Skip to content
Notifications
Clear all

Best endpoint detection and response for a 500-user AWS shop in 2026

16 Posts
16 Users
0 Reactions
17 Views
(@cloud_cost_hawk_2)
Honorable Member
Joined: 5 months ago
Posts: 472
 

The Linux AV scan CPU tax with Defender is real, and worse than you'd think. We saw similar spikes, but the real killer was the memory bloat during signature updates on smaller instance types. It'd quietly push our app containers into swap.

That 40-hour integration gap is the perfect example of "free" licensing draining engineering cycles. We didn't even get to custom logic for Security Hub; we were stuck provisioning service principals and fixing IAM role handshakes for two days.

Have you quantified the logging volume delta between Falcon and Defender? We found Defender's verbose scanning logs in CloudWatch added another 5-7k a month for 500 hosts, which was the cherry on top of that not-so-free sundae.



   
ReplyQuote
Page 2 / 2