# UnderDefense MAXI

> Vendor-agnostic MDR platform from UnderDefense, starting at $11 per endpoint per month.

UnderDefense MAXI is a managed detection and response platform from UnderDefense that runs a 24/7 SOC and agentic AI triage on top of a customer's own EDR, SIEM and cloud tools rather than its own agent, starting at $11 per endpoint per month (checked September 2026) for the Standard tier. Listing updated 6 September 2026. Checked by MSP Software 6 September 2026.

- Page: https://mspsoftware.net/software/underdefense-maxi
- Vendor: UnderDefense, https://mspsoftware.net/vendors/underdefense, website https://underdefense.com/maxi-ai/
- Categories: MDR and SOC (primary)
- Free trial: yes. Free version: yes.
- Deployment: cloud. Platforms: web. HQ: United States. Founded: 2017.
- Support: email, live chat, 24/7 and knowledge base. Training: documentation.

## From the vendor

UnderDefense MAXI is a managed detection and response platform from UnderDefense, a cybersecurity company established in 2017 with offices in New York, Jacksonville, Krakow and Lviv. MAXI pairs a 24/7 human-staffed SOC with an agentic AI layer that UnderDefense says handles most first- and second-line alert triage automatically, correlating signals from a customer's existing endpoint, network, identity, cloud, SaaS and Kubernetes tools rather than requiring UnderDefense's own telemetry agent. UnderDefense publishes a target of around two minutes to triage and containment within 15 minutes, and includes response actions such as host isolation inside the core MDR subscription rather than billing them as a separate incident response retainer, though a dedicated, higher-tier incident response retainer with faster remote or onsite SLAs is sold as a separate add-on for organisations that want it. MAXI is built to be vendor-agnostic: UnderDefense lists more than 250 integrations covering endpoint tools such as CrowdStrike, SentinelOne and Microsoft Defender, SIEM platforms including Splunk and Microsoft Sentinel, identity providers, and ticketing systems such as ServiceNow and Jira, and positions this against MDR rivals that push customers onto a single proprietary agent. The platform also runs compliance automation with evidence kits for frameworks including SOC 2, ISO 27001, HIPAA, PCI DSS and DORA, and a multi-tenant console that lets a managed security provider run several client environments from one place, with white-labelling for MSPs and MSSPs that want to resell the service under their own brand. Pricing starts at $11 per endpoint per month for the Standard tier, which UnderDefense publishes as a baseline rate; Enhanced and Professional tiers that add cloud, SaaS, email and managed SIEM detection are quoted based on infrastructure scope (checked September 2026). UnderDefense does offer a free, self-serve entry tier and a 14-day trial of the full platform with no credit card required, which is unusual among MDR providers that typically require a sales call before any hands-on access. MAXI suits an MSP or MSSP that already runs its own EDR, SIEM or cloud security tooling and wants a 24/7 SOC and bundled incident response layered on top without switching agents, and one that needs audited compliance evidence alongside detection. It suits a buyer wanting to compare a very simple published baseline price, or a very small shop wanting a single all-in-one agent rather than an integration-first platform, less well.

## Our take

UnderDefense MAXI stands out for publishing a baseline starting price and offering a real free, self-serve tier, which suits an MSP that already has EDR or SIEM tooling in place and does not want to rip it out for a single-vendor platform such as CrowdStrike or Arctic Wolf. The response actions and compliance evidence bundled into the core MDR subscription are worth comparing directly against Huntress or Field Effect MDR, which typically price incident response and compliance separately. Because the Enhanced and Professional tiers require custom quotes, get a written quote scoped to your actual endpoint and log volume before committing, and confirm exactly which integrations and compliance frameworks are covered at the tier you would actually buy, not just the baseline $11 rate.

## Pricing

UnderDefense MAXI starts at US$11.00 per endpoint per month, according to the vendor (pricing page: https://underdefense.com/mdr-pricing/).

| Plan | Price | Per | Highlights |
| --- | --- | --- | --- |
| Standard | US$11.00 | endpoint per month | Endpoint Detection and Response 24/7, AI-powered alert triage and response, Vendor-agnostic integrations |

## Features

| Feature | Supported | Note |
| --- | --- | --- |
| 24-hour human-staffed SOC | yes | 24/7 human-staffed SOC backed by 120+ security engineers. |
| Managed threat response and isolation | yes | Defined ~2-minute triage and containment within 15 minutes, including automated host isolation. |
| Own endpoint telemetry agent | no | Vendor-agnostic by design: runs on the customer's own EDR (CrowdStrike, SentinelOne, Microsoft Defender, etc.) rather than an UnderDefense-built agent. |
| Identity threat detection | yes | Identity is listed as one of the monitored layers alongside endpoint, network, cloud and SaaS. |
| Network monitoring | yes | Network is included among the covered environments. |
| Microsoft 365 monitoring | yes | Microsoft 365 security monitoring is listed as a MAXI capability. |
| PSA integration for ticketing | yes | Ticketing/ITSM integrations confirmed (ServiceNow, Jira, PagerDuty/OpsGenie); no MSP-specific PSA such as ConnectWise or Autotask is named on the integrations page. |
| Multi-tenant console | yes | Multi-tenant console lets a partner manage multiple client environments and dashboards from one place. |
| Works with third-party EDR | yes | Managed EDR service explicitly tunes and manages CrowdStrike, SentinelOne or Microsoft Defender. |
| Dedicated incident response | yes | Response and containment are included in core MDR; a separate, higher-tier incident response retainer is also sold for deeper crisis engagements. |

