had to reinstall anything.”
Security Lead
Managed Services
Managed Services
“The SOC isolated a finance PC at 1 a.m., and the Autotask ticket told my technician exactly what to check that morning.”
Service Desk Manager
Managed Services
Manufacturing
“Pointing our FortiGate syslog at a Windows agent was quick. We wish the Linux agent could collect firewall logs too.”
Network Engineer
Manufacturing
IT Services
“Moving from RocketCyber needed no new agent, though both consoles raised duplicate tickets for about a week.”
MSP Owner
IT Services
BFSI
“Four hundred days of logs answered the auditor’s look-back question. Where those logs are stored was the harder talk.”
IT Manager
BFSI
Healthcare
“Solid service, but we asked twice before the quote showed what the Pro tier adds over Express for our 60 endpoints.”
Head of IT
Healthcare
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the MDR market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag MDR Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Kaseya MDRThis page

Rebuilt in April 2026; quoted per endpoint; no analyst placement.

Grid 02 · The architecture

Telemetry Choice × Response Depth

The grid nobody publishes — how freely the service runs on the EDR, firewalls and cloud you already own vs how far its analysts go once a threat is confirmed.

Deep response, own agentDeep response, any stackOwn-agent watchersOpen feeds, light touch
Kaseya MDRThis page

Nine EDRs and 14 firewall brands; isolate, lock and revoke.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Kaseya MDR vs the MDR field

Against Sophos MDR, Barracuda Managed XDR, N-able Adlumin MDR, Rapid7 Managed Threat Complete and Bitdefender MDR — on telemetry, response, SOC, price, retention, MSP tooling and India.

DimensionKaseya MDRSophos MDRBarracuda Managed XDRN-able Adlumin MDRRapid7 Managed Threat CompleteBitdefender MDR
What it isRocketCyber, rebuiltAgentic SOC + analystsXDR platform + SOCAdlumin’s SOC and XDRMDR on Rapid7’s SIEMService + GravityZone
Whose telemetryIts agent + your EDRBring your own stackVendor-agnostic feedsAdlumin agent firstRapid7 Agent requiredBitdefender’s agent
Surfaces watchedEndpoint, firewall, M365Six layersEndpoint to cloudGrows with the tierEstate via its SIEMEndpoint, plus sensors
Response authorityIsolate, lock, revokeFull removal, no capsAutomated containmentContain, then hand over2 actions, unlimited IRPre-approved actions
SOC and contactFlorida and IrelandGlobal team, no citiesFollow-the-sun SOCPhone in an incident15-min start, contractThree SOCs, 30-min call
Pricing modelPer endpoint, quotedPer user or deviceBuild & Price, quotedThree tiers, quotedPer asset, no log capPlatform in the fee
Published entry priceNot publishedNot publishedNot publishedNot published~$15–22/asset/monthNot published
Included vs add-onSIEM, SaaS Alerts apartIntegrations includedVuln service separateWarranty needs a suiteVM and IR bundledPlatform included
Log retention400 daysNot publishedNot published30 or 90 days13 monthsNot stated
MSP toolingPSA tickets, RMM deployPartner dashboardMSP optionShared SOC consoleDirect-buyer focusPer-customer controls
India storage regionUS-hostedMumbai DC; check MDRMumbai listedNot documentedNo India regionSingapore SOC only
Lock-in and exitYour EDR staysTools stay putTerms not publicLogs are yoursAgent to replacePlatform bundled
Analyst standingNo placementIDC Leader, 2026None citedNone citedFrost Radar LeaderIDC Major Player
Best fitKaseya MSPs, mixed EDRMixed estates, full IRLogs must stay in IndiaN-able MSPsSOC plus scanningGravityZone estates
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Kaseya MDR if…

