EDR Gateways: SentinelOne, CrowdStrike, Huntress, and more
STAP note: EDR gateways are Strategic Technology Alliances under the Strategic Technology Alliance Program (STAP). XISEM extends and operationalizes EDR telemetry — it is not an EDR replacement.
Dual-Strike XISEM is not an EDR replacement. It is the correlation and governance layer that extends and operationalizes the EDR you already sell. EDR alliance gateways import detections, agent health, and asset mappings so COBRA², ASPIRE, and Threat Center see the same device the SOC already manages.
Route: Settings → Technology Alliances → EDR
Supported EDR families (public index)
• SentinelOne — MSP multi-tenant, Singularity API
• CrowdStrike Falcon — Enterprise and mid-market
• Huntress — SMB-focused managed EDR
• Microsoft Defender for Endpoint — M365-heavy clients
• Trend Micro, Sophos, others — See Technology Alliances wiki slug index
Exact setup steps live in Support wiki → Technology Alliances per vendor (API keys, OAuth, site IDs).
What XISEM adds on top of EDR
1. Asset reconciliation — EDR agent ID ↔ XISEM agent ↔ Entra user
2. Unified Threat Center — EDR + COBRA + FIM + browsing in one queue
3. Compliance mapping — EDR evidence satisfies endpoint protection controls
4. PSA tickets — detection → ticket with cross-source context
5. ASPIRE Security pillar — gap when EDR missing on managed asset
Deployment order
1. XISEM agent on endpoints (posture + browsing + FIM path)
2. EDR as today (keep vendor console for containment)
3. Enable EDR Gateway per client
4. Tune duplicate suppression — same malware signal from EDR and COBRA may merge
Field note: coverage truth
Extension Health and EDR health together answer: “Is this laptop actually protected?” An EDR agent without XISEM agent misses browsing and posture correlation. XISEM agent without EDR may still score ASPIRE but Security pillar reflects the gap honestly.
Docs: Technology Alliances → SentinelOne MSP · CrowdStrike Falcon · Huntress
Download agents: dual-strike.com/downloads
Vendor trademarks belong to their owners — integration availability subject to API terms.


