Skip to content
ISO 27001, SOC 2, the DPDP Act and manual VAPT.
Part of Managed Services7 services in this practice area

Eyes on Your Estate, Always

SOC as a Service

Attacks do not keep office hours, so neither do we. Our analysts watch your environment around the clock, catch threats early and act fast, without you having to build and staff your own security operations centre.

See the engagement path, 6 phasesSee the full Managed Services service index

Overview

SOC as a service gives you a full security operations centre without the cost of building one. We collect logs from across your estate, tune detections to your environment and monitor them every hour of every day. When something looks wrong, our analysts investigate, confirm whether it is real and respond. You get faster detection, calm and capable response, and monthly reporting that shows exactly what we caught and stopped.

Methodology

How the Engagement Runs

Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.

The Engagement, End to End

6 Phases, 6 Named Handovers

Flow

Flow chart of the SOC as a Service engagement, 6 phases in order, each one selectable. Phase 1, Onboarding and Log Sources. We connect your endpoints, servers, cloud and network to our monitoring platform, and agree what good and bad look like for your business. Activities: Connect log sources and validate parsing for each one; Baseline normal activity across users, servers and cloud; Agree severity levels and escalation contacts; Set log retention to match your compliance obligations. Hands over Onboarding Runbook and Log Source Inventory. Phase 2, Detection Tuning. We tune detection rules to your environment so real threats stand out and noise is filtered away. Fewer false alarms means faster response to the alerts that matter. Activities: Tune detections against MITRE ATT&CK coverage; Suppress known-good behaviour that generates repeat noise; Write custom rules for your business-specific applications; Validate each rule with simulated attack activity. Hands over Tuned Detection Ruleset. Phase 3, 24/7 Monitoring and Triage. Our analysts watch alerts around the clock. Each one is triaged, confirmed or dismissed, and escalated to you only when it needs your attention. Activities: Triage every alert against the agreed severity matrix; Enrich alerts with threat intelligence and asset context; Escalate confirmed threats to your named contacts; Track time to detect and time to respond for each case. Hands over Triage Log with Response Times. Phase 4, Threat Hunting. We proactively hunt for attackers who slip past automated detection, using threat intelligence and behavioural analysis to find what alerts miss. Activities: Form hunt hypotheses from current threat intelligence; Search historical telemetry for matching behaviour; Investigate anomalies in authentication and outbound traffic; Convert successful hunts into permanent detections. Hands over Threat Hunt Findings. Phase 5, Incident Response. When we confirm an incident, we contain it, guide your team through the response and help you recover, following an agreed IR playbook. Activities: Isolate affected hosts and revoke compromised credentials; Run the agreed IR playbook with your technical team; Preserve evidence for later forensic review; Guide recovery and confirm the attacker is out. Hands over Incident Report with Root Cause. Phase 6, Monthly Reporting. You get a clear monthly report covering what we saw, what we stopped, how fast we acted and where you can reduce risk further. Activities: Summarise alert volume, confirmed incidents and outcomes; Report detection and response times against agreed targets; Show ATT&CK coverage gained and gaps remaining; Recommend the next changes to reduce risk. Hands over Monthly SOC Report. Each phase begins from the artefact the phase before it produced.

Phase 01 Onboarding and Log Sources

We connect your endpoints, servers, cloud and network to our monitoring platform, and agree what good and bad look like for your business.

What Happens In This Phase

  • Connect log sources and validate parsing for each one
  • Baseline normal activity across users, servers and cloud
  • Agree severity levels and escalation contacts
  • Set log retention to match your compliance obligations

The Handover

Onboarding Runbook and Log Source Inventory

The next phase starts from this.

Read the handover cards on their own and you have the paper trail. Select a phase to see what happens inside it.
  1. 01

    Onboarding and Log Sources

    We connect your endpoints, servers, cloud and network to our monitoring platform, and agree what good and bad look like for your business.

