Huntress vs ThreatLocker: block everything, or watch everything
ThreatLocker blocks what is not on the list. Huntress watches what gets through. Most businesses comparing them are asking the wrong question.
Read articleEndpoint & Detection
Both run a 24/7 SOC for small businesses. Huntress publishes its prices and sells direct. Blackpoint publishes none and sells mainly through MSPs.
These two get shortlisted together more often than any other pair we see, and for a good reason: they are solving the same problem in the same way. Both run a 24/7 security operations centre aimed at businesses that will never hire a security analyst. Both cover endpoints and Microsoft 365. Both talk about containment rather than notification.
The difference that actually decides it is not detection philosophy. It is procurement.
Disclosure: Obsidian Ridge is a Huntress MSSP partner and delivers Huntress-powered managed detection and response. Read the recommendation below with that in mind. Blackpoint is a serious product and the "Blackpoint fits you better" case below is real.
Huntress lists per-product pricing on its own site — Managed EDR at $8.99 per endpoint per month, Managed ITDR at $4.80 per licensed identity, with a 50-seat minimum per product when buying direct or through a reseller and no Huntress-required minimum through an MSP.
Blackpoint's pricing page says the opposite, in their words:
"Blackpoint Cyber primarily offers our products and services via Managed Service Providers (MSPs). To preserve our partners' pricing confidentiality, we do not list our rates publicly on our website."
— blackpointcyber.com, retrieved 28 August 2026
Neither approach is wrong. They are different distribution strategies with different consequences for you. If you are a twelve-person firm trying to price security on a Tuesday afternoon, one of these lets you do arithmetic and the other requires a sales conversation first.
Treat any Blackpoint per-endpoint number you find on a comparison or aggregator site as unverified. Blackpoint publishes none, so those figures came from somewhere else.
The umbrella platform is CompassOne; the security suite is Blackpoint Response. It covers endpoint MDR with what they call active response, cloud MDR across "Microsoft 365, Google Workspace, Cisco DUO, and Azure SSO," and identity detection and response, with managed application control and dark web monitoring alongside. (blackpointcyber.com, retrieved 28 August 2026.)
Their positioning is aggressive about the difference between alerting and acting:
"Most MDR tools alert; Blackpoint's SOC takes ownership of the threat and responds."
"Blackpoint's 24/7/365 human-staffed, AI-accelerated Security Operations Center takes ownership of the threat, investigating, containing, and remediating it, not just flagging it and moving on."
That is a real distinction and worth taking seriously when you evaluate them.
They also publish performance claims — containment averaging "under two minutes, and as fast as 21 seconds," and a figure that "traditional EDR misses 72% of attacks." Those are Blackpoint's own marketing metrics with no published methodology attached. Ask for the methodology in a sales conversation rather than treating them as established facts. The same caution applies to vendor metrics on our side of the table.
Huntress. Read the price on the website. Above 50 seats you can buy direct. Below 50 you go through a partner, because a direct purchase makes you pay for seats you will not deploy.
Blackpoint. Fill in a form. Blackpoint publishes no partner directory that we could find, so a business with no existing IT provider submits a contact form and waits to be routed. Their reseller agreement does reserve direct rights — "Blackpoint, directly or through other resellers or sales agents, may also market and distribute the Services" — so it is partner-first rather than partner-only, but the public path assumes a partner.
One term is published, in a May 2025 datasheet: Cloud MDR Essentials and Endpoint MDR Essentials are described as available month-to-month with no annual commitment, with tiered volume pricing "available for 50 endpoints or more with a minimum one-year commitment." That datasheet is over a year old, so confirm it still holds before relying on it.
Blackpoint is wrong for you if you want to compare costs before talking to anyone, you have no MSP relationship and no appetite to acquire one, or you need a number this week for a budget you are building.
Huntress is wrong for you if you have fewer than 50 endpoints and no interest in a partner — the direct minimum means paying for seats you will never use — or if you specifically want a single vendor whose SOC will take containment actions across network, identity and endpoint under one contract with no intermediary.
Three questions, and the first hard answer ends it.
For the architectural version of this question against a differently-shaped competitor, Huntress vs Arctic Wolf covers what changes when a vendor correlates your existing tools instead of bringing its own.
Our own managed detection and response runs on Huntress with no minimum seat count, and Ridge Watch pricing is public for the same reason Huntress publishes theirs. If you want help running this comparison honestly, book a briefing.
If the deadline behind this decision is a carrier questionnaire rather than an incident, decide the cyber insurance readiness question first. Both products can produce a defensible yes; only one of them will match how your team actually operates at 2am.
Last updated
August 30, 2026. We refresh this content as the threat landscape and tools evolve.
FAQ
Blackpoint does not publish pricing. Their own pricing page states that they primarily sell through managed service providers and that, to preserve partner pricing confidentiality, they do not list rates publicly. Any per-endpoint figure on a third-party aggregator site is unverified until you have a quote in writing.
Not straightforwardly. Blackpoint describes its distribution as primarily through MSPs, and publishes no partner directory. A business with no existing IT provider would submit a contact form and expect to be routed to a partner. Their reseller agreement does reserve the right to sell directly, so it is not contractually MSP-exclusive.
Blackpoint runs a 24/7 security operations centre under the CompassOne platform, covering endpoint detection with active response, cloud detection across Microsoft 365, Google Workspace, Cisco Duo and Azure SSO, and identity detection and response. Their positioning emphasises the SOC taking containment action rather than forwarding alerts.
They are closer in model than most pairings in this market — both run a 24/7 SOC aimed at businesses without security staff. The practical difference is how you buy. Huntress publishes per-product pricing and sells direct above 50 seats. Blackpoint publishes nothing and expects a partner in the middle.
Yes. Their materials describe Cloud MDR covering Microsoft 365, Google Workspace, Cisco Duo and Azure SSO, alongside endpoint MDR and identity detection and response.
Related reading
ThreatLocker blocks what is not on the list. Huntress watches what gets through. Most businesses comparing them are asking the wrong question.
Read articleTodyl sells a six-module platform including the network layer, channel-only, with no published pricing. Huntress sells a layer and publishes its rates.
Read articleIf you pay for Microsoft 365 Business Premium you already have EDR. The question is who reads the alerts — and Microsoft will not sell you that service.
Read article