Aurora Managed Detection and Response (MDR) is Arctic Wolf’s core security operations service. Arctic Wolf’s Security Services monitor customer logs and telemetry collected through sensors, the Arctic Wolf Agent and third-party integrations. MDR can be licensed on its own or as part of a Security Operations Bundle.[1] Aurora Vulnerability Management (AVM), formerly Managed Risk (MR), is the companion vulnerability scanning service and follows the same pattern.[2] Arctic Wolf publishes no price list for either service. What is published is the list of included components, the add-ons that can be licensed separately, the Bundle definitions and the warranty program tied to them. Incident response readiness is sold separately as Incident360 Retainers. For the contract framework, see Arctic Wolf General Terms and partner terms.
Editions
MDR components. The MDR Supplemental Product Terms list four components. Software covers the object code of the software, including software on Equipment. Equipment means virtual network appliances (vSensor) or physical sensors (Sensor). Services covers support, onboarding, Security Services and the Cyber Resilience Assessment. The Platform covers one vSensor 100 series, unlimited data ingestion, Unified Portal access, the Arctic Wolf Agent, optional ITSM ticketing integrations, and 90-day log retention unless another retention period is bought on the Order Form.[1] Catalog: MDR includes unlimited data ingestion, one vSensor 100 and 90-day log retention; vSensor 100 series.
AVM components. AVM has the same structure. Its Equipment is virtual network appliances (vScanner) or physical scanners (Scanner), and its Platform also includes unlimited data ingestion.[2] The MDR Product Description adds that Scanners are included with a subscription as set out on the Order Form.[4] The Product List classes MDR, AVM, ASAT and Aurora MDR Connect (for MSPs only) as Security Operations Products. All their add-on features fall in the same class.[12]
Separately licensed MDR features. The MDR Product Description names several features that appear on the Order Form only if bought:
- Cloud Detection and Response (CDR) for AWS, Microsoft Azure and other supported IaaS and SaaS environments.[4]
- Data Explorer, which gives access to historical event and observation data and Raw Log Search. Raw Log Search is now offered only within Data Explorer.[4]
- Threat Intelligence, in a base and a “Plus” version.[4]
Metrics
The MDR and AVM terms do not name a per-unit metric. The quantity comes from the Order Form metric under the General Terms. In the Unified Portal’s licence details, MDR and AVM entitlements appear as counts such as protected users, sensors, scanners or log collectors.[11] Catalog rows: Order Form licensing metric, Sensor (vSensor), Scanner (vScanner) and Data ingestion.
Data Explorer licences are measured in days of searchable data. Data Explorer Lite searches analyzed data from the last three days. A full licence offers 14, 30 or 90 days and adds custom alerts and Raw Log Search.[5] The licence also sets the time ranges shown in Unified Portal widgets and dashboards.[5] Legacy Data Explorer customers moved from a 10-day window to the DE-14 tier.[4] Catalog: Data Explorer Lite, Data Explorer (14-, 30- or 90-day license); rule Data Explorer licence sets the searchable data window.
Counting / floors
Log volume. Because MDR and AVM include unlimited data ingestion, adding log sources does not change the licence quantity.[1][2] What can change cost is retention beyond 90 days, which is bought on the Order Form, and the Data Explorer window.[1][5]
Coverage. The MDR Product Description recommends at least 85% endpoint coverage within the environments included in the subscription.[4] This is a service recommendation, not a licence floor. Coverage does matter for the warranty and for retainers (see Programs).
AVM assets. Assets discovered by AVM scans can be marked inactive. If no scan source rediscovers an inactive asset, it is removed after 120 days. An Arctic Wolf Agent, an internal scanner or another source can bring it back.[10] Catalog: Inactive AVM assets drop out after 120 days unless rediscovered.
Equipment. If sensors or scanners are not returned within 90 days after use ends or the agreement ends, the customer owes their replacement cost. Arctic Wolf deletes customer Confidential Information when the Equipment is returned or 120 days after expiry, whichever comes first.[1][2] Catalog: Equipment must be returned within 90 days or paid for.
