---
title: Red Canary Reviews
meta_title: 'Red Canary Reviews 2026: Details, Pricing, & Features | G2'
meta_description: Filter 131 reviews by the users' company size, role or industry
  to find out how Red Canary works for a business like yours.
aggregate_rating:
  rating_value: 4.7
  review_count: 131
  scale: '5'
date_modified: '2026-08-07'
parent_category:
  name: System Security
  url: https://www.g2.com/categories/system-security
---


# Red Canary Reviews
**Vendor:** Zscaler  
**Category:** [Managed Detection and Response (MDR)  Software](https://www.g2.com/categories/managed-detection-and-response-mdr)  
**Average Rating:** 4.7/5.0  
**Total Reviews:** 131
## About Red Canary
Red Canary provides managed detection and response (MDR), finding and stopping threats before business impact. You get a security operations platform and 24x7 service that proactively monitors for malicious and suspicious behaviors and responds to stop them from becoming serious security incidents. MDR services complement and enhance your SOC, operating as a trusted partner, offering the expertise, tools, and support needed to strengthen your overall security posture. The platform works using several key components: Your existing endpoint and cloud workload sensors/agents Alert collectors and integrations with your alert-generating security products Integrations with your cloud service providers, identity platforms, and SaaS applications Cloud-hosted collection, detection, and response platforms Our Cyber Incident Response Team (CIRT) Our Threat Hunting team The sensors already running on the endpoints and cloud workloads that make up your corporate and production environments collect detailed telemetry about what is happening in those systems. The telemetry and alerts from your cloud service provider, identity platforms, SaaS applications, and other security products are both sent to our cloud-hosted platform. This allows our CIRT to perform analysis of that data to identify and confirm suspicious activity and security incidents. The security orchestration and response capabilities can execute automations using playbooks on endpoints for response and remediation. Our unique combination of detection-as-code detection engineering, proactive threat hunting, and agentic AI uncovers critical threats deep within your environment before they cause harm. Our renowned in-house intelligence team provides tactical insights tailored to your unique environment, helping you understand the adversaries you face, their specific tactics, and how to stop them. Red Canary enables 10X faster response to threats, helping you slash your mean time to respond (MTTR) by detecting threats early, investigating with precision, and enabling rapid containment, both expert-led and automated. Red Canary helps get more value from your existing tech stack continuously analyzing data across identities, endpoint, and cloud.



## Red Canary Pros & Cons
**What users like:**

- Users praise the **unparalleled customer support** from Red Canary, ensuring a successful security experience with ease. (40 reviews)
- Users value the **expert threat detection** by Red Canary, appreciating their in-depth analysis and responsive support. (26 reviews)
- Users value the **reliable support** from Red Canary&#39;s expert team, ensuring continuous protection against cyber threats. (20 reviews)
- Users value the **relevant alerts** from Red Canary, which streamline their focus on important incidents effectively. (16 reviews)
- Users highlight the **time-saving integrations** and excellent support from Red Canary, enhancing team&#39;s focus on critical tasks. (15 reviews)
- Users commend the **exceptional staff expertise** at Red Canary, highlighting their proactive support and deep technical knowledge. (15 reviews)
- Users appreciate the **continuous monitoring** of Red Canary, enhancing threat detection with clear insights and minimal false positives. (14 reviews)
- Investigation (14 reviews)
- Easy Integrations (13 reviews)
- Immediate Response (12 reviews)

**What users dislike:**

- Users experience an **inefficient alert system** with lag and missed notifications, impacting critical threat responses. (13 reviews)
- Users face **communication issues** with Red Canary, citing access problems and inconsistent support from various account representatives. (7 reviews)
- Users find Red Canary to be **expensive** , citing high costs and concerns over the pricing model and value. (6 reviews)
- Users find **difficult navigation** in Red Canary, especially in the mobile app, which requires adjustment over time. (4 reviews)
- Users express concerns about **integration issues** , noting a lack of robust options beyond Crowdstrike and delayed promises. (4 reviews)
- Users experience **poor customer support** with slow response times and inconsistent service from multiple representatives. (4 reviews)
- Lack of Automation (3 reviews)
- False Positives (2 reviews)
- Inadequate Detection (2 reviews)
- Learning Curve (2 reviews)

## Red Canary Reviews
  ### 1. Excellent MDR, Transparent Sales Process, Minor Support and Alert Delays

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Insurance | Enterprise (> 1000 emp.)

