Define
Confirm alert validation and the expected result.
Rapid triage and investigation of alerts, unusual activity, compromised accounts and suspected intrusion.
An alert rarely explains the whole event. Investigation brings together the agreed logs and activity records to determine what is known, what may be affected and where further evidence is needed.
Give decision-makers a supported incident timeline, scope assessment and recommended next actions.
The final scope identifies the applicable SIEM, EDR, Cloud audit logs environment, access boundaries and responsible owners.
Confirm alert validation and the expected result.
Agree access for SIEM and EDR.
Complete timeline development with visible ownership.
Document log and endpoint review and follow-up actions.
The starting scope can include alert validation, timeline development, log and endpoint review. The final responsibilities and deliverables are confirmed during discovery.
Relevant environments can include SIEM, EDR, Cloud audit logs, Identity logs. Exact versions, access and technical boundaries are reviewed before work begins.
This service is commonly used by hosting and cloud providers, saas and technology teams, managed service providers. The engagement can support an internal team or a clearly defined outsourced function.
Give decision-makers a supported incident timeline, scope assessment and recommended next actions.