Overview
Taegis XDR helps reduce the noise so you can identify more threats faster. We apply knowledge from 20+ years of attack and threat data plus 1400+ incident response engagements performed in the past year to recognize adversary behavior. This expertise is applied to your environment through behavioral analytics to detect the stealthiest of threat actor tactics with Tactic Graphs™. You'll see the full story of your endpoint, network and cloud activity in a single dashboard that makes event correlation easy. XDR operationalizes threat intelligence by automatically correlating our knowledge of the threat landscape with your security telemetry and built-in threat intelligence that's continuously updated.
Taegis XDR allows your security operations teams to respond to security incidents with greater confidence. With capabilities such as extended log retention, search query, user-defined reporting and custom use case support, security analysts gain more ability to actively investigate and proactively hunt for threats in your environment. With Ask an Expert live chat, your security team has 24x7 access to our expert analysts. As a result, XDR can easily replace your current SIEM giving you advanced threat detection as well as additional SIEM capabilities to gain actionable insights into malicious activity. Our goal is to give you enough business and security context to make sense of an investigation and take the right action.
Secureworks detects and responds to identity threats that bypass traditional identity security controls, protecting against 100% of MITRE ATT&CK Credential Access techniques. Taegis™ IDR, an add-on designed to improve your security posture, continuously monitors your environment for identity misconfigurations and risks, while also providing dark web intelligence on compromised credentials. Uncover identity risks in under 90 seconds compared to days with legacy solutions and benchmark the reduction of your attack surface over time.
Learn more at https://www.secureworks.com/products/xdr and https://www.secureworks.com/products/idr
Highlights
- Advanced Analytics
- Accelerated Investigation & Response
- Quickly Detect and Respond to Identity Attacks
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Security credentials achieved
(1)

Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/12 months |
|---|---|---|
TDR - 1000 Endpoints | Price per monitored endpoint, 1000 endpoints | $43,000.00 |
Custom Pricing | Custom pricing w/terms via Private Offer | $100,000.00 |
IDR Add-on Custom Pricing | Custom pricing w/terms via Private Offer | $16,500.00 |
Taegis MDR Combo | 10,001 to 25,000 Endpoints | $550,055.00 |
Penetration Test: External: Small | Penetration Test: External: Small | $9,280.00 |
Vendor refund policy
N/A
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Vendor resources
Support
Vendor support
Taegis™ XDR is supported through a web portal, live chat and live agent (telephone) support.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
FedRAMP
GDPR
HIPAA
ISO/IEC 27001
PCI DSS
SOC 2 Type 2
Standard contract
Customer reviews
Centralized log analysis has improved threat detection and now streamlines our incident response
What is our primary use case?
My main use case for Secureworks Taegis XDR is ingesting logs from all our resources, so we're using it as a SOC.
For example, in our SOC operations, we ingest logs from all our security providers; let's take an example of a firewall using Fortinet. We ingest all the firewall logs to Secureworks Taegis XDR , which then reviews these logs, picks up any malicious activity or abnormalities in the events, and notifies us.
The main purpose of using Secureworks Taegis XDR is as a SOC, and we have playbooks and connectors that help us with remediating risks with the endpoints; it also integrates with the antivirus, which is CrowdStrike. Secureworks Taegis XDR helps us to detect and remediate any vulnerabilities.
What is most valuable?
In my experience, the best features Secureworks Taegis XDR offers include advanced analytics, which provides an in-depth overview of incidents or events. In case an incident happens, we can go to Secureworks Taegis XDR, check all the logs, as it ingests and correlates all logs and gives us recommendations. It now has AI, which helps with recommended steps we need to take regarding incidents, and the Dell team is always available to look into and investigate incidents when we are unavailable or it's out of office hours.
Regarding features, integration stands out; Secureworks Taegis XDR is integrated with major antivirus security platforms such as CrowdStrike, so it ingests every log from CrowdStrike. If CrowdStrike misses anything, we're confident that Secureworks Taegis XDR will pick it up, automatically creating a ticket and informing us. In critical situations or out of office hours, we get notified or receive a call from the Secureworks Taegis XDR team. It's a very popular and helpful platform for reviewing logs, significantly reducing manpower. Going through all the logs to find abnormalities is very time-consuming, but Secureworks Taegis XDR does it for us, which is the main advantage.
