Threats found and triaged before they spread
Managed detection and response on your infrastructure, with detection rules tuned to your environment rather than a vendor default.
The challenge
Most SMEs have logs and no one reading them. Default detection rules generate so much noise that real alerts are lost inside it.
Scope — included and not included
Included
- Log ingestion from endpoints, servers, firewalls and cloud
- Detection rules mapped to MITRE ATT&CK
- Alert triage by an analyst
- Tuning to remove false positives
- Monthly reporting
- Threat intelligence enrichment
Not included
- Remediation on your systems
- Endpoint agent licences
- Log storage beyond the retention in your tier
- Response outside your tier coverage window
- Application-level logging you do not already produce
How it works
01
Connect log sources
Inventory your telemetry and connect endpoints, servers, firewalls and cloud.
02
Tune detection
Adapt rules to your environment and remove the noise a default ruleset generates.
03
Monitor and triage
An analyst investigates alerts, adds context and escalates with a recommended action.
04
Report monthly
Executive summary, detection coverage and tuning decisions, every month.
What you receive
- →Live dashboard
- →Triaged alerts with context and recommended action
- →Monthly executive summary
- →Detection coverage map against ATT&CK
- →Quarterly tuning review
What we need from you
- ·Log source inventory
- ·Agent deployment access
- ·A named technical contact
- ·Escalation contacts
- ·Two to three hours during onboarding
Timeline and engagement
Onboarding around 4 weeks. Recurring monthly, 30-day notice.
Standards, methods and tooling
WazuhMISPOpenCTIDFIR-IRISMITRE ATT&CKPortal hosted in Canada
Frequently asked questions