SIEM
Security monitoring and managed detection
Almost every organization we assess is already generating the logs that would have caught the breach. They are sitting in a firewall buffer that overwrites every six hours, or in a cloud tenant with a 30-day retention nobody configured. Detection is rarely a data problem. It is a correlation and attention problem.
This is what monitoring looks like from your side.
Read-only access for your team, the same view our analysts work from. Every alert carries the evidence that triggered it and the actions we took — so you are auditing our work, not taking it on trust.
- Events ingested
- 41.2M +6.8%
- Alerts raised
- 218 +14
- Escalated to you
- 6 +1
- Median time to ack
- 3m 41s −22s
Events per second · last 24 hours
| Time | Severity | Detection | Asset |
|---|---|---|---|
| 02:41:09 | Critical | Impossible travel followed by legacy auth success | svc-billing@corp |
| 01:12:55 | Critical | Mass file rename consistent with encryption | srv-fs02 |
| 23:47:31 | High | Kerberoasting — bulk service ticket harvest | ad01.corp.local |
| 22:03:12 | High | Outbound beacon, fixed 60-second jitter to new ASN | wks-4471 |
| 20:55:40 | Medium | Password spray against VPN portal | vpn-edge-01 |
Ingest tail
Alerts by severity · 24h
| Severity | Median ack | Target |
|---|---|---|
| Critical | 1m 34s | 5m |
| High | 2m 40s | 15m |
| Medium | 6m 14s | 60m |
| Time | Severity | Detection | Technique | Asset | Status |
|---|---|---|---|---|---|
| 02:41:09 | Critical | Impossible travel followed by legacy auth success | T1078.004 | svc-billing@corp | Escalated |
| 01:12:55 | Critical | Mass file rename consistent with encryption | T1486 | srv-fs02 | Contained |
| 23:47:31 | High | Kerberoasting — bulk service ticket harvest | T1558.003 | ad01.corp.local | In triage |
| 22:03:12 | High | Outbound beacon, fixed 60-second jitter to new ASN | T1071.001 | wks-4471 | Escalated |
| 20:55:40 | Medium | Password spray against VPN portal | T1110.003 | vpn-edge-01 | Auto-blocked |
| 17:21:06 | Medium | Local administrator created outside change window | T1136.001 | srv-app07 | Awaiting owner |
| 14:08:52 | Low | Storage container permission changed to public | T1580 | st-billing-prod | Closed · benign |
| 11:34:17 | Low | Endpoint telemetry service stopped | T1562.001 | wks-2210 | Closed · benign |
Select a row to open the full record
What happened
A service account authenticated from inside Pakistan at 02:38 and from a hosting provider in Eastern Europe three minutes later, the second attempt over a legacy protocol that bypasses multi-factor authentication. The second sign-in succeeded. This account holds delegated mailbox access.
Evidence
02:38:14 SignIn svc-billing@corp 103.x.x.x Pakistan MFA satisfied status=0 02:41:06 SignIn svc-billing@corp 198.51.100.61 Frankfurt, DE proto=IMAP4 status=0 02:41:09 Rule R-0142 fired confidence=high geo-delta=5,412km / 172s 02:41:22 Query mailbox rule enumeration observed count=3
Actions taken
- Session tokens revoked and account disabled at 02:43 under playbook PB-014.
- Legacy authentication blocked tenant-wide for the affected license group.
- Mailbox forwarding rules enumerated — one external rule found and removed.
- Client escalation call placed to the named on-call contact at 02:47.
- Sign-in history for the preceding 30 days exported for review.
Record
- Rule
- R-0142 · Identity
- Confidence
- High
- Detected
- 02:41:09 PKT
- Acknowledged
- +94 seconds
- Contained
- +2m 11s
- Analyst
- SOC shift C
Detection coverage mapped across the MITRE ATT&CK enterprise tactics. We publish the gaps as well as the coverage — a console claiming complete coverage of every tactic is not being straight with you. Collection and exfiltration are the usual weak columns, and closing them needs data sources most organizations have not turned on yet.
