Verified User in Investment Management
EI
Verified User in Investment Management
Mid-Market (51-1000 emp.)
"MDR service with strong focus on detection engineering for endpoints"
5/5
What do you like best about Red Canary?

Red Canary is very focused on writing detections and applying them to the telemetry from your environment. They are less concerned about alerts that pop-up from the rest of your detection stack. The other alerts are in the RC portal for context and can be acted upon, mostly by the customer.

For EDR the integration is pretty straightforward through API.

Their customer support is very good and personal. Review collected by and hosted on G2.com.

What do you dislike about Red Canary?

Red Canary seems very focused on cybercrime and commodity threats, perhaps a bit less on the APT and state-sponsored attackers. This may or may not fit your organization's risk profile.

We have also had issues with roadmap promises and new integrations, where time estimates seems to have been overly optimistic in the beginning. Review collected by and hosted on G2.com.

Verified User in Financial Services
AF
Verified User in Financial Services
Enterprise (> 1000 emp.)
"Great!"
5/5
What do you like best about Red Canary?

They are quick with their response time and do everything they can to help resolve your issues. Review collected by and hosted on G2.com.

What do you dislike about Red Canary?

I have not experienced any downsides with Red Canary yet. Review collected by and hosted on G2.com.

Verified User in Manufacturing
UM
Verified User in Manufacturing
Mid-Market (51-1000 emp.)
"Quick, Easy, and Supported by an Excellent Team"
5/5
What do you like best about Red Canary?

Red Canary is quick and easy to work with. They have excellent people working for them that greatly assist with triage of alerts. Review collected by and hosted on G2.com.

What do you dislike about Red Canary?

Identity threats can throw a lot of alerts that Red Canary folks can't act on. Review collected by and hosted on G2.com.

Josh V.
JV
Josh V.
Security Engineer
Mid-Market (51-1000 emp.)
"Red Canary Review"
5/5
What do you like best about Red Canary?

Red Canary allows our team to have 24/7 monitoring of alerts and threats without having to staff our team for after hours monitoring. We have playbooks configured to take actions for after hours alerts/threats to automated the handling of incidents. Review collected by and hosted on G2.com.

What do you dislike about Red Canary?

The one improvement I would like to see from Red Canary is the ability to trigger playbooks manually if needed while reviewing an incident. There are few use cases where this is necessary, but would be a huge benefit in when the scenario comes up. Review collected by and hosted on G2.com.

JL
James L.
Senior Information Security Engineer
Enterprise (> 1000 emp.)
"My RC Customer Support Team Rocks!!!"
5/5
What do you like best about Red Canary?

Almost no false positives, the fact that you have expects making new analytics to detect malicious activity and quickly adding those detections into our consoles. However, our support team is amazing. I love Steve McReynolds and Susannah Howard-Spink has been really awesome too! They have made the user experience enjoyable and integrations/updates to our instance seamless. Thank you!! Review collected by and hosted on G2.com.

What do you dislike about Red Canary?

I wish I actually had something constructive to add here, y'all just rock it so hard... i guess don't lose sight of your original mission as the business grows, keeping the same amount of investments that are made today in your support teams, your intel teams, and even the team that does all the external facing blogs (which I love to read). I know the bottom line and showing year over year profits are what is necessary from a business perspective, but I guess I hope that the spirit of Red Canary doesn't die with that growth. Review collected by and hosted on G2.com.

KS
Kim S.
Director of IT
Enterprise (> 1000 emp.)
"Red Canary Saves the Day"
5/5
What do you like best about Red Canary?

Red Canary's playbooks automate immediate actions to protect us. I appreciate the timely alerts, Red Canary always sends us alert before any other monitoring system we employ. The knowledge of the analysts is impeccable and unmatched in the field. Understanding, investigating and teaching our on-prem team is so valuable and has saved us several times and allowed us to shutdown attacks as they begin to happen. Awesome team and reporting systems! Review collected by and hosted on G2.com.

What do you dislike about Red Canary?

Nothing I can think of. SOmetimes responding to threats has required that we ask questions and learn more about what is proposed and the affects of approving or denying actions./ Review collected by and hosted on G2.com.

Verified User in Insurance
AI
Verified User in Insurance
Enterprise (> 1000 emp.)
"Great core product"
4/5
What do you like best about Red Canary?

Red Canary excels at ingesting and correlating telemetry and alerts from our Microsoft Defender suite, combining and deconflicting that data into a single, cohesive threat narrative for a given machine or activity. This correlation capability provides a clearer picture of threats than we get from our other tools and can reduce the time our analysts spend on manual investigation. The platform itself is intuitive and well-designed, making it easy to navigate and use. Additionally, the customer support has been excellent—particularly Annalise and Matthew, who have been responsive and helpful, with Matthew providing deep technical assistance on integrations and automation. Overall, Red Canary adds meaningful value to our security operations. Review collected by and hosted on G2.com.

What do you dislike about Red Canary?

While Red Canary offers strong automation capabilities, there are some limitations that impact our ability to fully leverage the platform. One of the main issues is the inconsistency between the GUI, automation platform, and API. For example, when closing out threats, the options available in the automation platform differ from those in the GUI and API—such as missing specific closure reasons like "Internal testing." Additionally, the automation platform only supports "AND" logic in trigger conditions, which makes it difficult to build flexible workflows that share common traits but differ in just one condition. These limitations force us to rely on custom scripts and direct API calls to achieve the functionality we need, rather than managing everything within Red Canary itself. Review collected by and hosted on G2.com.

Verified User in Business Supplies and Equipment
CB
Verified User in Business Supplies and Equipment
Small-Business (50 or fewer emp.)
"Red Canary’s team continuously monitors your environment"
5/5
What do you like best about Red Canary?

Threat Intelligence & Behavioral Analytics

Powered by thousands of analytics and deep threat research (mapping to MITRE ATT&CK), Red Canary delivers data-driven, intelligence-led operations Review collected by and hosted on G2.com.

What do you dislike about Red Canary?

Would you like to dive deeper into any component—such as their threat intelligence engine, MDR SOC workflows, or integration specifics? Review collected by and hosted on G2.com.

Verified User in Hospital & Health Care
AH
Verified User in Hospital & Health Care
Enterprise (> 1000 emp.)
"Satisfied Customer!"
4.5/5
What do you like best about Red Canary?

I provide cyber support for a healthcare organization. There are times where I need additional support whether it be in investigating an alert from our EDR or a technical question regarding the Red Canary web portal. Red Canary is quick to answer my questions and address any concerns I may have. Review collected by and hosted on G2.com.

What do you dislike about Red Canary?

I would like additional features when it comes to Threats that are published by Red Canary. For example, If I remediate a Threat by adding an end user to be allowed to use a specific application and later would like to revert those changes. I need to submit a ticket to Red Canary to have the user removed. Review collected by and hosted on G2.com.

VB
Victor B.
Security Analyst II
Enterprise (> 1000 emp.)
"Red Canary is Awesome!"
5/5
What do you like best about Red Canary?

Very easy to use. User friendly UI. Everybody has been extremely helpful for our company since the very beginning. I use it every day and never had any issues. We were able to hit the ground running from the very first day of implentation. Review collected by and hosted on G2.com.

What do you dislike about Red Canary?

Do not have any complaints about Red Canary. Had some issues with hunters not putting comments for certain threats but that was immediately fixed and the comments are now great. Review collected by and hosted on G2.com.