The Platform

One platform watching every plane an attacker uses

Attacks on small and mid-sized businesses rarely stay on the endpoint. They move through identity, email, cloud, network, and—increasingly—the phones your team carries. MDRwatchdog is extended detection (MXDR): we connect to the systems you already run, correlate the signals into single incidents mapped to MITRE ATT&CK, and turn the same telemetry into the evidence your compliance framework demands.

Six planes, one timeline

What we monitor

Each plane connects independently to a system you already operate. Turn on the ones that carry your risk; add the rest as your stack grows. Nothing is invented for a plane you haven’t connected.

Endpoint

Windows & Linux agents

Lightweight sensors on servers and workstations—Microsoft Defender, Sysmon, Windows Security, kernel ETW, and decoy “canary” files. Process lineage, credential-theft attempts, persistence mechanisms, and ransomware tripwires, with containment that runs on the machine itself.

Identity

Microsoft 365 · Google Workspace

Sign-in and directory telemetry from Entra ID and Google Workspace—where phishing, token theft, and password spray actually land. Brute force, risky sign-ins, privilege escalation, new-admin creation, and impossible-travel geo-velocity.

Email

Microsoft 365 / Defender for Office 365

Phishing, malware, and mailbox-rule abuse—including the auto-forwarding rules that business email compromise installs to hide fraud from the account's real owner.

Cloud

AWS CloudTrail

Management-plane activity across your cloud accounts: credential misuse, suspicious API calls, and configuration changes—tracked per tenant, correlated with the identity that made them.

Network

Syslog · flow

Firewall, DNS, and flow telemetry for the movement endpoint agents don't see: lateral movement between hosts, unusual outbound data volume, and DNS-tunneled command-and-control.

Mobile

Your MDM / MTD

Device posture from the platform you already run—Intune, Jamf, Lookout, or Zimperium: jailbroken or rooted devices, non-compliant phones reaching corporate data, and mobile-threat verdicts. We read what your device manager already knows. There is no MDRwatchdog agent on the phone.

Beyond the endpoint · ITDR + UEBA

Identity threat detection & behavioral baselines

Most breaches at small and mid-sized firms begin with a stolen credential, not malware. So the identity plane gets more than log collection: detections tuned to how accounts actually get taken over, and per-user baselines that learn what normal looks like and flag the deviation.

Identity threat detection

  • MFA fatigue and push-bombing — repeated prompts until someone approves
  • Impossible travel — sign-ins too far apart to be one person
  • Kerberoasting, AS-REP roasting and DCSync — AD credential theft, by attacker tooling and, with DC auditing on, at the protocol level
  • Privilege escalation and new-admin creation, in cloud or on-prem directories
  • Sign-ins from unmanaged or non-compliant devices

Behavioral baselines (UEBA)

  • Login-time baseline — the hours each user normally signs in
  • Location baseline — the countries a user normally signs in from

Baselines score against each user’s own history, so an alert means the activity is unusual for them — not that it broke a fixed rule — and each warms up before it scores. The same engine extends to further signals, such as data-access volume, as those sources connect.

Coverage activates with your stack: cloud-identity detection needs your Microsoft 365 or Google tenant connected; Active-Directory protocol detection needs a domain-controller sensor with auditing enabled; location baselining needs a geolocation source. Identity detections alert and recommend — response actions stay human-authorized.

From signal to evidence

What happens to a detection

The same pipeline every plane feeds into—transparent at each step, human in control of anything that touches your estate.

01

Detect

Every event runs through a transparent rule pack mapped to MITRE ATT&CK—no black box, so an analyst can always say exactly why something fired.

02

Correlate

Related detections across every plane collapse into one incident on the entity they share—a user, a host—with the full technique chain attached.

03

Triage

AI-assisted triage ranks by severity and response-time target, so the signal that actually matters surfaces first instead of drowning in noise.

04

Respond

Recommended actions by default; containment is human-authorized and executes through the agent already running on the endpoint. We report what actually happened—not what was merely attempted.

05

Evidence

The same telemetry becomes your compliance record—control matrix, SSP, POA&M, and a hash-chained audit trail an assessor can verify.

Monitoring becomes your compliance evidence

One monitored environment feeds every framework. The detections and audit trail the platform produces map straight onto CMMC, HIPAA, SOC 2, ISO 27001, NYDFS 500, NAIC, and the legal / OCG baseline—so the same coverage that catches an attack also produces the record an assessor asks for.

  • Detections mapped to MITRE ATT&CK techniques
  • Controls marked evidenced vs. attestation-required
  • Named, timestamped evidence artifacts
  • Hash-chained audit trail an assessor can verify
See the readiness packages

What we monitor, honestly. Every plane connects to a system you already run, and activates only once you connect it—we never fabricate telemetry for coverage you haven’t turned on. Mobile is device posture read from your MDM/MTD, not an on-device agent. Response is human-authorized by default. We surface and evidence what your environment actually produces—which is exactly what makes the record defensible when someone asks you to prove it.

Learn the landscape

Plain-language answers to the questions buyers ask most—readiness and evidence, not certification or legal advice.

Common questions

What does “extended detection” (MXDR) actually mean here?+

Endpoint-only monitoring sees the workstation and nothing else. Extended detection means we also watch the identity, email, cloud, network, and mobile planes—where most attacks on small and mid-sized businesses actually begin—and correlate signals across all of them. A risky sign-in, a new mailbox rule, and a cloud config change stop being three unrelated alerts and become one incident with the whole story attached.

Do you install an agent on employees' phones?+

No. Mobile coverage reads device posture from the device-management or mobile-threat platform you already run—Microsoft Intune, Jamf, Lookout, or Zimperium. We surface jailbroken or non-compliant devices and any mobile-threat verdicts those tools produce. There is no MDRwatchdog app on the phone, and we don't claim on-device forensics we don't collect.

What do you actually need access to?+

Read-only connections to systems you already operate: an app registration in your Microsoft 365 or Google tenant, an AWS role, a syslog feed, and—if you want mobile—read access to your MDM/MTD. Endpoint coverage installs a lightweight agent on the machines you choose. Each plane activates independently as it's connected; nothing is fabricated for a plane you haven't turned on.

Does turning on more coverage cost more?+

Coverage is priced by the size and scope of your environment, not by nickel-and-diming each connector. Most clients start with the planes that carry their real risk—commonly endpoint and identity—and add cloud, email, network, or mobile as their stack warrants. Scope is set on a short discovery call.

Is response automatic?+

By default, no. The platform recommends the action and a human authorizes it—because isolating a law firm's server or disabling an account at 2 a.m. on a false positive causes its own damage. Automatic containment for critical detections is available, but it is opt-in and off until you deliberately enable it. Mobile detections are alert-and-investigate; any device action happens in your MDM, with your approval.

Do you offer ITDR and UEBA, or just log collection?+

Both. Beyond collecting identity logs, the engine runs detections tuned to credential-based attacks—MFA fatigue, impossible travel, Kerberoasting, DCSync, privilege escalation—and it learns per-user behavioral baselines (UEBA) for sign-in time and location, flagging what is unusual for that specific user rather than applying a fixed rule. Some detections activate with your stack: cloud-identity needs your Microsoft 365 or Google tenant connected, and Active-Directory protocol detection needs a domain-controller sensor with auditing on. Response stays human-authorized.

See what your environment is already telling you.

Book a 15-minute review and we'll map the planes that carry your real risk—and which ones you can turn on first.

Schedule your 15-minute review