Secureworks Taegis XDR has positively impacted our organization by improving detection rates and reducing our time; as I mentioned, it saves us from manually going through all the logs, which is not practical. Instead, Secureworks Taegis XDR correlates logs from the different security vendors we use, makes recommendations, and detects any abnormalities in events or issues; this is very time-saving for us.
Since using Secureworks Taegis XDR, our organization has definitely saved time; initially, we were manually going through logs to find abnormalities in events, and if we found any, we had to conduct an in-depth investigation through all platforms. With Secureworks Taegis XDR, all logs are in one place, so we just have to look into it and see what went wrong; it saves a lot of time.
What needs improvement?
At this point, Secureworks Taegis XDR is doing everything intended, so I don't have any recommendations for improvements.
Regarding Secureworks Taegis XDR's AI capabilities, I don't see any governance and security framework details or governance details within the platform.
If Secureworks Taegis XDR could integrate with more tools such as Jira —although it has a limited current integration—that would be great.
For how long have I used the solution?
I have been using Secureworks Taegis XDR for about four to five years now.
What do I think about the stability of the solution?
Secureworks Taegis XDR is very stable.
What do I think about the scalability of the solution?
As our organization grows and adds more devices and data sources, I notice no challenges with Secureworks Taegis XDR handling the increased workload; although we had to make some changes as part of the contract, we are a small organization, so I haven't seen any issues when adding a few devices.
How are customer service and support?
Customer support for Secureworks Taegis XDR is not that bad; they are reachable but not super efficient.
Which solution did I use previously and why did I switch?
Previously, we didn't use any SOC; we were using CrowdStrike as an antivirus platform, so there was no SOC before Secureworks Taegis XDR.
How was the initial setup?
My advice for others looking into using Secureworks Taegis XDR is that it's very much reliable; you can run it on a public cloud, private cloud, or, as we do, on-premises. It's easy to install and deploy the collectors, and once we start using it, not much maintenance is needed, as all collector updates are managed by the Secureworks Taegis XDR team. We only need to log in, check the logs, and it flags anything wrong or malicious by giving severity ratings to each event or incident, which allows us to prioritize our investigations.
What's my experience with pricing, setup cost, and licensing?
I'm not sure about the pricing, setup cost, and licensing; it's managed by the Head of IT.
Which other solutions did I evaluate?
Before choosing Secureworks Taegis XDR, I think we evaluated Splunk, but ultimately decided to go with Secureworks Taegis XDR.
What other advice do I have?
Regarding the accuracy and reliability of Secureworks Taegis XDR's AI capabilities, accuracy is above 90-95 percent, and it is very much reliable. I would rate this review a 9 out of 10.
AI-driven triage has transformed my alert investigations and now simplifies incident reporting
What is our primary use case?
The main use for Secureworks Taegis XDR is to triage alerts from low to critical alerts and analyze and investigate different kinds of alerts from the platform. As a SOC analyst, Secureworks Taegis XDR is helpful to check every detection from the client's environment. It helps the SOC analyst to analyze the specific alert and provide more specific or comprehensive investigation or technical reports to clients.
I investigated a case wherein there was an impossible travel of a user or an account while using Secureworks Taegis XDR . The user logged in from different countries, then another country for the second time of his login. Secureworks Taegis XDR helped me to check which countries the user had logged in from and provided more details such as the time of login, the IP address that the user used, and more.
Secureworks Taegis XDR allows us to check or monitor every data collector we are managing and also the users or the endpoints that we are managing in that platform. We can verify if the endpoints or computers of the company have endpoint sensors installed in their endpoints so that we can ensure that their computers are in a managed asset.
What is most valuable?
I think the best features of Secureworks Taegis XDR simplify the triaging method for SOC analysts. The SOC analyst can check whether the alert is low, high, or critical. Secureworks Taegis XDR auto-triages the specific alerts, and that is the best feature.
The auto-triage feature of Secureworks Taegis XDR makes my workflow easier and efficient. It helped me to shorten the time of responding to every alert and also make my activities productive. I can manage everything that I need to check every alert and detection. This shortens my time of triaging and investigating numerous alerts.
Following the SLA or Service Level Agreement with the clients, we have plenty of time to deeply investigate or analyze the specific alert since using Secureworks Taegis XDR. Since the triaging reduced or the time of investigating is reduced because of the auto-triage of Secureworks Taegis XDR, this positively changes our point of view of investigating alerts and makes our investigation faster.
