How ElasticIT Relies on Petra’s Advanced Detection Models to Protect Its Clients
- 6
- Missed incidents surfaced during the Petra Scan
- 5
- Live incidents caught by Petra that Huntress and other tools missed
- 1
- False positive since deploying Petra
“Even if [other ITDRs] build all these features, they’re still missing attacks. The most important thing is detection. That’s why we switched to Petra.”
ElasticIT is a managed services provider based in Independence, Ohio, serving healthcare providers across the US. The firm pairs managed IT and cloud services with custom healthcare software development, all built around HIPAA, HL7, and FHIR compliance and an automation-first approach.
Evaluating Petra’s Behavioral Detection
The Petra Scan surfaced six compromises other ITDRs had missed.
Anthony first heard of Petra from a peer MSP who was evaluating Petra as an alternative to Huntress. ElasticIT was already running Huntress for ITDR alongside Blumira, but Anthony was intrigued enough to run a Petra Scan on the last six months of their logs. Within 48 hours, the Scan surfaced six uncaught incidents that ElasticIT’s existing tools had missed.
The Petra Scan surfaced six incidents. Yeah. You can’t unsee that.
In one case the attacker had access to the account through Microsoft’s Direct Send functionality to bypass email security through an email titled “Action Required: Service Termination Alert.” In another, the attacker went undetected by using a residential proxy. Both are the kind of modern attack that slips past traditional ITDRs, since the activity looks local and legitimate. Petra’s machine learning models uncover user intent, allowing them to identify these as compromises.
The Scan also surfaced compromises ElasticIT had already remediated, and Anthony was struck by how much time his team would have saved on forensics and reporting had Petra been deployed sooner. Two incidents in the weeks before he found Petra had each required a full-day Purview investigation. Petra’s forensic report was delivered in about ten minutes.
I log in and Petra built the report that took us all day to pull. So that was another thing that just sold itself.
Petra’s Detection in the Wild
Running side by side against three tools, Petra caught five live compromises missed by all the others.
The Scan convinced Anthony and the ElasticIT team to deploy Petra fully across their tenant base.
At one of their largest tenants, Petra runs side by side with Huntress, Aegis, and Abnormal Security for contractual reasons. So far, Petra has caught five compromises, none of which were caught by the other three tools.
In addition to upleveling their detection capabilities, Anthony’s team has also reduced noise from false positives.
Since we’ve signed up, we’ve had one false positive. It came through as an incident, and then you guys reclassified it as a leak.
Before Petra, ElasticIT never had password leaks surfaced by its security stack. Petra’s leak detection catches a specific gap that Anthony’s team was never able to stop before:
Before, these attackers would successfully log in using the username, password, and MFA, but then the conditional access would block them. Later, this same user submits a travel notice, so we exclude them, and the attacker gets into the account. We knew this was going to happen, except [our other tools] never told us. These password leak notices from Petra catch that.
Comprehensive Remediation and Reporting
ElasticIT now runs a tighter close on every incident, keeping clients happier and more loyal.
Detection is what Anthony cares about most, but he’s quick to point out that the rest of the platform is what keeps his team’s efficiency and service quality high.
Petra’s end-to-end remediation ensures his team fully closes out an incident:
The other thing too that we really love about Petra is that it forces the tech to go through the process. [Our other tools] do not; they just give you a text file of what you need to do as the tech, and if they do it or not, is another story. Petra requires them to go through the steps to mark it remediated. So yeah, that’s been huge too.
Anthony is also able to keep clients in the loop sooner thanks to Petra’s fast turnaround. Previously, ElasticIT often delayed notifying clients until investigations were complete to avoid causing panic. Their answers came from Purview searches that took all day and ran about 24 hours behind, with clients pressing for updates. White-labeled reports now go to clients when incidents occur, replacing a process that, according to Anthony, was resource intensive, slow and didn’t always produce user-friendly output.
Now within 10 minutes, we can just go here’s your report of exactly what happened. In the future, some of our clients might not even call their cyber carrier because they feel we can handle it since we’re able to just confidently hand them this piece of paper in a very quick turnaround. That’s definitely something that keeps the relationship healthy in a big way.
Audit Log Search
Petra’s audit log search is an included capability that Anthony rates above paid SIEM tools.
That audit log search is invaluable. To be able to go in there and search the tenant… we never had that with our past ITDR.
Petra’s audit log search has become one of Anthony’s favorite features. The ElasticIT team spends far less time in Purview these days as a result. Anthony touts the search as better than paid SIEM tools, and values it enough that he thinks it could stand on its own as a product.
To do the same thing inside of Huntress, you would have had to pay for a SIEM license, and the search in UI wouldn’t have been as good. You run a search [in Purview] and then wait three hours for results, then ... I screwed up the filter, so I gotta run it again. And then you waste three more hours. Like this is just so fast.
ElasticIT is a managed services provider based in Independence, Ohio, serving healthcare providers across the US. The firm pairs managed IT and cloud services with custom healthcare software development, all built around HIPAA, HL7, and FHIR compliance and an automation-first approach. To get best-in-class Microsoft 365 identity protection through a world-class MSP, visit https://www.elasticit.com/.
More Stories
See what's in your last six months of logs.
Get insurance-grade forensics on the last 6 months of your M365 logs. Setup takes 5 minutes with results in 48 hours.


