No more typing reviews! Try our Samantha, our new voice AI agent.

Expel vs Field Effect MDR comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Expel
Ranking in Managed Detection and Response (MDR)
14th
Average Rating
9.0
Reviews Sentiment
8.2
Number of Reviews
1
Ranking in other categories
SOC as a Service (4th)
Field Effect MDR
Ranking in Managed Detection and Response (MDR)
5th
Average Rating
9.2
Reviews Sentiment
7.5
Number of Reviews
31
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of August 2026, in the Managed Detection and Response (MDR) category, the mindshare of Expel is 2.5%, up from 1.9% compared to the previous year. The mindshare of Field Effect MDR is 1.5%, down from 3.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Managed Detection and Response (MDR) Mindshare Distribution
ProductMindshare (%)
Field Effect MDR1.5%
Expel2.5%
Other96.0%
Managed Detection and Response (MDR)
 

Featured Reviews

reviewer2578461 - PeerSpot reviewer
MDR Specialist at a tech services company with 201-500 employees
Rapid threat management and diverse technology integration for effective monitoring
Expel has made it easier for companies to monitor and manage various log sources. With its vast integration portfolio, customers can efficiently monitor diverse environments. Time to value is quick, as Expel can turn their service up very rapidly. They have both automated active responses and human processes that quicken threat resolution.
reviewer2753850 - PeerSpot reviewer
Owner at a tech services company with 1-10 employees
Customer security is enhanced with software and update detection while licensing process needs improvement
A quick specific example of how I use Field Effect MDR to keep my customers secure is that it helps me identify computers that need updates, even when I believe they are already updated. Field Effect MDR finds software and Windows updates that aren't being completed, which I find very valuable.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Their threat hunting protocol and process with AI and machine learning are strong, allowing for active and rapid responses."
"There are user notifications about our cloud solutions and access, meaning authentication and possible breaches. Overall, the notifications and alerts are valuable. There are also new features like the DNS protection, which is quite good."
"The standout feature is its continuous 24/7 monitoring of all network traffic, providing unparalleled vigilance."
"We now have a single cybersecurity product that protects all of our threat services, and all the endpoints."
"Hackers are trying to breach a business when they least expect it - that's often at night, weekends, and holidays. Covalence never sleeps or misses a second of monitoring."
"A client of ours with Field Effect MDR is less likely to be a victim of a cyber attack."
"The most valuable aspects of Covalence for me are the exceptional customer service and the support from the dedicated team."
"The alerts that we get are valuable. It notifies us if there is any attempted access and if there are any areas where we need to create more security for clients. It is stopping anything from happening before there is even an issue."
"The most valuable features are Action Recommendations of Observations, which keep us informed about existing vulnerabilities so we can proactively update our endpoints and those of our customers against potential threats."
 

Cons

"The one area where Expel may not measure up is if a customer requires a managed SIEM as part of their overall solution. There's a gap there, and solutions might require third-party assistance for management."
"While Covalence addresses our notification and visibility needs, it falls short in keeping information up-to-date, which is where our MSP comes in to supplement its functionality."
"The cost of the solution has room for improvement."
"The tagging of ARO closure has room for improvement."
"It would be incredibly valuable to have the Field Effect team handle some of the third-party application patching they're currently identifying."
"While it's essential to stay informed about potential issues, the recurring notifications about past vulnerabilities can lead to confusion and may detract from our focus on current threats."
"Covalence should provide a live view of the endpoint because the endpoint view in the portal is 5 to 15 minutes behind the actual status of the endpoint and its vulnerabilities. When it doesn't update with the actual status, it makes managing those things harder because sometimes something gets updated, and one of those vulnerabilities has gone away, but that doesn't appear in the ARO."
"One limitation is that if someone takes their laptop outside the office building, the DNS firewall provides minimal coverage, and we are unable to generate reports."
"I'd suggest that Field Effect focus more on including things like phishing simulation and cybersecurity training."
 

Pricing and Cost Advice

Information not available
"While Field Effect Covalence's pricing seems competitive for the market, the biggest hurdle lies in the lack of dedicated security budgets within many organizations."
"The pricing is fair and reasonable."
"We were particularly impressed with their pricing model, which charges per user rather than per system."
"The cost of the solution is high."
"It is a little pricey. It is a little on the high end, but we are continuing to use it. We signed the contract and have not canceled, so we find value in having it."
"The pricing is comparable to what else is out there."
"Although Covalence is expensive, it provides good value for the price."
"Field Effect is fairly priced from my perspective. You get a lot of bang for the buck with this and a level of visibility that provides you with greater peace of mind knowing that the system is carefully monitored. You also have automated responses for known malicious behavior at any time of the day. Someone could have their Office 365 mailbox compromised at 2 in the morning on a Saturday when most people are asleep or not paying attention, and the system can prevent an issue in an automated way."
report
Use our free recommendation engine to learn which Managed Detection and Response (MDR) solutions are best for your needs.
908,800 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
15%
Construction Company
11%
Manufacturing Company
9%
Computer Software Company
9%
Computer Software Company
22%
Manufacturing Company
14%
Outsourcing Company
8%
Construction Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business32
Midsize Enterprise3
 

Questions from the Community

What is your experience regarding pricing and costs for Expel?
Expel's pricing has adapted as the market evolved and has become competitive over the past twelve months.
What needs improvement with Expel?
The one area where Expel may not measure up is if a customer requires a managed SIEM as part of their overall solution. There's a gap there, and solutions might require third-party assistance for m...
What is your primary use case for Expel?
I have experience reselling Expel. Customers often come to me wanting to evaluate multiple providers to make a choice based on their specific use cases, requirements, technology investments, and so...
What is your experience regarding pricing and costs for Field Effect Covalence?
Pricing was initially a concern, but the recent updates have resolved that by offering a more accessible buying cost.
What needs improvement with Field Effect Covalence?
One way Field Effect MDR can be improved is through its licensing process, which is not ideal. The licensing process is difficult because I have to access a separate website to complete it.
What is your primary use case for Field Effect Covalence?
My main use case for Field Effect MDR is keeping my customers secure.
 

Also Known As

Workbench, Expel SOC-as-a-Service
Field Effect Covalence
 

Overview

 

Sample Customers

Amanda Fennell CSO
Field Effect MDR is widely adopted by managed service providers (MSPs) and organizations with lean IT teams. It is used to monitor, detect, and respond to threats across distributed environments, helping businesses strengthen their cybersecurity posture while maintaining operational efficiency. Organizations rely on Field Effect MDR to protect hybrid infrastructures, secure cloud applications, and defend against modern threats, including increasingly automated and AI-driven attacks, while maintaining compliance and resilience in a rapidly evolving threat landscape.
Find out what your peers are saying about Huntress, SentinelOne, CrowdStrike and others in Managed Detection and Response (MDR). Updated: July 2026.
908,800 professionals have used our research since 2012.