nesrine cherrabi

THREAT HUNTER

home / services

Services

Four ways to work together.

Every engagement starts with a 30-minute discovery call and ends with something you can act on: documented findings, working detection rules, or a team that can run the hunt themselves.

01 · Compromise assessment

Answer the question your dashboards can’t.

A time-boxed, hypothesis-driven threat hunt across endpoint, identity and network telemetry, aligned to MITRE ATT&CK. I start from how real adversaries behave and work backward into your data — assuming the alert never fired.

Typical shape

2–4 weeks · Fixed scope · Remote

Best fit when you have telemetry you’re not confident in, an acquisition to check before you connect it, or a suspicion nobody has had time to chase.

Tooling: Elastic Stack, Splunk, CrowdStrike Falcon; Volatility and Wireshark for forensic analysis.

Typical shape

1–3 weeks · Or monthly block · Remote

Best fit for MSSPs shipping detection content across client estates, and for SOC teams whose alert volume no longer matches their headcount.

Deliverables land as rules in your platform plus a written changelog — nothing locked in a consultant’s laptop.

02 · Detection rules

Turn an alert firehose into signal your team trusts.

Rule creation and tuning for Elastic Security, Splunk and EDR platforms. I audit what you can actually detect today, map it against ATT&CK, write the missing detections, and tune the ones burning your analysts out.

03 · Elastic Security training

Teach the team to run the hunt.

Hands-on remote sessions for analysts and SOC teams working in Elastic: building queries that answer real questions, authoring detection rules, and running a structured hunt end to end. Labs, not slideware.

Typical shape

Half-day to 3 days · Remote · Team or 1:1

Runs in your own stack where possible, so the exercises use data your team already recognises. Syllabus is agreed on the discovery call against the level you’re starting from.

Typical shape

Monthly · 3-month minimum · Remote

Priced on scope during the discovery call. Incident response is available inside a retainer or as a standalone engagement if something is already underway.

04 · Retainer & on-call advisory

A hunter on the books, not on the payroll.

A recurring monthly block of hunting and detection work, plus someone to call when something looks wrong. If an incident does start, you already have a responder who knows your environment.

Questions

Practical details.

The discovery call covers the rest — scope, access, and price against your actual environment.

Primarily Elastic Stack and Elastic Security, plus Splunk for SIEM work and CrowdStrike Falcon on the EDR side. Forensic analysis with Volatility and Wireshark.

Fixed price for scoped assessments and detection work, monthly for retainers, per-session for training. Scope is agreed in writing before anything starts — no open-ended hourly billing.

Read access to the relevant telemetry is usually enough to begin. Anything more invasive is requested explicitly, scoped to the engagement, and documented.

Yes — subcontracted hunting and detection content is a regular part of the work, under your brand and your process if that’s what you need.

Always. Client identities and engagement details never leave the engagement without written permission.

Tell me what’s keeping you up at night.

A 30-minute discovery call is the fastest way to work out which of these — if any — you actually need.

Scroll to Top