Building a detection capability
Collecting logs is not detection. Without relevant sources, without rules suited to your environment and without human qualification, a platform costs a great deal and produces only noise. Here is how we build detection you can actually use.
The problem is not the data, it is the signal
Most organisations already hold logs — directory, endpoints, firewall, cloud — but cannot answer simple questions: would we know that a privileged account had been used from an unusual machine? that access had been created outside procedure? that exfiltration had started?
Two pitfalls recur. The first is collecting everything without priorities, which makes ingestion costs explode without improving detection. The second is leaving the default rules in place, generating too many low-value alerts: the whole thing is soon ignored, and the real signals drown.
Our approach starts from the scenarios that genuinely threaten you, selects the sources that cover them, then writes and tunes the matching detections. Human qualification completes it: an alert is only worth something if someone handles it and closes it out.
- Critical sources missing from the collection scope
- Too many alerts, so nobody handles them any more
- Generic detections, unsuited to your environment
- No qualification or escalation procedure
- Ingestion costs drifting with no detection gain
A chain where every stage filters and enriches
How we proceed
We start on a narrow but useful scope, then extend once the chain has proved itself.
Threat scenarios
Identifying the scenarios that genuinely concern you — ransomware, mailbox compromise, privileged account abuse, exfiltration — and the assets to protect first.
Source selection
Choosing the logs that cover those scenarios, with an explicit trade-off between detection value and ingestion cost. Five sources well used beat thirty left idle.
Detection use cases
Writing and tuning the rules, mapped to MITRE ATT&CK, with thresholds suited to your environment. Every detection comes with its handling procedure.
Triage and noise reduction
Setting up the qualification process, the priorities and the escalation path, then tuning iteratively to eliminate recurring false positives.
Operations and progress
Managed monitoring (SOC-E or SOC-X), proactive threat hunting, readable reporting and continuous enrichment of the detections as your exposure evolves.
Several disciplines, a single point of contact
Building detection, operating it and knowing how to react when it fires: the three are inseparable.
- Prioritised threat scenarios and the matching sources
- Collection platform configured and documented
- Library of detection use cases
- Triage, prioritisation and escalation procedures
- Regular reporting and continuous improvement plan
Frequently asked questions
Would you detect an intrusion today?
Let's start from your threat scenarios: we scope the sources and detections that actually matter.