UnderDefense MAXI is a managed detection and response platform from UnderDefense that runs a 24/7 SOC and agentic AI triage on top of a customer's own EDR, SIEM and cloud tools rather than its own agent, starting at $11 per endpoint per month (checked September 2026) for the Standard tier.
Listing updated . Checked by MSP Software .
UnderDefense MAXI is a managed detection and response platform from UnderDefense, a cybersecurity company established in 2017 with offices in New York, Jacksonville, Krakow and Lviv. MAXI pairs a 24/7 human-staffed SOC with an agentic AI layer that UnderDefense says handles most first- and second-line alert triage automatically, correlating signals from a customer's existing endpoint, network, identity, cloud, SaaS and Kubernetes tools rather than requiring UnderDefense's own telemetry agent. UnderDefense publishes a target of around two minutes to triage and containment within 15 minutes, and includes response actions such as host isolation inside the core MDR subscription rather than billing them as a separate incident response retainer, though a dedicated, higher-tier incident response retainer with faster remote or onsite SLAs is sold as a separate add-on for organisations that want it.
MAXI is built to be vendor-agnostic: UnderDefense lists more than 250 integrations covering endpoint tools such as CrowdStrike, SentinelOne and Microsoft Defender, SIEM platforms including Splunk and Microsoft Sentinel, identity providers, and ticketing systems such as ServiceNow and Jira, and positions this against MDR rivals that push customers onto a single proprietary agent. The platform also runs compliance automation with evidence kits for frameworks including SOC 2, ISO 27001, HIPAA, PCI DSS and DORA, and a multi-tenant console that lets a managed security provider run several client environments from one place, with white-labelling for MSPs and MSSPs that want to resell the service under their own brand.
Pricing starts at $11 per endpoint per month for the Standard tier, which UnderDefense publishes as a baseline rate; Enhanced and Professional tiers that add cloud, SaaS, email and managed SIEM detection are quoted based on infrastructure scope (checked September 2026). UnderDefense does offer a free, self-serve entry tier and a 14-day trial of the full platform with no credit card required, which is unusual among MDR providers that typically require a sales call before any hands-on access. MAXI suits an MSP or MSSP that already runs its own EDR, SIEM or cloud security tooling and wants a 24/7 SOC and bundled incident response layered on top without switching agents, and one that needs audited compliance evidence alongside detection. It suits a buyer wanting to compare a very simple published baseline price, or a very small shop wanting a single all-in-one agent rather than an integration-first platform, less well.
UnderDefense MAXI stands out for publishing a baseline starting price and offering a real free, self-serve tier, which suits an MSP that already has EDR or SIEM tooling in place and does not want to rip it out for a single-vendor platform such as CrowdStrike or Arctic Wolf. The response actions and compliance evidence bundled into the core MDR subscription are worth comparing directly against Huntress or Field Effect MDR, which typically price incident response and compliance separately. Because the Enhanced and Professional tiers require custom quotes, get a written quote scoped to your actual endpoint and log volume before committing, and confirm exactly which integrations and compliance frameworks are covered at the tier you would actually buy, not just the baseline $11 rate.
| Feature | Supported | Note |
|---|---|---|
| 24-hour human-staffed SOC | yes | 24/7 human-staffed SOC backed by 120+ security engineers. |
| Managed threat response and isolation | yes | Defined ~2-minute triage and containment within 15 minutes, including automated host isolation. |
| Own endpoint telemetry agent | no | Vendor-agnostic by design: runs on the customer's own EDR (CrowdStrike, SentinelOne, Microsoft Defender, etc.) rather than an UnderDefense-built agent. |
| Identity threat detection | yes | Identity is listed as one of the monitored layers alongside endpoint, network, cloud and SaaS. |
| Network monitoring | yes | Network is included among the covered environments. |
| Microsoft 365 monitoring | yes | Microsoft 365 security monitoring is listed as a MAXI capability. |
| Monthly threat reporting | unknown | Vendor describes dashboards and a 30-day onboarding impact report; a specifically monthly cadence is not stated. |
| PSA integration for ticketing | yes | Ticketing/ITSM integrations confirmed (ServiceNow, Jira, PagerDuty/OpsGenie); no MSP-specific PSA such as ConnectWise or Autotask is named on the integrations page. |
| Multi-tenant console | yes | Multi-tenant console lets a partner manage multiple client environments and dashboards from one place. |
| Works with third-party EDR | yes | Managed EDR service explicitly tunes and manages CrowdStrike, SentinelOne or Microsoft Defender. |
| Dedicated incident response | yes | Response and containment are included in core MDR; a separate, higher-tier incident response retainer is also sold for deeper crisis engagements. |
UnderDefense publishes a starting price of $11 per endpoint per month for its Standard MDR tier (checked September 2026). Enhanced and Professional tiers that add cloud, SaaS, email and managed SIEM detection are priced by custom quote depending on organisation size and infrastructure scope. A prospective buyer should get a written quote scoped to their actual endpoint and log volume before comparing against per-endpoint rates from other MDR vendors.
Yes, UnderDefense offers a free, self-serve MAXI tier that can be started without a credit card or sales call, alongside a 14-day trial of the full platform. UnderDefense's own company history notes that nearly 2,000 businesses were using the platform on this freemium basis as of 2024. Paid Standard, Enhanced and Professional tiers require either the $11/endpoint/month starting rate or a custom quote for higher tiers once a business needs full 24/7 MDR coverage.
Yes, UnderDefense MAXI is built to be vendor-agnostic and lists more than 250 integrations, including CrowdStrike, SentinelOne, Microsoft Defender, Splunk and Microsoft Sentinel, rather than requiring a customer to switch to a proprietary UnderDefense agent. UnderDefense positions this directly against MDR rivals that are built around a single EDR ecosystem. MSPs should confirm their specific tool version is on UnderDefense's current integration list before switching.
UnderDefense includes response actions such as alert triage and host isolation inside its core MDR subscription rather than treating them as a separate line item, with a published target of roughly two minutes to triage and containment within 15 minutes. A dedicated, deeper incident response retainer with faster remote or onsite service levels is also sold separately for organisations that want a pre-agreed crisis response arrangement. MSPs should clarify which level of response is included at their specific MDR tier before buying.
Yes, UnderDefense's MSP/MSSP partner programme includes product branding so a partner can offer the service under its own name, alongside a multi-tenant console for managing multiple client environments from one place. The programme also covers ticketing integration for alert handoffs, sales enablement and onboarding support. UnderDefense does not publish partner pricing; MSPs need a partner conversation to get a quote.
Reviews are moderated. How reviews work.
Share what it is like to use this product day to day. Your experience helps other MSPs choose with confidence.
Write the first review