We manage a lot of alerts and with Secureworks Taegis XDR, we can scrub and triage or decide if the alerts are false positive or true positive in a faster way.
What needs improvement?
I suggest that we can check also the data sources of every data collector so that we can be informed of what data source the alerts came from and add that to our investigation.
The efficiency or the smooth navigation of the website or the application can be improved in Secureworks Taegis XDR. We can reduce lag or slow navigation of the tool.
For how long have I used the solution?
I used Secureworks Taegis XDR last year for about less than a year.
What do I think about the stability of the solution?
Secureworks Taegis XDR is a bit stable in my experience.
What do I think about the scalability of the solution?
Secureworks Taegis XDR can handle increasing workload for us users.
How are customer service and support?
I had a good experience with Secureworks Taegis XDR customer support. They are reachable and they reply in a prompt manner. I have no problem with them.
Which solution did I use previously and why did I switch?
I used Trend Micro XDR before using Secureworks Taegis XDR.
I did not really switch from Trend Micro XDR to Secureworks Taegis XDR. I just had the opportunity to go to another company where they use an XDR platform.
What other advice do I have?
Secureworks Taegis XDR has been dependable for me regarding its AI capabilities in terms of accuracy and reliability of its output.
The Taegis XDR AI is helpful to analysts such as myself to check and to be more comprehensive of every detection and alert.
It stands out because it is very comprehensive for users or analysts to learn or to analyze the specific alerts. It is also user-friendly or newbie-friendly. New analysts can understand faster how the triaging and investigating an incident is conducted. What keeps it from being a perfect 10 is the occasional lag issues on the platform.
You can also first try to check their certifications regarding Secureworks Taegis XDR.
My overall review rating for Secureworks Taegis XDR is 9 out of 10.
Easy-to-Use OpenXDR with Great Performance, Support, and Taegis AI
Improved network protection has secured our servers and monitors web and application traffic
What is our primary use case?
I use Secureworks Taegis XDR within my organization primarily to secure our network infrastructure so that none can access our servers and our devices in the LAN portion.
What is most valuable?
I appreciate that they introduced the NDR feature and zero-day protection in this product.
The running interface is good enough; I can see the web traffic, web monitor, and application monitor traffic here, so it is adequate for now.
What needs improvement?
Till now, I have not seen any weak point that needs to be improved in Secureworks Taegis XDR .
I think that since the technology is becoming upgraded, it will be good for Sophos to include more features in future updates of this solution.
Secureworks Taegis XDR is a good product, but it should include AI technology.
For how long have I used the solution?
I have been working with Sophos for three years, and before that I was working in network-related roles with other devices, including Cisco devices and Chinese Huawei devices such as Huawei routers and Huawei switches.
What do I think about the stability of the solution?
Till now, we are just using the firewall and not any other devices for analytics tools in this product.
What do I think about the scalability of the solution?
I have not integrated any third-party tools in our network involvement, so there are no issues during integration.
How are customer service and support?
They are very helpful regarding technical support of Sophos.
I can definitely give a rating of 10 for the support because I always receive prompt service from them.
Which solution did I use previously and why did I switch?
In our country, we have an authorized vendor from Sophos, and we are purchasing Sophos devices from them.
How was the initial setup?
I say it is easy to deploy Secureworks Taegis XDR .
Two people should be good to complete the implementation.
It requires a couple of days to configure it, then a couple of days to test the scenario, such as what will be the outcome if I deploy the firewall in a running environment and running infrastructure, what will be the output?
The entire deployment took that long.
What about the implementation team?
I took part in the deployment, and in my company, I deployed XGS 4300 in high availability feature.
What was our ROI?
Definitely, Secureworks Taegis XDR is cost effective for the long run since the product is at a lower cost rather than other brands.
What's my experience with pricing, setup cost, and licensing?
I think Sophos product is comparatively the best price rather than other brands when considering the licensing cost for Secureworks Taegis XDR.
Which other solutions did I evaluate?
I have not worked yet with product Sophos Labs Intellex.
I have not worked with Sophos Cybersecurity as a service.
What other advice do I have?
I have not used the threat hunting feature of Secureworks Taegis XDR.
I have not used customizable workflows in Secureworks Taegis XDR.
My overall review rating for this product is 8.5.