| Source | Type | Events / sec | Retention | Status |
|---|---|---|---|---|
| fw-edge-01 | FortiGate 600F | 4,180 | 400 d | Healthy |
| fw-edge-02 | FortiGate 600F | 3,905 | 400 d | Healthy |
| ad01.corp.local | Windows Security | 2,640 | 400 d | Healthy |
| ad02.corp.local | Windows Security | 2,588 | 400 d | Healthy |
| Sysmon fleet · 412 hosts | Endpoint telemetry | 6,120 | 180 d | Healthy |
| Entra ID tenant | Cloud identity | 910 | 730 d | Healthy |
| vpn-edge-01 | SSL VPN | 155 | 400 d | Healthy |
| srv-sql03 | SQL audit | 340 | 400 d | Degraded · 3.1% parse errors |
| st-billing-prod | Azure storage | 0 | 90 d | No data · 4h 12m |
Source health is a control in its own right. A firewall that quietly stopped forwarding logs four hours ago is a blind spot, not a quiet night — so silence is alerted on with the same weight as noise. The two non-healthy rows above are deliberate: this is what an honest console looks like on an ordinary day.
What is included.
Right for you if you have more than roughly 50 endpoints, any internet-facing service, or a compliance requirement to retain and review security logs.
- Log pipeline engineeringCollection from firewalls, endpoints, domain controllers, cloud tenants, databases, VPN concentrators and applications — normalized, timestamped and stored with tamper-evident retention.
- Detection engineeringCorrelation rules mapped to MITRE ATT&CK techniques and tuned to your environment, so the alerts that fire are the ones that mean something.
- 24/7 monitored SOCAnalyst coverage around the clock, with defined acknowledgement and escalation times per severity and a named account lead who knows your estate.
- Triage and responseAlert validation, containment actions taken under a pre-agreed playbook, and a written incident record for every escalation.
- Compliance reportingRetention, review evidence and audit trails aligned to ISO 27001, SOC 2 and PCI DSS logging requirements — produced monthly, not scrambled together the week before an audit.
- Threat huntingMonthly hypothesis-driven hunts across historical data for activity that never triggered a rule.
Four phases, in this order.
The order matters more than the speed. Every phase has an exit condition you sign off before the next one starts.
Source inventory
We identify every device and service that produces security-relevant logs, and confirm what is currently retained versus silently discarded.
Onboard and normalize
Collectors deployed, parsing validated, time synchronized. We prove end to end that a test event reaches the platform and is searchable.
Tune to a workable signal
Baseline for two to four weeks, suppress the noise your environment generates legitimately, and publish the detection catalog for your approval.
Monitor and improve
Live monitoring with monthly rule review, coverage gap analysis against ATT&CK and a quarterly detection maturity report.
What you receive.
- Documented log source inventory and coverage map
- Detection catalog mapped to MITRE ATT&CK
- Response playbooks per alert class
- Monthly SOC report: alerts, incidents, response times
- Audit-ready log retention evidence
What we work with.
- Microsoft Sentinel
- Wazuh
- Elastic Security
- Splunk
- Graylog
- Suricata
- Sysmon
- MITRE ATT&CK
- Sigma rules
We hold no exclusive reseller obligations. Recommendations are made on fit, your team's capacity to operate the thing, and local support availability — in that order.
SIEM, specifically.
Do we have to buy an expensive platform?
No. We deploy on Wazuh or Elastic where budget is the constraint, and on Microsoft Sentinel where you already hold the Microsoft licensing that makes it cheap. The engineering matters far more than the badge on the console.
What actually happens when something fires at 2am?
An analyst validates it within the acknowledgement window for that severity. If it matches a pre-approved containment playbook — isolate host, disable account, block address — we act immediately and tell you. If it does not, we call your escalation contact. You get a written record either way.
How much log volume is this?
For a 200-endpoint environment, typically 15–40 GB a day depending on how verbose your firewall is. We size and filter at the collector so you are not paying to ingest routine noise.
Often scoped alongside this.
Cybersecurity
Full-program security: risk assessment, policy, controls, audit readiness and the people to run it.
→VAPT
We break in the way an attacker would, then hand you the exact path, the evidence and the fix.
→Threat Intelligence
Region-specific intelligence on who is targeting your sector, plus continuous watch on your leaked credentials and exposed assets.
→Scope your siem engagement.
Send us the shape of your environment. You will get a written scope, a fixed price and a delivery timeline — usually within two business days.
Scoping calls are free · Reply within one business day