**Reviewed Date:** October 15, 2025

**What do you like best about Red Canary?**

Overall, this is a very good MDR solution. Communication about their roadmap, internal processes, and threat intelligence is clear and informative. Their blog is also excellent, providing valuable information. A few points stand out to me: The initial sales and POC process was handled very professionally, they were transparent about any issues or unknowns and never tried to hide anything. The setup and rollout were seamless and straightforward. Integrations are simple to manage. I appreciate being able to view some of the detection logic, which is extremely helpful when troubleshooting or checking if a specific detection exists. Automation is both easy to configure and highly customizable. Although we no longer use it, the Red Canary Linux agent performed very well, with minimal overhead and solid telemetry, though I do wish there had been more visibility into that telemetry.

**What do you dislike about Red Canary?**

1. Sometimes the level 1 support has been underwhelming, but it has been rare.
2. Sometimes the time to raise an alert takes longer than expected. Not common, but has occurred more than once.
3. Not able to create custom detections (at least I am not aware of that functionality).

**What problems is Red Canary solving and how is that benefiting you?**

An excellent MDR augmenting our SOC at all levels, as well as providing their own detections and threat intelligence.

  ### 2. Exceptional Partner, But Detection Gaps During Pen Tests

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Insurance | Enterprise (> 1000 emp.)

**Reviewed Date:** October 31, 2025

**What do you like best about Red Canary?**

The IR team and detection engineers here are truly outstanding, and it's always a pleasure to collaborate with them. The implementation of Red Canary was very easy and their onboarding team was great to work with.

**What do you dislike about Red Canary?**

Over the past few years, we've undergone several external penetration tests, and during these assessments, Red Canary was not able to identify the malicious activity while the tests were ongoing.
Also, they do not have any sort of alert ingestion integrations with Splunk or other SIEM platforms, and we needed to rely on custom API scripts to ingest alerts into our SIEM.

**What problems is Red Canary solving and how is that benefiting you?**

Red Canary serves as our 24/7 SOC analyst, monitoring our systems during off hours. In addition, Red Canary acts as an extra layer of oversight, working alongside our internal SOC team to enhance our security monitoring.

  ### 3. Two years with Red Canary

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Information Technology and Services | Small-Business (50 or fewer emp.)

**Reviewed Date:** January 14, 2025

**What do you like best about Red Canary?**

Very satisfied with Red Canary's service and dedication to cybersecurity. Their proactive approach and advanced threat detection capabilities have significantly enhanced our organization's security posture. The team's expertise and responsiveness are truly amazing, we feel confident and well-protected. Red Canary's commitment to continuous improvement and customer satisfaction is evident in every interaction.

**What do you dislike about Red Canary?**

It's not so much dislike but sometimes there is a high volume of alearts and it can be a little overwhelming since our team is very small, but I also understand they are necessary.

**What problems is Red Canary solving and how is that benefiting you?**

Threat detection and response which helps us monitor our environment by detecting and responding to threats. Enhances visibility which it helps us address vulnerabilities more effectively

  ### 4. Quick, Easy, and Supported by an Excellent Team

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Manufacturing | Mid-Market (51-1000 emp.)

**Reviewed Date:** October 28, 2025

**What do you like best about Red Canary?**

Red Canary is quick and easy to work with. They have excellent people working for them that greatly assist with triage of alerts.

**What do you dislike about Red Canary?**

Identity threats can throw a lot of alerts that Red Canary folks can't act on.

**What problems is Red Canary solving and how is that benefiting you?**

Red Canary is helping to scrub through all of our alerts to help identify security threats.

  ### 5. Red Canary Is Amaizing

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Entertainment | Enterprise (> 1000 emp.)

**Reviewed Date:** May 08, 2025

**What do you like best about Red Canary?**

I really love how the timeline makes investigating threats so much easier. It becomes very obvious what do when a threat is doing something very malicious in your environment and it allows for immediate action.

