EDR Gateways: SentinelOne, CrowdStrike, Huntress, and more
STAP note: EDR gateways are Strategic Technology Alliances under the Strategic Technology Alliance Program (STAP). XISEM extends and operationalizes EDR telemetry — it is not an EDR replacement.
Dual-Strike XISEM is not an EDR replacement. It is the correlation and governance layer that extends and operationalizes the EDR you already sell. EDR alliance gateways import detections, agent health, and asset mappings so COBRA², ASPIRE, and Threat Center see the same device the SOC already manages.
Route: Settings → Technology Alliances → EDR
Supported EDR families (public index)
SentinelOne — MSP multi-tenant, Singularity API
CrowdStrike Falcon — Enterprise and mid-market
Huntress — SMB-focused managed EDR
Microsoft Defender for Endpoint — M365-heavy clients
Trend Micro, Sophos, others — See Technology Alliances wiki slug index
Exact setup steps live in Support wiki → Technology Alliances per vendor (API keys, OAuth, site IDs).
What XISEM adds on top of EDR
Asset reconciliation — EDR agent ID ↔ XISEM agent ↔ Entra user
Unified Threat Center — EDR + COBRA + FIM + browsing in one queue
Compliance mapping — EDR evidence satisfies endpoint protection controls
PSA tickets — detection → ticket with cross-source context
ASPIRE Security pillar — gap when EDR missing on managed asset
Deployment order
XISEM agent on endpoints (posture + browsing + FIM path)
EDR as today (keep vendor console for containment)
Enable EDR Gateway per client
Tune duplicate suppression — same malware signal from EDR and COBRA may merge
Field note: coverage truth
Extension Health and EDR health together answer: “Is this laptop actually protected?” An EDR agent without XISEM agent misses browsing and posture correlation. XISEM agent without EDR may still score ASPIRE but Security pillar reflects the gap honestly.
Docs: Technology Alliances → SentinelOne MSP · CrowdStrike Falcon · Huntress
Download agents: dual-strike.com/downloads
Vendor trademarks belong to their owners — integration availability subject to API terms.


