on the scent
On watch, around the clock

One pipeline. Every threat. Evidence on the way out.

Compliance-native Managed Detection & Response (MDR) for regulated small and mid-sized businesses and defense contractors—built for teams without a full internal SOC. Six sensors hunt threats around the clock with human-in-the-loop response, and auto-generate the audit-ready compliance evidence your auditors demand across CMMC, HIPAA, and SOC 2—so your assessment is already underway, not starting from a blank binder.

Proof it works

How every event becomes evidence

Every event in your environment flows through a single engine — captured by six sensors, mapped to MITRE ATT&CK, triaged by AI, and turned into timestamped compliance evidence. This is the machine that never sleeps.

1 · Six sensors
Defender, Sysmon, Windows Security, ETW kernel, canary, Linux — plus cloud & identity
2 · Detection engine
Correlated into incidents, mapped to MITRE ATT&CK
3 · AI triage agent
gpt-4o verdict, reasoning, playbook selection
4 · Response, human-gated
Isolate & block — high-impact actions require your approval
5 · Tamper-evident trail
SHA-256 hash-chained audit log an auditor can verify
6 · Evidence & SOC console
Incident queue, control matrix, SSP & POA&M export
Six sensors, one watchdog

Every corner of your estate, on watch

Six purpose-built sensors feed a single detection pipeline — from the Windows kernel to your Linux servers to the cloud — so nothing moves through your environment unseen.

EDR

Microsoft Defender

Malware detections and endpoint alerts, streamed and correlated in real time.

Process / Network / DNS

Sysmon

Deep process, network, and DNS behavioral telemetry from every Windows endpoint.

Identity

Windows Security

Logon, privilege, and account-lifecycle events for identity and access monitoring.

Kernel process

ETW Kernel

Kernel-sourced process start and stop telemetry via Event Tracing for Windows — real kernel visibility.

Deception

Canary

Decoy files planted as tripwires; any touch is an instant, high-confidence intrusion signal.

Auth + kernel

Linux

SSH, sudo, and login monitoring plus kernel-level process telemetry via eBPF on Linux servers and cloud nodes.

All six report over encrypted transport to a hosted backend, each with its own revocable per-agent credential. Detections are correlated into incidents and written to a tamper-evident audit trail.

New capability · Extended detection

The watchdog’s reach just went e​X​tended.

Detection no longer stops at the endpoint. MDRwatchdog now correlates signal from email, identity, cloud, and network into one timeline—so an attack is seen wherever it lands, not just on the laptop. That’s the X in MXDR: managed eXtended detection and response.

What is MXDR?
EndpointEmailIdentityCloudNetworkCorrelationcoreonetimeline

Endpoint

Established

Email

New

Identity

New

Cloud

New

Network

New

Each source connects per client—the same quick, read-only setup as Microsoft 365 today. Coverage extends as you turn each one on.

Seven regulated worlds, one watchdog

Built for the industries that can't afford a breach

Examine · Test · Interview

How the watchdog works

It hunts

24/7 monitoring across Windows and Linux endpoints, cloud, and identity. The watchdog sniffs out threats, correlates them into incidents, and contains them—with a human in the loop for the calls that matter.

It documents

Every action is logged and mapped to your framework's controls, then exported as clean, timestamped, auditor-ready evidence—plus your control matrix, SSP, and POA&M.

It keeps you covered

Built by a compliance-fluent team that lives in this regulatory language. Continuous evidence means you're always assessment-ready, not scrambling before an audit.

Live detection coverage

Kill-chain coverage, mapped to MITRE ATT&CK

Detections spanning eight techniques across six adversary tactics.

Initial Access
T1110
SSH brute-force
Execution
T1059CRITICAL
Web shell spawned
T1105
Download-and-execute
Credential Access
T1003CRITICAL
Credential dumping
T1078CRITICAL
Auth after brute-force
Persistence
T1098
Backdoor SSH key
T1053
Cron modification
Defense Evasion
T1136
Security config modified
8
ATT&CK techniques
6
Tactics covered
3
Critical severity
AI-augmented triage

Autonomous incident analysis

An LLM agent triages each incident, decides, and acts — humans approve high-impact steps.

Credential dumping (LSASS / Mimikatz)
T1003 · Credential Access
MALICIOUS · 95%
Engine
gpt-4o
Autonomy
auto_critical
Root cause
LSASS credential access consistent with Mimikatz tradecraft
Blast radius
Single host — lateral-movement risk if unremediated
Playbook — Credential Dumping Response
Isolate hostauto-executed
Block source IPauto-executed
Force password resetsescalated — human approval

Response actions execute against integrated EDR/firewall in production; high-impact actions require analyst approval.

The Assessment Factory

Your compliance package, generated from live evidence

One monitored environment feeds every framework. The Assessment Factory turns your live telemetry into a readiness package—control matrix, gap report, and framework-specific artifacts—across CMMC, HIPAA, NYDFS, NAIC, SOC 2, ISO 27001, and legal / OCG. Evidenced controls are marked as proven; the rest are flagged for attestation, so what you hand an auditor is honest and defensible.

