What you are evaluating
Incident response and Incident360 are other solutions, not automatic inside MDR. Managed containment depends on the customer's EDR and firewall access. IR hours may sit in a retainer rather than the MDR SKU.
A useful evaluation context
Evaluation is whether concierge-style MDR plus separately purchased IR matches how the organization wants to delegate monitoring versus surge forensics.
Documented capabilities
The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.
- Around-the-clock detect, respond, and remediate guidance with a concierge operating model.
- Open XDR integrations so telemetry can come from tools the customer already runs.
- Guidance-led response that still depends on customer EDR or firewall control for containment.
Where it fits in the work
- Onboard telemetry, concierge contacts, and the EDR or firewall access required for any managed containment.
- Investigate concierge-raised cases and confirm which acts Arctic Wolf performs versus customer IT.
- Hand confirmed compromise that exceeds MDR to Incident360 or emergency IR, which are sold separately.
APPLY THE IDEA / ILLUSTRATIVE EXERCISE
Make the outcome observable.
In an authorized test environment, raise a harmless detection the service supports, then record whether the concierge provided guidance or executed containment, and whether IR was treated as a separate SKU.
Evidence to look for
The case shows telemetry used, the containment dependency on customer tools, and that Incident360 was not assumed to be included.
Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.
Questions for your evaluation
- Which EDR or firewall access does managed containment require, and who must authorize each action?
- Are IR hours inside Aurora MDR or only in an Incident360 retainer?
- Is Cylance or Aurora Endpoint on the order as a product, not as a second MDR brand?