Virtualization & partitioning
There are no processor, core or partitioning rules. Virtual sensors (vSensor) and virtual scanners (vScanner) are Equipment, just like physical devices.[1][2]
Cloud / BYOL
Customer data is stored in the third-party data centres for the Platform location on the Order Form.[1] Cloud workloads are covered by the separately licensed CDR feature.[4] For Microsoft US Government Community (GCC) environments, the MDR terms state that Arctic Wolf is not FedRAMP compliant. They also state that only supported, integrated applications are monitored there.[1]
Programs
Security Operations Bundles
| Bundle | Elements[3] | Security Operations Warranty[3] |
|---|---|---|
| Core | MDR; Data Explorer Lite for MDR | USD 100K with a three-year Committed Term |
| Plus | MDR; Data Explorer Lite; AVM | USD 500K (one-year term) or USD 1M (three-year Committed Term) |
| Total | MDR; Data Explorer Lite; AVM; ASAT tier; JumpStart Retainer | USD 750K (one-year term) or USD 1.5M (three-year Committed Term) |
For Plus and Total, a two-year Committed Term may qualify for the one-year warranty level in each annual period, at Arctic Wolf’s discretion. In the Total Bundle, ASAT+ or ASAT CCP can be licensed for an additional fee.[3] Catalog: Warranty level depends on the Bundle and the committed term.
Concierge Security Tiers
Every Bundle includes a Concierge Security Tier, and the customer buys the tier it chooses. All three tiers include a Concierge Security Team and 24x7x365 SOC availability.[3] Silver includes four Security Touchpoints a year, Gold twelve and Platinum eighteen. In each case four of them are delivered with the quarterly business review. Each higher tier also adds more Security Posture In-Depth Reviews (SPiDRs).[3]
Security Operations Warranty
An Order Form can include the Security Operations Warranty, but signing the Order Form does not enroll the customer. The customer must enroll through the warranty provider’s link, receive a confirmation and accept the Subscriber Terms.[7] Catalog: Warranty requires separate enrollment. The warranty covers Participants with MDR, Managed Risk, Managed Security Awareness or Aurora Managed Endpoint Defense (AMED).[6] Benefits are paid for qualifying events such as ransomware, business email compromise, compliance, business income and cyber legal liability events. These events must occur in an Environment where the Solutions are deployed.[6] For AMED-level benefits, AMED must be fully deployed within 45 days of the Order Form.[6] Catalog: AMED warranty benefits need full deployment within 45 days. If product subscriptions change during the term, the warranty amount may change and the customer may need to re-enroll.[3]
Incident360 Retainers
The Incident360 Retainer terms cover three subscriptions: JumpStart Retainer, Incident360 Retainer and Incident360 Plus Retainer.[8] The Product Description compares them:[9]
| Feature | JumpStart | Incident360 | Incident360 Plus |
|---|---|---|---|
| Scoping-call response SLA | 4 hours | 3 hours | 3 hours |
| Covered Incident engagements | 0 | 1 | 1 |
| Threat Intelligence reports | No | Yes | Yes |
| Readiness Touchpoints | 0 | 0 | 3 |
Hourly IR engagements are charged at USD 325 per hour. Any hourly engagement, including Business Email Compromise, must be for at least 25 hours. The Rapid Response add-on shortens the SLA to one hour and lowers the rate to USD 295.[9] Catalog: IR Services hour; Hourly IR engagements have a 25-hour minimum.
The endpoint count on the Order Form matters for retainers. A Covered Incident cannot be used if Arctic Wolf finds that the customer’s actual endpoint count is materially greater than ordered; the engagement is then billed hourly. For a standalone retainer, a Covered Incident does not apply to incidents before, or within 10 days of, accepting the Order Form in the initial term. It also does not apply where the event starts in an environment or on an endpoint without Arctic Wolf solutions or another up-to-date prevention tool. Ransom payments are never included.[8] Catalog: Covered Incident is lost if actual endpoints materially exceed the Order Form.
Trial Access
AVM may be offered as Trial Access for 30 days from activation, for evaluation only, as is and without support.[2] Catalog: Trial Access.
Out of scope
This article does not cover the Scope of Service, response-time objectives, supported log sources, Aurora Attack Surface Management, IR Services statements of work, or MSP pricing for Aurora MDR Connect. Security awareness training and Aurora Managed Endpoint Defense are covered in Arctic Wolf security awareness and training licensing and Arctic Wolf Aurora Endpoint Security licensing.