Services
Partners
Use cases
Clients
Company
Contact
FRENDE
Managed detection

Building a detection capability

Collecting logs is not detection. Without relevant sources, without rules suited to your environment and without human qualification, a platform costs a great deal and produces only noise. Here is how we build detection you can actually use.

The challenge

The problem is not the data, it is the signal

Most organisations already hold logs — directory, endpoints, firewall, cloud — but cannot answer simple questions: would we know that a privileged account had been used from an unusual machine? that access had been created outside procedure? that exfiltration had started?

Two pitfalls recur. The first is collecting everything without priorities, which makes ingestion costs explode without improving detection. The second is leaving the default rules in place, generating too many low-value alerts: the whole thing is soon ignored, and the real signals drown.

Our approach starts from the scenarios that genuinely threaten you, selects the sources that cover them, then writes and tunes the matching detections. Human qualification completes it: an alert is only worth something if someone handles it and closes it out.

What is at stake
  • Critical sources missing from the collection scope
  • Too many alerts, so nobody handles them any more
  • Generic detections, unsuited to your environment
  • No qualification or escalation procedure
  • Ingestion costs drifting with no detection gain
Diagram

A chain where every stage filters and enriches

From collection to useful detection PLATFORMOPERATIONS1Source collectionidentity · endpoints · network · cloud2Normalisationconsistent formats · enrichment3Detection use casesscenarios mapped to MITRE ATT&CK4Triage and qualificationnoise reduction · prioritisation5Response and improvementactions · rule tuningSOC-E / SOC-Xmaintained rulesthreat huntingintegrated response
The platform collects and normalises; operations turn events into qualified alerts, and then into action.
Our approach

How we proceed

We start on a narrow but useful scope, then extend once the chain has proved itself.

01

Threat scenarios

Identifying the scenarios that genuinely concern you — ransomware, mailbox compromise, privileged account abuse, exfiltration — and the assets to protect first.

02

Source selection

Choosing the logs that cover those scenarios, with an explicit trade-off between detection value and ingestion cost. Five sources well used beat thirty left idle.

03

Detection use cases

Writing and tuning the rules, mapped to MITRE ATT&CK, with thresholds suited to your environment. Every detection comes with its handling procedure.

04

Triage and noise reduction

Setting up the qualification process, the priorities and the escalation path, then tuning iteratively to eliminate recurring false positives.

05

Operations and progress

Managed monitoring (SOC-E or SOC-X), proactive threat hunting, readable reporting and continuous enrichment of the detections as your exposure evolves.

Services involved

Several disciplines, a single point of contact

Building detection, operating it and knowing how to react when it fires: the three are inseparable.

Deliverables
  • Prioritised threat scenarios and the matching sources
  • Collection platform configured and documented
  • Library of detection use cases
  • Triage, prioritisation and escalation procedures
  • Regular reporting and continuous improvement plan
Frequently asked questions

Frequently asked questions

No, and this is the main lever for saving money. We start from the scenarios to detect in order to choose the sources that cover them. Exhaustive collection costs a lot in ingestion and storage without improving detection if no rule makes use of it.

A useful foundation — main sources, first detections, triage procedure — takes a few weeks. Maturity is then built by iteration, adding use cases and refining thresholds.

No. Our managed monitoring runs during business hours, with clear escalation procedures. We prefer to say so plainly rather than promise round-the-clock cover we do not provide.

We work mainly on Microsoft Sentinel and the Defender suite, where our added value is greatest. If you run another platform, let's discuss it: depending on the context, our support then focuses on the use cases and the triage process rather than on the tool.

Would you detect an intrusion today?

Let's start from your threat scenarios: we scope the sources and detections that actually matter.