## Integrations

- CrowdStrike Falcon, https://mspsoftware.net/software/crowdstrike-falcon
- SentinelOne, https://mspsoftware.net/software/sentinelone
- Microsoft Defender for Endpoint, https://mspsoftware.net/software/defender-for-endpoint
- Splunk, https://www.splunk.com
- Microsoft Sentinel, https://azure.microsoft.com/en-us/products/microsoft-sentinel
- Elastic Security, https://mspsoftware.net/software/elastic-security
- KnowBe4, https://mspsoftware.net/software/knowbe4
- ServiceNow, https://www.servicenow.com

## Alternatives

- Sophos MDR: Vendor-agnostic 24/7 MDR from Sophos, priced per user and server on a quote-only basis. https://mspsoftware.net/software/sophos-mdr. Compare: https://mspsoftware.net/compare/sophos-mdr-vs-underdefense-maxi
- Guardz: Unified MDR, endpoint, email and identity security for MSPs, priced per user on request. https://mspsoftware.net/software/guardz. Compare: https://mspsoftware.net/compare/guardz-vs-underdefense-maxi
- Barracuda Managed XDR: A 24-hour SOC and XDR service for MSPs, priced per user on a quote-only basis. https://mspsoftware.net/software/barracuda-managed-xdr. Compare: https://mspsoftware.net/compare/barracuda-managed-xdr-vs-underdefense-maxi
- Field Effect MDR: MDR from Field Effect for endpoints, cloud and network, priced $5 to $25 per user a month via quote. https://mspsoftware.net/software/field-effect-mdr. Compare: https://mspsoftware.net/compare/field-effect-mdr-vs-underdefense-maxi

## FAQ

### How much does UnderDefense MAXI cost?

UnderDefense MAXI starts at US$11.00 per endpoint per month, according to the vendor, checked September 2026.

### Does UnderDefense MAXI offer a free trial?

UnderDefense MAXI offers a free trial. There is a genuinely free version.

### What does UnderDefense MAXI integrate with?

UnderDefense MAXI lists integrations with CrowdStrike Falcon, SentinelOne, Microsoft Defender for Endpoint, Splunk, Microsoft Sentinel and Elastic Security.

### Is UnderDefense MAXI cloud or on-premises?

UnderDefense MAXI is cloud-hosted; there is no on-premises version.

### Who is UnderDefense MAXI for?

MSPs report using UnderDefense MAXI at sizes of 6-15, 16-50, 51-200 and 200+ technicians.

### Is UnderDefense MAXI priced per endpoint?

UnderDefense publishes a starting price of $11 per endpoint per month for its Standard MDR tier (checked September 2026). Enhanced and Professional tiers that add cloud, SaaS, email and managed SIEM detection are priced by custom quote depending on organisation size and infrastructure scope. A prospective buyer should get a written quote scoped to their actual endpoint and log volume before comparing against per-endpoint rates from other MDR vendors.

### Is there a free version of UnderDefense MAXI?

Yes, UnderDefense offers a free, self-serve MAXI tier that can be started without a credit card or sales call, alongside a 14-day trial of the full platform. UnderDefense's own company history notes that nearly 2,000 businesses were using the platform on this freemium basis as of 2024. Paid Standard, Enhanced and Professional tiers require either the $11/endpoint/month starting rate or a custom quote for higher tiers once a business needs full 24/7 MDR coverage.

### Does UnderDefense MAXI work with our existing EDR and SIEM?

Yes, UnderDefense MAXI is built to be vendor-agnostic and lists more than 250 integrations, including CrowdStrike, SentinelOne, Microsoft Defender, Splunk and Microsoft Sentinel, rather than requiring a customer to switch to a proprietary UnderDefense agent. UnderDefense positions this directly against MDR rivals that are built around a single EDR ecosystem. MSPs should confirm their specific tool version is on UnderDefense's current integration list before switching.

### Does UnderDefense MAXI include incident response, or is that billed separately?

UnderDefense includes response actions such as alert triage and host isolation inside its core MDR subscription rather than treating them as a separate line item, with a published target of roughly two minutes to triage and containment within 15 minutes. A dedicated, deeper incident response retainer with faster remote or onsite service levels is also sold separately for organisations that want a pre-agreed crisis response arrangement. MSPs should clarify which level of response is included at their specific MDR tier before buying.

### Can an MSP white-label UnderDefense MAXI for its own clients?

Yes, UnderDefense's MSP/MSSP partner programme includes product branding so a partner can offer the service under its own name, alongside a multi-tenant console for managing multiple client environments from one place. The programme also covers ticketing integration for alert handoffs, sales enablement and onboarding support. UnderDefense does not publish partner pricing; MSPs need a partner conversation to get a quote.