Security platform engineering for MSPs and MSSPs

The Falcon and Sentinel engineer you have been trying to hire.

We build, migrate, onboard and tune CrowdStrike Falcon and Microsoft Sentinel for managed service providers. Fixed scope, fixed price, delivered under your brand, on your clients' tenants, on US hours.

Example finding 04. High severity.
Client
Tenant ID
--
Scope
3 host groups, 412 hosts
Hosts
and 411 more
Exclusion
C:\ProgramData\**\*.exe
Added
Unknown. Owner: unknown.
Effect
ML off in ProgramData
Evidence
11 untriaged detections, 30d
Fix
Hash exclusion; re-enable ML
Effort
2h, week 1
Report summary
23 findings in the report:
2 critical 6 high 11 medium 4 low
30-day plan: 20 actions, 3 weeks
Example finding 04. High severity.
Client
Hosts
+411
Exclusion
C:\ProgramData\**\*.exe
Fix
Hash excl.; re-enable ML
Effort
2h, week 1
Report summary
23 findings in the report:
2 critical 6 high 11 medium 4 low
30-day plan: 20 actions, 3 weeks

An example finding from a Falcon Health Check. Client data stays redacted, in our reports and in our hands.

Redacted. Client data does not leave the tenant.
  • CCFA

    CrowdStrike Certified Falcon Administrator

  • 500+

    Detection rules running in production

  • 100,000+

    Endpoints across 20+ Falcon tenants

  • UTC-3

    Working US and EU business hours

Why MSPs call us

You sold the platform. Now someone has to make it work.

Falcon and Sentinel are only as good as their configuration. Most tenants we see have sensors missing, exclusions nobody remembers adding, detections that fire on the same false positive every week, and SIEM ingestion bills nobody can explain. Your SOC monitors what the platform produces. If the platform is badly built, the SOC is watching noise.

Hiring a senior Falcon or Sentinel engineer in the US costs $150,000 to $220,000 a year fully loaded, and the job stays open for months. We are the engineer behind your brand, at a fraction of that, starting with a single fixed-scope project.

  1. 1

    Read-only first.

    Every engagement starts with access you can revoke in one click. We audit before we touch anything.

  2. 2

    Your tenant, your brand.

    Nothing leaves the client tenant. No logs on our machines. Reports carry your logo. We never contact your end clients.

  3. 3

    Fixed scope, fixed price.

    You know the cost before we start. Scope changes are a new SOW, not a surprise invoice.

Work you can inspect

We are publishing our Falcon and Sentinel detection library. Each one ships with the logic, the expected false positives and the recommended response. Ask for early access on the call.

Who you are working with

Gabriel Jabour

Founder

Security engineer with 4+ years in security operations, detection engineering and incident response for organisations in the UK, Canada and the US. CrowdStrike Certified Falcon Administrator. Daily work in Falcon, Next-Gen SIEM, Microsoft Sentinel and Defender XDR, including Falcon operations across 20+ client tenants and 100,000+ endpoints. Builds open-source security tooling used by analysts.

Certifications
CCFA, CompTIA Security+, Microsoft SC-900, AZ-900, AI-901

FAQ

Yes. Reports, documentation and communication carry your brand. We never contact your end clients and we sign a 24-month non-solicitation.

Brazil, UTC-3. We cover US Eastern to Pacific business hours and UK and EU hours.

For health checks, read-only roles only (Falcon read-only Administrator or Analyst; Sentinel Reader). For migrations and onboarding, scoped admin roles through a named account you issue, with MFA, revoked at the end.

No. We operate inside your tenant as your contractor, under CrowdStrike's and Microsoft's customer contractor terms. Your partner status and licensing stay with you.

All data stays in the client tenant. We do not export logs, telemetry or evidence to our systems. Devices are managed and encrypted. We sign your NDA and DPA.

No. We build and tune what your SOC monitors. If you use Falcon Complete or a white label SOC, we are the engineering layer in front of it.

No. We do not access CUI, ITAR-controlled data or FedRAMP environments.

USD, by international transfer or Wise; card through Stripe on request. 50% at SOW signature, 50% at delivery. Monthly in advance for dedicated engineers.

Start with a health check.

One tenant, read-only access, ten business days, $2,500. You get a report you can hand to your client and a 30-day plan you can execute with or without us.

Engagement: day 0, access; days 1 to 8, review in your tenant; day 9, report; day 10, walkthrough; then the next 30 days, plan executed by your team or by us.

Book a 20-minute call