    OutputOnboarding Runbook and Log Source Inventory

    Activities

    • Connect log sources and validate parsing for each one
    • Baseline normal activity across users, servers and cloud
    • Agree severity levels and escalation contacts
    • Set log retention to match your compliance obligations
  2. 02

    Detection Tuning

    We tune detection rules to your environment so real threats stand out and noise is filtered away. Fewer false alarms means faster response to the alerts that matter.

    OutputTuned Detection Ruleset

    Activities

    • Tune detections against MITRE ATT&CK coverage
    • Suppress known-good behaviour that generates repeat noise
    • Write custom rules for your business-specific applications
    • Validate each rule with simulated attack activity
  3. 03

    24/7 Monitoring and Triage

    Our analysts watch alerts around the clock. Each one is triaged, confirmed or dismissed, and escalated to you only when it needs your attention.

    OutputTriage Log with Response Times

    Activities

    • Triage every alert against the agreed severity matrix
    • Enrich alerts with threat intelligence and asset context
    • Escalate confirmed threats to your named contacts
    • Track time to detect and time to respond for each case
  4. 04

    Threat Hunting

    We proactively hunt for attackers who slip past automated detection, using threat intelligence and behavioural analysis to find what alerts miss.

    OutputThreat Hunt Findings

    Activities

    • Form hunt hypotheses from current threat intelligence
    • Search historical telemetry for matching behaviour
    • Investigate anomalies in authentication and outbound traffic
    • Convert successful hunts into permanent detections
  5. 05

    Incident Response

    When we confirm an incident, we contain it, guide your team through the response and help you recover, following an agreed IR playbook.

    OutputIncident Report with Root Cause

    Activities

    • Isolate affected hosts and revoke compromised credentials
    • Run the agreed IR playbook with your technical team
    • Preserve evidence for later forensic review
    • Guide recovery and confirm the attacker is out
  6. 06

    Monthly Reporting

    You get a clear monthly report covering what we saw, what we stopped, how fast we acted and where you can reduce risk further.

    OutputMonthly SOC Report

    Activities

    • Summarise alert volume, confirmed incidents and outcomes
    • Report detection and response times against agreed targets
    • Show ATT&CK coverage gained and gaps remaining
    • Recommend the next changes to reduce risk

Specification

What We Run, and What We Measure You Against

The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.

Scope

What Is Examined, and What it Is Measured Against

Map

Map of the SOC as a Service scope, running left to right in three stages. Stage one, what we run, 8 tools and techniques: Splunk, Elastic / ELK, Wazuh, Microsoft Sentinel, TheHive, MISP, Suricata, Velociraptor. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 5 published standards: NIST SP 800-61, MITRE ATT&CK, SANS incident handling, ISO 27035, MITRE D3FEND.

What We Run

8 tools

  • Splunk
  • Elastic / ELK
  • Wazuh
  • Microsoft Sentinel
  • TheHive
  • MISP
  • Suricata
  • Velociraptor

Converges On

One Set of Proven Findings

Every issue is reproduced by hand before it is written down, and it is written down once.

Measured Against

5 standards

  • NIST SP 800-61
  • MITRE ATT&CK
  • SANSIncident handling
  • ISO 27035
  • D3FENDMITRE
One pass of testing and analysis, one set of findings, then that single set is graded against every standard on the right. You are not paying for the same work once per framework.

Deliverables

What You Receive

  • 24/7 monitoring with agreed response times
  • Tuned detection ruleset for your environment
  • Incident reports for every confirmed event
  • Monthly security operations report
  • Quarterly review with recommendations

Scope This Engagement

Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

How quickly will you respond to a threat?

We agree response targets with you up front, based on severity. Critical events get immediate attention, and every confirmed incident comes with a clear next step, not just an alert.

Do we need to replace our existing tools?

No. We work with the tools you already have where we can, and only recommend additions when there is a real gap in visibility.

Who handles incident response when something is confirmed?

Our analysts lead the technical response and guide your team through containment and recovery, following a playbook we agree with you before go-live.

Keep Moving Through Managed Services

Service 2 of 7 in this practice area