What is our primary use case?
My main use case for Red Canary is to watch our computers and servers for any suspicious activity. The biggest value for us is that we don't have to sit and watch security alerts all day as we previously did. Red Canary monitors the environment and brings something to our attention when it looks like a real threat. For example, if an employee accidentally opens a suspicious attachment and it starts running PowerShell or an unusual process, Red Canary can follow what happened instead of just showing us one alert. We can see what started the activity, what happened next, and whether anything else was affected.
On a normal day for me, I am mostly checking the alerts and investigations that Red Canary has raised. If something is marked as suspicious, I look at the timeline and details around the activity. Sometimes it turns out to be normal employee activity, so we close it. If it looks malicious, we investigate further and take action on the affected machine or account. We also use Red Canary when our other security tools raise an alert, and it is helpful at getting more context instead of making us investigate every alert from scratch.
Another thing I appreciate about Red Canary is 24/7 monitoring. If something happens at night or over the weekend when I'm out of office, Red Canary still gives us what is happening and gives us an alert. We don't have to wait until I or our team come back to work. Typically that is how we use Red Canary at our organization.
This happened two months back when Red Canary flagged an unusual PowerShell activity on one of our employee laptops. The user had opened an attachment from an email, and shortly after that, a PowerShell process started running in a way that was not normal for that user. Red Canary showed us the sequence of events and alerted us on that malicious incident.
What is most valuable?
The best features that Red Canary offers is the attack timeline. For example, if a suspicious file is opened, we can follow what happened after that, what process started it, and what other activity followed, and whether the machine made unusual connections. We can see those events, which makes investigations much easier.
I also appreciate the 24/7 monitoring. We don't have to depend completely on our team or me being available. If something suspicious happens outside our working hours, Red Canary can investigate it and escalate it to us when action is needed.
The feature I had forgotten to mention, and we use it mostly, is the threat detection. When Red Canary sees something unusual, it doesn't give us just an alert. It gives us more information about what happened and activity around it.
The biggest impact that Red Canary has had for us positively is reducing the amount of time I and our team spend investigating security alerts. When we were using traditional antivirus tools, we could spend a lot of time collecting logs and checking different tools just to understand whether an alert was actually malicious or not serious. With Red Canary, we can get the investigation context and timeline much earlier. For example, for a normal endpoint alert that could take us sixty minutes or one hour to investigate, it can be understood within less than five minutes.
What needs improvement?
To improve Red Canary, I think we should improve the alerts. Red Canary does a good job when identifying suspicious activity, but sometimes in a busy environment, I would appreciate a feature whereby it can separate urgent threats from threats that can wait. This would reduce the amount of time we spend reviewing lower-risk cases.
Another improvement would be a faster investigation process. For example, simple alerts have straightforward investigations, but complex incidents require us to look through a lot of information to determine what is happening.
For how long have I used the solution?
I have been using Red Canary for two years.
What do I think about the stability of the solution?
Red Canary has been quite stable for us. The monitoring generally runs in the background without causing noticeable problems for our endpoints, and it doesn't disrupt our normal work.
What do I think about the scalability of the solution?
Red Canary has scaled well for us. As we added more endpoints and users, it has scaled well.
How are customer service and support?
Customer support for Red Canary is good and better than I expected. The support team is always there for us to help us mitigate any security incident we get when we receive a suspicious alert and are not sure what to do next.
I would rate the customer support an eight out of ten because sometimes more complex cases take a day or longer to be solved.
Which solution did I use previously and why did I switch?
We did not use any previous solution.
What was our ROI?
There has been a reduction in time needed to investigate a typical endpoint alert. The average investigation time dropped almost up to five minutes for common cases. We also save good hours, around eighty hours saved per week for me and my security team on alert investigation.
We got back roughly around seventy thousand dollars per year. The biggest saving came from analyst time, and we estimated saving about two hundred and forty hours per year on alert triage and initial investigations. At an estimated cost of our internal security labor around sixty dollars per hour, that is approximately fourteen thousand dollars saved annually.
What's my experience with pricing, setup cost, and licensing?
For our environment, we are paying roughly thirty-five thousand to sixty thousand dollars per year for Red Canary. The actual cost depends mainly on the number of endpoints we are monitoring and the level of managed detection and response coverage we need. When I look at the cost, I don't compare it only with any other security product because it is a bit expensive, but it provides for us a 24/7 monitoring and investigations. The way it saves us time, it is worth an investment.
Which other solutions did I evaluate?
Before choosing Red Canary, we evaluated Microsoft Defender for Endpoint and CrowdStrike for endpoint. We decided to go with Red Canary.
What other advice do I have?
My advice to others looking into using Red Canary is to start with a small group of important endpoints and then run them. Don't just look at how many alerts Red Canary has given you. Instead, look at whether the alerts are useful and whether the investigation actually saves your team time. I also advise connecting Red Canary to the security tools you already use, as it becomes more useful when Red Canary scans the entire environment. I would rate this review an eight out of ten overall.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?