Been with them a bit over 2 years now and feel like we're in safe hands with Endpoint and M365 monitoring. Rarely log in to the portal because it's set and forget, and the setup process is easy enough with their KB articles.
Had several informational emails to verify things at our end (i.e. checking a suspicious application), and have now had several escalations suspicious enough to warrant a call to our team, mostly for suspicious M365 logins.
They feel more hands on than Huntress, and feel like they're usually about 6-12 months ahead of Huntress' product releases for things like Defender for Endpoint integrations and such.
Support is also good Review collected by and hosted on G2.com.
I'd be much happier if there was more visibility into actions the SOC Analysts have taken. We see many events that are flagged as suspicious in the SNAP Portal, and that they were "Resolved" by an analyst. I appreciate them, not hounding us with all the false positives they find, but it would make us feel safer if there was a way to click into each event and see a note from the SOC as to why it was determined safe. This was one thing we quite liked about Huntress - the visibility.
Huntress has also now got a better ITDR portal than Blackpoint IMO for things like suspicious M365 logins. Being able to see exact details about the suspicious activity, and historic VPN usage or browser use is something that Blackpoint could improve on when it comes to us trying to decide on whether a login a client has made is suspicious enough to action further, though Blackpoint will usually solve this with a phone call to us which is nice.
I do feel like Huntress is quickly catching up on feature parity - Blackpoint is putting all their effort into CompassOne which looks decent but seems to be more marketing hype than actual updates. Review collected by and hosted on G2.com.
