home / services
Services
Four ways to work together.
Every engagement starts with a 30-minute discovery call and ends with something you can act on: documented findings, working detection rules, or a team that can run the hunt themselves.
01 · Compromise assessment
Answer the question your dashboards can’t.
A time-boxed, hypothesis-driven threat hunt across endpoint, identity and network telemetry, aligned to MITRE ATT&CK. I start from how real adversaries behave and work backward into your data — assuming the alert never fired.
- Findings documented with evidence, host, and ATT&CK technique
- Detection gaps that let the activity go unnoticed
- Plain-language report for both engineers and management
- Escalation to full incident response if the hunt finds something live
Typical shape
2–4 weeks · Fixed scope · Remote
Best fit when you have telemetry you’re not confident in, an acquisition to check before you connect it, or a suspicion nobody has had time to chase.
Tooling: Elastic Stack, Splunk, CrowdStrike Falcon; Volatility and Wireshark for forensic analysis.
Typical shape
1–3 weeks · Or monthly block · Remote
Best fit for MSSPs shipping detection content across client estates, and for SOC teams whose alert volume no longer matches their headcount.
Deliverables land as rules in your platform plus a written changelog — nothing locked in a consultant’s laptop.
02 · Detection rules
Turn an alert firehose into signal your team trusts.
Rule creation and tuning for Elastic Security, Splunk and EDR platforms. I audit what you can actually detect today, map it against ATT&CK, write the missing detections, and tune the ones burning your analysts out.
- Coverage audit mapped to ATT&CK tactics and techniques
- New rules written, tested against real telemetry, and documented
- False-positive tuning on the rules generating the most noise
- Triage notes per rule so on-call analysts know what to do
03 · Elastic Security training
Teach the team to run the hunt.
Hands-on remote sessions for analysts and SOC teams working in Elastic: building queries that answer real questions, authoring detection rules, and running a structured hunt end to end. Labs, not slideware.
- Query building and data exploration in Elastic Security
- Writing and testing detection rules against live telemetry
- Structured hunting: hypothesis, data, verdict, documentation
- Team sessions or one-to-one mentoring for individual analysts
Typical shape
Half-day to 3 days · Remote · Team or 1:1
Runs in your own stack where possible, so the exercises use data your team already recognises. Syllabus is agreed on the discovery call against the level you’re starting from.
Typical shape
Monthly · 3-month minimum · Remote
Priced on scope during the discovery call. Incident response is available inside a retainer or as a standalone engagement if something is already underway.
04 · Retainer & on-call advisory
A hunter on the books, not on the payroll.
A recurring monthly block of hunting and detection work, plus someone to call when something looks wrong. If an incident does start, you already have a responder who knows your environment.
- Agreed hours per month across hunting, rules, and review
- Priority response on suspected incidents, with a pre-agreed fast path
- Triage, containment guidance, and attacker timeline reconstruction
- Overflow capacity for MSSPs and MSPs across MENA and Europe during busy periods
Questions
Practical details.
The discovery call covers the rest — scope, access, and price against your actual environment.
Which SIEM and EDR platforms do you work with?
Primarily Elastic Stack and Elastic Security, plus Splunk for SIEM work and CrowdStrike Falcon on the EDR side. Forensic analysis with Volatility and Wireshark.
How are engagements priced?
Fixed price for scoped assessments and detection work, monthly for retainers, per-session for training. Scope is agreed in writing before anything starts — no open-ended hourly billing.
What access do you need?
Read access to the relevant telemetry is usually enough to begin. Anything more invasive is requested explicitly, scoped to the engagement, and documented.
Do you work with MSSPs on their clients’ environments?
Yes — subcontracted hunting and detection content is a regular part of the work, under your brand and your process if that’s what you need.
Can you sign an NDA?
Always. Client identities and engagement details never leave the engagement without written permission.
Tell me what’s keeping you up at night.
A 30-minute discovery call is the fastest way to work out which of these — if any — you actually need.