Security platform engineering for MSPs and MSSPs
The Falcon and Sentinel engineer you have been trying to hire.
We build, migrate, onboard and tune CrowdStrike Falcon and Microsoft Sentinel for managed service providers. Fixed scope, fixed price, delivered under your brand, on your clients' tenants, on US hours.
- Client
- Tenant ID
- --
- Scope
- 3 host groups, 412 hosts
- Hosts
- and 411 more
- Exclusion
- C:\ProgramData\**\*.exe
- Added
- Unknown. Owner: unknown.
- Effect
- ML off in ProgramData
- Evidence
- 11 untriaged detections, 30d
- Fix
- Hash exclusion; re-enable ML
- Effort
- 2h, week 1
- Client
- Hosts
- +411
- Exclusion
- C:\ProgramData\**\*.exe
- Fix
- Hash excl.; re-enable ML
- Effort
- 2h, week 1
An example finding from a Falcon Health Check. Client data stays redacted, in our reports and in our hands.
- CCFA
CrowdStrike Certified Falcon Administrator
- 500+
Detection rules running in production
- 100,000+
Endpoints across 20+ Falcon tenants
- UTC-3
Working US and EU business hours
Why MSPs call us
You sold the platform. Now someone has to make it work.
Falcon and Sentinel are only as good as their configuration. Most tenants we see have sensors missing, exclusions nobody remembers adding, detections that fire on the same false positive every week, and SIEM ingestion bills nobody can explain. Your SOC monitors what the platform produces. If the platform is badly built, the SOC is watching noise.
Hiring a senior Falcon or Sentinel engineer in the US costs $150,000 to $220,000 a year fully loaded, and the job stays open for months. We are the engineer behind your brand, at a fraction of that, starting with a single fixed-scope project.
What we do
How we work
Access, data and paperwork- 1
Read-only first.
Every engagement starts with access you can revoke in one click. We audit before we touch anything.
- 2
Your tenant, your brand.
Nothing leaves the client tenant. No logs on our machines. Reports carry your logo. We never contact your end clients.
- 3
Fixed scope, fixed price.
You know the cost before we start. Scope changes are a new SOW, not a surprise invoice.
Work you can inspect
We are publishing our Falcon and Sentinel detection library. Each one ships with the logic, the expected false positives and the recommended response. Ask for early access on the call.
Who you are working with
Gabriel Jabour
Founder
Security engineer with 4+ years in security operations, detection engineering and incident response for organisations in the UK, Canada and the US. CrowdStrike Certified Falcon Administrator. Daily work in Falcon, Next-Gen SIEM, Microsoft Sentinel and Defender XDR, including Falcon operations across 20+ client tenants and 100,000+ endpoints. Builds open-source security tooling used by analysts.
- Certifications
- CCFA, CompTIA Security+, Microsoft SC-900, AZ-900, AI-901
FAQ
Yes. Reports, documentation and communication carry your brand. We never contact your end clients and we sign a 24-month non-solicitation.
Brazil, UTC-3. We cover US Eastern to Pacific business hours and UK and EU hours.
For health checks, read-only roles only (Falcon read-only Administrator or Analyst; Sentinel Reader). For migrations and onboarding, scoped admin roles through a named account you issue, with MFA, revoked at the end.
No. We operate inside your tenant as your contractor, under CrowdStrike's and Microsoft's customer contractor terms. Your partner status and licensing stay with you.
All data stays in the client tenant. We do not export logs, telemetry or evidence to our systems. Devices are managed and encrypted. We sign your NDA and DPA.
No. We build and tune what your SOC monitors. If you use Falcon Complete or a white label SOC, we are the engineering layer in front of it.
No. We do not access CUI, ITAR-controlled data or FedRAMP environments.
USD, by international transfer or Wise; card through Stripe on request. 50% at SOW signature, 50% at delivery. Monthly in advance for dedicated engineers.
Start with a health check.
One tenant, read-only access, ten business days, $2,500. You get a report you can hand to your client and a 30-day plan you can execute with or without us.
Engagement: day 0, access; days 1 to 8, review in your tenant; day 9, report; day 10, walkthrough; then the next 30 days, plan executed by your team or by us.
https://gardiensecurity.com/