Detection Engineering Pack

Ten detections built for your client's actual threats, not copied from a blog.

Duration
2 to 3 weeks
Price
$4,000
Access
Named accounts only, issued by you, MFA on, least privilege, revoked at the end.

How it works

  1. We agree on the threat scenarios with you.
  2. We write the detections in KQL (Sentinel) or CQL and custom IOAs (Falcon).
  3. We test each one with attack simulation in the tenant.
  4. We document the logic, expected false positives and recommended response.
  5. We hand over with a tuning note.
Duration
2 to 3 weeks.
Price
$4,000.
Book a 20-minute call