MDR Feature Matrix
Armor’s XDR+SOC solution combines cloud-native detection and automated response capabilities with our 24 / 7 team of cybersecurity experts and our comprehensive, AI-enabled threat hunting and alerting library to deliver critical security outcomes. This document details the product topology of ’s XDR+SOC solution and lists the components included with each SKU and bundle.
Basic Subscription Tier
Out-of-the-box essentials for gaining comprehensive responsive security coverage and incident management and response.
XDR Basic Subscription (SKU: XDR-BASIC-SUBSCRIPTION
)
Subscription for XDR services including basic configuration and access to the underlying infrastructure-as-code modules and resources.
Component | Included Quantity |
---|---|
XDR Onboarding & Deployment | Included |
SIEM Rule Library Subscription | Included |
Infrastructure-as-Code Library Subscription | Included |
Open Source Threat Intelligence Feeds | Included |
Basic Data Enrichment | Included |
Basic SOAR Playbook Library | Included |
Basic Dashboards & Reporting | Included |
SOC Basic Subscription (SKU: SOC-BASIC-SUBSCRIPTION
)
Subscription for SOC services including incident management and response.
Component | Included Quantity |
---|---|
SIEM Alert Review | Included |
Incident Triage | Included |
Threat and Vulnerability Analysis | Included |
Professional Subscription Tier
Everything from the Basic plan, plus custom rules and SOAR integration with access to additional commercial threat intelligence feeds.
XDR Professional Subscription (SKU: XDR-PRO-SUBSCRIPTION
)
Subscription for XDR services including continuous configuration, tuning and management, as well as access to the underlying infrastructure-as-code modules and resources.
Component | Included Quantity |
---|---|
XDR Onboarding & Deployment | Included |
SIEM Rule Library Subscription | Included |
Infrastructure-as-Code Library Subscription | Included |
Open Source Threat Intelligence Feeds | Included |
Commercial Threat Intelligence Feeds | Included |
Basic Data Enrichment | Included |
Basic SOAR Playbook Library | Included |
Basic Dashboards & Reporting | Included |
Custom SIEM rule development | 6 |
Custom SOAR Playbook Development | 2 |
Custom Workbook and Dashboard Development | 1 |
SOC Professional Subscription (SKU: SOC-PRO-SUBSCRIPTION
)
Subscription for SOC services including incident management, response, and remediation guidance with orchestration automation assistance.
Component | Included Quantity |
---|---|
SIEM Alert Review | Included |
Incident Triage | Included |
Incident Response | Included |
Threat and Vulnerability Analysis | Included |
Threat Hunting | Included |
Monthly SIEM Volume (SKU: SOC-PRO-SIEM-VOLUME
)
The total monthly volume of log messages and events being submitted to the SIEM for analysis.
Component | Included Quantity |
---|---|
Daily SIEM Volume (Professional) | Consumption |
Enterprise Subscription Tier
Everything from the Professional plan, plus analyst-supported tuning with a fully-custom threat intelligence feed and advanced forensics.
XDR Enterprise Subscription (SKU: XDR-ENTERPRISE-SUBSCRIPTION
)
Subscription for XDR services including continuous configuration, analyst-supported tuning and management, as well as access to the underlying infrastructure-as-code modules and resources.
Component | Included Quantity |
---|---|
XDR Onboarding & Deployment | Included |
SIEM Rule Library Subscription | Included |
Infrastructure-as-Code Library Subscription | Included |
Open Source Threat Intelligence Feeds | Included |
Commercial Threat Intelligence Feeds | Included |
Customer Threat Intelligence Programme | Included |
Basic Data Enrichment | Included |
Basic SOAR Playbook Library | Included |
Basic Dashboards & Reporting | Included |
Custom SIEM rule development | 12 |
Custom SOAR Playbook Development | 4 |
Custom Workbook and Dashboard Development | 2 |
SOC Enterprise Subscription (SKU: SOC-ENTERPRISE-SUBSCRIPTION
)
Subscription for SOC services including incident management, response, remediation guidance with orchestration automation assistance, and advanced forensic investigations.
Component | Included Quantity |
---|---|
SIEM Alert Review | Included |
Incident Triage | Included |
Incident Response | Included |
Threat and Vulnerability Analysis | Included |
Threat Hunting | Included |
Forensic Investigation | Included |
Monthly SIEM Volume (SKU: SOC-ENTERPRISE-SIEM-VOLUME
)
The total monthly volume of log messages and events being submitted to the SIEM for analysis.
Component | Included Quantity |
---|---|
Daily SIEM Volume (Enterprise) | Consumption |
Additional Information
Consumption Billing
Note that Services in the tables above with an Included Quantity labelled “Consumption” are usage-based SKUs and the amounts billed for these items will vary based on the amount you “use” or “consume”. Quantities of these items paid in advance qualify for the applicable term discount. Any overages will be billed in arrears at the non-discounted price listed on your service order.
Included Items
Quantities of Services in the tables above where the Included Quantity is labelled “Included” should be interpreted to include reasonable usage of the Services which should, without limitation, be within the guidelines and constraints defined in the Acceptable Use Policy and at the sole discretion of Armor. If you fail to observe these limitations, Armor may charge additional fees or terminate your Services.