Services · Core module
Detection & Response
Covers logging, detection rules, alert triage, EDR, threat hunting, incident response, and post-incident reviews.
- Replaces
- Detection Engineer
- Where it sits
- Included in Complete
Scope
What we own.
Every line is work an engineer carries, reports on monthly, and hands over documented if the retainer ends.
- Log pipeline design — what to collect, where, retention
- SIEM deployment and tuning, or management of an existing one
- Detection rule development and false-positive tuning
- Alert triage and investigation (business hours)
- EDR / XDR deployment, policy and response actions
- Threat hunting on a defined cadence
- Incident response playbooks and runbooks
- Incident response execution and coordination
- Post-incident review and corrective actions
Boundaries
What this does not cover.
Stated up front so the scope in your proposal matches what actually gets done.
- Triage and investigation run during business hours with a defined escalation path.
- DevOps & Cloud sets up cloud-native logging. This module builds detections on it and triages what fires. See DevOps & Cloud.
Related
The rest of the retainer.
Modules combine. Most engagements run three or four together.
Talk through Detection & Response.
Bring the systems, the role this has to cover, and the deadline. We come back inside 48 hours with a written scope.