  • ✓You are an MSP whose clients run different EDRs and you want one 24/7 SOC over all of them, without swapping agents
  • ✓Incidents should land as tickets in Autotask, Kaseya BMS, ConnectWise Manage or Syncro with the next steps written in
  • ✓You already buy Kaseya 365 Endpoint, where the Pro tier carries MDR beside the RMM, EDR and backup

Compare alternatives if…

  • ✓Logs must be stored in India — Barracuda Managed XDR documents a Mumbai option, and Sophos runs a Mumbai data centre
  • ✓You want full incident response written in — Sophos MDR and Rapid7 Managed Threat Complete both state it
  • ✓You need a vulnerability programme too — Rapid7 bundles unlimited InsightVM scanning in its per-asset price

Do not expect…

  • ✓A published price or a rupee quote from Kaseya — everything is quoted per endpoint
  • ✓SaaS user-activity monitoring by default — Kaseya sells that as SaaS Alerts, and correlation as Kaseya SIEM
  • ✓An analyst placement — no Gartner, Forrester or IDC report covers Kaseya MDR

Kaseya MDR is one of 19 managed detection & response products TechBag carries. The Managed Detection & Response guide narrows them to a shortlist and shows the reasoning. →

Do the math

What does reading alerts in-house cost you?

Drag the sliders (endpoints monitored; analyst-hour cost). Estimates model in-house time spent reading and triaging EDR, firewall and Microsoft 365 alerts, at an assumed 1.5 hours per endpoint a year, with 70% of it taken over by a managed SOC. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual alert-triage cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Not published. Kaseya prints no price for Kaseya MDR and asks buyers to request a demo. It is quoted per endpoint, either standalone or inside Kaseya 365 Endpoint Pro, the bundle tier that adds MDR to the RMM, Datto EDR and AV, third-party patching and endpoint backup; the Express tier leaves MDR out, and new bundle customers start at 50 endpoints. Existing RocketCyber customers move across with no price increase, per Kaseya. TechBag lays the two quotes next to each other and adds GST.

Kaseya MDR standalone

Best for MSPs keeping their own EDR and RMM

  • Quoted per endpoint; no list price
  • Works with Datto EDR, Defender, SentinelOne and more
  • Kaseya SIEM and SaaS Alerts are separate SKUs

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

Kaseya 365 Endpoint Pro

Best for buying the SOC with RMM, EDR and backup

  • Quoted; 50-endpoint minimum for new customers
  • MDR is in Pro only; Express leaves it out
  • Bundles the RMM, Datto EDR and AV, and backup

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Coverage

Which surfaces must the SOC watch — endpoints, firewalls, Microsoft 365 — and is SaaS user activity in or out?

2
EDR

Is every client’s EDR on Kaseya’s integration list: Datto, Defender, SentinelOne, Sophos, Bitdefender or others?

3
Devices

Any ARM machines, Raspberry Pis or Linux boxes expected to collect syslog? The agent will not cover them.

4
Authority

What may the SOC do without asking — isolate, lock accounts, revoke sessions — and who approves anything else?

5
Data location

Kaseya lists only US hosting; does any client contract, regulator or insurer require logs to be kept in India?

6
Retention

Is 400 days enough for your auditors and insurers, and can logs be exported before the contract ends?

7
Migration

Coming from RocketCyber? Plan for both consoles running in parallel and duplicate PSA tickets for a while.

8
Licence

Standalone or Kaseya 365 Endpoint Pro? New bundle customers start at 50 endpoints; ask for both quotes with GST.

FAQ

Questions buyers ask

Kaseya MDR is a 24/7 managed detection and response service. An agent on each Windows, macOS or Linux device, plus feeds from your EDR, firewalls and Microsoft 365, reach a SOC where AI triages alerts and analysts in Florida and Ireland investigate and contain real threats.

Ready to evaluate Kaseya MDR?

Check every client’s EDR and firewall against Kaseya’s integration list first, or let a TechBag advisor get MDR quoted standalone and inside Kaseya 365 Endpoint Pro.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.