Detection Engineering Pack
Ten detections built for your client's actual threats, not copied from a blog.
- Duration
- 2 to 3 weeks
- Price
- $4,000
- Access
- Named accounts only, issued by you, MFA on, least privilege, revoked at the end.
How it works
- We agree on the threat scenarios with you.
- We write the detections in KQL (Sentinel) or CQL and custom IOAs (Falcon).
- We test each one with attack simulation in the tenant.
- We document the logic, expected false positives and recommended response.
- We hand over with a tuning note.
- Duration
- 2 to 3 weeks.
- Price
- $4,000.