**What do you dislike about Red Canary?**

Since Red Canary is an MDR solution, it relies on data from endpoint detection tools like CrowdStrike to generate its alerts. One improvement I’d like to see is better suppression of redundant alerts. For example, if CrowdStrike already detects and blocks an unwanted application or process, it would be ideal if Red Canary could recognize that the threat was contained and avoid triggering a separate alert for the same event. This would help reduce alert fatigue and streamline the response process. Aside from that Red Canary is my favorite MDR solution.

**What problems is Red Canary solving and how is that benefiting you?**

Red Canary makes investigating threats a lot easier. It saves me so much time by breaking down what happened and giving me the key details upfront, so I’m not stuck piecing everything together from scratch.

  ### 6. Security Advancement & Hardening

**Rating:** 4.5/5.0 stars

**Reviewed by:** Michael T. | Cloud Operation Engineer, Mid-Market (51-1000 emp.)

**Reviewed Date:** January 01, 2025

**What do you like best about Red Canary?**

A deep of security analytic and ingest into every endpoint activity for best hunt and investigation.

**What do you dislike about Red Canary?**

Currently experience intermittent alert or notification issue working with Red Canary support due to global sms/governance regulations issue. It's great if there is multiplatform especially on the alert notification which is very critical and important as to acknowledge for a high severity threat to be exploit.

**What problems is Red Canary solving and how is that benefiting you?**

Security measurement especially threat on pre-breaking stages to be "determine" and prevention.

  ### 7. red canary experirence

**Rating:** 2.5/5.0 stars

**Reviewed by:** Verified User in Non-Profit Organization Management | Enterprise (> 1000 emp.)

**Reviewed Date:** January 22, 2025

**What do you like best about Red Canary?**

It provides visibility and valuable alerting on our various workloads, especially the cloud. It covers cloud security alerts extensively and empowers end users to create their own automation.

**What do you dislike about Red Canary?**

I used to like the way they helped with investigations. Now, I am being told our MSP doesn't have access. If there is an access issue, this should have been brought to our attention immediately. And we never get any Defender for endpoint alerts. When we followed up, they stated those alerts were just being closed and resolved without evidence.

**What problems is Red Canary solving and how is that benefiting you?**

visibility and and single view and alerting for our workloads. 24/7 protection and response

  ### 8. Overall good.

**Rating:** 3.5/5.0 stars

**Reviewed by:** Mike S. | Information Security Manager, VP, Mid-Market (51-1000 emp.)

**Reviewed Date:** January 03, 2025

**What do you like best about Red Canary?**

The Threat Hunting Team is excellent. Of the times I've reached out to them, they responded quickly and they provided good information and insight. I appreciate their recommendations and look for opportunities to reach out to them when we need assistance. The Technical Support Team is also excellent. They know their stuff and go the extra mile to provide essential information. I work with a lot of support teams and I am thankful for how well the RC team functions. That is rare in my experience. I never regret opening tickets for assistance.

**What do you dislike about Red Canary?**

There have been several instances where we expected RC to identify an issue and no alert was surfaced. Because of this, senior leadership feels, at times, that RC isn't the right partner for us. I think this is due to differences in methodology. RC has a set process, however in certain environments we have activity that for us would be considered unusual and requires follow up, but for RC it's not something that the team will alert on. I also think, that at times we looking for evidence that detections are functioning as described but this can be difficult to come by. Also, I think on the account rep side, there is a lack of training, such that when asked for clarification from our rep, those requests are either insufficiently responded to or outright ignored. It's my job as manager to ask questions and provide explanations to our leadership when there is an issue, I feel unsupported from the RC team in this fashion. I think the RC portal could be more useful. I know it's being improved but 2 years in, I still struggle to get useful information when I need it.

**What problems is Red Canary solving and how is that benefiting you?**

Obviously, we are using RC to monitor our environment.

  ### 9. Alerts

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Manufacturing | Enterprise (> 1000 emp.)

**Reviewed Date:** May 22, 2025

**What do you like best about Red Canary?**

The interface is quite nice, and the customer support team is pretty approachable.

**What do you dislike about Red Canary?**

The alerts are too automated sometimes, and there are times when a Human analyst is preferred.

**What problems is Red Canary solving and how is that benefiting you?**

It get rids of alot of the false positive.