See the frameworks & pricing
CMMC L2
HIPAA
NYDFS 500
NAIC #668
SOC 2
ISO 27001
Legal / OCG
+ evidence kit

Transparent framework pricing

Indicative ranges for early engagements—final scope is set after a short discovery call. See full framework pricing →

Phase 1

Setup & assessment prep

One-time operational build-out.

$5,000 – $15,000
  • Stand up continuous monitoring
  • Generate initial SSP & POA&M
  • Map your control matrix
Ongoing
Phase 2

MDR + evidence refresh

Predictable monthly management.

$2,000 – $5,000/mo
  • 24/7 monitoring, human-in-the-loop escalation
  • Automated monthly evidence exports
  • Ongoing SSP & POA&M upkeep
  • Security awareness training (add-on)
No six-week rollout

Protected the same day you sign

Enterprise security rollouts take weeks. Ours takes a day.

Provisioned in minutes

Your monitoring tenant is stood up the moment you sign.

One-script sensor install

Each endpoint is protected with a single install script.

Microsoft 365 in ~10 min

Cloud-identity monitoring connects with a read-only app registration.

Evidence day one

Your first audit-ready compliance evidence is captured the same day.

Full compliance readiness still depends on your own attestations and remediation—but monitoring and evidence start on day one.

Straight-shooting terms

No traps in the contract

30-day cancellation

Leave with 30 days’ notice. No 60-day traps, no auto-renewal to fight.

Locked pricing

Your rate is fixed for your term. No automatic annual increases compounding on your invoice.

You own your data

Every detection, report, and piece of evidence is yours—full export included, 90-day window.

No enterprise minimums

Priced for your actual size. A ten-person practice pays like a ten-person practice.

Better monitoring, better insurability

Insurers reward organizations that can prove continuous monitoring and real controls. Our evidence is built to support your cyber-insurance application—and can help you qualify for coverage or improve your rates.

A commitment we can keep

Instead of a headline number we couldn’t stand behind, our agreement spells out uptime and response commitments in plain language—with service credits if we fall short. No fine-print games.

CMMC is paused — your DFARS obligations are not

In July 2026 the DoD suspended CMMC Phase II, so third-party (C3PAO) certification isn't currently required in new contracts—but DFARS 252.204-7012, NIST SP 800-171 self-assessment, and your SPRS score all remain firmly in force. The expensive audit paused; the work you still owe did not. We turn monitoring you already run into that self-assessment evidence—SSP, POA&M, and a live SPRS score—so you stay ready whatever the reform task force decides.

Defense & CMMC

Learn the landscape

Plain-language answers to the questions buyers ask most—readiness and evidence, not certification or legal advice.

Straight answers

MDR, MSSP, and compliance — what MDRwatchdog actually is

Common questions

What is MDRwatchdog?+

MDRwatchdog is a compliance-native Managed Detection and Response service for regulated small and mid-sized businesses. It monitors your environment around the clock and turns that telemetry into audit-ready readiness evidence mapped to frameworks like CMMC, HIPAA, and SOC 2.

Does MDRwatchdog certify my compliance?+

No. MDRwatchdog provides readiness and evidence, not certification. Certification is issued only by the appropriate authorized body — a C3PAO for CMMC, a licensed CPA firm for SOC 2, an accredited body for ISO 27001. We prepare you and keep you assessment-ready.

How is MDR different from a traditional MSSP?+

A traditional MSSP typically forwards alerts for your team to triage. MDR adds active detection, investigation, and human-in-the-loop response. MDRwatchdog goes one step further by turning that same monitoring into continuous, control-mapped compliance evidence — so security work and audit prep happen at once.

What is the difference between EDR and MDR?+

EDR (Endpoint Detection and Response) is the tooling that watches endpoints. MDR is the service that operates detection and response across endpoints, cloud, and identity, with people in the loop. MDRwatchdog is MDR, and it additionally generates the compliance evidence your frameworks require.

Which frameworks does MDRwatchdog support?+

Readiness and evidence for CMMC Level 2, the HIPAA Security Rule, SOC 2, ISO 27001, NYDFS 23 NYCRR 500, the NAIC Insurance Data Security Model Law, the FTC Safeguards Rule, and outside-counsel security baselines. One monitored environment feeds every applicable framework.

Is CMMC still required after the 2026 pause?+

Yes, the underlying obligations remain. In July 2026 the DoD suspended CMMC Phase 2, pausing the third-party C3PAO certification milestone — but DFARS 252.204-7012, NIST SP 800-171 self-assessment, and SPRS scoring are still fully required. This is not legal advice; confirm your obligations with your contracting officer and counsel.

Put the watchdog on your data tonight.

Turn the security monitoring you already need into continuous compliance evidence. Book a 15-minute review and we'll map where you stand.

Schedule your 15-minute review