MSP first 7 days: Dual-Strike XISEM quickstart
Onboarding a new MSP practice or client org on Dual-Strike XISEM follows a predictable arc. This 7-day quickstart is the public version of what successful partners run internally — no internal codenames, no infra details.
The Anti-Venom prevent suite is four surfaces on one correlated graph:
• Secure Access — browser policy, phishing paths, SaaS / Shadow AI visibility (dual-strike.com/antivenom/access)
• Secure Resolve — endpoint DNS protection that travels with the laptop (dual-strike.com/antivenom/resolve)
• Secure Elevate — just-in-time local admin; eliminate standing privilege (dual-strike.com/antivenom/elevate)
• Secure Control — desired-state policy and drift assurance on the endpoint (dual-strike.com/antivenom/control)
All four feed Dual-Strike XISEM evidence, ASPIRE, Threat Center, and compliance — they do not replace your EDR, IdP, or RMM.
Day 1 — Foundation
• Create MSP org and first client org
• Invite analyst seats (role-based access)
• Download XISEM Agent (Scout) and Anti-Venom components from dual-strike.com/downloads
• Deploy agent to 3–5 pilot endpoints (mix of desktop + laptop)
• Confirm the pilot set can take Secure Elevate and Secure Resolve later in the week (Windows 10/11 for Resolve)
Day 2 — Secure Access (browser)
• Install Anti-Venom Secure Access from Chrome Web Store / Edge Add-ons / Firefox AMO
• Publish browser policy in Settings → Browser Extension (start Monitor / learning where appropriate)
• Open Browsing Insights — verify sessions within 24h
• Check Extension Health — aim for Healthy, not Not Detected on active machines
• Spot-check one Shadow AI / risky SaaS signal so the client narrative is ready for Day 7
Day 3 — Secure Resolve + Secure Elevate
• Enable Anti-Venom Secure Resolve on the pilot agents — endpoint DNS protection for apps and browsers that bypass OS filtering
• Confirm Resolve blocks / allows show up as evidence on the same asset timeline as Secure Access sessions
• Enable Anti-Venom Secure Elevate on pilot endpoints — remove standing local admin; run one JIT elevation with full audit
• Walk helpdesk through the elevation request path once so Day 7 demos are not the first live use
Day 4 — Identity Gateways
• Establish Microsoft GDAP (or client-specific identity Gateway — Entra, Google Workspace, Okta as applicable)
• Validate Entra / Workspace sign-ins on Asset timelines
• Skim Conditional Access intelligence — context only this week, no enforcement experiments on production users
• Tie one elevated admin identity from Day 3 back to the sign-in story (privilege + identity correlation)
Day 5 — EDR, PSA, and Secure Control
• Connect primary EDR Gateway (SentinelOne, CrowdStrike, Huntress, Microsoft Defender, etc.)
• Connect PSA (ConnectWise, Autotask, Halo, SuperOps, …)
• Fire a test detection → confirm ticket creates with readable evidence body
• Turn on Anti-Venom Secure Control desired-state / drift baselines for the pilot (USB / peripheral and host configuration posture as licensed)
• Start Control in audit / observe before block so the client sees evidence first
Day 6 — Detection, compliance, and reporting
• Enable COBRA² rules in learning mode: shadow AI, posture regression, identity drift, privilege misuse
• Review Threat Center volume — disable noisy rules; keep Elevate / Resolve / Access signals in the same queue story
• Select target framework (SOC 2, NIST, CMMC, …) and review initial control gaps
• Schedule first monthly executive report — include Anti-Venom coverage and Elevate standing-admin reduction
Day 7 — Client readout
• Walk the client through the Asset modal on one device (live demo)
• Show Browsing Insights (Secure Access) + a Resolve block/allow on the same user
• Show one Secure Elevate elevation with who / when / why evidence
• Show Secure Control drift or USB posture if in scope for the pilot
• Agree remediation priorities from POA&M top items
Success metrics at day 7
• Agent coverage — >80% of managed endpoints in pilot
• Secure Access — active users reporting Healthy / Idle Extension Health
• Secure Resolve — at least one policy sync + evidence event on pilot devices
• Secure Elevate — standing local admin removed on pilot set; ≥1 audited JIT elevation
• Secure Control — baseline observed (audit mode) with zero unexplained critical drift
• Identity events — sign-ins visible for M365 / Workspace clients
• PSA loop — at least one ticket round-trip with readable evidence
• Detections — <5 false-positive Criticals after tuning
Deep dives: Anti-Venom suite · Evidence doctrine · COBRA² guide · GDAP onboarding · press.dual-strike.com
Adjust pacing for client size — enterprise may need 14 days for change windows. Ship Access first if browser risk is the sales driver; ship Elevate first if standing admin is the audit finding.