  ### 10. Provides actionable insights and recommendations for incident response

**Rating:** 5.0/5.0 stars

**Reviewed by:** john c. | security analyst - Incident Response, Small-Business (50 or fewer emp.)

**Reviewed Date:** January 14, 2025

**What do you like best about Red Canary?**

i mostly like redcanary due to its analytical structure on how it seamlessly integrates with your endpoints utilizes threat intelligance and automation to reduce work load on security teams.

**What do you dislike about Red Canary?**

there is some lag between the alert in MDE and when RC responds.

**What problems is Red Canary solving and how is that benefiting you?**

24/7 monitoring and automaition

  ### 11. Customer for several years using RC as nights and weekend staff augmentation for Incident Response.

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Financial Services | Enterprise (> 1000 emp.)

**Reviewed Date:** January 07, 2025

**What do you like best about Red Canary?**

Knowledge and responsivness of staff and support.

**What do you dislike about Red Canary?**

At times there is a prolonged delay from when an a system alert is generated and RC alerts us to an issue.

**What problems is Red Canary solving and how is that benefiting you?**

Nights and weekends Incident Response.  The benefit is Staff Augmentation.

  ### 12. Delay in threat response

**Rating:** 4.0/5.0 stars

**Reviewed by:** Lilli C. | Security Analyst, Enterprise (> 1000 emp.)

**Reviewed Date:** January 27, 2025

**What do you like best about Red Canary?**

customer service and the improved data metrics report

**What do you dislike about Red Canary?**

the delay in time for alerts that are tagged as threats

**What problems is Red Canary solving and how is that benefiting you?**

playbooks and ingesting alerts to our ticketing system

  ### 13. Great 24/7 coverage and knowledgeable help.

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Furniture | Enterprise (> 1000 emp.)

**Reviewed Date:** January 07, 2025

**What do you like best about Red Canary?**

The resources and help from the Threat Hunters is very helpful day to day. They are very professional and document their findings well for us.

**What do you dislike about Red Canary?**

Sometimes the search UI can be clunky. Alerts also don't seem to populate unless gone through a link to the alert itself.

**What problems is Red Canary solving and how is that benefiting you?**

Giving 24/7 coverage to help create a well monitored system.


## Red Canary Discussions
  - [How does Red Canary work?](https://www.g2.com/discussions/how-does-red-canary-work) - 1 comment

- [View Red Canary pricing details and edition comparison](https://www.g2.com/products/red-canary/reviews?filters%5Bsentiment_snippet%5D=1995909&qs=pros-and-cons&section=pricing&secure%5Bexpires_at%5D=2026-08-14+22%3A05%3A23+-0500&secure%5Bsession_id%5D=f7c0eff6-4c29-4e07-83a0-d548c69ddc36&secure%5Btoken%5D=b65fd43cd596a73bd2bf05711b94aeb31db711db78302419b3478585782fc7f9&format=llm_user)
## Red Canary Integrations
  - [CrowdStrike Falcon Endpoint Protection Platform](https://www.g2.com/products/crowdstrike-falcon-endpoint-protection-platform/reviews)
  - [Microsoft 365](https://www.g2.com/products/microsoft365/reviews)
  - [Microsoft Defender for Endpoint](https://www.g2.com/products/microsoft-defender-for-endpoint/reviews)
  - [Microsoft Defender XDR](https://www.g2.com/products/microsoft-defender-xdr/reviews)
  - [Microsoft Sentinel](https://www.g2.com/products/microsoft-sentinel/reviews)
  - [SentinelOne Singularity Endpoint](https://www.g2.com/products/sentinelone-singularity-endpoint/reviews)

## Red Canary Features
**Platform Features**
- 24/7 support
- Proactive report alerts
- Application  control
- Proactive threat hunting
- Rapid response time
- Customizeable reports
- Managed Services

**Automation Capabilities**
- Automated remediation
- Automated investigation
- AI Agents

## Top Red Canary Alternatives
  - [Arctic Wolf](https://www.g2.com/products/arctic-wolf/reviews) - 4.7/5.0 (276 reviews)
  - [Huntress Managed EDR](https://www.g2.com/products/huntress-managed-edr/reviews) - 4.8/5.0 (887 reviews)
  - [CrowdStrike Falcon Endpoint Protection Platform](https://www.g2.com/products/crowdstrike-falcon-endpoint-protection-platform/reviews) - 4.6/5.0 (418 reviews)

